Live data from Hacker News

What Happened to HackerOne?

blog.teknogeek.io

81–90 of 210 posts

Re: What Happened to HackerOne?

#81
post #76

Last time I reported a DoS bug to HackerOne, the company behind the bounty tried incite me to commit a crime against them by DoS'ing their servers using the hack I had reported in detail! I literally showed them their server taking over a minute to respond to my request. I even showed how the delay increased proportionally to the message size... Clearly doing more processing; classic DoS vulnerability... Doesn't leav…

To be fair “we will compensate you if you do X” sounds a lot like a contract so you’d probably be just fine in court. (Though likely wise to avoid the chance of a legal headache)

I don't trust the legal system. They could cover up the evidence, get me blocked on HackerOne, claim that my screenshots are AI-generated, hire top lawyers then make the judge to charge me for the lawyers' bill.

The big company always wins. The legal system is pure fiction at this point. What lawyer would stand against the big companies? Permanently destroying all their future career prospects.

Erin Brockovich? That's a corporate propaganda movie.

Reality is more like what happened to Julian Assange or Steven Donziger. And they had support from some powerful groups. If they didn't, we wouldn't even have heard of them. That would have been my situation. Not worth the $200 bounty.

Re: What Happened to HackerOne?

#82
post #51

Earlier quoted context omitted.

Also PITA for people as well, we have a 33% tax on crypto selling here in Italy on profits…

why its fucking high ??

Italy has progressive taxes on salary, with marginal rates from 23% to 43%. The latter on income above €50k

And if you've got taxes like that on earned income - shouldn't people with unearned income pay just as much? If your tax on investment gains is too small, you end up with an economy where the salaried worker renting a house pays more tax than their landlord, who owns ten houses.

Re: What Happened to HackerOne?

#83
post #19

I reported some exploits on hackerone. Most got dismissed. One of them, a remotely triggerable DoS vector got downgraded in severity. I got a token payment from the company, and 7 years later, it is still not marked as resolved. I doubt my situation is unique.

One of my only bug bounty payouts was a DoS against a site via their customer query engine. I was quite proud of it, and was relieved when they actually paid out a token amount.

It took down the entire application for all users and tenants, not just the tenant submitting the poisoned query.

I don't remember how much I was paid, a token amount for sure, but I was happy with any amount because it was a hobby and any payment was good for the CV.

Re: What Happened to HackerOne?

#84
post #51

Earlier quoted context omitted.

PITA for a large company to handle stable coins etc with accounting, etc

Also PITA for people as well, we have a 33% tax on crypto selling here in Italy on profits…

But we are talking here about assets you just receive. Not buy and resell.

Re: What Happened to HackerOne?

#85
post #19

I reported some exploits on hackerone. Most got dismissed. One of them, a remotely triggerable DoS vector got downgraded in severity. I got a token payment from the company, and 7 years later, it is still not marked as resolved. I doubt my situation is unique.

I reported a security bug, it was all processed very quickly and I got paid. I doubt my situation is unique.

I think it would be the individual companies slowing things down, not the platform.

Re: What Happened to HackerOne?

#86
post #28

> To the companies: You don’t need HackerOne anymore. The tokens to build your own in-house platform cost less than single year of HackerOne. You know, the biggest thing that HackerOne delivers is a universal payments system that requires absolutely no efforts from companies. Have you tried to manually pay hackers from around the world? It is a laborious process involving trying to find what providers are compatible…

> universal payments system that requires absolutely no efforts from companies.

Indeed. I use a third party company (not HackerOne) to handle our bug bounty and the primary reason is so they handle all the payment hassles, I don't need to be involved. They also handle all the screening for false positives, which in the AI age are exploding. I also don't want to deal with that.

In general I lean towards building in-house, but this is one area I'm happy to oursource all the busywork.

Re: What Happened to HackerOne?

#87

Earlier quoted context omitted.

Doesn't that problem benefit from having automatic bug triage that can avoid fast tracking these bad reports?

An LLM finds a dubious bug, an LLM turns it into a convincing report, and now the proposed solution is to have an LLM triage it? There are a lot of turtles holding up this approach and the circular logic seems hard to miss. Automated triage can filter obvious spam, which was already fast and easy for humans to do. The hard part is independently reproducing a plausible finding and assessing its actual impact. If LLMs…

>If you could build the thing they wanted to build it would fix the slop problem

It sounds like a reason to try and build it than a reason to not build it.

Re: What Happened to HackerOne?

#88

Sending the sales team on a paid vacation to a tropical paradise while the engineering product flounders is such a perfect representation of corporate rot it sounds like something out of a Mike Judge movie

I'm confused at the way they promoted it. Is there any way someone outside the company reading a Twitter post would consider this a positive thing for the product to be told what incentives the sales team get?

It's not aimed at consumers of their product.

Someone outside the company who was thinking of joining a B2B sales team, and who likes tropical vacations, might react positively to this post.

Or a potential investor might be impressed to see the company has a mature sales pipeline and plenty of revenue to reward its top salespeople.

Re: What Happened to HackerOne?

#90
post #79

Earlier quoted context omitted.

This and the pre-triage are the only reasons we even use a bug bounty platform. If paying out bounties was easy I would do it all via email; but as you said it’s almost impossible to do (unless you are maybe bigcorp and have a team just for that)

I worked at a big corp and we paid out randoms for a program (not bug bounty). It was an absolute minefield, people would lie to us about where they were located only for us to find out they’re in and then legal tells us we have to pay them but we’re not allowed to at the same time. Outsourcing all that mess is a great use of money.

Yea we also handled it ourselves the first couple years but it was so painful. Literally the same thing you described happened - as well spending weeks+ how we need to file it as tax when we pay bounty to someone in Pakistan etc.
Post reply on HN