• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to secondary sidebar
  • Skip to footer
  • DroneRacingLife
  • DroneFlyers
  • Newsletter
DroneLife

DRONELIFE

Stay up to date on all the latest Drone News

  • News
  • Products
  • Industries
    • Agriculture
    • Construction
    • Delivery
    • Dual Use
    • Inspection
    • Public Safety
    • Surveying
  • Enthusiasts
  • Regulations
  • Business
  • Video
  • Podcasts

DJI to Pay Out Thousands of Dollars After Successful Bug Bounty Reports

October 12, 2017 by Malek Murison 3 Comments

Dronelife understands that DJI has agreed to pay out a combined total in excess of $30,000 to multiple security researchers as part of its Bug Bounty program.

No money has yet been paid out, but several researchers have confirmed their bug reports have been successful and that they have handed over bank details to DJI for payment. That total includes at least one ‘top bounty’: $30,000 – the reward for a security flaw judged to be of the highest possible threat level.

The initiative was launched in August in response to security concerns that came to public attention over the summer, as hackers were able to override the manufacturer’s geofencing system and the US Army halted the use of DJI equipment due to ‘cyber vulnerabilities’.

dji bug bounty report message
A message from DJI to a security researcher. Although Dronelife has seen messages confirming successful applications, we won’t be publishing them here.

Bug bounty program still not up and running

The official reveal of the DJI bug bounty program stated the following:

The DJI Threat Identification Reward Program aims to gather insights from researchers and others who discover issues that may create threats to the integrity of our users’ private data, such as their personal information or details of the photos, videos and flight logs they create. The program is also seeking vulnerabilities that may reveal proprietary source codes and keys or backdoors created to bypass safety certifications.

Rewards for qualifying bugs will range from $100 to $30,000, depending on the potential impact of the threat. DJI is developing a website with full program terms and a standardized form for reporting potential threats related to DJI’s servers, apps or hardware. Starting today, bug reports can be sent to bugbounty@dji.com for review by technical experts.

However, no website has yet been launched detailing the full terms and conditions of the program, and no money has yet been transferred to successful bug finders. This slow progress suggests that the bounty program was hastily thrown together in response to an increasing number of negative stories about DJI’s data security.

We also understand that some of the researchers with successful claims have already submitted new reports detailing new bugs, despite no money exchanging hands for the original bounties. So it looks like an amicable relationship is developing between DJI and the same hackers the company was fighting against not so long ago. Successful bug finders have also been asked to refrain from discussing the details of their reports for the time being.

This news goes some way to confirming what we suspected already: that DJI’s software contains security vulnerabilities. But it’s promising that the company appears willing to act upon these issues. It will be interesting to see how the bug bounty program progresses and how DJI deals publicly with its results. At the moment, it looks like a collaborative move that could help foster a more positive relationship between the world’s most popular drone manufacturer and the security community. It should also (eventually) plug those holes in security and go some way to reassuring concerned commercial pilots.

Malek Murison
Malek Murison

Malek Murison is a freelance writer and editor with a passion for tech trends and innovation. He handles product reviews, major releases and keeps an eye on the enthusiast market for DroneLife.
Email Malek
Twitter:@malekmurison

Subscribe to DroneLife here.

Filed Under: Business and Finance, DL Exclusive, Drone News Feeds, Enthusiasts, Featured, Featured – Safety and Security, News Tagged With: bug bounty, DJI

Reader Interactions

Trackbacks

  1. Issue 17 Counter-UAS Newsletter – AISC | First in Drone Threats says:
    November 16, 2017 at 5:30 pm

    […] Drone Life: DJI to Pay Out Thousands of Dollars After Successful Bug Bounty Reports […]

    Reply
  2. DJI to Pay Out Thousands of Dollars After Successful Bug Bounty Reports - Drone Flights R Us says:
    October 15, 2017 at 6:18 am

    […] Source link […]

    Reply
  3. DJI to Pay Out Thousands of Dollars After Successful Bug Bounty Reports – Drone Magazine says:
    October 12, 2017 at 11:05 pm

    […] Source […]

    Reply

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

LATEST

Airspace Security at 2026 JUNO Awards

RF-Cyber counter-drone system enables non-disruptive protection for large public event D-Fend Solutions announced that its EnforceAir counter-drone system was deployed…

Continue Reading Airspace Security at 2026 JUNO Awards

Will States Be Ready with Counter Drone Tech for the FIFA World Cup?

Funding snafu, other issues delay counter-UAS ramp-up in Maryland, elsewhere By DRONELIFE Features Editor Jim Magill (Editor’s note: This is…

Continue Reading Will States Be Ready with Counter Drone Tech for the FIFA World Cup?

Strait of Hormuz Tensions Highlight a Growing Role for Small Drone Surveillance

Maritime risk, insurance pressure, and degraded navigation signals point to new use cases for commercial UAV systems Ongoing tension in…

Continue Reading Strait of Hormuz Tensions Highlight a Growing Role for Small Drone Surveillance

From Missions to Management: The Shift Defining Public Safety Drone Programs [DRONELIFE Exclusive Interview]

As public safety drone use scales, data, compliance, and coordination define success Public safety drone programs have reached an inflection…

Continue Reading From Missions to Management: The Shift Defining Public Safety Drone Programs [DRONELIFE Exclusive Interview]

Can One Drone Safely Stop Another? Vector and Wrap Think So

Vector teams with Wrap to create killer-drone system By DRONELIFE Features Editor Jim Magill Vector, a Utah-based technology company that…

Continue Reading Can One Drone Safely Stop Another? Vector and Wrap Think So

American Drone Network and BRANDT Partner to Advance Agricultural Drone Spraying

Collaboration focuses on improving application efficiency, product performance, and pilot training American Drone Network (ADN) has announced a new partnership…

Continue Reading American Drone Network and BRANDT Partner to Advance Agricultural Drone Spraying

Honeywell and Odys Aviation Introduce Airborne Layer for Counter-UAS Defense

New system highlights the need for layered protection against evolving drone threats As drone threats continue to evolve, defense strategies…

Continue Reading Honeywell and Odys Aviation Introduce Airborne Layer for Counter-UAS Defense

The Real FCC Drone Debate: Who Controls the Airwaves?

A closer look at how spectrum policy and licensing could determine the future of U.S. drone operations The FCC is…

Continue Reading The Real FCC Drone Debate: Who Controls the Airwaves?

Why Japan’s AAM Roadmap May Be the Most Realistic in the World

A phased, system-wide approach focuses on operations, infrastructure, and public acceptance Japan’s leading AAM provider, SkyDrive, has translated the country’s…

Continue Reading Why Japan’s AAM Roadmap May Be the Most Realistic in the World

DroneShield Opens European Headquarters in Amsterdam Amid Growing Counter-Drone Demand

DroneShield has officially opened its new European headquarters in Amsterdam, The Netherlands. The move strengthens the counter-drone company’s operational presence…

Continue Reading DroneShield Opens European Headquarters in Amsterdam Amid Growing Counter-Drone Demand

Secondary Sidebar

Footer

SPONSORED

Inspired Flight Gremsy IF800 VIO F1 drones geo week

What Will It Take to Strengthen U.S. Drone Manufacturing? A Conversation with Inspired Flight’s CEO

Global Mapper Mobile data collection

Collection Ground Control Points with Global Mapper Mobile

Military Drone Mapping Solutions

How SimActive’s Correlator3D™ is Revolutionizing Military Mapping: An Exclusive Interview with CEO Philippe Simard

Photogrammetry Accuracy Standards

SimActive Photogrammetry Software: Enabling Users to Meet Accuracy Standards for Over 20 Years

NACT Engineering Parrot ANAFI tether indoor shot

Smart Tether for Parrot ANAFI USA from NACT Engineering

Blue Marble, features global mapper, features Blue Marble

Check Out These New Features in Global Mapper v25 from Blue Marble

About Us | Contact Us | Advertise With Us | Write for Us | Privacy Policy | Terms of Service

The Trusted Source for the Business of Drones.

This website uses cookies and third party services. By clicking OK, you are agreeing to our privacy policy. ACCEPT

Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT