Live data from Hacker News

What Happened to HackerOne?

blog.teknogeek.io

121–130 of 210 posts

Re: What Happened to HackerOne?

#121
post #44
post #19

I reported some exploits on hackerone. Most got dismissed. One of them, a remotely triggerable DoS vector got downgraded in severity. I got a token payment from the company, and 7 years later, it is still not marked as resolved. I doubt my situation is unique.

Yeah I reported a j-frog vulnerability to Anthropic. It was downgraded to “informative” and they asked me to prove that I could exfiltrate data. I replied that exfiltrating data is against their program’s safe harbor policy and they just never responded. 2 months later the claude code source code leaked.

Hacking someone who asks you to hack them is legally safe even if not written in their default policy

Re: What Happened to HackerOne?

#122
post #28

> To the companies: You don’t need HackerOne anymore. The tokens to build your own in-house platform cost less than single year of HackerOne. You know, the biggest thing that HackerOne delivers is a universal payments system that requires absolutely no efforts from companies. Have you tried to manually pay hackers from around the world? It is a laborious process involving trying to find what providers are compatible…

Interesting. Do you think they are using something like Deel/Stripe to handle a lot of this ? i mean to figure out the "paying ppl around the world" complexity ... also local payment methods .. currencies .. compliance .. tax docs etc ?

Re: What Happened to HackerOne?

#124

Earlier quoted context omitted.

It's not just the transfer of cash. It's also complying with tax and employment laws in the country the hacker is in, to the satisfaction of your legal and finance teams. Sure, in western-style legal systems you can call them a contractor and they can pay their own tax. Just don't employ them full time for long enough to trigger 'sham contract' rules that would make them employees. But your corporate legal team doesn…

Why would you or anyone in your American company care about complying with Tajikistan law?

Less about that. More about “not accidentally funding terrorism” (or, more realistically, not giving money to sanctioned countries which can have significant consequences).

Re: What Happened to HackerOne?

#125
post #25
post #23

Earlier quoted context omitted.

it isn't simple request flooding, it is application level resource exhaustion

Yeah, I figured that's what you meant, and most bounty programs won't pay out for stuff like that. Every application has those bugs; on a software pentest, we'd sev:lo them.

> Every application has those bugs; on a software pentest, we'd sev:lo them.

Every application has a bug that can bring the whole application down for every user without owning a botnet? That comes often with a significant business cost, if someone exploits it. Many companies take them seriously. I have reported many as high and business has agreed. Not with HackerOne thought. If there is a bug where someone can make your whole product down with a single laptop isn't really something you can just ignore.

Re: What Happened to HackerOne?

#126
post #92

Earlier quoted context omitted.

> Good luck recalling a wrong crpyto transaction. No better than recalling a wrong bank transfer or Zelle transaction.

Wrong bank transfers can't get recalled? I know I disputed a debit card transaction and got my money back the other month

Most bank transfers cannot be reversed without agreement between parties. You're using a b2c mindset for a b2b problem. Bitcoin is a b2b tool.

Re: What Happened to HackerOne?

#127

Earlier quoted context omitted.

Wrong bank transfers can't get recalled? I know I disputed a debit card transaction and got my money back the other month

Most bank transfers cannot be reversed without agreement between parties. You're using a b2c mindset for a b2b problem. Bitcoin is a b2b tool.

Bangladesh bank got its reversed when hacked by NK. Does that look b2c?

Re: What Happened to HackerOne?

#129

Earlier quoted context omitted.

In Canada, every bank has Interac e-Transfer, essentially we can easily email or text either other money. It's really wicked, and I'm always amazed other places like America don't have it built into their bank accounts and have to use 3rd-party apps to handle sending money to each other. But anyway, the point is that it tells you every single time you send a transfer that way to be careful, because you can't undo a t…

Banks can always try to undo a transaction - it's just not guaranteed to work. AFAIK, credit/debit card reversals are always reversible because if the merchant doesn't have the money, it becomes their bank's problem to get the money or eat the loss. This works because the merchant is easily identifiable, well known, and has a reputation to uphold (at least to their bank). Other methods of transfer don't come with suc…

They can. Maybe in some jurisdictions they don't have to so they try to avoid it. But if there is crime involved for example, they can be required to do what's inconvenient

Re: What Happened to HackerOne?

#130

Earlier quoted context omitted.

> travel and t&e budgets just never returned. It is also worth remembering that the cost of travel itself, and the cost of venues itself has also increased substantially. As well as associated costs such as catering and insurance. So in-person events have issues from both sides, those attending and those hosting. You also do not mention corporate policies. Under pressure from investors, their employees and sometimes…

Cost of everything has increased massively, but they tell us inflation is 4%.

Iphones are still with the same price tag attached, bit you also get more compute for the same buck.

You can find many examples like this.

Post reply on HN