← Security Cameras
D

BlackVue DR900X-2CH

Serious concerns
Pittasoft Co., · 🇰🇷 South Korea · WiFi + Bluetooth
PolicyApp PermissionsNetwork TrafficFirmwareRegulatory
Technical details
FCC ID: YCK-DR900X-2CH
Chipset: HiSilicon Hi3559
App: comb.blackvuec
Manufacturer: Pittasoft Co., Ltd.

⚠️ The bottom line

BlackVue sells dash cams to employers who can watch live video from any work vehicle, track where every driver goes, and monitor how they drive. The privacy policy is written for consumers who choose to buy the camera. When your employer installs one in your work vehicle, you have no real choice about being surveilled throughout your entire working day. Your BlackVue keeps recording and uploading to Korean cloud servers even when your car is parked. People walking past your parked car have no idea they are being filmed and that their images are being sent to servers in South Korea. Bystanders never consented to being part of your dash cam's continuous surveillance operation.

Legal jurisdiction
🇰🇷 South Korea (headquarters)
PIPA read more →
Strict data protection — fined Google, Meta. But National Intelligence Service has broad surveillance powers
B
Parent company: Pittasoft (BlackVue)
Public-by-default GPS exposure across all products
1 structural risks · 1 products →
Spying
4/4 EXTREME
Is someone spying on me?
Data Sharing
4/4 EXTREME
Who gets my data?
Security
3/4 HIGH
Is it actually secure?
Honesty
4/4 EXTREME
Can I trust what they say?
REPLACE Extreme risk. Look for alternatives or lock down hard.
14Contradictions
4Critical
8High
2Medium
19Sources
Findings by concern
Spying 4/4 EXTREME 5 findings
⚠️ criticalregulatory findings vs policy claims
BlackVue sells dash cams to employers who can watch live video from any work vehicle, track where every driver goes, and monitor how they drive. The privacy policy is written for consumers who choose to buy the camera. When your employer installs one in your work vehicle, you have no real choice about being surveilled throughout your entire working day.

What they claim: BlackVue actively markets dash cams for fleet management with real-time GPS tracking, speed monitoring, driving behaviour analysis, and remote live view

What we found: Fleet management features create a workplace surveillance infrastructure: employers can watch live video from any vehicle, track driver locations in real time, monitor driving speed and behaviour, and access all recorded footage. Pittasoft's privacy policy focuses on individual consumer consent but does not address the power asymmetry in employer-deployed systems. Employees in fleet vehicles may have no meaningful ability to consent to continuous video and GPS surveillance as a condition of employment.

⚠️ criticalfirmware analysis vs regulatory findings
Your BlackVue keeps recording and uploading to Korean cloud servers even when your car is parked. People walking past your parked car have no idea they are being filmed and that their images are being sent to servers in South Korea. Bystanders never consented to being part of your dash cam's continuous surveillance operation.

What they claim: DR900X parking mode operates as a 24/7 surveillance camera covering public spaces around parked vehicles

What we found: The DR900X's parking mode with motion/impact detection continuously records video and GPS location when the vehicle is parked. With cloud connectivity, this footage is uploaded to blackvuecloud.com servers in South Korea. Under Australian law, recording in public spaces is generally permitted, but continuous cloud upload of surveillance footage of public spaces — capturing pedestrians, license plates, and activity around the vehicle — raises privacy concerns for bystanders who have no knowledge they are being recorded and whose images are being transferred overseas.

⚡ highapp permissions vs policy claims
The BlackVue app includes Google's advertising system and Facebook's login and sharing features. This means your dash cam app — which knows everywhere you drive and when — sends data to Google's ad network and can link your driving patterns to your Facebook profile. A surveillance camera app is wired into advertising and social media tracking.

What they claim: BlackVue app (v3.37) embeds 6 trackers: Google Firebase Analytics, Google CrashLytics, Google Tag Manager, Google AdMob, Facebook Login, Facebook Share

What we found: Pittasoft's privacy policy discloses collection of "personal data, usage data, and cookies." The app embeds Google AdMob (advertising SDK that serves ads and shares user data with Google's ad network), Facebook Login (links BlackVue account to Facebook identity), and Facebook Share (enables sharing dash cam footage to Facebook, creating a bridge between driving data and social media profiles). A dash cam surveillance app sends data to advertising and social media networks.

⚡ highapp permissions vs firmware analysis
Your BlackVue dash cam has its own GPS, camera, and microphone built in. Yet the app separately asks to track your phone's location in the background, use your phone camera, and record audio through your phone. The app is building a second surveillance profile of you through your phone, independent of what the camera itself records.

What they claim: BlackVue app requests ACCESS_BACKGROUND_LOCATION, RECORD_AUDIO, CAMERA, READ_PHONE_STATE, and AD_ID — 36 permissions total

What we found: The DR900X has its own GPS receiver, 4K camera (Sony STARVIS IMX307), and built-in microphone. FCC ID YCK-DR900X-2CH confirms the camera has all these sensors onboard. The app's ACCESS_BACKGROUND_LOCATION duplicates the camera's GPS, tracking the phone's location even when the app is closed. RECORD_AUDIO and CAMERA duplicate the dash cam's own sensors. AD_ID provides an advertising identifier for a device whose sole purpose is security recording. The app tracks the user separately from the camera.

⚡ highregulatory findings vs policy claims
Every recording from your BlackVue dash cam — where you drove, how fast you went, any impacts detected — gets uploaded to cloud servers in South Korea. Australian privacy law has limited reach once your driving surveillance data leaves the country. Your complete driving history is stored in a foreign jurisdiction where Australian regulators cannot easily enforce your privacy rights.

What they claim: Pittasoft (BlackVue) is headquartered in Seoul, South Korea. Personal data from users worldwide is processed and stored in South Korea and the United States

What we found: Pittasoft's privacy policy states data may be "transferred to the Republic of Korea for processing." Cloud storage at blackvuecloud.com, api.blackvuecloud.com, and fota.blackvuecloud.com holds video recordings, GPS location data, speed data, G-sensor impact data, and timestamps from every connected camera. For Australian customers, continuous driving surveillance data (where you drive, how fast, impact events) is transferred to South Korea with no Australian data sovereignty protections.

Data Sharing 4/4 EXTREME 2 findings
⚠️ criticalmarketing vs third party research
BlackVue's default settings were so bad that police cars and ambulances running their dashcams were broadcasting live video and GPS to anyone who downloaded a free app. Security researcher Andy Gill could see registration plates in the feeds. He called it an easy shopping list of cars to steal. Emergency vehicle locations were exposed in real time to anyone on the internet.

What they claim: BlackVue markets its dashcams as secure private recording devices for personal vehicles.

What we found: Andy Gill discovered that the public-by-default exposure extended to emergency services vehicles. Ambulances and police cars running BlackVue dashcams were broadcasting their live video feeds and GPS locations to anyone with the free app. Registration plates were visible in camera feeds, creating what Gill called an easy shopping list of cars to steal.

⚡ highpolicy claims vs app permissions
BlackVue says it collects your data for internal analysis and improving services. The app contains Google's advertising system, which exists to show you ads and share your data with advertisers. It also plugs into Facebook. "Improving services" apparently includes generating advertising revenue from your dash cam usage data.

What they claim: Pittasoft's privacy policy states "usage data is retained for internal analysis purposes" and data collection is for "improving services"

What we found: The app embeds Google AdMob — an advertising SDK that serves ads and shares data with Google's advertising ecosystem. AdMob is not an internal analysis tool; it is a third-party advertising platform. Combined with AD_ID (persistent Google advertising identifier) and Facebook Login/Share integrations, the data pipeline extends far beyond internal analysis to Google's ad network and Meta's social graph. "Improving services" is doing heavy lifting to cover advertising revenue generation.

Security 3/4 HIGH 3 findings
⚡ highpolicy claims vs firmware analysis
BlackVue claims to comply with Australian cyber security standards. The dash cam accepts firmware from anyone on the network with zero verification — no password, no signature check. An attacker can upload modified software to your camera. On models with mobile data, this attack works from anywhere on the internet. This is the opposite of the security standard they claim to meet.

What they claim: BlackVue Australia publishes a Cyber Security Commitment page stating compliance with the Cyber Security Act 2024 and Security Standards for Smart Devices Rules 2025

What we found: CVE-2023-27748 (critical): FOTA service on port 9771/TCP accepts firmware uploads without authentication or signature verification. An attacker on the same network can upload malicious firmware by extracting official packages, modifying files, and recalculating checksums. On LTE-connected models, this service is accessible from the internet. A company claiming compliance with cyber security standards ships devices that accept unsigned firmware from anyone on the network.

⚡ highfirmware analysis vs policy claims
Anyone who connects to your BlackVue camera's Wi-Fi can watch your live video feed, download all your recordings, see everywhere you have driven, and change your settings — with no password required. The Wi-Fi password protecting this access is only 8 characters and can be cracked in about four days for around forty dollars.

What they claim: CVE-2023-27747: BlackVue webserver on port 80 exposes live video, vehicle telemetry, recording downloads, configuration uploads, and credential extraction without authentication

What we found: When connected to the camera's Wi-Fi AP, the webserver on port 80 requires no authentication for: live video feed access, vehicle GPS telemetry retrieval, recording downloads, configuration uploads, and credential extraction. The DR900X uses HiSilicon Hi3559 SoC with Sony STARVIS IMX307 sensor capturing 4K UHD video. CVE-2023-27746: Wi-Fi passphrase is only 8 lowercase alphanumeric characters, brute-forceable in ~4 days for ~0 using commercial GPU rental.

⚡ highpolicy claims vs firmware analysis
BlackVue claims to meet Australian cyber security standards. The camera runs on a chip made by a Huawei subsidiary — a company under international security restrictions. The camera also accepts firmware updates from anyone without checking if they are genuine. A cyber security commitment built on sanctioned hardware with unsigned firmware updates is not a credible commitment.

What they claim: BlackVue's Cyber Security Commitment page (updated February 2026) claims compliance with mandatory security standards for connected products

What we found: The DR900X uses HiSilicon Hi3559 SoC — a chip manufactured by Huawei's wholly-owned subsidiary. HiSilicon chips have been subject to US export controls and security scrutiny. The camera's firmware runs on this Chinese-manufactured chipset while Pittasoft's security commitment makes no mention of the supply chain dependency on Huawei hardware. The firmware accepts unsigned updates (CVE-2023-27748) running on a chip from a company under international sanctions.

Honesty 4/4 EXTREME 4 findings
⚠️ criticalprivacy policy vs third party research
BlackVue says sharing your location is opt-in. Three separate researchers over four years found the opposite. In 2018, a security researcher discovered every new BlackVue camera defaulted to broadcasting live video and GPS to anyone with the free app -- no email verification needed. Motherboard proved it by writing a script that tracked every BlackVue user across the eastern United States every two minutes for a week, collecting the exact driveways where people parked. BlackVue said they fixed it. In 2022, Andy Gill tested it again and found GPS was still on by default. BlackVue's response: it's a feature, not a bug.

What they claim: BlackVue states the sharing of GPS, video, or audio data on the public World Map is opt-in only.

What we found: In September 2018, security researcher Tim Woodruff discovered that public location and live video were enabled by default on new camera registrations. Anyone could download the free app (no email verification required) and tap into random dashcams, watching live feeds and tracking car speed and GPS location with enough resolution to identify driveways. In January 2020, Vice/Motherboard reverse-engineered the iOS app and wrote scripts that collected GPS coordinates of every BlackVue user with mapping enabled across the eastern US, polling every two minutes for a week. In January 2022, researcher Andy Gill found GPS access was STILL enabled by default, contradicting BlackVue's claim of having fixed it in October 2018. BlackVue's response: it's a feature, not a bug.

⚡ highfirmware analysis vs policy claims
BlackVue's cloud service terms are hidden behind a JavaScript app that will not load without running code first. You cannot read the privacy rules before signing up. Meanwhile, the LTE-equipped models connect to the cloud on their own without needing your phone, meaning the camera can upload your driving data 24/7 whether the app is open or not.

What they claim: BlackVue Cloud service requires internet connectivity (via phone hotspot, car-embedded connection, or LTE module) for remote features

What we found: The cloud service terms page failed to load content ("You need to enable JavaScript to run this app"). The privacy policy for the cloud service is embedded in a JavaScript application that cannot be read without executing code — making it inaccessible to users with accessibility needs, privacy-focused browsers, or anyone trying to review terms before creating an account. FCC ID YCK-DR900X-2CH confirms optional LTE connectivity means the camera can maintain cloud connection independent of the owner's phone.

⚫ mediumprivacy policy vs third party research
After the 2018 scandal, BlackVue said they fixed it by setting everyone's privacy to private. But CSO Online found a catch: if you ever re-registered your camera -- say, after a reset or switching cars -- you were silently opted back into public sharing. The fix was a one-time band-aid that did not survive normal product use.

What they claim: BlackVue announced in October 2018 that it set all users' camera location, name, video and audio sharing settings to private as a server-level change.

What we found: CSO Online reported that even if users opted out of public sharing, re-registering their camera (e.g. after a factory reset or switching vehicles) would opt them back in without their knowledge or consent. The fix was a one-time server-side change that did not persist through the normal product lifecycle.

⚫ mediummarketing vs third party research
You set up a BlackVue Cloud account to check on your parked car once. From that moment, your dashcam silently uploads 184MB of footage thumbnails every single day in the background. Data retention? Unlimited by default. Nobody told you. To stop it, you need to find three separate settings buried in the app and turn them all off.

What they claim: BlackVue Cloud is presented as a feature for remote live view and video backup that users actively choose to use.

What we found: Dashcam Insight's 2026 privacy test found that BlackVue with a cloud account transmitted 184MB of footage thumbnails in 24 hours without the user actively using cloud features. Cloud upload is default-on when a BlackVue Cloud account exists, and data retention is set to unlimited by default. Users must actively disable auto-upload, review retention policies, and opt out of traffic pattern data collection.

Sources