Not only was there significant personal liability, but there had been multiple instances of hackers being criminally charged and sentenced to jail time for finding and reporting security vulnerabilities prior to this. I don't think this is true, although it's a very commonly-held belief. Dan Goodin (I think?) wrote an article about this a long time ago, and was only able to come up with a few examples, and none of th…
What Happened to HackerOne?
71–80 of 210 posts
Re: What Happened to HackerOne?
#72Earlier quoted context omitted.
That is a Silicon Valley thing, around the world you get a regular office salary and that's it.
First of all it's not just SV - all of US sales is like this. Second, if you're talking about Europe - base/variable comps split may not be 50/50 but it's often the same OTE structure with some modifications due to local legalese
I never seen this on my 30+ years on the job, other than being an early joiner to startups, equity isn't a thing.
> Engineers who find it distasteful should be happy to know engineers typically get way more equity than sales reps.
At very best, some companies might offer some kind of fixed bonus, if you over delivered as part of the KPI/OKR/whatever goals for the year, or the profits were nice enough that everyone gets a cut.
Re: What Happened to HackerOne?
#73I literally showed them their server taking over a minute to respond to my request. I even showed how the delay increased proportionally to the message size... Clearly doing more processing; classic DoS vulnerability... Doesn't leave much to the imagination! But they said they would not pay me anything unless I actually proved that it scaled and caused disruption of their service!
It seemed like they were baiting me into incriminating myself for a crime that they wanted me to commit against them. It's not even the first time that I've been baited by a software company into committing a crime against themselves. I never took the bait though.
Re: What Happened to HackerOne?
#74When COVID restrictions were lifted, travel and t&e budgets just never returned. Layoffs started happening and what were lavish, expensive events just couldn’t happen anymore. Hackerone charged for and likely made a lot of money on these events. I think a lot of what is talked about in the article is true but I think Covid is a big part of the why that led to it.
Re: What Happened to HackerOne?
#75Earlier quoted context omitted.
First of all it's not just SV - all of US sales is like this. Second, if you're talking about Europe - base/variable comps split may not be 50/50 but it's often the same OTE structure with some modifications due to local legalese
I am talking about software developers, not sales. I never seen this on my 30+ years on the job, other than being an early joiner to startups, equity isn't a thing. > Engineers who find it distasteful should be happy to know engineers typically get way more equity than sales reps. At very best, some companies might offer some kind of fixed bonus, if you over delivered as part of the KPI/OKR/whatever goals for the yea…
Even without the equity part i think most engineers should be thankful for not having to hit their kpis to get full paycheck
Re: What Happened to HackerOne?
#76Last time I reported a DoS bug to HackerOne, the company behind the bounty tried incite me to commit a crime against them by DoS'ing their servers using the hack I had reported in detail! I literally showed them their server taking over a minute to respond to my request. I even showed how the delay increased proportionally to the message size... Clearly doing more processing; classic DoS vulnerability... Doesn't leav…
Re: What Happened to HackerOne?
#77Earlier quoted context omitted.
First of all it's not just SV - all of US sales is like this. Second, if you're talking about Europe - base/variable comps split may not be 50/50 but it's often the same OTE structure with some modifications due to local legalese
I am talking about software developers, not sales. I never seen this on my 30+ years on the job, other than being an early joiner to startups, equity isn't a thing. > Engineers who find it distasteful should be happy to know engineers typically get way more equity than sales reps. At very best, some companies might offer some kind of fixed bonus, if you over delivered as part of the KPI/OKR/whatever goals for the yea…
Re: What Happened to HackerOne?
#78> To the companies: You don’t need HackerOne anymore. The tokens to build your own in-house platform cost less than single year of HackerOne. You know, the biggest thing that HackerOne delivers is a universal payments system that requires absolutely no efforts from companies. Have you tried to manually pay hackers from around the world? It is a laborious process involving trying to find what providers are compatible…
Just pay them in stable coins. That's a solved problem.
It's also complying with tax and employment laws in the country the hacker is in, to the satisfaction of your legal and finance teams.
Sure, in western-style legal systems you can call them a contractor and they can pay their own tax. Just don't employ them full time for long enough to trigger 'sham contract' rules that would make them employees.
But your corporate legal team doesn't have anyone trained and licensed to give advice on Tajikistan tax and employment law, so they can't approve this proposed contract without hiring an outside legal expert. And of course all suppliers, regardless of country, must agree to our anti-slave-labour policy which permits audits of...
One might say "skip that nonsense, just send the money" - but the larger the company, the more their in-house infosec becomes a load of uptight squares who love compliance and audit. And the kind of companies that can pay out five-figure bounties tend to be pretty large.
Re: What Happened to HackerOne?
#79> To the companies: You don’t need HackerOne anymore. The tokens to build your own in-house platform cost less than single year of HackerOne. You know, the biggest thing that HackerOne delivers is a universal payments system that requires absolutely no efforts from companies. Have you tried to manually pay hackers from around the world? It is a laborious process involving trying to find what providers are compatible…
This and the pre-triage are the only reasons we even use a bug bounty platform. If paying out bounties was easy I would do it all via email; but as you said it’s almost impossible to do (unless you are maybe bigcorp and have a team just for that)
Outsourcing all that mess is a great use of money.
Re: What Happened to HackerOne?
#80I know Joel well and think a lot here is both accurate and well written. I led the Yahoo bug bounty program from 2023-2024 and was involved in it from about 2021. A major event that this glosses over is Covid which also happened right around this time as well. Covid killed travel (and budget) which in turn made it impossible to do the live events. A lot of companies ended up shifting to virtual live events which just…
It is also worth remembering that the cost of travel itself, and the cost of venues itself has also increased substantially. As well as associated costs such as catering and insurance.
So in-person events have issues from both sides, those attending and those hosting.
You also do not mention corporate policies. Under pressure from investors, their employees and sometimes their home-countries, many corporates have also introduced environmental policies. So if you want the company to pay for your flight, you not only have to justify it financially, but you have to justify it environmentally too.