Live data from Hacker News

We are retiring our bug bounty program

turso.tech

181–190 of 303 posts

Re: We are retiring our bug bounty program

#181
post #8

Which goes on to prove that bottleneck isn't in writing the code. It is in reading and understanding the code. We all had that one "productive" engineer in our teams who would write huge PRs that would have large swaths of refactoring whether warranted or not and that was way before anyone even could imagine in their wildest dreams that neural networks could generate that huge amounts of code. The net effect of such…

My whole career I yearned for green field projects but somehow predominantly worked on existing grown code bases and legacy projects.

That naturally meant reading and understanding more code than writing. Sometimes my LOC count was even negative, and I was proud of that accomplishment.

Now with AI I write even less and I've given up on the dream to gain fulfillment that way. The ability to quickly understand large amounts of code from questionable sources, be them machine or human, should hopefully stay valuable until my retirement, especially when supported by AI? What do you think?

Re: We are retiring our bug bounty program

#182
post #17
post #8

Which goes on to prove that bottleneck isn't in writing the code. It is in reading and understanding the code. We all had that one "productive" engineer in our teams who would write huge PRs that would have large swaths of refactoring whether warranted or not and that was way before anyone even could imagine in their wildest dreams that neural networks could generate that huge amounts of code. The net effect of such…

Sounds a like a tactical tornado, made me think of this paragraph: “Almost every software development organization has at least one developer who takes tactical programming to the extreme: a tactical tornado. The tactical tornado is a prolific programmer who pumps out code far faster than others but works in a totally tactical fashion. When it comes to implementing a quick feature, nobody gets it done faster than the…

That paragraph uses the word tactictal a lot without explaning what "in a totally tactical fashion" means

Re: We are retiring our bug bounty program

#183
post #127

Earlier quoted context omitted.

The critics didn't do themselves any favors. Part think the Terminator has something useful to say on the subject, part invent contrived scenarios like self-driving cars having to resolve trolley problems. Reality turned out to be much more boring. But yes, what you said but unironically. Like it or not it's here, it's not going away, so all the remaining options have to assume that.

> The critics didn't do themselves any favors. Part think the Terminator has something useful to say on the subject, part invent contrived scenarios like self-driving cars having to resolve trolley problems. Reality turned out to be much more boring. You do very well in battles against straw men.

I'm referring to actual people I argued with in the past. People convinced that AI in a self-driving car would involve the car calculating whether to kill a pedestrian or the driver, rather than trying to figure out whether this thing half obscured by foliage is a speed limit sign or not.

Obviously that's not what everyone argues, my point is that there's a lot of chaff in such arguments and not much wheat. People make a lot of noise about dramatic but completely unrealistic scenarios, while ignoring the far more boring reality.

The PauseAI people are for instance talking about human extinction, somehow. And not crappy GitHub PRs.

Re: We are retiring our bug bounty program

#184

Good time to mention this fantastic repo acting as a bot honeypot: https://github.com/UnsafeLabs/Bounty-Hunters The corresponding leaderboard: https://clankers-leaderboard.pages.dev

That's a great project! It's likely to get blacklisted by AI bots, soon enough, though.

I think you greatly overestimate the collaborative capacity of vibe coders

Re: We are retiring our bug bounty program

#185

Closing the program is totally reasonable. However, there is another option: Make submitters pay a nominal fee that is returned in the case that a real bug is found.

Honestly I think this is a great idea. My only suggestion is instead of being very nominal, it should be "reasonable" (so $10 and not $1). It's even possible to directly link this to maintainers/employees - if you can review 10 such AI/real things per hour (likely more if it's AI slop that's easy to detect), you're generating another revenue stream. Now, I have no idea if these guys are based in SF Bay or a 3rd world…

I believe the company is based in SF, but the developers are all over the world, so $100/hr is probably in the ballpark. Interestingly one of the senior developers is working from prison so his costs are probably a bit lower: https://news.ycombinator.com/item?id=44288937

Re: We are retiring our bug bounty program

#186
post #8

Which goes on to prove that bottleneck isn't in writing the code. It is in reading and understanding the code. We all had that one "productive" engineer in our teams who would write huge PRs that would have large swaths of refactoring whether warranted or not and that was way before anyone even could imagine in their wildest dreams that neural networks could generate that huge amounts of code. The net effect of such…

The reality is somewhere in the middle. Features are shipping 2x to 5x faster at a lot of organizations, with solid code still being produced and reviewed. Anyone trying to suggest that AI hasn't sped up quality code production is just insisting on keeping their head in the sand, IMO.

I predict a golden age for security is coming soon to those organizations. Dude, we can all literally see your code crumbling in our web browsers.

Re: We are retiring our bug bounty program

#187
post #153

I don't get it. Can't they ask Claude to check slop? This sounds like a bit of a baby/bathwater situation. (Okay Claude is too expensive, but Deepseek can probably handle it.)

How do you verify that Claude's output when checking slop is, in fact, correct, and not just more slop itself?

Re: We are retiring our bug bounty program

#188

Good time to mention this fantastic repo acting as a bot honeypot: https://github.com/UnsafeLabs/Bounty-Hunters The corresponding leaderboard: https://clankers-leaderboard.pages.dev

I don't understand this. If that project is not offering a bug bounty, why are they getting so many PRs? What possible incentive is there to spend real money on tokens just to push junk PRs? Are the PRs spamming a product or something?

They're offering bounties: https://github.com/UnsafeLabs/Bounty-Hunters/issues

Re: We are retiring our bug bounty program

#189

Earlier quoted context omitted.

It can be a company wide policy rather than trying to target a single individual even if the outcome is that they are targeted. This is something that should be addressed to them through a manager etc or if not, it's time to leave while they ruin the product over time.

This "you should leave" thing is a very boring and tired take and it should be said regularly that almost no engineer can afford it nowadays. Beautiful theory, but only that.

What's the alternative? You push back or you don't, leaving you likelier to leave in the future. For non-junior devs, the market is still humming along.

Re: We are retiring our bug bounty program

#190
post #142

Being a verifiable human identity (not as-in age verification or whatever) but as in having a known, public, reputation online will go a long way in this new slop-first world.

There is hardly a bright line between real and fake. An influencer is just a person who rents out their identity. Can you imagine getting a real PR from a human engineer you trust, but the description says "This pull request was sponsored by Skeezy Software Inc."?

Well, yes and no. What I mean is, being a related person who is indeed a person (by whatever means you establish that) and having some sort of standard by which you won't be bought, seems increasingly rare and therefore valuable.

By "bought" I don't mean they won't sponsor stuff. I mean they've got a public standard that can be trusted to some degree.

Your final example isn't exactly what I'm thinking of here. I'm thinking that a well-known identity and name within a community bypasses a lot of this BS with AI slop and communities bombarded by the slop will continue to close themselves off which will increase the value of being a known, contributing member.

Idk I need to figure out a way to articulate this better but essentially the value of being verifiably human is increasing IMO.

Post reply on HN