Live data from Hacker News

What Happened to HackerOne?

blog.teknogeek.io

131–140 of 210 posts

Re: What Happened to HackerOne?

#131
post #70

Earlier quoted context omitted.

Nor safe. Good luck recalling a wrong crpyto transaction.

If the recipient is identifiable they legally have to give the money back and you can press charges if they don't.

And if the jurisdictions don't have a treaty?

Re: What Happened to HackerOne?

#132
post #99
post #91

Earlier quoted context omitted.

Exactly. Revolut is a bank that allows cryptocurrencies. HN really is living in their own bubble.

No it doesn't. You can gamble with it, but it doesn't let you own or send it.

> No it doesn't.

Yes it does.

> You can gamble with it, but it doesn't let you own or send it.

You can deposit (receive) and withdraw (send) cryptocurrencies there.

"Owning" is a matter at the private key level which of course you use a self-hosted wallet for "true" ownership. But no argument was made on ownership.

My point still stands that Revolut is a bank that allows cryptocurrencies.

Re: What Happened to HackerOne?

#133
post #132
post #99

Earlier quoted context omitted.

No it doesn't. You can gamble with it, but it doesn't let you own or send it.

> No it doesn't. Yes it does. > You can gamble with it, but it doesn't let you own or send it. You can deposit (receive) and withdraw (send) cryptocurrencies there. "Owning" is a matter at the private key level which of course you use a self-hosted wallet for "true" ownership. But no argument was made on ownership. My point still stands that Revolut is a bank that allows cryptocurrencies.

It doesn't let me, it says says sending crypto is temporarily blocked. Maybe they just blocked me.

Re: What Happened to HackerOne?

#134
I've disclosed vulns across just about every industry — banking, healthcare, oil & gas, government, cybersecurity, etc -- and to some of the largest companies in the world, OpenAI, Salesforce and Google. I've been doing this for nearly 20 years.

Most of my research starts with: _There is absolutely no way this works_. Then it works.

I've been thinking that a lot more lately.

Companies and hackers are both heavily incentivised to reduce the friction involved in vulnerability disclosure, particularly for large organisations. The platforms are good enough now. They're email in 2007: imperfect, occasionally frustrating, but substantially better than what came before.

They make SLAs possible. They provide structure and administration. Things still go wrong — companies stop responding, analysts drop the ball, hackers can be idiots — but the model basically works.

Decentralising disclosure again would make life significantly harder for individual hackers. We'd end up back on email, probably building email-powered bounty CRMs that consume a small country's worth of tokens just to keep track of everything.

For smaller organisations, though, I wouldn't touch a public bounty platform with a 10-foot pole. Run a private program first (through the platform). Having been on the receiving end of beg bounties, automated scanner output and increasingly AI-generated slop, most smaller security teams simply cannot scale to absorb the noise.

The more interesting way to think about these platforms is that they're becoming the LinkedIn of hacking.

For hackers, the path is fairly straightforward: build a rep through useful -- but oftentimes unsolicited disclosures, get invited onto private programs, and gradually establish a profile with a strong signal-to-noise ratio.

For companies, they're increasingly a recruiting and relationship-building tool.

And for the platforms, I think there's a much larger opportunity for them in community.

They should be significantly better at understanding hackers: what they're good at, what technologies interest them, which industries they understand, and where they're located. Today, that profiling is laughably poor, to the point the questionnaires on areas by these large platforms are out of date by several years.

Then use the data.

Run small, highly targeted events: state- or city-based meetups, lunch-and-learns, product launches, bounty program launches and technical briefings. They don't need huge sponsorship budgets or prize pools. They need the actual community involved. Pay for dinner, sponsor a talk.

A lot of existing events seem to start with companies, sponsorship packages and monetary amounts, then work backwards. I think that's backwards.

As a weekend hacker, I'm far more likely to spend time on a program because something about it is interesting: you're launching an AI feature, handling financial data in a new way, using Node/GCP/a TI-82 calculator, or exposing some weird technical surface I want to understand.

And I'm far more likely to build a useful relationship with a company if I can actually meet the people behind the program. Hackers can provide much better feedback than a semi-generated report, and companies can explain far more than a stale domain list and scope document — which, realistically, we'll be ignoring 99.99% of the time anyway.. Unless it's government. I quite like my freedom.

Re: What Happened to HackerOne?

#136

Earlier quoted context omitted.

Cost of everything has increased massively, but they tell us inflation is 4%.

Iphones are still with the same price tag attached, bit you also get more compute for the same buck. You can find many examples like this.

That's true. I bought 256GB RAM for an amount that used to only get 32GB. Wait, I swapped those two numbers around.

Re: What Happened to HackerOne?

#137
post #44
post #19

I reported some exploits on hackerone. Most got dismissed. One of them, a remotely triggerable DoS vector got downgraded in severity. I got a token payment from the company, and 7 years later, it is still not marked as resolved. I doubt my situation is unique.

Yeah I reported a j-frog vulnerability to Anthropic. It was downgraded to “informative” and they asked me to prove that I could exfiltrate data. I replied that exfiltrating data is against their program’s safe harbor policy and they just never responded. 2 months later the claude code source code leaked.

In my experience, program requirements are mostly there for the lawyers.

If you act in good faith, communicate clearly, and conduct yourself reasonably, most companies will work with you — even when you've technically wandered outside the neat boundaries of their risk-appropriate, regulatory-reviewed policy.

That isn't protection, of course. Eventually you'll encounter a bounty program run primarily by lawyers, procurement, or someone optimising a graph trend-line.

And we know what tends to happen next.

Those programs, and organisations, develop reputations. Researchers talk. Companies get discussed at conferences, in private groups and across the community, and some become informally blacklisted.

Microsoft is a useful recent example: researchers have publicly walked away from five-figure bounties to make a point. There are excellent people working there, but organisationally Microsoft has repeatedly struggled to engage with the security community in a way that feels collaborative, rather than adversarial. Unless you're one of their paid partners, intermingled in their ecosystem.

A lot of that seems to come down to incentives: somebody, somewhere, wants the numbers to look better.

That doesn't work particularly well in an industry that, like most industries, ultimately runs on relationships, trust and specialisation.

If a company marks something critical as informational, sometimes the most effective response is a CVSS parameter argument. It's a snarky comment:

"Okay — so if I find a way to abuse your own infrastructure to message your customers, trigger a major incident and create regulatory problems for your clients, you'd prefer I treat that as informational too, and instead just report it to regulators?"

Surprisingly often, that gets the issue reconsidered.

Have you annoyed an analyst? Maybe. Does it matter? Probably not. Neither of you will remember the exchange a week later, but you might have corrected a bad risk decision on their side and you'll see a positive outcome on your side. Mistakes happen.

I generally advise companies and hackers alike to follow Kiwicon's #1 rule.

Re: What Happened to HackerOne?

#138

Earlier quoted context omitted.

> travel and t&e budgets just never returned. It is also worth remembering that the cost of travel itself, and the cost of venues itself has also increased substantially. As well as associated costs such as catering and insurance. So in-person events have issues from both sides, those attending and those hosting. You also do not mention corporate policies. Under pressure from investors, their employees and sometimes…

Cost of everything has increased massively, but they tell us inflation is 4%.

Do they? https://www.bls.gov/charts/consumer-price-index/consumer-pri...

Re: What Happened to HackerOne?

#139

Earlier quoted context omitted.

Cost of everything has increased massively, but they tell us inflation is 4%.

Iphones are still with the same price tag attached, bit you also get more compute for the same buck. You can find many examples like this.

Inflation famously measures iPhone prices alone.

Re: What Happened to HackerOne?

#140
post #139

Earlier quoted context omitted.

Iphones are still with the same price tag attached, bit you also get more compute for the same buck. You can find many examples like this.

Inflation famously measures iPhone prices alone.

Now you're thinking like a central bank! Houses +200%, iPhones -200% (as measured by CPU clock speed), inflation 0%, everything is good!
Post reply on HN