Live data from Hacker News

We are retiring our bug bounty program

turso.tech

151–160 of 303 posts

Re: We are retiring our bug bounty program

#151

Earlier quoted context omitted.

> forget about the shutting it down and think of something actually realistic. Why is it not realistic? Small teams do excellent work. Keep your team small and trusted. Only accept contributions from your team, and people outside your team who are personally vouched for by someone on your team. It's like climbing mountains or sailing or any other type of inherently risky activity--you don't go out with people you don…

> It's eminently possible, you just don't like the idea of it. Sounds like you can't accept AI is here to stay

"I shit on your floor, guess you have to get used to shit on your floor"

No. You go out the door, and then I clean it up, and you don't get invited back. That's how that works.

Re: We are retiring our bug bounty program

#152

Earlier quoted context omitted.

I don't understand why one wouldn't just auto reject big PRs and tell them to make smaller ones. Sounds like it's a communication and social problem, not a technological one. Even with AI, just tell it to make smaller self contained PRs. I do this with Claude or GPT models and they do just fine.

Power dynamics. Usually the person making the giant PRs is the one with all the sway. An earlier-career engineer is unlikely to push back against that level of influence.

And honestly, even if you do push back, you probably can't succeed. I used to work with a guy that made enormous, 10k line PRs to our Jenkins code, and would give only 3-4 days for people to review it. We tried to push back on it, but he was the golden boy of one of the people in charge of the project. Even the (inevitable) breakage of software builds when he merged his changes didn't cause any consequences for him. Unfortunately, sometimes with office politics there's absolutely nothing you can do.

Re: We are retiring our bug bounty program

#154
post #17

Earlier quoted context omitted.

Sounds a like a tactical tornado, made me think of this paragraph: “Almost every software development organization has at least one developer who takes tactical programming to the extreme: a tactical tornado. The tactical tornado is a prolific programmer who pumps out code far faster than others but works in a totally tactical fashion. When it comes to implementing a quick feature, nobody gets it done faster than the…

I have seen precisely zero consequences for these people because they usually leave after not too long and go somewhere else, sometimes for higher pay. The slower folks end up getting the worse code and no raises in exchange for comradery. But also I have no idea how that situation arises unless the slower folks are just auto-approving PRs. You kind of did that to yourself if you let the new person get away with it.

My experience is exactly the opposite. The TT ends up being the last engineer standing a lot of the time. The people who want to have better refactoring and more maintainable code are usually the ones who move on. The TT often stays in the same place for 25 years. Often correcting mistakes they themselves made in the past.

I knew one engineer who came in every Sunday night to process missed orders from an e-com system they wrote. They were unable to actually fix the problems with their code, so they just fixed the problems by hand. Every week...for years on end. Management thought he was a star who worked hard. The devs knew he was the worst engineer they have ever worked with. He still works at that same company 25 years later.

The correlation between what management thinks and reality can be pretty large at times.

Re: We are retiring our bug bounty program

#155

Earlier quoted context omitted.

But it really doesn't have to be like this. For their bug bounty program, the company can just charge 5-10$ per submission to guarantee everything you send gets thoroughly reviewed by a human, and so it completely eliminates bot slop DDoS submissions overnight. If your bug and PR was actually good, then you get 10 + 1000$ back, and if it wasn't good, then you need to do better due diligence next time, and the skilled…

I said it before and I'll say it again, for opportunities open to the entire world on the internet, adding monetary friction is the only way to filter out serious people from bad actors doing spray-and-pray hoping they make some money or get that job through weaponizing AI bots and sucking all the air in the room. So many problems can be solved that way, including customer support. Instead of having to post a sob sto…

I wonder if transaction costs get in the way. Someone has to pay the payment provider in both directions.

Re: We are retiring our bug bounty program

#157

Earlier quoted context omitted.

I don't understand this. If that project is not offering a bug bounty, why are they getting so many PRs? What possible incentive is there to spend real money on tokens just to push junk PRs? Are the PRs spamming a product or something?

Why does every programming job application ask for your GitHub profile? The industry used open source contributions as a proxy for candidate quality, and this is Goodhart's law in action.

It's also why the default approach is to install several hundred unnecessary dependencies.

Re: We are retiring our bug bounty program

#158
Why not require putting up some money, say $20, to submit a bug eligible for a payout? If you know what you’re doing you wouldn’t mind this at all because you’ve proven it to yourself and you’ll get paid $1000. If the bug turns out to not be legit and it was a good faith effort then you can return the deposit as well. Slop doesn’t get a refund.

Re: We are retiring our bug bounty program

#159
post #82

Bots are using real tokens for this. So, ultimate honeypot idea: post heavily commented skeleton code in a github repo, promise a generous money reward for closing issues and never pay anyone. See the bots swarm and burn their tokens to write code for you.

:D https://github.com/UnsafeLabs/Bounty-Hunters

[deleted]

Re: We are retiring our bug bounty program

#160
post #75

Earlier quoted context omitted.

This response is incredibly annoying and insufferable. It's only "impossible" at this point because people continually ignored skeptics and anyone warning about exactly these outcomes. Now that doom is here, it's too late to do anything about it. Just accept the doom!

> Now that doom is here, it's too late to do anything about it. Just accept the doom! What doom? This is a mildly annoying problem that will likely be self correcting long term.

You need to get out of your SV big tech bubble and go attend your local planning board meeting, the vast majority of the public hates this technology. It's literally killing members in their community and ruining the ecology.

The question we should ask is why a subset of humans are so gung-ho about this technology when all it's done is induced mass misery at even a greater scale. We all know the actual answer to this: they want more money even if the costs is more societal misery.

Be careful tho, we already know people are willing to commit violence and if it's one thing you can count on in the USA is when economic conditions worsen more people become desperate. That desperation leads to pretty extreme reactions, and these reactions are typically adored by the public writ large too (see the public's Luigi reactions).

Quite the powder keg and I don't think SV realizes the potential backlash that they are brewing themselves.

Post reply on HN