Restructuring GitHub's bug bounty program
21–30 of 38 posts
Re: Restructuring GitHub's bug bounty program
#22Earlier quoted context omitted.
How does decreasing pay for humans discourage slop reports, exactly?
It discourages all reports, so you get the reduced slop reports for free.
Re: Restructuring GitHub's bug bounty program
#23Another reason why LLMs suck. So far cons > pros
Re: Restructuring GitHub's bug bounty program
#24Another reason why LLMs suck. So far cons > pros
Lets say 80% of the world's population decides the cons outweight the pros, now what? Put the genie back in the bottle, something that is famously easy and trivial to do?
Re: Restructuring GitHub's bug bounty program
#25> We’re formalizing a permanent private/invite-only VIP program for qualified researchers who consistently deliver high-quality, high-impact work. > VIP program bounty table: Severity Payout -------- -------- Low $1,000 Medium $7,500 High $20,000 Critical $30,000+ > We are adjusting our public program rates to accommodate this shift in focus towards quality of relationships and findings over quantity of reports. We a…
Almost as though they want the quality and consistency of hired labor but not the cost
Re: Restructuring GitHub's bug bounty program
#26Why take the lower offer by going directly.
That sounds like a win for everyone involved.
Re: Restructuring GitHub's bug bounty program
#27So if the "wrong" person finds a critical vulnerability in GitHub, the payout is capped at $10,000. Might reduce the likelihood of it being submitted to the bug bounty program.
If it was me finding such a vulnerability, this discrimination would offend me so much that I would prefer to sell it to semi-legal actors that would pay multiple of that...
Re: Restructuring GitHub's bug bounty program
#28So if the "wrong" person finds a critical vulnerability in GitHub, the payout is capped at $10,000. Might reduce the likelihood of it being submitted to the bug bounty program.
It might, but as someone who has to review public vulnerability reports for a much less popular website, I completely understand why they’re building a vouch program to dissuade slop reports. One would presume their internal team is using frontier models for red team agent scanning against potential attack surface, and so this is a potential risk they’re willing to take. Tragedy of the commons that someone who hasn’t…
Re: Restructuring GitHub's bug bounty program
#29Another reason why LLMs suck. So far cons > pros
> So far cons > pros Lets say 80% of the world's population decides the cons outweight the pros, now what? Put the genie back in the bottle, something that is famously easy and trivial to do?
Re: Restructuring GitHub's bug bounty program
#30Earlier quoted context omitted.
It might, but as someone who has to review public vulnerability reports for a much less popular website, I completely understand why they’re building a vouch program to dissuade slop reports. One would presume their internal team is using frontier models for red team agent scanning against potential attack surface, and so this is a potential risk they’re willing to take. Tragedy of the commons that someone who hasn’t…
You're forgetting that GitHub aka Microsoft is one of the big slop peddlers. They made the problem but now don't want to pay for it.