Live data from Hacker News

We are retiring our bug bounty program

turso.tech

111–120 of 303 posts

Re: We are retiring our bug bounty program

#111
post #88

Earlier quoted context omitted.

Unfortunately this isn't all black-and-white. There are some bug bounty where the company is very eager not to pay any bounty, aggressively marking vulnerabilities as out-of-scope or working-as-intended. In those case you already lose time, but in the future you would also lose money. Unfortunately you don't know how a company will react before submitting, especially if it's a small one.

It already doesn't stand on face value. These people are spending money to open PRs via their token costs

No, not them, but those who provide subsidies to AI labs, which is why such people spend almost nothing

Re: We are retiring our bug bounty program

#112
post #8

Which goes on to prove that bottleneck isn't in writing the code. It is in reading and understanding the code. We all had that one "productive" engineer in our teams who would write huge PRs that would have large swaths of refactoring whether warranted or not and that was way before anyone even could imagine in their wildest dreams that neural networks could generate that huge amounts of code. The net effect of such…

With AI everybody gets to be “that guy” now.

Re: We are retiring our bug bounty program

#113
post #8

Which goes on to prove that bottleneck isn't in writing the code. It is in reading and understanding the code. We all had that one "productive" engineer in our teams who would write huge PRs that would have large swaths of refactoring whether warranted or not and that was way before anyone even could imagine in their wildest dreams that neural networks could generate that huge amounts of code. The net effect of such…

Context is everything for massive PRs. If you don't ever have a massive PR from a dynamite session, then you cannot ever be better than "average and plodding". So the question is, what's the context of the massive PR and how should it be handled? * Mature product making money, intermediate engineer just refactored everything so it's "better"? Shut the fuck up, kindly please, you will have to demonstrate that you unde…

> If you don't ever have a massive PR from a dynamite session, then you cannot ever be better than "average and plodding".

That's just cope to avoid learning how to turn a big change into a well organized patch series.

Re: We are retiring our bug bounty program

#114
post #25

Earlier quoted context omitted.

AI can be the ultimate tactical tornado.

But it really doesn't have to be like this. For their bug bounty program, the company can just charge 5-10$ per submission to guarantee everything you send gets thoroughly reviewed by a human, and so it completely eliminates bot slop DDoS submissions overnight. If your bug and PR was actually good, then you get 10 + 1000$ back, and if it wasn't good, then you need to do better due diligence next time, and the skilled…

The bots spam even when there's no bug bounty program. The emails start out with "I received $500 for a similar reported on another site"

Re: We are retiring our bug bounty program

#115
post #95
post #80

Earlier quoted context omitted.

There are many cryptocurrencies that allow anyone to move money quickly, cheaply, and on the same day in less than a minute and requires zero bank accounts. At this point there isn't an excuse.

And which are trivial to convert back and forth between real money and cryptocurrency? And hold their value with sufficient stability that you can convert USD into the currency, make a transaction, wait a few weeks, make a transaction the other direction and then convert back into USD, with roughly no loss in value?

For this use case, that's a virtuous proof-of-work requirement.

Re: We are retiring our bug bounty program

#117

Earlier quoted context omitted.

I don't understand why one wouldn't just auto reject big PRs and tell them to make smaller ones. Sounds like it's a communication and social problem, not a technological one. Even with AI, just tell it to make smaller self contained PRs. I do this with Claude or GPT models and they do just fine.

Power dynamics. Usually the person making the giant PRs is the one with all the sway. An earlier-career engineer is unlikely to push back against that level of influence.

PRs are all about power dynamics and (un)spoken deals…

If you rubberstamp some people‘s PRs all the time, you can then get them to greenlight your unpleasant PRs via pm instantly.

The other way round, retaliation: I once added some serious review notes to the PR of a very senior engineer because it was a dangerous topic. He would then spend the next months nitpicking every single PR I created. Had to post my PR in slack whenever he was not online to get them merged. After that I never seriously reviewed his PRs again. Too much of a headache.

Re: We are retiring our bug bounty program

#118

Good time to mention this fantastic repo acting as a bot honeypot: https://github.com/UnsafeLabs/Bounty-Hunters The corresponding leaderboard: https://clankers-leaderboard.pages.dev

I don't understand this. If that project is not offering a bug bounty, why are they getting so many PRs? What possible incentive is there to spend real money on tokens just to push junk PRs? Are the PRs spamming a product or something?

Re: We are retiring our bug bounty program

#120

Good time to mention this fantastic repo acting as a bot honeypot: https://github.com/UnsafeLabs/Bounty-Hunters The corresponding leaderboard: https://clankers-leaderboard.pages.dev

That's a great project! It's likely to get blacklisted by AI bots, soon enough, though.

There's an AI bot blacklist? How do I get all my projects onto that?
Post reply on HN