What Happened to HackerOne?
151–160 of 209 posts
Re: What Happened to HackerOne?
#152Earlier quoted context omitted.
This and the pre-triage are the only reasons we even use a bug bounty platform. If paying out bounties was easy I would do it all via email; but as you said it’s almost impossible to do (unless you are maybe bigcorp and have a team just for that)
My largest problem with H1 is how braindead scripted/AI their triage is. - Starting scenario: no way to contact a company outside of H1 (or some other managed programme) - The company is compromised, their customer support has no idea what this means, they have no security.txt or any other security contact - I have explicitly told H1 to just forward it with no bounty, I don't want a bounty, only remediation, I do not…
Re: What Happened to HackerOne?
#153Sending the sales team on a paid vacation to a tropical paradise while the engineering product flounders is such a perfect representation of corporate rot it sounds like something out of a Mike Judge movie
Presidents club is a standard way to reward top performing sales reps across many industries. It doesn't indicate anything other than the company is trying to reward and retain their top sales reps. Engineers who find it distasteful should be happy to know engineers typically get way more equity than sales reps.
Re: What Happened to HackerOne?
#154All good things don't last forever. A organization or company lasting forever with the same goal/mission while using the same methods is a statistical anomaly.
What is the corrupting force?
This is not VCs being evil and corrupting a pristine engineer- or hacker-defined concept of true value. The VCs are all following the rules and are trying to make money off of risky investments (it's "venture" capital, after all). But the incentive structure just forces the market into either an oligopoly of largely extractive services (or into everything being free: that's why open source is also a stable point for software).
My hope is that in time, basic software services, like for communication, socialising, community hosting, and so on, will eventually become seen as core social infrastructure. I don't really think this can happen via existing institutions, even open source, because the fixed costs of making software are really high. You really need _tax_ to support this. But it's very difficult to do because the internet cuts across borders.
Re: What Happened to HackerOne?
#155Earlier quoted context omitted.
bitcoin is neither cheap and stable
Nor safe. Good luck recalling a wrong crpyto transaction.
Re: What Happened to HackerOne?
#156Earlier quoted context omitted.
Yea we also handled it ourselves the first couple years but it was so painful. Literally the same thing you described happened - as well spending weeks+ how we need to file it as tax when we pay bounty to someone in Pakistan etc.
Are you in the US? You simply collect a W8 from them that you keep on file and then the payment would be counted as an expense on taxes. We do payout to hundreds o f affiliates every year and this is how we handle it, it's really not complicated. The actual payments are done via Wise batch payments which just requires their email address.
Re: What Happened to HackerOne?
#157Earlier quoted context omitted.
Yeah, I figured that's what you meant, and most bounty programs won't pay out for stuff like that. Every application has those bugs; on a software pentest, we'd sev:lo them.
> Every application has those bugs; on a software pentest, we'd sev:lo them. Every application has a bug that can bring the whole application down for every user without owning a botnet? That comes often with a significant business cost, if someone exploits it. Many companies take them seriously. I have reported many as high and business has agreed. Not with HackerOne thought. If there is a bug where someone can make…
Re: What Happened to HackerOne?
#158Not only was there significant personal liability, but there had been multiple instances of hackers being criminally charged and sentenced to jail time for finding and reporting security vulnerabilities prior to this. I don't think this is true, although it's a very commonly-held belief. Dan Goodin (I think?) wrote an article about this a long time ago, and was only able to come up with a few examples, and none of th…
https://m.slashdot.org/story/159162-- example circa 2011 I can think of 4-5 other situations from around that era (~2012) where people were at least charged and needed a lot of help to navigate the legal proceedings to avoid jail time. In 2010 it was more than risky on paper. 2017-2018 is well into the established era and probably even the golden age of bug bounties when a lot of corporate and judicial thinking re: w…
Re: What Happened to HackerOne?
#159Earlier quoted context omitted.
This (money transfer) is one thing Pix would solve trivially.
Any universal system would. The problem is there isnt a universal system.
Re: What Happened to HackerOne?
#160Sending the sales team on a paid vacation to a tropical paradise while the engineering product flounders is such a perfect representation of corporate rot it sounds like something out of a Mike Judge movie