HackerOne raises $40M in their C-round of funding
11–14 of 14 posts
Re: HackerOne raises $40M in their C-round of funding
#12Earlier quoted context omitted.
I had the exact opposite experience. I filed a vuln report for a company that promised guaranteed bug bounties, complete with a polished PoC. I received no response at all. I contacted HackerOne, who pinged the company a couple times, didn't get a response either, apologized to me and that was it. The company remained on HackerOne and continued to promise bug bounties (and occasionally even paid some). Meanwhile, sin…
Wow, I'm definitely really surprised to hear that just because it is in such stark contrast to my own experience. If you don't mind me asking, how long ago was this? From my own experience, they're continually improving (they just added the response efficiency stats last may) and are putting a ton of effort into growing the hacker community.
Support simply told me to self-close the report because the company seemed inactive, without removing the company from their web site.
I get that they can't force them to pay or triage all issues, but the very least they could do would be letting researchers publish reports if ignored for over 90 days, and remove companies that are inactive. However, HackerOne wants to be able to show off a huge customer list, so they keep them on board, and what the companies want is king, so they don't allow disclosure unless the company allows it. (They also mix bug bounties managed by them with other bug bounties, to make it seem like they have more customers than they really do.)
Re: HackerOne raises $40M in their C-round of funding
#13Earlier quoted context omitted.
Just wanted to chime in and say that working with them as a hacker is also a great experience. They put a ton of emphasis on the community with publicly disclosed reports ( https://hackerone.com/hacktivity/popular ), statistics on response efficiency (e.g. https://hackerone.com/uber ), and a great support/mediation team ( https://support.hackerone.com/hc/en-us/articles/210782803-Ho... ). In addition, they also have a…
I had the exact opposite experience. I filed a vuln report for a company that promised guaranteed bug bounties, complete with a polished PoC. I received no response at all. I contacted HackerOne, who pinged the company a couple times, didn't get a response either, apologized to me and that was it. The company remained on HackerOne and continued to promise bug bounties (and occasionally even paid some). Meanwhile, sin…
Re: HackerOne raises $40M in their C-round of funding
#14Earlier quoted context omitted.
Wow, I'm definitely really surprised to hear that just because it is in such stark contrast to my own experience. If you don't mind me asking, how long ago was this? From my own experience, they're continually improving (they just added the response efficiency stats last may) and are putting a ton of effort into growing the hacker community.
The original report was roughly a year ago. I've checked that the company is still on their web site with 404-ing signup links roughly 30 minutes ago. I see response efficiency stats, but I don't know how they handle still-open reports. If they only consider reports that have received a response, a company that resolves a couple of reports quickly while ignoring hundreds of others will still have great stats. Support…
Good luck with everything!