Earlier quoted context omitted.
stablecoins arent crypto in EU anymore, its e-money. No tax on converting to euros.
IIRC all cryptocurrency that's money is money (so bitcoin, ethereum, etc but not necessarily project-specific tokens) and if you happen to make or lose money on a currency conversion it doesn't have tax implications.
What Happened to HackerOne?
161–170 of 209 posts
Re: What Happened to HackerOne?
#162Earlier quoted context omitted.
> No it doesn't. Yes it does. > You can gamble with it, but it doesn't let you own or send it. You can deposit (receive) and withdraw (send) cryptocurrencies there. "Owning" is a matter at the private key level which of course you use a self-hosted wallet for "true" ownership. But no argument was made on ownership. My point still stands that Revolut is a bank that allows cryptocurrencies.
It doesn't let me, it says says sending crypto is temporarily blocked. Maybe they just blocked me.
Re: What Happened to HackerOne?
#163> To the companies: You don’t need HackerOne anymore. The tokens to build your own in-house platform cost less than single year of HackerOne. You know, the biggest thing that HackerOne delivers is a universal payments system that requires absolutely no efforts from companies. Have you tried to manually pay hackers from around the world? It is a laborious process involving trying to find what providers are compatible…
I see some people with the idea that businesses are going to use AI to solve everything in their own one-off bespoke manners for everything, but I don't think it's going to happen. What's going to happen is that the SaaS providers are going to get even better at making yet more stuff go away than they were before and it'll actually be harder for a business to replicate it themselves then it used to be.
(Of course the "go away" isn't perfect, but clearly, neither is the idea that solving everything yourself with AI is either.)
Re: What Happened to HackerOne?
#164I don't understand the controversy at the heart of this post. H1 stated they don't use reports to train LLMs. Then they revealed they were using LLMs to triage reports based on previous reports. These two facts are not necessarily incompatible. It's entirely possible to use an LLM with a db tool installed to triage reports without using the body of the reports as training fodder. The article doesn't give any evidence…
> I don't understand the controversy at the heart of this post. Did you miss this part from the article: > They switched from talking about bug bounty programs, live hacking events, and how they could help you stay secure, to promoting their in-house AI security product and continuous security monitoring tool. notably the in-house AI security product is trained on existing bug bounty reports. > It sounds to me more l…
Re: What Happened to HackerOne?
#165> To the companies: You don’t need HackerOne anymore. The tokens to build your own in-house platform cost less than single year of HackerOne. You know, the biggest thing that HackerOne delivers is a universal payments system that requires absolutely no efforts from companies. Have you tried to manually pay hackers from around the world? It is a laborious process involving trying to find what providers are compatible…
Re: What Happened to HackerOne?
#166Earlier quoted context omitted.
Cost of everything has increased massively, but they tell us inflation is 4%.
Do they? https://www.bls.gov/charts/consumer-price-index/consumer-pri...
Re: What Happened to HackerOne?
#167Earlier quoted context omitted.
> Every application has those bugs; on a software pentest, we'd sev:lo them. Every application has a bug that can bring the whole application down for every user without owning a botnet? That comes often with a significant business cost, if someone exploits it. Many companies take them seriously. I have reported many as high and business has agreed. Not with HackerOne thought. If there is a bug where someone can make…
You can report a self-XSS sev:hi (and bounty hunters do) and get many orgs to take them seriously, because they don't have serious security practices. But DoS is generally sev:lo.
Which can be definitely high, if it can be triggered by giving specific URL, for example.
I think there is too much generalization happening here.
Re: What Happened to HackerOne?
#168Sending the sales team on a paid vacation to a tropical paradise while the engineering product flounders is such a perfect representation of corporate rot it sounds like something out of a Mike Judge movie
Most (enterprise focused) companies, even outside of tech, has something like this. Called Club, P-club, presidents club, circle of excellence, etc.
HackerOne chose a sales-first culture and this is their way of rewarding that growth.
Re: What Happened to HackerOne?
#169Sending the sales team on a paid vacation to a tropical paradise while the engineering product flounders is such a perfect representation of corporate rot it sounds like something out of a Mike Judge movie
I'm confused at the way they promoted it. Is there any way someone outside the company reading a Twitter post would consider this a positive thing for the product to be told what incentives the sales team get?
Re: What Happened to HackerOne?
#170> To the companies: You don’t need HackerOne anymore. The tokens to build your own in-house platform cost less than single year of HackerOne. You know, the biggest thing that HackerOne delivers is a universal payments system that requires absolutely no efforts from companies. Have you tried to manually pay hackers from around the world? It is a laborious process involving trying to find what providers are compatible…
This is a great example of a general trend, which is why I don't think SaaS is going anywhere. The bar may be raised, but it's not going anywhere. HackerOne and SaaS in general makes problems go away for money. If you use your own tokens and solve it yourself, it's still your problem. The deficiencies are your problem. The support and ongoing maintenance are your problem. Discovering some country split in two and now…
The flip side, of course, is that I can fix my problem - which may be unique and not something a large SaaS will ever do - on my timeline.