Earlier quoted context omitted.
Walt Disney's program covers substantially more surface area, there's 6? publicly traded companies listed there. In addition to covering far fewer domains & apps, AT&T's conditions and exclusions disqualify a lot more. The market for bounties is a circus, breadcrumbs for free work from people trying to 'make it'. It can safely be analogized to the classic trope of those wanting to work in games getting paid fractiona…
> The market for bounties is a circus, breadcrumbs for free work from people trying to 'make it'. > The number of CVSS vulns with a score above 8 that have floated across the front page of HN in the past year without anyone getting paid tells you that much. You make it sound like there's a ton of people going around who can just dig up CVSS vulns above 8 and is making me all confused. Is that really happening? I have…
XBOW, an autonomous penetration tester, has reached the top spot on HackerOne
121–128 of 128 posts
Re: XBOW, an autonomous penetration tester, has reached the top spot on HackerOne
#122I'm confused on whether or not this actually outperformed humans. The more interesting statistic would be how much money it made versus the average hacker one top ranked contributor.
Re: XBOW, an autonomous penetration tester, has reached the top spot on HackerOne
#123«XBOW submitted nearly 1,060 vulnerabilities. All findings were fully automated, though our security team reviewed them pre-submission to comply with HackerOne’s policy on automated tools» That seems a bit unethical. I’ve thought companies specifically deny usage of automated tools. A bit too late ey…?
They acknowledge that in the article and all submissions are human reviewed before they are submitted.
Re: XBOW, an autonomous penetration tester, has reached the top spot on HackerOne
#124Earlier quoted context omitted.
Might be fixable by adding a $ 100 submission fee that is returned when you're proving working exploit code. Would make the Curl team a lot of money.
I've been on Hackerone for almost 8 years and I think the problem with this is that too many companies won't pay for legitimate bugs, even when you have a working exploit. I had one critical bug take 3 years to get a pay out. I had a full walkthrough with videos and report. The company kept stalling and at one point told me that because they completely had the app remade, they weren't going to pay me anything. Hacker…
Most companies should not do bug bounties.
Re: XBOW, an autonomous penetration tester, has reached the top spot on HackerOne
#125Earlier quoted context omitted.
One would think if AI can generate the slop it could also triage the slop.
How does it know the difference?
Re: XBOW, an autonomous penetration tester, has reached the top spot on HackerOne
#126Earlier quoted context omitted.
They acknowledge that in the article and all submissions are human reviewed before they are submitted.
The policies states it’s not allowed to use automated tools, not to submit report using automated tools alone. Human review does not really change that.
bug works and is repro - as a software owner, do you care if human or ai found it?
Re: XBOW, an autonomous penetration tester, has reached the top spot on HackerOne
#127Earlier quoted context omitted.
The policies states it’s not allowed to use automated tools, not to submit report using automated tools alone. Human review does not really change that.
if a human reviewer can repro the bug, there is no difference between automated or human found bug. bug works and is repro - as a software owner, do you care if human or ai found it?
Re: XBOW, an autonomous penetration tester, has reached the top spot on HackerOne
#128It’s humans who: - Design the system and prompts - Build and integrate the attack tools - Guide the decision logic and analysis This isn’t just semantics — overstating AI capabilities can confuse the public and mislead buyers, especially in high-stakes security contexts. I say this as someone actively working in this space. I participated in the development of PentestGPT, which helped kickstart this wave of research…
> It's humans Who would it be, gremlins? Those humans weren't at the top of the leaderboard before they had the AI, so clearly it helps.
What's being critized here is the hype, which can be misleading and confusing. On this topic, wrote a small essay: “Cybersecurity AI: The Dangerous Gap Between Automation and Autonomy,” to sort fact from fiction -> https://shorturl.at/1ytz7