Live data from Hacker News

What Happened to HackerOne?

blog.teknogeek.io

151–160 of 209 posts

Re: What Happened to HackerOne?

#152
post #104

Earlier quoted context omitted.

This and the pre-triage are the only reasons we even use a bug bounty platform. If paying out bounties was easy I would do it all via email; but as you said it’s almost impossible to do (unless you are maybe bigcorp and have a team just for that)

My largest problem with H1 is how braindead scripted/AI their triage is. - Starting scenario: no way to contact a company outside of H1 (or some other managed programme) - The company is compromised, their customer support has no idea what this means, they have no security.txt or any other security contact - I have explicitly told H1 to just forward it with no bounty, I don't want a bounty, only remediation, I do not…

[flagged]

Re: What Happened to HackerOne?

#153
post #32

Sending the sales team on a paid vacation to a tropical paradise while the engineering product flounders is such a perfect representation of corporate rot it sounds like something out of a Mike Judge movie

Presidents club is a standard way to reward top performing sales reps across many industries. It doesn't indicate anything other than the company is trying to reward and retain their top sales reps. Engineers who find it distasteful should be happy to know engineers typically get way more equity than sales reps.

[dead]

Re: What Happened to HackerOne?

#154

All good things don't last forever. A organization or company lasting forever with the same goal/mission while using the same methods is a statistical anomaly.

What is the corrupting force?

It's just economics. VCs dump large amounts of money into early-stage platforms with the express purpose of exploiting it later. This is an inevitable part of the lifecycle of high capital, low margin industries with strong network effects.

This is not VCs being evil and corrupting a pristine engineer- or hacker-defined concept of true value. The VCs are all following the rules and are trying to make money off of risky investments (it's "venture" capital, after all). But the incentive structure just forces the market into either an oligopoly of largely extractive services (or into everything being free: that's why open source is also a stable point for software).

My hope is that in time, basic software services, like for communication, socialising, community hosting, and so on, will eventually become seen as core social infrastructure. I don't really think this can happen via existing institutions, even open source, because the fixed costs of making software are really high. You really need _tax_ to support this. But it's very difficult to do because the internet cuts across borders.

Re: What Happened to HackerOne?

#155
post #70

Earlier quoted context omitted.

bitcoin is neither cheap and stable

Nor safe. Good luck recalling a wrong crpyto transaction.

That was not my point. Money with bancs also not, if it would be so easy, there would be no problems with nigerian oncles and so on. Good look get your grandmas scammed money back.

Re: What Happened to HackerOne?

#156

Earlier quoted context omitted.

Yea we also handled it ourselves the first couple years but it was so painful. Literally the same thing you described happened - as well spending weeks+ how we need to file it as tax when we pay bounty to someone in Pakistan etc.

Are you in the US? You simply collect a W8 from them that you keep on file and then the payment would be counted as an expense on taxes. We do payout to hundreds o f affiliates every year and this is how we handle it, it's really not complicated. The actual payments are done via Wise batch payments which just requires their email address.

[dead]

Re: What Happened to HackerOne?

#157
post #125
post #25

Earlier quoted context omitted.

Yeah, I figured that's what you meant, and most bounty programs won't pay out for stuff like that. Every application has those bugs; on a software pentest, we'd sev:lo them.

> Every application has those bugs; on a software pentest, we'd sev:lo them. Every application has a bug that can bring the whole application down for every user without owning a botnet? That comes often with a significant business cost, if someone exploits it. Many companies take them seriously. I have reported many as high and business has agreed. Not with HackerOne thought. If there is a bug where someone can make…

You can report a self-XSS sev:hi (and bounty hunters do) and get many orgs to take them seriously, because they don't have serious security practices. But DoS is generally sev:lo.

Re: What Happened to HackerOne?

#158
post #18

Not only was there significant personal liability, but there had been multiple instances of hackers being criminally charged and sentenced to jail time for finding and reporting security vulnerabilities prior to this. I don't think this is true, although it's a very commonly-held belief. Dan Goodin (I think?) wrote an article about this a long time ago, and was only able to come up with a few examples, and none of th…

https://m.slashdot.org/story/159162-- example circa 2011 I can think of 4-5 other situations from around that era (~2012) where people were at least charged and needed a lot of help to navigate the legal proceedings to avoid jail time. In 2010 it was more than risky on paper. 2017-2018 is well into the established era and probably even the golden age of bug bounties when a lot of corporate and judicial thinking re: w…

It's true that I'm speaking entirely in an American context.

Re: What Happened to HackerOne?

#159

Earlier quoted context omitted.

This (money transfer) is one thing Pix would solve trivially.

Any universal system would. The problem is there isnt a universal system.

That's untrue because it assumes all systems are interchangeable just because they are centralized and global, but intention matters and how you operate them creates hidden incentives that can alter how these systems evolve over time. Pix in Brazil, unlike other solutions, is entirely state-run and shouldn't suffer from investor pressure. It can still potentially suffer from service quality degradation and lack of transparency, but enshitification and anti-consumer practices are also very much present in private-owned initiatives, so it's not exclusive to this project.

Re: What Happened to HackerOne?

#160

Sending the sales team on a paid vacation to a tropical paradise while the engineering product flounders is such a perfect representation of corporate rot it sounds like something out of a Mike Judge movie

It's because of the CEO: Kara Sprague. Just another Marissa Meyer story, nothing new. We all saw how Yahoo turned out in the end.
Post reply on HN