7 ms·
> maybe the author did have malicious intent to harm the reputation of DJI In the context of a bug-bounty program, it's not malicious to "harm the reputation"
by emmab 9y ago
> maybe the author did have malicious intent to harm the reputation of DJI
In the context of a bug-bounty program, it's not malicious to "harm the reputation" of the entity in question, it's malicious to attempt to profit off the hack itself.
> The author wanted to sign the papers, take the money, and advertise the hack.
Of course! It's part of their portfolio.
It's common for security researchers to share details of a hack once it's been fixed. It's not "malicious" to tell the truth.