Live data from Hacker News

What Happened to HackerOne?

blog.teknogeek.io

101–110 of 211 posts

Re: What Happened to HackerOne?

#101

Earlier quoted context omitted.

An LLM finds a dubious bug, an LLM turns it into a convincing report, and now the proposed solution is to have an LLM triage it? There are a lot of turtles holding up this approach and the circular logic seems hard to miss. Automated triage can filter obvious spam, which was already fast and easy for humans to do. The hard part is independently reproducing a plausible finding and assessing its actual impact. If LLMs…

>If you could build the thing they wanted to build it would fix the slop problem It sounds like a reason to try and build it than a reason to not build it.

I tried to build it (kind of). My team is going to use it to alert us to the most critical issues so we can hop on them before waiting for triage. It's decent at figuring out criticality but it's TERRIBLE at actually doing triage and assessing whether the report is plausibly or implausibly true. Security can be really nuanced, and from my experience so far with the model I'm using it's really bad at being skeptical enough to actually figure out if something is a legit issue with impact or not. I agree though, it would be awesome if we could get AI triage that worked.

Re: What Happened to HackerOne?

#102
post #91
post #65

Earlier quoted context omitted.

Not anymore! Most places allow this very easily now.

Exactly. Revolut is a bank that allows cryptocurrencies. HN really is living in their own bubble.

Revolut does not have a banking license in the US. At the moment they are a front for another bank. Don't be gullible and believe blindly what the marketing departments tell you.

Re: What Happened to HackerOne?

#103
post #76

Earlier quoted context omitted.

To be fair “we will compensate you if you do X” sounds a lot like a contract so you’d probably be just fine in court. (Though likely wise to avoid the chance of a legal headache)

I don't trust the legal system. They could cover up the evidence, get me blocked on HackerOne, claim that my screenshots are AI-generated, hire top lawyers then make the judge to charge me for the lawyers' bill. The big company always wins. The legal system is pure fiction at this point. What lawyer would stand against the big companies? Permanently destroying all their future career prospects. Erin Brockovich? That'…

The Steven Donziger story is so insane.

Re: What Happened to HackerOne?

#104
post #28

> To the companies: You don’t need HackerOne anymore. The tokens to build your own in-house platform cost less than single year of HackerOne. You know, the biggest thing that HackerOne delivers is a universal payments system that requires absolutely no efforts from companies. Have you tried to manually pay hackers from around the world? It is a laborious process involving trying to find what providers are compatible…

This and the pre-triage are the only reasons we even use a bug bounty platform. If paying out bounties was easy I would do it all via email; but as you said it’s almost impossible to do (unless you are maybe bigcorp and have a team just for that)

My largest problem with H1 is how braindead scripted/AI their triage is.

- Starting scenario: no way to contact a company outside of H1 (or some other managed programme)

- The company is compromised, their customer support has no idea what this means, they have no security.txt or any other security contact

- I have explicitly told H1 to just forward it with no bounty, I don't want a bounty, only remediation, I do not care about a bounty or any reward

- H1 closes as "not eligible" and tells me to not submit stuff I can't prove it's my compromise by putting my username on it

- Corporate server is still compromised and being used as a proxy to brute force my services

Re: What Happened to HackerOne?

#105
post #91

Earlier quoted context omitted.

Exactly. Revolut is a bank that allows cryptocurrencies. HN really is living in their own bubble.

Revolut does not have a banking license in the US. At the moment they are a front for another bank. Don't be gullible and believe blindly what the marketing departments tell you.

It works in Europe, which is one of the few advantages we have over the US.

Re: What Happened to HackerOne?

#106
post #70

Earlier quoted context omitted.

Nor safe. Good luck recalling a wrong crpyto transaction.

Can't do that with cash either, yet lots of people are using that.

it's a problem only if you can accidentally 100 000 dollars in cash, most of us can't (the amount of paper makes it tricky)

Re: What Happened to HackerOne?

#107
post #79

Earlier quoted context omitted.

I worked at a big corp and we paid out randoms for a program (not bug bounty). It was an absolute minefield, people would lie to us about where they were located only for us to find out they’re in and then legal tells us we have to pay them but we’re not allowed to at the same time. Outsourcing all that mess is a great use of money.

Yea we also handled it ourselves the first couple years but it was so painful. Literally the same thing you described happened - as well spending weeks+ how we need to file it as tax when we pay bounty to someone in Pakistan etc.

Are you in the US? You simply collect a W8 from them that you keep on file and then the payment would be counted as an expense on taxes. We do payout to hundreds o f affiliates every year and this is how we handle it, it's really not complicated. The actual payments are done via Wise batch payments which just requires their email address.

Re: What Happened to HackerOne?

#108
post #28

> To the companies: You don’t need HackerOne anymore. The tokens to build your own in-house platform cost less than single year of HackerOne. You know, the biggest thing that HackerOne delivers is a universal payments system that requires absolutely no efforts from companies. Have you tried to manually pay hackers from around the world? It is a laborious process involving trying to find what providers are compatible…

Many solutions nowadays. https://www.payoneer.com/ is one of them. Of course this one is a bit racist depending on which contry you were born in.

Race and country of origin are not the same

Re: What Happened to HackerOne?

#109
post #92
post #70

Earlier quoted context omitted.

Nor safe. Good luck recalling a wrong crpyto transaction.

> Good luck recalling a wrong crpyto transaction. No better than recalling a wrong bank transfer or Zelle transaction.

Wrong bank transfers can't get recalled? I know I disputed a debit card transaction and got my money back the other month
Post reply on HN