Slashdot Mirror


DJI Threatens Researcher Who Reported Exposed Cert Key, Credentials, and Customer Data (arstechnica.com)

An anonymous reader quotes Ars Technica: DJI, the Chinese company that manufactures the popular Phantom brand of consumer quadcopter drones, was informed in September that developers had left the private keys for both the "wildcard" certificate for all the company's Web domains and the keys to cloud storage accounts on Amazon Web Services exposed publicly in code posted to GitHub. Using the data, researcher Kevin Finisterre was able to access flight log data and images uploaded by DJI customers, including photos of government IDs, drivers licenses, and passports. Some of the data included flight logs from accounts associated with government and military domains.

Finisterre found the security error after beginning to probe DJI's systems under DJI's bug bounty program, which was announced in August. But as Finisterre worked to document the bug with the company, he got increasing pushback -- including a threat of charges under the Computer Fraud and Abuse Act. DJI refused to offer any protection against legal action in the company's "final offer" for the data. So Finisterre dropped out of the program and published his findings publicly yesterday, along with a narrative entitled, "Why I walked away from $30,000 of DJI bounty money."

The company says they're now investigating "unauthorized access of one of DJI's servers containing personal information," adding that "the hacker in question" refused to agree to their terms and shared "confidential communications with DJI employees."

3 of 81 comments (clear)

  1. Re:Why is DJI doing this? by stephanruby · · Score: 5, Insightful

    Why was DJI unwilling to offer the guy a deal that said "if you agree to destroy all our data (credentials, keys, customer data etc), not use it for any purpose and not talk publicly about it, we will agree not to take you to court over it".

    A better agreement would have been:

    "if you agree to destroy all our data (credentials, keys, customer data etc), not use it for any purpose and not talk publicly about it for a period of one year ending on Nov 1st, 2018, we will agree to credit you publicly and pay you the bounty."

    Threatening someone you already gave permission to, and someone who has been acting in good faith all this time, is really a bad idea. It turns what is supposed to be a collaborative relationship into a confrontational one.

    Furthermore, a bug bounty program can't expect to silence a white hacker from a foreign country forever. Hackers are very ego-driven. Also, they make money and recruit new clients from recounting their exploit stories to others.

  2. Re: Great drones, but invasive... by NicknameUnavailable · · Score: 5, Insightful

    I control my DJI drone with my burner phone, not my primary device. There is nothing on it for them to steal.

    Except anything said in conversation around the device, images it points at, photos your drone takes, GIS information based on the drone flying around mapping your neighborhood, etc. If WW3 rolls around you're basically painting your house for a potential invasion site, since they already have detailed maps of your area.

  3. Re:Why is DJI doing this? by Aighearach · · Score: 3, Insightful

    THat's what they tried to do! It is lame and slimy.

    If you have a bug bounty, people who are finding security bugs are security researchers, if they can't talk about it how do they build their career?!

    And when you give somebody permission to check your security for bugs, offering not to take them to court is actually a threat to take them to court, just phrased backwards, because you don't have any right to accuse them of crimes when you agreed for them to check your security.

    He left $30k on the table over those lame, slimy, offered terms. Bug bounty is bug bounty! If anything he should sue them for calling him a hacker and claiming he's some kind of black hat!

    The offer goes like this: Thanks for finding our bug, here is your money, thanks again, will you sign a document that says this is everything you found so far? There is no threats or demands. Nor is there even power to be making demands. Bug bounty is a service that helps the company!