Earlier quoted context omitted.
> So far cons > pros Lets say 80% of the world's population decides the cons outweight the pros, now what? Put the genie back in the bottle, something that is famously easy and trivial to do?
If the will was there we could shut down commercial providers tomorrow, which would already solve most of the problem.
Restructuring GitHub's bug bounty program
31–38 of 38 posts
Re: Restructuring GitHub's bug bounty program
#32Earlier quoted context omitted.
It might, but as someone who has to review public vulnerability reports for a much less popular website, I completely understand why they’re building a vouch program to dissuade slop reports. One would presume their internal team is using frontier models for red team agent scanning against potential attack surface, and so this is a potential risk they’re willing to take. Tragedy of the commons that someone who hasn’t…
tbh hackerone should just implement a +/- reputation points feature on researcher profiles. Like, the researcher submits a slop report to GitHub via H1, GitHub looks at it and identifies it as slop, GitHub presses the -rep button on reaearcher profile which bans them from submitting to GitHub on H1 again and makes their rep points minus 1. Companies should be able to configure you need at least 10 rep points to recei…
Re: Restructuring GitHub's bug bounty program
#33> We’re formalizing a permanent private/invite-only VIP program for qualified researchers who consistently deliver high-quality, high-impact work. > VIP program bounty table: Severity Payout -------- -------- Low $1,000 Medium $7,500 High $20,000 Critical $30,000+ > We are adjusting our public program rates to accommodate this shift in focus towards quality of relationships and findings over quantity of reports. We a…
> VIP program for qualified researchers who consistently deliver high-quality, high-impact work. Almost as though they want the quality and consistency of hired labor but not the cost
also given that nowadays most bounty hunters have some level of automation don't see the issue of getting paid by the task instead of the by the hour. diversification of source of income is always good :)
Re: Restructuring GitHub's bug bounty program
#34Earlier quoted context omitted.
It might, but as someone who has to review public vulnerability reports for a much less popular website, I completely understand why they’re building a vouch program to dissuade slop reports. One would presume their internal team is using frontier models for red team agent scanning against potential attack surface, and so this is a potential risk they’re willing to take. Tragedy of the commons that someone who hasn’t…
You're forgetting that GitHub aka Microsoft is one of the big slop peddlers. They made the problem but now don't want to pay for it.
Re: Restructuring GitHub's bug bounty program
#35I wonder if this incentivizes people to form groups that self-vet for quality submissions to enhance their reputation.
Re: Restructuring GitHub's bug bounty program
#36So if the "wrong" person finds a critical vulnerability in GitHub, the payout is capped at $10,000. Might reduce the likelihood of it being submitted to the bug bounty program.
It might, but as someone who has to review public vulnerability reports for a much less popular website, I completely understand why they’re building a vouch program to dissuade slop reports. One would presume their internal team is using frontier models for red team agent scanning against potential attack surface, and so this is a potential risk they’re willing to take. Tragedy of the commons that someone who hasn’t…
Re: Restructuring GitHub's bug bounty program
#37Seems to me like the game theory here is un-credentialed reporters need to submit their reports through credentialed folks who will vet and take a cut on the way through. Why take the lower offer by going directly. That sounds like a win for everyone involved.
this is formalizing some very enterprise-esque processes for security research, software resellers anyone?
Re: Restructuring GitHub's bug bounty program
#38Earlier quoted context omitted.
You're forgetting that GitHub aka Microsoft is one of the big slop peddlers. They made the problem but now don't want to pay for it.
"one of the big" is an understatement. They own OpenAI, which created and popularized the whole field.