Earlier quoted context omitted.
Just pay them in stable coins. That's a solved problem.
PITA for a large company to handle stable coins etc with accounting, etc
What Happened to HackerOne?
51–60 of 210 posts
Re: What Happened to HackerOne?
#52Sending the sales team on a paid vacation to a tropical paradise while the engineering product flounders is such a perfect representation of corporate rot it sounds like something out of a Mike Judge movie
Presidents club is a standard way to reward top performing sales reps across many industries. It doesn't indicate anything other than the company is trying to reward and retain their top sales reps. Engineers who find it distasteful should be happy to know engineers typically get way more equity than sales reps.
Re: What Happened to HackerOne?
#53> To the companies: You don’t need HackerOne anymore. The tokens to build your own in-house platform cost less than single year of HackerOne. You know, the biggest thing that HackerOne delivers is a universal payments system that requires absolutely no efforts from companies. Have you tried to manually pay hackers from around the world? It is a laborious process involving trying to find what providers are compatible…
If paying out bounties was easy I would do it all via email; but as you said it’s almost impossible to do (unless you are maybe bigcorp and have a team just for that)
Re: What Happened to HackerOne?
#54All good things don't last forever. A organization or company lasting forever with the same goal/mission while using the same methods is a statistical anomaly.
What is the corrupting force?
Re: What Happened to HackerOne?
#55Not only was there significant personal liability, but there had been multiple instances of hackers being criminally charged and sentenced to jail time for finding and reporting security vulnerabilities prior to this. I don't think this is true, although it's a very commonly-held belief. Dan Goodin (I think?) wrote an article about this a long time ago, and was only able to come up with a few examples, and none of th…
I can think of 4-5 other situations from around that era (~2012) where people were at least charged and needed a lot of help to navigate the legal proceedings to avoid jail time.
In 2010 it was more than risky on paper.
2017-2018 is well into the established era and probably even the golden age of bug bounties when a lot of corporate and judicial thinking re: white hat cybersecurity had been shifted.
Re: What Happened to HackerOne?
#56Earlier quoted context omitted.
Presidents club is a standard way to reward top performing sales reps across many industries. It doesn't indicate anything other than the company is trying to reward and retain their top sales reps. Engineers who find it distasteful should be happy to know engineers typically get way more equity than sales reps.
That is a Silicon Valley thing, around the world you get a regular office salary and that's it.
Re: What Happened to HackerOne?
#57> To the companies: You don’t need HackerOne anymore. The tokens to build your own in-house platform cost less than single year of HackerOne. You know, the biggest thing that HackerOne delivers is a universal payments system that requires absolutely no efforts from companies. Have you tried to manually pay hackers from around the world? It is a laborious process involving trying to find what providers are compatible…
Just pay them in stable coins. That's a solved problem.
Re: What Happened to HackerOne?
#58Earlier quoted context omitted.
From what I've seen in the bounty-related subreddits, AI is flooding bug bounty inboxes with low-value or meaningless reports, or straight-up hallucinations when people use smaller models (to turn a profit, you make lots of low-value bug reports and see who pays out). This has a negative effect on humans doing their work with or without LLMs: curl shut down their bounty program, and GitHub just announced they're "res…
Doesn't that problem benefit from having automatic bug triage that can avoid fast tracking these bad reports?
Automated triage can filter obvious spam, which was already fast and easy for humans to do. The hard part is independently reproducing a plausible finding and assessing its actual impact. If LLMs could already do that reliably, then the slop report problem wouldn't exist in the first place.