What Happened to HackerOne?
11–20 of 208 posts
Re: What Happened to HackerOne?
#12I'm surprised someone could get upset at AI triaging of bugs which would save everyone time.
Re: What Happened to HackerOne?
#13I'm surprised someone could get upset at AI triaging of bugs which would save everyone time.
Re: What Happened to HackerOne?
#14I'm surprised someone could get upset at AI triaging of bugs which would save everyone time.
This has a negative effect on humans doing their work with or without LLMs: curl shut down their bounty program, and GitHub just announced they're "restructuring" theirs. The author of this post also makes a case that HackerOne hasn't been honest about LLM training and use, either to hackers or to their own staff.
Re: What Happened to HackerOne?
#15Re: What Happened to HackerOne?
#16Re: What Happened to HackerOne?
#17> Co-founder Michiel Prins was allowed to leave the HackerOne dungeon to perform damage control with this absolute banger of an AI slop response: [...] Wow, it's like he prompted for the most stereotypically AI response possible. There's a tired trope in every sentence going on for four whole paragraphs! I originally quoted it too but thought better and decided to snip it out because I'm pretty sure it would get my a…
Re: What Happened to HackerOne?
#18I don't think this is true, although it's a very commonly-held belief. Dan Goodin (I think?) wrote an article about this a long time ago, and was only able to come up with a few examples, and none of them fit this fact pattern.
https://news.ycombinator.com/item?id=16642155
What is true is that it is much less legally risky to test someone else's computer than it was 10-15 years ago. People forget that's what you're doing when you look for web vulns! The DOJ has had a norm over the past ~many years not to prosecute good-faith vulnerability research, even though strictly speaking it contravenes CFAA directly. But "risky on paper" is the most you could say about doing that kind of testing back in 2010.
Re: What Happened to HackerOne?
#19Most got dismissed.
One of them, a remotely triggerable DoS vector got downgraded in severity. I got a token payment from the company, and 7 years later, it is still not marked as resolved.
I doubt my situation is unique.
Re: What Happened to HackerOne?
#20I'm surprised someone could get upset at AI triaging of bugs which would save everyone time.