Live data from Hacker News

Restructuring GitHub's bug bounty program

github.blog

21–30 of 38 posts

Re: Restructuring GitHub's bug bounty program

#22

Earlier quoted context omitted.

How does decreasing pay for humans discourage slop reports, exactly?

It discourages all reports, so you get the reduced slop reports for free.

To my mind, it encourages more reports because that way you're more likely to have some of them slip through and get approved, meaning your future reports are worth more.

Re: Restructuring GitHub's bug bounty program

#24

Another reason why LLMs suck. So far cons > pros

> So far cons > pros

Lets say 80% of the world's population decides the cons outweight the pros, now what? Put the genie back in the bottle, something that is famously easy and trivial to do?

Re: Restructuring GitHub's bug bounty program

#25
post #14

> We’re formalizing a permanent private/invite-only VIP program for qualified researchers who consistently deliver high-quality, high-impact work. > VIP program bounty table: Severity Payout -------- -------- Low $1,000 Medium $7,500 High $20,000 Critical $30,000+ > We are adjusting our public program rates to accommodate this shift in focus towards quality of relationships and findings over quantity of reports. We a…

> VIP program for qualified researchers who consistently deliver high-quality, high-impact work.

Almost as though they want the quality and consistency of hired labor but not the cost

Re: Restructuring GitHub's bug bounty program

#27

So if the "wrong" person finds a critical vulnerability in GitHub, the payout is capped at $10,000. Might reduce the likelihood of it being submitted to the bug bounty program.

I find it quite offensive that there is a payout difference for major vulnerabilities when the outcome is the end in the end.

If it was me finding such a vulnerability, this discrimination would offend me so much that I would prefer to sell it to semi-legal actors that would pay multiple of that...

Re: Restructuring GitHub's bug bounty program

#28

So if the "wrong" person finds a critical vulnerability in GitHub, the payout is capped at $10,000. Might reduce the likelihood of it being submitted to the bug bounty program.

It might, but as someone who has to review public vulnerability reports for a much less popular website, I completely understand why they’re building a vouch program to dissuade slop reports. One would presume their internal team is using frontier models for red team agent scanning against potential attack surface, and so this is a potential risk they’re willing to take. Tragedy of the commons that someone who hasn’t…

You're forgetting that GitHub aka Microsoft is one of the big slop peddlers. They made the problem but now don't want to pay for it.

Re: Restructuring GitHub's bug bounty program

#29

Another reason why LLMs suck. So far cons > pros

> So far cons > pros Lets say 80% of the world's population decides the cons outweight the pros, now what? Put the genie back in the bottle, something that is famously easy and trivial to do?

If the will was there we could shut down commercial providers tomorrow, which would already solve most of the problem.

Re: Restructuring GitHub's bug bounty program

#30

Earlier quoted context omitted.

It might, but as someone who has to review public vulnerability reports for a much less popular website, I completely understand why they’re building a vouch program to dissuade slop reports. One would presume their internal team is using frontier models for red team agent scanning against potential attack surface, and so this is a potential risk they’re willing to take. Tragedy of the commons that someone who hasn’t…

You're forgetting that GitHub aka Microsoft is one of the big slop peddlers. They made the problem but now don't want to pay for it.

"one of the big" is an understatement. They own OpenAI, which created and popularized the whole field.
Post reply on HN