TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Walking away from $30,000 of DJI bounty money [pdf]

326 pointsby drumlover 7 years ago

20 comments

fencepostover 7 years ago
&quot;In the days following no less than 4 lawyers told me in various ways that the agreement was not only extremely risky, but was likely crafted in bad faith to silence anyone that signed it.&quot;<p>The whole article sounds like a mishmash of incompetence, being unprepared, and having a legal team not really interested in having a robust or even good bounty program. Basically a bounty program driven by Marketing and&#x2F;or Legal to be able to say &quot;we take bugs seriously&quot; rather than by Engineering with an interest in actually getting problems resolved.
评论 #15722052 未加载
ukuleleover 7 years ago
TL;DR: DJI rolled out a bug bounty program from $100-$30,000 but it was vague and poorly executed. Author found AWS keys and subsequent data, to which DJI responded with onerous legal terms and threats. After many weeks of back and forth, author walked away.
评论 #15722936 未加载
评论 #15722611 未加载
评论 #15722833 未加载
spydumover 7 years ago
Sounds like DJI kicked off a bounty program and didn&#x27;t have their ducks in a row on setting bounty scope, legal terms, or process. Researcher found PII leaks and keys to some pretty sensitive stuff, and DJI didn&#x27;t know how to respond.<p>After DJI dragging it out for weeks, giving overly broad terms, and sending a poorly crafted CFAA threat (which in charitably interpreted was just to ensure he deleted any sensitive material), researcher walked away after being frustrated by the time sink.
评论 #15723164 未加载
chakalakaspover 7 years ago
Being stingy with big bounty money seems so shortsighted - if you are going to have a B.B. program and encourage people to suss out exploits, why would you then want to piss those people off? It’s not like there isn’t a completely separate market out there for the same exploits run by people you’d collectively refer to as “the enemy”.
评论 #15721978 未加载
jstewartmobileover 7 years ago
Freelance pentesting in a nutshell:<p><pre><code> 1. Research and find vulnerabilities 2. Apply for bounty 3. Parry legal threats 4. Exit empty-handed</code></pre>
评论 #15723292 未加载
WhitneyLandover 7 years ago
tldr:<p>DJI started a bug bounty program, but mismanagement and dick moves ended up costing a guy a deserved 30k bounty.<p>longer tldr:<p>The problems found revealed they were in fact in desperate need of the help.<p>The program was managed poorly. DJI had a chance to correct the situation, but instead acted in bad faith to researchers who had went out of their way to help them, even threatening leagal action for no good reason.<p>The guy legit earned the 30k bounty, but effectively had no way to get the money due to legal threats and&#x2F;or requirements to sign draconian restrictive legal documents.<p>Important subject, interesting story, takes forever to get to the point. Reads like this was partially due to the guy having no sleep and being worn down after a long period of emotional exasperation.
评论 #15727055 未加载
GCU-Empiricistover 7 years ago
I remember reading recently that the U.S. military had to ground all DJI drones they had in inventory because of suspected hooks in the software and I was thinking it was just malicious backdoors, interesting to see there&#x27;s a bit more of Hanlon&#x27;s razor in there too.
评论 #15721861 未加载
alkriegerover 7 years ago
Fck, man. I was fired from DJI because of all that story. I was nowhere connected to things you found and privacy disclosure. I just had a small repository with and unreal engine plugin to use open source exif library inside our internal project.<p>But on the other hand, really thank you, working in DJI is not so good anyway.
评论 #15739490 未加载
ColanRover 7 years ago
Sounds like they got the report for free. Maybe the incompetence was just a way of getting out of paying the bounty.
评论 #15726181 未加载
matthewaveryusaover 7 years ago
From DJI&#x27;s perspective I think they don&#x27;t have experience with bug bounties so the legal team drafted something not expecting a fight, especially when they offered 30k. Seeing the back-and-forth on legal terms queued them that maybe the author did have malicious intent to harm the reputation of DJI (whether that&#x27;s a good argument or not is out of scope.) and because of that the legal team turtled. DJI wanted the author to sign the papers, take the money and shut up. The author wanted to sign the papers, take the money, and advertise the hack.
评论 #15724068 未加载
评论 #15726454 未加载
评论 #15727125 未加载
curiousgalover 7 years ago
Clauses that he considered limiting to his freedom of speech seemed quite reasonable to me but then I remembered he&#x27;s active in the drone jailbreaking scene so they do interfere with that.
评论 #15727135 未加载
brodockover 7 years ago
I think this is the value in using platforms like HackerOne vs trusting a random half-backed bug bounty program someone made as crisis management.
makmanalpover 7 years ago
Is there not an official standard &#x2F; &quot;best practices&quot; document for what each party should follow with bug reporting &#x2F; bounty procedures? Something that anyone in a company that&#x27;s starting a bug bounty program can point their legal department to, and say: &quot;here&#x27;s what amazon and google and X and Y and Z follow, so we should do the same&quot;? From the security researcher perspective, there&#x27;s the responsible disclosure stuff. But not much from the other side, AFAIK.
dreamcompilerover 7 years ago
Here&#x27;s another DJI story which demonstrates their incompetence. At EAA Oshkosh 2017 (the premier event of the year for private pilots and experimental aircraft fans of every stripe), DJI had set up a large tent to show off their newest drones. I walked in and asked to see a demo. Mind you, they had an outdoor flying area adjacent to the tent that was fully enclosed with netting. There was no way a drone could have escaped.<p>&quot;Can&#x27;t do a demo,&quot; the DJI rep said. &quot;We&#x27;re waiting on a firmware upgrade from China. None of the drones are working.&quot;<p>&quot;Um, why?&quot; I asked.<p>&quot;Because the firmware in the drones contains a database of all known aircraft control towers and every drone has GPS. When it sees the drone is within [a few] miles of a control tower, it shuts down the drone. And right now we&#x27;re only about 100 feet from a control tower.&quot;<p>&quot;But you&#x27;re inside a netted enclosure?&quot;<p>&quot;The firmware doesn&#x27;t know that. The new firmware we&#x27;re waiting on includes an exception for this location.&quot;<p>I don&#x27;t know if the upgrade ever arrived, but this episode taught me I don&#x27;t want a DJI product. DJI probably lost hundreds of thousands of dollars in sales because of that boneheaded move.
评论 #15732551 未加载
评论 #15732650 未加载
cyberferretover 7 years ago
Almost a case here for someone to start up a BBaaS (Bug Bounty as a Service)?<p>They could act as the &#x27;go between&#x27; for the SaaS or manufacturer, as well as protect the privacy (and possibly identity) of the bounty hunters. The BBaaS could have tried and tested boilerplate terms and conditions for both parties, as well as handle the reward payouts and filing&#x2F;validating of reports.
评论 #15726003 未加载
caio1982over 7 years ago
Is this 18-pages-long PDF worth reading at such small font size at all? Honest question.
评论 #15722140 未加载
评论 #15721863 未加载
评论 #15721955 未加载
评论 #15721852 未加载
评论 #15723105 未加载
评论 #15722848 未加载
评论 #15726824 未加载
pbhjpbhjover 7 years ago
Is the a place for a third-party bug reporting platform that can insulate security researchers from the companies seeking the disclosures?<p>EFF?
评论 #15722669 未加载
评论 #15726919 未加载
lathiatover 7 years ago
In many ways I believe this the value of HackerOne (they effectively administer bug bounties on behalf of other companies).<p>They understand what constitutes reasonable, necessary and&#x2F;or expected by both the security communities AND company&#x2F;legal and can work as a party to both sides with standard agreements, suggestions, etc.
goldfeldover 7 years ago
Because you don&#x27;t have financial security concerns?
评论 #15723609 未加载
gjem97over 7 years ago
It&#x27;s not clear to me that OP has consulted a lawyer about this. IANAL, but the question here is not whether the servers are&#x2F;were in-scope, but whether DJI agreed to pay him $30,000 and then later made it a condition that he sign a contract to get the payment. I hate to be that guy, but it seems like a letter from a lawyer threatening legal action may change this conversation completely.<p>Edit: Please take a look at my comment below before downvoting?
评论 #15722498 未加载
评论 #15722807 未加载