Live data from Hacker News

Restructuring GitHub's bug bounty program

github.blog

31–38 of 38 posts

Re: Restructuring GitHub's bug bounty program

#31

Earlier quoted context omitted.

> So far cons > pros Lets say 80% of the world's population decides the cons outweight the pros, now what? Put the genie back in the bottle, something that is famously easy and trivial to do?

If the will was there we could shut down commercial providers tomorrow, which would already solve most of the problem.

Alright, so assuming thats done now, obviously everyone moves to local models. Would the suggestion be to outlaw those too, and if so, what would the enforcement look like?

Re: Restructuring GitHub's bug bounty program

#32
post #6

Earlier quoted context omitted.

It might, but as someone who has to review public vulnerability reports for a much less popular website, I completely understand why they’re building a vouch program to dissuade slop reports. One would presume their internal team is using frontier models for red team agent scanning against potential attack surface, and so this is a potential risk they’re willing to take. Tragedy of the commons that someone who hasn’t…

tbh hackerone should just implement a +/- reputation points feature on researcher profiles. Like, the researcher submits a slop report to GitHub via H1, GitHub looks at it and identifies it as slop, GitHub presses the -rep button on reaearcher profile which bans them from submitting to GitHub on H1 again and makes their rep points minus 1. Companies should be able to configure you need at least 10 rep points to recei…

Signal and Reputation already do these things but public programs are…well public.

Re: Restructuring GitHub's bug bounty program

#33
post #14

> We’re formalizing a permanent private/invite-only VIP program for qualified researchers who consistently deliver high-quality, high-impact work. > VIP program bounty table: Severity Payout -------- -------- Low $1,000 Medium $7,500 High $20,000 Critical $30,000+ > We are adjusting our public program rates to accommodate this shift in focus towards quality of relationships and findings over quantity of reports. We a…

> VIP program for qualified researchers who consistently deliver high-quality, high-impact work. Almost as though they want the quality and consistency of hired labor but not the cost

it's voluntary and a nice incentive for those whose have spent time on getting familiar with the systems.

also given that nowadays most bounty hunters have some level of automation don't see the issue of getting paid by the task instead of the by the hour. diversification of source of income is always good :)

Re: Restructuring GitHub's bug bounty program

#34

Earlier quoted context omitted.

It might, but as someone who has to review public vulnerability reports for a much less popular website, I completely understand why they’re building a vouch program to dissuade slop reports. One would presume their internal team is using frontier models for red team agent scanning against potential attack surface, and so this is a potential risk they’re willing to take. Tragedy of the commons that someone who hasn’t…

You're forgetting that GitHub aka Microsoft is one of the big slop peddlers. They made the problem but now don't want to pay for it.

Large organizations are complex machines. The security team responsible for triaging these reports is very likely not the same as the one peddling slop. The nuance and irony is not lost on me.

Re: Restructuring GitHub's bug bounty program

#36

So if the "wrong" person finds a critical vulnerability in GitHub, the payout is capped at $10,000. Might reduce the likelihood of it being submitted to the bug bounty program.

It might, but as someone who has to review public vulnerability reports for a much less popular website, I completely understand why they’re building a vouch program to dissuade slop reports. One would presume their internal team is using frontier models for red team agent scanning against potential attack surface, and so this is a potential risk they’re willing to take. Tragedy of the commons that someone who hasn’t…

vouch programs where other users put their trust in you are a good thing. this is a centralized vip program where membership can be added or removed from anyone for no reason. there is no guaranteed way to get in. its a private club not a trust system.

Re: Restructuring GitHub's bug bounty program

#37

Seems to me like the game theory here is un-credentialed reporters need to submit their reports through credentialed folks who will vet and take a cut on the way through. Why take the lower offer by going directly. That sounds like a win for everyone involved.

still removing work from github.

this is formalizing some very enterprise-esque processes for security research, software resellers anyone?

Re: Restructuring GitHub's bug bounty program

#38
post #30

Earlier quoted context omitted.

You're forgetting that GitHub aka Microsoft is one of the big slop peddlers. They made the problem but now don't want to pay for it.

"one of the big" is an understatement. They own OpenAI, which created and popularized the whole field.

Saying they “own” OpenAI is a massive stretch, considering their stake is less than 30%, post-recapitalization into a PBC.
Post reply on HN