Live data from Hacker News

What Happened to HackerOne?

blog.teknogeek.io

201–209 of 209 posts

Re: What Happened to HackerOne?

#201
I'm not so sure anyone was let out of the dungeon. All the "co-founder" statements read exactly like Claude drivel.

If I were a betting man, I'd bet HackerOne simply wired LLMs up to post as Alex and Michiel.

Re: What Happened to HackerOne?

#202

Earlier quoted context omitted.

I disagree, they don't cooperate just because they operate immersed in competition. Take out competition for instance by state sponsored cooperation treaties and see the technical limitations dissolve by creating the right incentives.

So what's your plan to merge Bitcoin, Monero and Ethereum into a single currency?

I don't need to have this plan to study the VC incentive structure that powers their market competition and is responsible for the market fracture. I might even be wrong in my assessment, but not because I lack this hypothetical plan you are asking.

Re: What Happened to HackerOne?

#203
post #28

> To the companies: You don’t need HackerOne anymore. The tokens to build your own in-house platform cost less than single year of HackerOne. You know, the biggest thing that HackerOne delivers is a universal payments system that requires absolutely no efforts from companies. Have you tried to manually pay hackers from around the world? It is a laborious process involving trying to find what providers are compatible…

This is, in general, a good statement of a durable problem one can 'solve' profitably. Basically take a problem that is hard to do 1:1, systemize it such that you can easily tune the solution to "all" variants of that problem, and then sell that as a service taking a percentage which is still going to be less than the cost of the customer doing a one-off solution.

Re: What Happened to HackerOne?

#204
post #104

Earlier quoted context omitted.

This and the pre-triage are the only reasons we even use a bug bounty platform. If paying out bounties was easy I would do it all via email; but as you said it’s almost impossible to do (unless you are maybe bigcorp and have a team just for that)

My largest problem with H1 is how braindead scripted/AI their triage is. - Starting scenario: no way to contact a company outside of H1 (or some other managed programme) - The company is compromised, their customer support has no idea what this means, they have no security.txt or any other security contact - I have explicitly told H1 to just forward it with no bounty, I don't want a bounty, only remediation, I do not…

If a company's server is attacking yours, I'd go to legal@company.com before I go to H1.

Re: What Happened to HackerOne?

#205

Earlier quoted context omitted.

So what's your plan to merge Bitcoin, Monero and Ethereum into a single currency?

I don't need to have this plan to study the VC incentive structure that powers their market competition and is responsible for the market fracture. I might even be wrong in my assessment, but not because I lack this hypothetical plan you are asking.

If other people are telling you that it's technically impossible and you can't even come up with a sketch of a technical design that works, that is a clue that it may be technically impossible.

No country will intentionally make its economy completely reliant on another country unless things are completely in the shitter (like Zimbabwe switching to US$). Even Visa/MC are a problem in Europe and they only act at the highest layers of the stack - there are plenty of ways to transfer money without relying on Visa/MC but cutting them off would already be a huge disruption.

Re: What Happened to HackerOne?

#206

Sending the sales team on a paid vacation to a tropical paradise while the engineering product flounders is such a perfect representation of corporate rot it sounds like something out of a Mike Judge movie

This is normal. Almost 3 decades in the industry and sales get very nice vacation to tropical paradise all the time. At best we go some decent conference.

Re: What Happened to HackerOne?

#207
post #86

Earlier quoted context omitted.

> universal payments system that requires absolutely no efforts from companies. Indeed. I use a third party company (not HackerOne) to handle our bug bounty and the primary reason is so they handle all the payment hassles, I don't need to be involved. They also handle all the screening for false positives, which in the AI age are exploding. I also don't want to deal with that. In general I lean towards building in-ho…

Mind sharing which company you use for this?

There are many options, probably mostly equivalent, just depends where you can negotiate a price agreeable to your budget.

But to answer the question, currently using Inspectiv.

Re: What Happened to HackerOne?

#208

Earlier quoted context omitted.

Literally just pay them in bitcoin. They're hackers, they'll be able to handle it.

That solves the literal "how to pay" but so does an envelope full of cash via FedEx. That's not the actual complicated part of legally paying someone for contract work in a foreign possibly-hostile nation.

In the early days Meta (Facebook back then) used to pay bounties by physically mailing pre-paid debit cards, so you are not far off with the idea of envelopes full of cash.

Re: What Happened to HackerOne?

#209

Earlier quoted context omitted.

I don't need to have this plan to study the VC incentive structure that powers their market competition and is responsible for the market fracture. I might even be wrong in my assessment, but not because I lack this hypothetical plan you are asking.

If other people are telling you that it's technically impossible and you can't even come up with a sketch of a technical design that works, that is a clue that it may be technically impossible. No country will intentionally make its economy completely reliant on another country unless things are completely in the shitter (like Zimbabwe switching to US$). Even Visa/MC are a problem in Europe and they only act at the h…

Not sure why we sidetracked to crypto, it's not relevant for the discussion. They wouldn't be suitable for such global payment systems even if they were unified, given their volatility.
Post reply on HN