James Burnett

prepare for the reckoning so you don't have to wait for the rescue.

Radioddity GM-30 Pro Data Leak UPDATE: Vulnerability in the Companion App

Welcome back, everybody! In this post, I’m giving you an update on the Radioddity app data security issue I originally uncovered in a previous video. If you haven’t seen that video yet, here’s the quick recap: the companion app that pairs with the Radioddity GM-30 Pro (and likely other radios, including some other brands) was sending personal information across the internet completely unencrypted — meaning anyone with the right know-how could intercept it. This included usernames, passwords, GPS coordinates, and even private details like names and email addresses of other app users, thanks to a built-in social media-style feature. On top of that, this data was clearly being routed to servers based in China. If you want the full technical breakdown of how I discovered this, check out the link to my original video.

Now, I’m happy to say I have some positive news to share. Radioddity actually reached out to me quickly, and I want to walk you through their response, what they’re fixing, and why — even with this fix — you should still think carefully about your privacy when it comes to apps like this.

Watch this video on YouTube

Radioddity’s Response

I’ll admit, my initial message to Radioddity wasn’t exactly friendly — when personal data and privacy are on the line, I think a little bit of pressure is warranted. But credit where credit is due: they responded within about 24 hours, acknowledged the issue, and committed to fixing it. Here’s an excerpt from their reply, from Alexander Lee, Brand Manager at Radioddity:

“Hi James, thank you for your email video. I’m Alexander Lee, brand manager at Radioddity. It’s a pleasure to connect with you. We appreciate you bringing concerns about the GM30 Pro app’s data transmission and permissions to our attention. We promptly followed up with the app’s development partner and have urged them to implement the following enhancements…”

What Radioddity Is Fixing

Here’s a breakdown of the specific changes Radioddity says they’re implementing to address the vulnerability:

  • No more plain-text data: The app will no longer transmit user passwords, GPS coordinates, or personal data in unencrypted plain text.
  • AES-256 encryption: They’re adding AES-256 encryption to account information. For those unfamiliar, AES-256 (Advanced Encryption Standard, 256-bit) is an industry-standard encryption method used by governments and security professionals worldwide to protect sensitive data — it’s currently considered extremely secure.
  • Minimal data collection: Only the minimum necessary encrypted information will be sent back to their servers for user accounts, rather than everything they were previously grabbing.
  • Regulatory compliance consideration: They stated they’ll be paying closer attention to security implementation and regulatory compliance moving forward.
  • Enforcing HTTPS: This is probably the biggest and most important fix. Previously, the app was using Port 80, which is the old, unencrypted way of transmitting data over the internet. They’re switching to HTTPS, which uses Port 443 and encrypts data in transit, making it far harder for anyone to intercept.
  • No registration required: Users will no longer be required to create an account just to configure their radio. This alone removes a big chunk of the personal data collection that was happening.
  • Optional GPS permissions: Users will be able to decline GPS access, meaning your location data won’t automatically be grabbed and sent through the app.

As for timing, Radioddity indicated that once these security enhancements are approved internally, they plan to roll out a patch within 1 to 4 business days.

My Take on the Fix

I have to give Radioddity credit here. They responded quickly, admitted there was a real problem, and outlined concrete steps to fix it. That’s more than a lot of companies do when confronted with a security issue like this.

That said, I still have some reservations — and this isn’t just about Radioddity. This applies to any brand: Baofeng, Radioddity, BTECH, Midland, you name it. In my opinion, an app used purely to configure a device over Bluetooth should have zero need to connect to the internet or any external servers at all. There’s simply no technical reason a configuration app needs to phone home to a server just to let you program a radio.

The reality is, we live in a data-driven economy where personal information has become a valuable commodity. Collecting and monetizing user data is often baked into the business model of many apps, even ones as seemingly simple as a radio programming tool. So even with this fix in place, it’s worth staying cautious about any app — regardless of brand — that requires an internet connection for what should be a purely local, offline function.

Why I’ve Been Focusing More on Personal Privacy

This whole situation is part of why I’ve been putting more effort into locking down my own digital privacy lately. As a quick example, I want to give a shoutout to the Unplugged team and their Unplugged Phone (available at unplugged.com). To be clear, I have no affiliate relationship with them — I’m not selling anything here, just sharing what’s worked for me.

This device lets you hard-block things like your microphone and GPS location at the hardware level, and it includes built-in firewalls designed to block trackers embedded in apps. In fact, having these protections active is part of what allowed me to catch some of the tracking behavior happening within the Radioddity app in the first place.

Beyond the technical privacy features, I appreciate that the Unplugged team seems genuinely committed to privacy and freedom as core values. They’ve even built in a feature that lets you wipe your phone using a special code if you’re ever subjected to an unlawful search and seizure — a real concern given ongoing issues with improper searches of personal devices.

Final Thoughts

Overall, kudos to Radioddity for taking this seriously and moving to fix the vulnerability. It’s a good example of a company doing the right thing after being called out. That said, I’m still not thrilled that any data needs to be transmitted externally just to open or use the app in the first place. We’ll take the win where we can get it, and I appreciate their transparency in addressing the issue.

Thanks for reading, everybody — I’ll see you in the next one.