I reported some exploits on hackerone. Most got dismissed. One of them, a remotely triggerable DoS vector got downgraded in severity. I got a token payment from the company, and 7 years later, it is still not marked as resolved. I doubt my situation is unique.
Yeah I reported a j-frog vulnerability to Anthropic. It was downgraded to “informative” and they asked me to prove that I could exfiltrate data. I replied that exfiltrating data is against their program’s safe harbor policy and they just never responded. 2 months later the claude code source code leaked.
What Happened to HackerOne?
121–130 of 210 posts
Re: What Happened to HackerOne?
#122> To the companies: You don’t need HackerOne anymore. The tokens to build your own in-house platform cost less than single year of HackerOne. You know, the biggest thing that HackerOne delivers is a universal payments system that requires absolutely no efforts from companies. Have you tried to manually pay hackers from around the world? It is a laborious process involving trying to find what providers are compatible…
Re: What Happened to HackerOne?
#123Re: What Happened to HackerOne?
#124Earlier quoted context omitted.
It's not just the transfer of cash. It's also complying with tax and employment laws in the country the hacker is in, to the satisfaction of your legal and finance teams. Sure, in western-style legal systems you can call them a contractor and they can pay their own tax. Just don't employ them full time for long enough to trigger 'sham contract' rules that would make them employees. But your corporate legal team doesn…
Why would you or anyone in your American company care about complying with Tajikistan law?
Re: What Happened to HackerOne?
#125Earlier quoted context omitted.
it isn't simple request flooding, it is application level resource exhaustion
Yeah, I figured that's what you meant, and most bounty programs won't pay out for stuff like that. Every application has those bugs; on a software pentest, we'd sev:lo them.
Every application has a bug that can bring the whole application down for every user without owning a botnet? That comes often with a significant business cost, if someone exploits it. Many companies take them seriously. I have reported many as high and business has agreed. Not with HackerOne thought. If there is a bug where someone can make your whole product down with a single laptop isn't really something you can just ignore.
Re: What Happened to HackerOne?
#126Earlier quoted context omitted.
> Good luck recalling a wrong crpyto transaction. No better than recalling a wrong bank transfer or Zelle transaction.
Wrong bank transfers can't get recalled? I know I disputed a debit card transaction and got my money back the other month
Re: What Happened to HackerOne?
#127Earlier quoted context omitted.
Wrong bank transfers can't get recalled? I know I disputed a debit card transaction and got my money back the other month
Most bank transfers cannot be reversed without agreement between parties. You're using a b2c mindset for a b2b problem. Bitcoin is a b2b tool.
Re: What Happened to HackerOne?
#128Re: What Happened to HackerOne?
#129Earlier quoted context omitted.
In Canada, every bank has Interac e-Transfer, essentially we can easily email or text either other money. It's really wicked, and I'm always amazed other places like America don't have it built into their bank accounts and have to use 3rd-party apps to handle sending money to each other. But anyway, the point is that it tells you every single time you send a transfer that way to be careful, because you can't undo a t…
Banks can always try to undo a transaction - it's just not guaranteed to work. AFAIK, credit/debit card reversals are always reversible because if the merchant doesn't have the money, it becomes their bank's problem to get the money or eat the loss. This works because the merchant is easily identifiable, well known, and has a reputation to uphold (at least to their bank). Other methods of transfer don't come with suc…
Re: What Happened to HackerOne?
#130Earlier quoted context omitted.
> travel and t&e budgets just never returned. It is also worth remembering that the cost of travel itself, and the cost of venues itself has also increased substantially. As well as associated costs such as catering and insurance. So in-person events have issues from both sides, those attending and those hosting. You also do not mention corporate policies. Under pressure from investors, their employees and sometimes…
Cost of everything has increased massively, but they tell us inflation is 4%.
You can find many examples like this.