Live data from Hacker News

What Happened to HackerOne?

blog.teknogeek.io

111–120 of 210 posts

Re: What Happened to HackerOne?

#111

Earlier quoted context omitted.

Just pay them in stable coins. That's a solved problem.

Skip the crypto, cut out the middle man, and just pay the hackers in cocaine directly from the board of director's supply.

Probably a similar ecological footprint to Bitcoin too...

Re: What Happened to HackerOne?

#112
post #38

Earlier quoted context omitted.

Engineers who find it distasteful should be happy to know engineers typically get way more equity than sales reps. That isn't true. Early sales employees ('customer success', 'technical sales', 'growth', maybe product roles) get just as much equity as engineers who join at a similar time. The difference is that engineers often join earlier, with the commensurate risk that comes with. Also equity rarely pays out so yo…

Technical sales and customer growth also don’t get the cut of sales that usually the actual sales reps do. In general i think sales reps make more money overall but have a much more stressful job and can get axed whenever they underperform for a quarter etc

Having done sales before, I can assure you that it's differently stressful rather than more stressful. Trying to sign a customer for a substantial booking is stressful, but so is deploying a complex change that you can't roll back. There's hard things about every role.

Engineers can also be axed at any time for performance. They're fortunate that most companies are bad at measuring that, but they're also subject to things like stack ranking at very bad companies (fire worst 10% every year) so it's certainly not better to be in eng rather than sales.

Ultimately all roles have aspects of them that suck, so you need to find the one that sucks least for you.

Re: What Happened to HackerOne?

#113
post #28

> To the companies: You don’t need HackerOne anymore. The tokens to build your own in-house platform cost less than single year of HackerOne. You know, the biggest thing that HackerOne delivers is a universal payments system that requires absolutely no efforts from companies. Have you tried to manually pay hackers from around the world? It is a laborious process involving trying to find what providers are compatible…

Yep, spot on - this and some level of inbound filtering are the only reason we use an external platform.

That said, with the volume of inbound reports coming from LLMs, the signal-to-noise ratio has plummeted, and the time taken to triage has gone through the roof.

Re: What Happened to HackerOne?

#114
post #28

> To the companies: You don’t need HackerOne anymore. The tokens to build your own in-house platform cost less than single year of HackerOne. You know, the biggest thing that HackerOne delivers is a universal payments system that requires absolutely no efforts from companies. Have you tried to manually pay hackers from around the world? It is a laborious process involving trying to find what providers are compatible…

Literally just pay them in bitcoin. They're hackers, they'll be able to handle it.

Re: What Happened to HackerOne?

#115
post #92

Earlier quoted context omitted.

> Good luck recalling a wrong crpyto transaction. No better than recalling a wrong bank transfer or Zelle transaction.

Wrong bank transfers can't get recalled? I know I disputed a debit card transaction and got my money back the other month

In Canada, every bank has Interac e-Transfer, essentially we can easily email or text either other money. It's really wicked, and I'm always amazed other places like America don't have it built into their bank accounts and have to use 3rd-party apps to handle sending money to each other.

But anyway, the point is that it tells you every single time you send a transfer that way to be careful, because you can't undo a transfer after it's been sent. I'm assuming it's the same for most methods of bank transfer? I mean, debit transactions are surely a different beast.

Re: What Happened to HackerOne?

#116

Earlier quoted context omitted.

Just pay them in stable coins. That's a solved problem.

It's not just the transfer of cash. It's also complying with tax and employment laws in the country the hacker is in, to the satisfaction of your legal and finance teams. Sure, in western-style legal systems you can call them a contractor and they can pay their own tax. Just don't employ them full time for long enough to trigger 'sham contract' rules that would make them employees. But your corporate legal team doesn…

Why would you or anyone in your American company care about complying with Tajikistan law?

Re: What Happened to HackerOne?

#117
post #61
post #51

Earlier quoted context omitted.

Also PITA for people as well, we have a 33% tax on crypto selling here in Italy on profits…

stablecoins arent crypto in EU anymore, its e-money. No tax on converting to euros.

IIRC all cryptocurrency that's money is money (so bitcoin, ethereum, etc but not necessarily project-specific tokens) and if you happen to make or lose money on a currency conversion it doesn't have tax implications.

Re: What Happened to HackerOne?

#118
post #70

Earlier quoted context omitted.

bitcoin is neither cheap and stable

Nor safe. Good luck recalling a wrong crpyto transaction.

If the recipient is identifiable they legally have to give the money back and you can press charges if they don't.

Re: What Happened to HackerOne?

#119

Earlier quoted context omitted.

Wrong bank transfers can't get recalled? I know I disputed a debit card transaction and got my money back the other month

In Canada, every bank has Interac e-Transfer, essentially we can easily email or text either other money. It's really wicked, and I'm always amazed other places like America don't have it built into their bank accounts and have to use 3rd-party apps to handle sending money to each other. But anyway, the point is that it tells you every single time you send a transfer that way to be careful, because you can't undo a t…

Banks can always try to undo a transaction - it's just not guaranteed to work. AFAIK, credit/debit card reversals are always reversible because if the merchant doesn't have the money, it becomes their bank's problem to get the money or eat the loss. This works because the merchant is easily identifiable, well known, and has a reputation to uphold (at least to their bank). Other methods of transfer don't come with such contractual protection, but can still have best-effort.

Re: What Happened to HackerOne?

#120
post #74

I know Joel well and think a lot here is both accurate and well written. I led the Yahoo bug bounty program from 2023-2024 and was involved in it from about 2021. A major event that this glosses over is Covid which also happened right around this time as well. Covid killed travel (and budget) which in turn made it impossible to do the live events. A lot of companies ended up shifting to virtual live events which just…

> travel and t&e budgets just never returned. It is also worth remembering that the cost of travel itself, and the cost of venues itself has also increased substantially. As well as associated costs such as catering and insurance. So in-person events have issues from both sides, those attending and those hosting. You also do not mention corporate policies. Under pressure from investors, their employees and sometimes…

Cost of everything has increased massively, but they tell us inflation is 4%.
Post reply on HN