• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to secondary sidebar
  • Skip to footer
  • DroneRacingLife
  • DroneFlyers
  • Newsletter
DroneLife

DRONELIFE

Stay up to date on all the latest Drone News

  • News
  • Products
  • Industries
    • Agriculture
    • Construction
    • Delivery
    • Dual Use
    • Inspection
    • Public Safety
    • Surveying
  • Enthusiasts
  • Regulations
  • Business
  • Video
  • Podcasts

DJI Responds to Bug Bounty Issues, SSL & AWS Leaks and ICE Memo

November 24, 2017 by Malek Murison 4 Comments

DJI has just released an extensive statement regarding the recent raft of cybersecurity stories enveloping the popular drone manufacturer.

You can read more about the Bug Bounty program here.

Here it is…

DJI us army cyber vulnerabilities

Statement About DJI’s Cyber Security and Privacy Practices

Recent news and blog coverage of DJI has raised a number of key questions about DJI’s practices regarding cybersecurity and privacy. We recognize that there are several reasonable concerns brought up about DJI’s record in this space, so we’d like to set the record straight on the current state of DJI’s security efforts.

1. SSL Certificate

In early September, DJI was notified that its SSL Certificate for the DJI website had been compromised. Immediately upon receiving this report, DJI revoked this certificate and replaced it with a new certificate.

Based on its investigation, DJI has no reason to believe that customer data has been compromised as a result. As a part of responsible disclosure to our customers, we have been working with an independent cyber forensics company to confirm our findings. We will continue monitoring the activities related to the expired SSL certificate and alert relevant customers if there is any evidence that their data integrity might have been impacted.

2. AWS Server Data

DJI received a report from an independent security researcher that an AWS server repository was accessible by unauthorized parties. We took this issue very seriously, and fixed it within a day of receiving the report.

After doing an internal audit, we identified the DJI developers responsible for this error, and took immediate disciplinary actions against them. We terminated their employment because we considered their behavior inexcusable and not in line with company policy. We also reduced the number of people who had authorization to change the public and private settings of our servers to prevent this situation from happening in the future. In addition, DJI further enhanced security measures and employee training to prevent similar incidents from occurring again.

Similar to the SSL Certificate issue we have engaged a third party cyber forensics firm to investigate this incident. Based on our analysis so far, only one party was able to download data from the server, including personal information of our developers. The investigation is ongoing, and we will notify customers if evidence suggests that the data has been misused.

3. Bug Bounty Program

DJI created the DJI Security Response Center (DSRC) to provide a channel for independent researchers to report issues that may impact the security of DJI’s products as a part of our focus on addressing data integrity.

Since announcing the DJI Bug Bounty program in August 2017, DJI has rewarded almost a dozen security researchers who have discovered potential vulnerabilities and received payment for their contributions after they complied with the program’s terms.

Claims that we have threatened one of the participants in the program, or required that he remain silent about his discovery, are false. The record of email exchanges and communication with the person in question shows that DJI continued negotiating the terms of the bounty in good faith with the participant until he chose to walk away from the program. While the participant did receive an unsigned draft letter via email expressing DJI’s concern about activities outside the program and potentially in violation of applicable laws, he did not complain to DJI when he received it, and continued negotiating terms of his bounty for two subsequent weeks.

The last version of the terms DJI sent to this person provided for a limited, 90 day confidentiality period in which DJI could address the security vulnerability and provide any required legal notices, after which point he would be free to disclose to the public the facts about his discovery.  This person agreed in principle to this provision, as well as the other main provisions of the last draft sent to him.  While DJI waited two weeks for this person’s final comments and proposed revisions to this latest version of the terms, the person unilaterally decided to terminate negotiations.  Subsequently, he posted the draft letter, the redacted developer information, confidential communications with DJI employees, and published an incomplete and misleading narrative of his negotiation process with DJI.

With the DSRC program, we showed that we have no intention to downplay concerns about data protection. The experience with the one person is an outlier and not representative of a program which has already paid almost a dozen researchers who have worked with us in good faith and who have adhered to the terms of the program.  DJI remains committed to the DSRC program and continues to work together with researchers to help improve the security of our products.

4. ICE Memo

We are aware of a bulletin about DJI issued in August by an agent in the Los Angeles office of U.S. Immigration and Customs Enforcement (ICE).  The bulletin is based on clearly false and misleading claims from an unidentified source.

Several of the key claims made by this unnamed source show a fundamental lack of understanding of DJI, its technology and the drone market. 
Some of the claims made are easily refuted with a few minutes of research. Had this research been done, the unnamed informant would know that:

  • Neither DJI drones nor the GO App perform facial recognition when the system is off.  In fact, even when powered on, no DJI product has the ability to “recognize” a face as a particular person for identification purposes.  Advanced new products have “Active Track” algorithms that can track the movement of the shape of a face or the shape of a person to facilitate control of the drone or movement of the camera (when the product is powered on, and Active Track mode is engaged by the user). 
  • DJI’s pricing strategy has not caused Parrot or Yuneec to stop production. While many companies in our industry have reduced staff, there are still several companies producing new models of drones every year.
  • DJI does not sell products at a loss or cheaper in the United States than in China. Pricing information has been and remains publicly available on DJI’s website. For example, through November, the Spark was $499 in the US and RMB 3,299 ($500) in China.

Based on these easily disproved claims, the statement makes several other false or misleading claims about our technology, how we manage data and our relationship with the Chinese government.

DJI does strive to comply with local laws and regulations in each country where its drones operate and to facilitate compliance by our customers. To the extent that there are location-specific rules and policies within China, we ensure that our systems comply with these rules, including the need to register or include no-fly zones on board. In compliance with the Chinese regulation, DJI utilizes the user’s IP address, GPS location, and MCC ID to determine if a drone is being operated in China. If so, DJI provides the customer with the features necessary to comply with Chinese regulations and policies. Otherwise, DJI provides no information about or data collected by the drone to the Chinese government.

Malek Murison
Malek Murison

Malek Murison is a freelance writer and editor with a passion for tech trends and innovation. He handles product reviews, major releases and keeps an eye on the enthusiast market for DroneLife.
Email Malek
Twitter:@malekmurison

Subscribe to DroneLife here.

Filed Under: Business and Finance, Drone News Feeds, Enthusiasts, Featured, Legal, News Tagged With: AWS, Cuber security, DJI, Leak, SSL

Reader Interactions

Trackbacks

  1. DJI Responds to Bug Bounty Issues, SSL & AWS Leaks and ICE Memo - Drone Flights R Us says:
    November 25, 2017 at 5:06 am

    […] Source link […]

    Reply
  2. DJI Responds to Bug Bounty Issues, SSL & AWS Leaks and ICE Memo - Drone Services Company | Aerial Photo and Video | Miami Florida says:
    November 24, 2017 at 6:42 pm

    […] post DJI Responds to Bug Bounty Issues, SSL & AWS Leaks and ICE Memo appeared first on […]

    Reply
  3. DJI Responds to Bug Bounty Issues, SSL & AWS Leaks and ICE Memo | Drone Magazine says:
    November 24, 2017 at 2:05 pm

    […] Source […]

    Reply
  4. DJI Responds to Bug Bounty Issues, SSL & AWS Leaks and ICE Memo – Dronegram says:
    November 24, 2017 at 1:00 pm

    […] post DJI Responds to Bug Bounty Issues, SSL & AWS Leaks and ICE Memo appeared first on […]

    Reply

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

LATEST

AirData Launches 3D Flight Player for Advanced Drone Flight Review

New tool converts flight logs into interactive 3D visualizations for training and analysis AirData has introduced a new tool designed…

Continue Reading AirData Launches 3D Flight Player for Advanced Drone Flight Review

Lucid Bots Raises $20M to Scale Autonomous Exterior Cleaning Drone Platform

Funding supports expansion of robotics, AI, and subscription-based service model for cleaning operators Lucid Bots has raised $20 million in…

Continue Reading Lucid Bots Raises $20M to Scale Autonomous Exterior Cleaning Drone Platform

Drones Transform Warehouse Operations at Southern Glazer’s

Corvus Robotics rollout supports supply chain transformation and improved warehouse performance Southern Glazer’s Wine & Spirits has expanded its use…

Continue Reading Drones Transform Warehouse Operations at Southern Glazer’s

Flying Lion Launches DroneBooth for Rapid Drone Dock Deployment

Portable system enables 24×7 operations without fixed power or internet infrastructure Flying Lion, Inc. has announced the release of DroneBooth™,…

Continue Reading Flying Lion Launches DroneBooth for Rapid Drone Dock Deployment

BRINC Launch Signals Next Phase of U.S. Public Safety Drone Industry

New Guardian platform and Seattle factory highlight scaling pressure, public safety adoption, and policy shifts shaping the U.S. drone market.…

Continue Reading BRINC Launch Signals Next Phase of U.S. Public Safety Drone Industry

Red Force as a Service Brings Realistic Counter-UAS Testing to Pendleton

Pendleton UAS Range (PUR) and Gambit have partnered to deliver Red Force as a Service for counter-UAS testing, validation, and…

Continue Reading Red Force as a Service Brings Realistic Counter-UAS Testing to Pendleton

Unifly Expands European Drone Consulting with New Acquisition

Unifly acquires EuroUSC-Benelux to expand drone regulatory and compliance consulting across Belgium, the Netherlands, Luxembourg, and France. Unifly, a global…

Continue Reading Unifly Expands European Drone Consulting with New Acquisition

Photojournalist Challenges FAA Temporary Flight Restriction as First Amendment Violation

By Dronelife Features Editor Jim Magill A drone pilot has sued the FAA, claiming that an FAA temporary flight restriction…

Continue Reading Photojournalist Challenges FAA Temporary Flight Restriction as First Amendment Violation

Terra Drone Announces Entry into Defense Market with Planned U.S. Subsidiary

Company outlines strategy to expand unmanned systems across global defense markets Tokyo-based Terra Drone Corporation has announced a full-scale entry…

Continue Reading Terra Drone Announces Entry into Defense Market with Planned U.S. Subsidiary

China Leads Global Surge in Counter-Drone Patents as Security Concerns Grow

New data highlights rising investment in jamming, laser, and microwave systems as governments and industry seek scalable drone defense solutions…

Continue Reading China Leads Global Surge in Counter-Drone Patents as Security Concerns Grow

Secondary Sidebar

Footer

SPONSORED

Inspired Flight Gremsy IF800 VIO F1 drones geo week

What Will It Take to Strengthen U.S. Drone Manufacturing? A Conversation with Inspired Flight’s CEO

Global Mapper Mobile data collection

Collection Ground Control Points with Global Mapper Mobile

Military Drone Mapping Solutions

How SimActive’s Correlator3D™ is Revolutionizing Military Mapping: An Exclusive Interview with CEO Philippe Simard

Photogrammetry Accuracy Standards

SimActive Photogrammetry Software: Enabling Users to Meet Accuracy Standards for Over 20 Years

NACT Engineering Parrot ANAFI tether indoor shot

Smart Tether for Parrot ANAFI USA from NACT Engineering

Blue Marble, features global mapper, features Blue Marble

Check Out These New Features in Global Mapper v25 from Blue Marble

About Us | Contact Us | Advertise With Us | Write for Us | Privacy Policy | Terms of Service

The Trusted Source for the Business of Drones.

This website uses cookies and third party services. By clicking OK, you are agreeing to our privacy policy. ACCEPT

Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT