Live data from Hacker News

What Happened to HackerOne?

blog.teknogeek.io

21–30 of 209 posts

Re: What Happened to HackerOne?

#21
post #19

I reported some exploits on hackerone. Most got dismissed. One of them, a remotely triggerable DoS vector got downgraded in severity. I got a token payment from the company, and 7 years later, it is still not marked as resolved. I doubt my situation is unique.

Most bounty programs won't pay for DoS at all.

Re: What Happened to HackerOne?

#23
post #21
post #19

I reported some exploits on hackerone. Most got dismissed. One of them, a remotely triggerable DoS vector got downgraded in severity. I got a token payment from the company, and 7 years later, it is still not marked as resolved. I doubt my situation is unique.

Most bounty programs won't pay for DoS at all.

it isn't simple request flooding, it is application level resource exhaustion

Re: What Happened to HackerOne?

#24

> Co-founder Michiel Prins was allowed to leave the HackerOne dungeon to perform damage control with this absolute banger of an AI slop response: [...] Wow, it's like he prompted for the most stereotypically AI response possible. There's a tired trope in every sentence going on for four whole paragraphs! I originally quoted it too but thought better and decided to snip it out because I'm pretty sure it would get my a…

Imagine doing this article as a thorough writeup to provide feedback, rewriting this for like an hour before you post it.

And then you get an AI slop response like that in return where you can't even tell whether it was just a CEO not giving a damn...or a standard dumb chat bot with a stupid response.

I'm not sure if founders are aware that these are tipping points in customer care where the people that care about your product and ecosystem will leave your company for good, and you're irreparably damaging your own reputation.

If I were OP I'd never ever touch anything with a 10ft pole that the founders will build in their lifetime, and I'd warn everyone I know in the community about it.

That's the damage they're doing with these AI optimizations to themselves.

There's a reason why everyone starts to hate your company right after your stupid chatbot was introduced.

Re: What Happened to HackerOne?

#25
post #23
post #21

Earlier quoted context omitted.

Most bounty programs won't pay for DoS at all.

it isn't simple request flooding, it is application level resource exhaustion

Yeah, I figured that's what you meant, and most bounty programs won't pay out for stuff like that. Every application has those bugs; on a software pentest, we'd sev:lo them.

Re: What Happened to HackerOne?

#26
post #14

I'm surprised someone could get upset at AI triaging of bugs which would save everyone time.

From what I've seen in the bounty-related subreddits, AI is flooding bug bounty inboxes with low-value or meaningless reports, or straight-up hallucinations when people use smaller models (to turn a profit, you make lots of low-value bug reports and see who pays out). This has a negative effect on humans doing their work with or without LLMs: curl shut down their bounty program, and GitHub just announced they're "res…

Doesn't that problem benefit from having automatic bug triage that can avoid fast tracking these bad reports?

Re: What Happened to HackerOne?

#27
I don't understand the controversy at the heart of this post. H1 stated they don't use reports to train LLMs. Then they revealed they were using LLMs to triage reports based on previous reports. These two facts are not necessarily incompatible. It's entirely possible to use an LLM with a db tool installed to triage reports without using the body of the reports as training fodder. The article doesn't give any evidence that this was not the case. It sounds to me more like the OP already disliked H1 (for its sales practices and general enshittification) and the LLM issue was a convenient excuse to make a clean break.

Re: What Happened to HackerOne?

#28
> To the companies: You don’t need HackerOne anymore. The tokens to build your own in-house platform cost less than single year of HackerOne.

You know, the biggest thing that HackerOne delivers is a universal payments system that requires absolutely no efforts from companies. Have you tried to manually pay hackers from around the world? It is a laborious process involving trying to find what providers are compatible and what forms of money go where. It is extremely taxing to handle this. HackerOne provides real, tangible value in not making people think about how precisely to pay a hacker and in what currency. No amount of tokens solve the accounting problem, and it is foolish to imply otherwise.

Re: What Happened to HackerOne?

#29
post #14

I'm surprised someone could get upset at AI triaging of bugs which would save everyone time.

From what I've seen in the bounty-related subreddits, AI is flooding bug bounty inboxes with low-value or meaningless reports, or straight-up hallucinations when people use smaller models (to turn a profit, you make lots of low-value bug reports and see who pays out). This has a negative effect on humans doing their work with or without LLMs: curl shut down their bounty program, and GitHub just announced they're "res…

Didn't Daniel later report that curl recently started getting mostly high-quality LLM reports on their bounty program? I can imagine that there would definitely be a few "bounty spammers" trying to get hits, but it seems like most of them are doing good work.

I'd say instead that the problem is that a lot of people don't care anymore about the quality of the work being done, and LLMs are accelerating it. Bounty programs have shifted from ways for people to report security bugs to ways for people to try to make money.

Post reply on HN