Live data from Hacker News

What Happened to HackerOne?

blog.teknogeek.io

51–60 of 210 posts

Re: What Happened to HackerOne?

#51

Earlier quoted context omitted.

Just pay them in stable coins. That's a solved problem.

PITA for a large company to handle stable coins etc with accounting, etc

Also PITA for people as well, we have a 33% tax on crypto selling here in Italy on profits…

Re: What Happened to HackerOne?

#52
post #32

Sending the sales team on a paid vacation to a tropical paradise while the engineering product flounders is such a perfect representation of corporate rot it sounds like something out of a Mike Judge movie

Presidents club is a standard way to reward top performing sales reps across many industries. It doesn't indicate anything other than the company is trying to reward and retain their top sales reps. Engineers who find it distasteful should be happy to know engineers typically get way more equity than sales reps.

That is a Silicon Valley thing, around the world you get a regular office salary and that's it.

Re: What Happened to HackerOne?

#53
post #28

> To the companies: You don’t need HackerOne anymore. The tokens to build your own in-house platform cost less than single year of HackerOne. You know, the biggest thing that HackerOne delivers is a universal payments system that requires absolutely no efforts from companies. Have you tried to manually pay hackers from around the world? It is a laborious process involving trying to find what providers are compatible…

This and the pre-triage are the only reasons we even use a bug bounty platform.

If paying out bounties was easy I would do it all via email; but as you said it’s almost impossible to do (unless you are maybe bigcorp and have a team just for that)

Re: What Happened to HackerOne?

#54

All good things don't last forever. A organization or company lasting forever with the same goal/mission while using the same methods is a statistical anomaly.

What is the corrupting force?

Bureaucracy is a major one, as it tends to dissipate more and more resources to sustain its own infrastructure, neglecting the core mission (J. Pournelle's Law).

Re: What Happened to HackerOne?

#55
post #18

Not only was there significant personal liability, but there had been multiple instances of hackers being criminally charged and sentenced to jail time for finding and reporting security vulnerabilities prior to this. I don't think this is true, although it's a very commonly-held belief. Dan Goodin (I think?) wrote an article about this a long time ago, and was only able to come up with a few examples, and none of th…

https://m.slashdot.org/story/159162-- example circa 2011

I can think of 4-5 other situations from around that era (~2012) where people were at least charged and needed a lot of help to navigate the legal proceedings to avoid jail time.

In 2010 it was more than risky on paper.

2017-2018 is well into the established era and probably even the golden age of bug bounties when a lot of corporate and judicial thinking re: white hat cybersecurity had been shifted.

Re: What Happened to HackerOne?

#56
post #52
post #32

Earlier quoted context omitted.

Presidents club is a standard way to reward top performing sales reps across many industries. It doesn't indicate anything other than the company is trying to reward and retain their top sales reps. Engineers who find it distasteful should be happy to know engineers typically get way more equity than sales reps.

That is a Silicon Valley thing, around the world you get a regular office salary and that's it.

First of all it's not just SV - all of US sales is like this. Second, if you're talking about Europe - base/variable comps split may not be 50/50 but it's often the same OTE structure with some modifications due to local legalese

Re: What Happened to HackerOne?

#57
post #28

> To the companies: You don’t need HackerOne anymore. The tokens to build your own in-house platform cost less than single year of HackerOne. You know, the biggest thing that HackerOne delivers is a universal payments system that requires absolutely no efforts from companies. Have you tried to manually pay hackers from around the world? It is a laborious process involving trying to find what providers are compatible…

Just pay them in stable coins. That's a solved problem.

You got downvoted, but sadly we have 2026 and it's still not easy to send money to any bank in the world. You can say a lot of bad things about the crypto world, but thats a problem Bitcoin solved two decades ago.

Re: What Happened to HackerOne?

#58
post #14

Earlier quoted context omitted.

From what I've seen in the bounty-related subreddits, AI is flooding bug bounty inboxes with low-value or meaningless reports, or straight-up hallucinations when people use smaller models (to turn a profit, you make lots of low-value bug reports and see who pays out). This has a negative effect on humans doing their work with or without LLMs: curl shut down their bounty program, and GitHub just announced they're "res…

Doesn't that problem benefit from having automatic bug triage that can avoid fast tracking these bad reports?

An LLM finds a dubious bug, an LLM turns it into a convincing report, and now the proposed solution is to have an LLM triage it? There are a lot of turtles holding up this approach and the circular logic seems hard to miss.

Automated triage can filter obvious spam, which was already fast and easy for humans to do. The hard part is independently reproducing a plausible finding and assessing its actual impact. If LLMs could already do that reliably, then the slop report problem wouldn't exist in the first place.

Post reply on HN