What Happened to HackerOne?

(blog.teknogeek.io)

326 points | by hipparchus 13 hours ago

28 comments

  • Shank 11 hours ago
    > To the companies: You don’t need HackerOne anymore. The tokens to build your own in-house platform cost less than single year of HackerOne.

    You know, the biggest thing that HackerOne delivers is a universal payments system that requires absolutely no efforts from companies. Have you tried to manually pay hackers from around the world? It is a laborious process involving trying to find what providers are compatible and what forms of money go where. It is extremely taxing to handle this. HackerOne provides real, tangible value in not making people think about how precisely to pay a hacker and in what currency. No amount of tokens solve the accounting problem, and it is foolish to imply otherwise.

    • jerf 1 hour ago
      This is a great example of a general trend, which is why I don't think SaaS is going anywhere. The bar may be raised, but it's not going anywhere. HackerOne and SaaS in general makes problems go away for money. If you use your own tokens and solve it yourself, it's still your problem. The deficiencies are your problem. The support and ongoing maintenance are your problem. Discovering some country split in two and now has to have currency handled in some other way is still your problem. And they never end.

      I see some people with the idea that businesses are going to use AI to solve everything in their own one-off bespoke manners for everything, but I don't think it's going to happen. What's going to happen is that the SaaS providers are going to get even better at making yet more stuff go away than they were before and it'll actually be harder for a business to replicate it themselves then it used to be.

      (Of course the "go away" isn't perfect, but clearly, neither is the idea that solving everything yourself with AI is either.)

      • ceejayoz 1 hour ago
        > If you use your own tokens and solve it yourself, it's still your problem.

        The flip side, of course, is that I can fix my problem - which may be unique and not something a large SaaS will ever do - on my timeline.

        • jerf 43 minutes ago
          That's not a new flip side, though. That's always been with us. SaaS will be more able to take on more requirements then they used to be but no one SaaS will ever be able to take on everything. And the decision between "roll our own and own it forever versus buy this one service that almost does everything we need, but not quite, but maybe it's worth living with it because it's still better than rolling it ourselves" isn't going anywhere either.

          I would not want to be a SaaS that offers some really simple service that can be replicated in a heartbeat, though. Something like "how do I pay people all over the world" is already very complicated, and over the next decades as governments start writing laws with the understanding that AIs can implement them in code no matter how complicated they are, it's likely these problems will become even more complicated and even more important to just buy a service that can deal with them. (I'm not celebrating that, merely predicting it.) But I sure wouldn't want to be selling some super simple scheduled reminder service or something else really small.

          In the worst case, envision a world where home owner associations or townships or whatever other local governmental division of just perhaps a few hundred people start levying sales taxes, with their own complicated exclusions and offsets and conditions, because LLMs make it possible to handle the code for all of the literally hundreds of thousands or millions of such jurisdictions. Even if you can throw tokens at that problem to solve it yourself, you probably don't want to. And again... I'm not celebrating that. More a world-weary bowing to the inevitable despite it being an obviously bad idea.

          • ceejayoz 41 minutes ago
            > That's always been with us.

            But the ability to meaningfully make a personal implementation has changed.

    • jjav 6 hours ago
      > universal payments system that requires absolutely no efforts from companies.

      Indeed. I use a third party company (not HackerOne) to handle our bug bounty and the primary reason is so they handle all the payment hassles, I don't need to be involved. They also handle all the screening for false positives, which in the AI age are exploding. I also don't want to deal with that.

      In general I lean towards building in-house, but this is one area I'm happy to oursource all the busywork.

    • GeneticGenesis 5 hours ago
      Yep, spot on - this and some level of inbound filtering are the only reason we use an external platform.

      That said, with the volume of inbound reports coming from LLMs, the signal-to-noise ratio has plummeted, and the time taken to triage has gone through the roof.

    • icantevenhold 9 hours ago
      This and the pre-triage are the only reasons we even use a bug bounty platform.

      If paying out bounties was easy I would do it all via email; but as you said it’s almost impossible to do (unless you are maybe bigcorp and have a team just for that)

      • maccard 7 hours ago
        I worked at a big corp and we paid out randoms for a program (not bug bounty). It was an absolute minefield, people would lie to us about where they were located only for us to find out they’re in <insert sanctioned country here> and then legal tells us we have to pay them but we’re not allowed to at the same time.

        Outsourcing all that mess is a great use of money.

        • icantevenhold 6 hours ago
          Yea we also handled it ourselves the first couple years but it was so painful. Literally the same thing you described happened - as well spending weeks+ how we need to file it as tax when we pay bounty to someone in Pakistan etc.
          • weird-eye-issue 5 hours ago
            Are you in the US? You simply collect a W8 from them that you keep on file and then the payment would be counted as an expense on taxes. We do payout to hundreds o f affiliates every year and this is how we handle it, it's really not complicated. The actual payments are done via Wise batch payments which just requires their email address.
      • kay_o 5 hours ago
        My largest problem with H1 is how braindead scripted/AI their triage is.

        - Starting scenario: no way to contact a company outside of H1 (or some other managed programme)

        - The company is compromised, their customer support has no idea what this means, they have no security.txt or any other security contact

        - I have explicitly told H1 to just forward it with no bounty, I don't want a bounty, only remediation, I do not care about a bounty or any reward

        - H1 closes as "not eligible" and tells me to not submit stuff I can't prove it's my compromise by putting my username on it

        - Corporate server is still compromised and being used as a proxy to brute force my services

    • gchamonlive 3 hours ago
      This (money transfer) is one thing Pix would solve trivially.
      • nonethewiser 3 hours ago
        Any universal system would. The problem is there isnt a universal system.
        • gchamonlive 1 hour ago
          That's untrue because it assumes all systems are interchangeable just because they are centralized and global, but intention matters and how you operate them creates hidden incentives that can alter how these systems evolve over time. Pix in Brazil, unlike other solutions, is entirely state-run and shouldn't suffer from investor pressure. It can still potentially suffer from service quality degradation and lack of transparency, but enshitification and anti-consumer practices are also very much present in private-owned initiatives, so it's not exclusive to this project.
      • gruez 58 minutes ago
        ...or UPI (India), wechat pay/alipay (China), SEPA (EU). The problem is that none of these systems are actually global.
        • gchamonlive 19 minutes ago
          Hence "would solve" and not "solves"
    • gyanchawdhary 4 hours ago
      Interesting. Do you think they are using something like Deel/Stripe to handle a lot of this ? i mean to figure out the "paying ppl around the world" complexity ... also local payment methods .. currencies .. compliance .. tax docs etc ?
    • stellamariesays 1 hour ago
      [flagged]
    • inigyou 5 hours ago
      Literally just pay them in bitcoin. They're hackers, they'll be able to handle it.
      • StilesCrisis 2 hours ago
        That solves the literal "how to pay" but so does an envelope full of cash via FedEx. That's not the actual complicated part of legally paying someone for contract work in a foreign possibly-hostile nation.
    • AustinDev 10 hours ago
      Just pay them in stable coins. That's a solved problem.
      • michaelt 7 hours ago
        It's not just the transfer of cash.

        It's also complying with tax and employment laws in the country the hacker is in, to the satisfaction of your legal and finance teams.

        Sure, in western-style legal systems you can call them a contractor and they can pay their own tax. Just don't employ them full time for long enough to trigger 'sham contract' rules that would make them employees.

        But your corporate legal team doesn't have anyone trained and licensed to give advice on Tajikistan tax and employment law, so they can't approve this proposed contract without hiring an outside legal expert. And of course all suppliers, regardless of country, must agree to our anti-slave-labour policy which permits audits of...

        One might say "skip that nonsense, just send the money" - but the larger the company, the more their in-house infosec becomes a load of uptight squares who love compliance and audit. And the kind of companies that can pay out five-figure bounties tend to be pretty large.

        • inigyou 5 hours ago
          Why would you or anyone in your American company care about complying with Tajikistan law?
          • michaelt 2 hours ago
            CISO: "We're going to invite random strangers from all around the globe to hack us, and pay them for their findings"

            CEO: "I'm not sure I like the idea of us inviting people to hack us - or paying a 'bounty' to hackers holding a knife to our throat. Will they at least agree to a binding NDA and terms of engagement, in advance?"

            CISO: "No, they won't."

            CEO: "Well, at least if the hackers are in poor countries, a $500 payout for a critical bug will be plenty, right?"

            CISO: "No, critical issues will be 10-100x that"

            CEO: "Well will the average quality of these reports better than those we get from our hired pentesters?"

            CISO: "On average these will be the lowest quality reports you've ever seen. But 0.1% might be gold. Oh, and I need to hire 3 more guys to sift through these terrible reports. Also our sifters might miss the gold."

            CEO: "Oh. Well at least we won't be breaking the law though, right?"

            CISO: "Uh, about that..."

          • ofjcihen 4 hours ago
            Less about that. More about “not accidentally funding terrorism” (or, more realistically, not giving money to sanctioned countries which can have significant consequences).
      • victorbjorklund 9 hours ago
        PITA for a large company to handle stable coins etc with accounting, etc
        • fuomag9 9 hours ago
          Also PITA for people as well, we have a 33% tax on crypto selling here in Italy on profits…
          • Jommi 8 hours ago
            stablecoins arent crypto in EU anymore, its e-money. No tax on converting to euros.
            • inigyou 5 hours ago
              IIRC all cryptocurrency that's money is money (so bitcoin, ethereum, etc but not necessarily project-specific tokens) and if you happen to make or lose money on a currency conversion it doesn't have tax implications.
              • Jommi 1 hour ago
                nope. not the case at all.
          • tonyhart7 8 hours ago
            why its fucking high ??
            • michaelt 7 hours ago
              Italy has progressive taxes on salary, with marginal rates from 23% to 43%. The latter on income above €50k

              And if you've got taxes like that on earned income - shouldn't people with unearned income pay just as much? If your tax on investment gains is too small, you end up with an economy where the salaried worker renting a house pays more tax than their landlord, who owns ten houses.

              • freeone3000 3 hours ago
                I think America’s tax policy and redistribution scheme have made it the country where private individuals have the most money in the world - and that saying the landlord should pay just as much tax disincentivizes wealth concentration!
            • bdavbdav 8 hours ago
              Same in a lot of countries - he said profits - it’s a taxable gain like any other asset or holding.
            • reddalo 8 hours ago
              I don't know. It used to be 26%, like capital gains from shares, securities, etc. but since 1st January 2026 crypto is taxed at 33% unless it's euro stablecoins (still 26%).

              At this point, I think most crypto investors in Italy will just evade taxes altogether.

          • dolmen 7 hours ago
            But we are talking here about assets you just receive. Not buy and resell.
            • jaapz 6 hours ago
              You can't buy bread with stable coins
        • Jommi 8 hours ago
          Im working on a solution to this. If you are interested pls email me at jommi(at)megaeth.com
      • MikeNotThePope 9 hours ago
        Buying stable coins is a mild pain because so many banks think crypto is radioactive. Then you have to wait for your deposited funds to completely settle before you can withdraw the crypto from your account and send it elsewhere. Doable, sure. Easy & convenient, not so much. I wouldn't call it a solved problem in the same way you can hand someone cash, tap to pay with your phone, or pay by scanning a QR Code.
        • Jommi 8 hours ago
          Not anymore! Most places allow this very easily now.
          • rvz 6 hours ago
            Exactly. Revolut is a bank that allows cryptocurrencies.

            HN really is living in their own bubble.

            • freeone3000 3 hours ago
              For those who can’t use Revolut: WealthSimple in Canada and Chase in the US offer custodial cryptocurrency accounts.
            • interactivecode 6 hours ago
              Revolut does not have a banking license in the US. At the moment they are a front for another bank. Don't be gullible and believe blindly what the marketing departments tell you.
              • Shorel 5 hours ago
                It works in Europe, which is one of the few advantages we have over the US.
              • rvz 3 hours ago
                > Revolut does not have a banking license in the US.

                The US is not the entire world.

                Revolut has major banking licenses in Europe, UK and Mexico. That doesn't mean it is not bank.

                Wells Fargo does not operate in the UK, but it is still a major bank in the US and it is still a bank.

                Royal Bank of Scotland (RBS) is a bank in the UK. Just because it doesn't operate in the US, does not mean it isn't a bank.

                > Don't be gullible and believe blindly what the marketing departments tell you.

                Revolut is still a major bank even if they don't operate in the US (yet).

            • stavros 6 hours ago
              No it doesn't. You can gamble with it, but it doesn't let you own or send it.
              • rvz 4 hours ago
                > No it doesn't.

                Yes it does.

                > You can gamble with it, but it doesn't let you own or send it.

                You can deposit (receive) and withdraw (send) cryptocurrencies there.

                "Owning" is a matter at the private key level which of course you use a self-hosted wallet for "true" ownership. But no argument was made on ownership.

                My point still stands that Revolut is a bank that allows cryptocurrencies.

                • stavros 4 hours ago
                  It doesn't let me, it says says sending crypto is temporarily blocked. Maybe they just blocked me.
                  • Jommi 1 hour ago
                    Highly country specific
      • DonHopkins 9 hours ago
        Skip the crypto, cut out the middle man, and just pay the hackers in cocaine directly from the board of director's supply.
        • olelele 5 hours ago
          Probably a similar ecological footprint to Bitcoin too...
      • _trampeltier 8 hours ago
        You got downvoted, but sadly we have 2026 and it's still not easy to send money to any bank in the world. You can say a lot of bad things about the crypto world, but thats a problem Bitcoin solved two decades ago.
        • tonyhart7 8 hours ago
          bitcoin is neither cheap and stable
          • reddalo 8 hours ago
            Nor safe. Good luck recalling a wrong crpyto transaction.
            • inigyou 5 hours ago
              If the recipient is identifiable they legally have to give the money back and you can press charges if they don't.
              • dsr_ 4 hours ago
                And if the jurisdictions don't have a treaty?
            • _trampeltier 2 hours ago
              That was not my point. Money with bancs also not, if it would be so easy, there would be no problems with nigerian oncles and so on. Good look get your grandmas scammed money back.
            • stavros 6 hours ago
              Can't do that with cash either, yet lots of people are using that.
              • ShinyLeftPad 5 hours ago
                it's a problem only if you can accidentally 100 000 dollars in cash, most of us can't (the amount of paper makes it tricky)
            • rvz 6 hours ago
              > Good luck recalling a wrong crpyto transaction.

              No better than recalling a wrong bank transfer or Zelle transaction.

              • ShinyLeftPad 5 hours ago
                Wrong bank transfers can't get recalled? I know I disputed a debit card transaction and got my money back the other month
                • Hugsbox 5 hours ago
                  In Canada, every bank has Interac e-Transfer, essentially we can easily email or text either other money. It's really wicked, and I'm always amazed other places like America don't have it built into their bank accounts and have to use 3rd-party apps to handle sending money to each other.

                  But anyway, the point is that it tells you every single time you send a transfer that way to be careful, because you can't undo a transfer after it's been sent. I'm assuming it's the same for most methods of bank transfer? I mean, debit transactions are surely a different beast.

                  • inigyou 5 hours ago
                    Banks can always try to undo a transaction - it's just not guaranteed to work. AFAIK, credit/debit card reversals are always reversible because if the merchant doesn't have the money, it becomes their bank's problem to get the money or eat the loss. This works because the merchant is easily identifiable, well known, and has a reputation to uphold (at least to their bank). Other methods of transfer don't come with such contractual protection, but can still have best-effort.
                    • ShinyLeftPad 4 hours ago
                      They can. Maybe in some jurisdictions they don't have to so they try to avoid it. But if there is crime involved for example, they can be required to do what's inconvenient
                • AureliusMA 4 hours ago
                  Most bank transfers cannot be reversed without agreement between parties. You're using a b2c mindset for a b2b problem. Bitcoin is a b2b tool.
                  • ShinyLeftPad 4 hours ago
                    Bangladesh bank got its reversed when hacked by NK. Does that look b2c?
                    • freeone3000 3 hours ago
                      The method of “reversal” was sending the money back, because it was a transfer between banks. The actual method of transfer or underlying currency is of no import in such circumstance.
                      • ShinyLeftPad 1 hour ago
                        The entire point is that the bank can send the money back and transaction is always between banks. Whereas in cryptocurrency world transaction is direct. Like with cash, except you can accidentally a million dollars
    • rjzzleep 11 hours ago
      Many solutions nowadays.

      https://www.payoneer.com/ is one of them. Of course this one is a bit racist depending on which contry you were born in.

  • jrozner 7 hours ago
    I know Joel well and think a lot here is both accurate and well written. I led the Yahoo bug bounty program from 2023-2024 and was involved in it from about 2021. A major event that this glosses over is Covid which also happened right around this time as well. Covid killed travel (and budget) which in turn made it impossible to do the live events. A lot of companies ended up shifting to virtual live events which just never delivered on the same value, scale, or impact.

    When COVID restrictions were lifted, travel and t&e budgets just never returned. Layoffs started happening and what were lavish, expensive events just couldn’t happen anymore. Hackerone charged for and likely made a lot of money on these events. I think a lot of what is talked about in the article is true but I think Covid is a big part of the why that led to it.

    • traceroute66 7 hours ago
      > travel and t&e budgets just never returned.

      It is also worth remembering that the cost of travel itself, and the cost of venues itself has also increased substantially. As well as associated costs such as catering and insurance.

      So in-person events have issues from both sides, those attending and those hosting.

      You also do not mention corporate policies. Under pressure from investors, their employees and sometimes their home-countries, many corporates have also introduced environmental policies. So if you want the company to pay for your flight, you not only have to justify it financially, but you have to justify it environmentally too.

      • inigyou 5 hours ago
        Cost of everything has increased massively, but they tell us inflation is 4%.
        • mynameisjonny_ 3 hours ago
          • 8organicbits 1 hour ago
            The link shows the first six months of 2026 for "all items" as: 2.4%, 2.4%, 3.3%, 3.8%, 4.2%, 3.5%. Gasoline ranged from -7.5% to 40.5% over the same range, which I've definitely noticed.
        • ponector 4 hours ago
          Iphones are still with the same price tag attached, bit you also get more compute for the same buck.

          You can find many examples like this.

          • wpm 3 hours ago
            Inflation famously measures iPhone prices alone.
            • inigyou 3 hours ago
              Now you're thinking like a central bank! Houses +200%, iPhones -200% (as measured by CPU clock speed), inflation 0%, everything is good!
          • inigyou 3 hours ago
            That's true. I bought 256GB RAM for an amount that used to only get 32GB. Wait, I swapped those two numbers around.
  • paradox460 12 hours ago
    Sending the sales team on a paid vacation to a tropical paradise while the engineering product flounders is such a perfect representation of corporate rot it sounds like something out of a Mike Judge movie
    • ralph84 11 hours ago
      Presidents club is a standard way to reward top performing sales reps across many industries. It doesn't indicate anything other than the company is trying to reward and retain their top sales reps. Engineers who find it distasteful should be happy to know engineers typically get way more equity than sales reps.
      • onion2k 10 hours ago
        Engineers who find it distasteful should be happy to know engineers typically get way more equity than sales reps.

        That isn't true. Early sales employees ('customer success', 'technical sales', 'growth', maybe product roles) get just as much equity as engineers who join at a similar time. The difference is that engineers often join earlier, with the commensurate risk that comes with.

        Also equity rarely pays out so you'd need to be comparing the probability of an exit that actually rewards the share class that engineers get, whether or not they've been diluted to nothing, whether there's a secondary market to sell on before an exit event, etc. It also depends on whether someone even wants the potential reward equity gives them over the more tangible rewards of money and perks.

        Comparing this stuff is hard.

        The point here though, is that the company is rewarding sales people at a time when the product is doing poorly, which implies the leadership team care more about selling a bad product than turning it into a good product. I hope that's not the case because it used to be a good platform.

        • icantevenhold 6 hours ago
          Technical sales and customer growth also don’t get the cut of sales that usually the actual sales reps do.

          In general i think sales reps make more money overall but have a much more stressful job and can get axed whenever they underperform for a quarter etc

          • onion2k 5 hours ago
            Having done sales before, I can assure you that it's differently stressful rather than more stressful. Trying to sign a customer for a substantial booking is stressful, but so is deploying a complex change that you can't roll back. There's hard things about every role.

            Engineers can also be axed at any time for performance. They're fortunate that most companies are bad at measuring that, but they're also subject to things like stack ranking at very bad companies (fire worst 10% every year) so it's certainly not better to be in eng rather than sales.

            Ultimately all roles have aspects of them that suck, so you need to find the one that sucks least for you.

      • pjmlp 9 hours ago
        That is a Silicon Valley thing, around the world you get a regular office salary and that's it.
        • dilyevsky 8 hours ago
          First of all it's not just SV - all of US sales is like this. Second, if you're talking about Europe - base/variable comps split may not be 50/50 but it's often the same OTE structure with some modifications due to local legalese
          • pjmlp 8 hours ago
            I am talking about software developers, not sales.

            I never seen this on my 30+ years on the job, other than being an early joiner to startups, equity isn't a thing.

            > Engineers who find it distasteful should be happy to know engineers typically get way more equity than sales reps.

            At very best, some companies might offer some kind of fixed bonus, if you over delivered as part of the KPI/OKR/whatever goals for the year, or the profits were nice enough that everyone gets a cut.

            • dilyevsky 7 hours ago
              Agree on the equity, afaik it’s due to how eager European countries are to tax illiquid shares on exercise instead of on sale like in US.

              Even without the equity part i think most engineers should be thankful for not having to hit their kpis to get full paycheck

      • superxpro12 2 hours ago
        [dead]
    • Hasz 1 hour ago
      Completely standard for enterprise (and even commercial/etc) sales. It would be extremely surprising if they did not have it. Usually take top n% of reps by quota attainment, GP, or incentive/SPIFF hits.

      Most (enterprise focused) companies, even outside of tech, has something like this. Called Club, P-club, presidents club, circle of excellence, etc.

      HackerOne chose a sales-first culture and this is their way of rewarding that growth.

    • ygouzerh 6 hours ago
      This one looks shocking on the outside indeed! It's however a sales HR practice: lower salary and commission, but use the alluring treat that top performers will have a special exclusive trip at the end of the year. Many are crazy for it.

      It's more a reward for a competition-style work mindset.

    • technion 10 hours ago
      I'm confused at the way they promoted it. Is there any way someone outside the company reading a Twitter post would consider this a positive thing for the product to be told what incentives the sales team get?
      • dmurray 6 hours ago
        It's not aimed at consumers of their product.

        Someone outside the company who was thinking of joining a B2B sales team, and who likes tropical vacations, might react positively to this post.

        Or a potential investor might be impressed to see the company has a mature sales pipeline and plenty of revenue to reward its top salespeople.

      • Hasz 1 hour ago
        It is to hire new reps, they are competing for talent.
    • neya 1 hour ago
      It's because of the CEO: Kara Sprague. Just another Marissa Meyer story, nothing new. We all saw how Yahoo turned out in the end.
    • dilyevsky 9 hours ago
      if i'm working for a company i sure hope they're sending their sales reps to a tropical paradise, and if they don't, i hope i don't own any equity.
  • codexon 11 hours ago
    I reported some exploits on hackerone.

    Most got dismissed.

    One of them, a remotely triggerable DoS vector got downgraded in severity. I got a token payment from the company, and 7 years later, it is still not marked as resolved.

    I doubt my situation is unique.

    • nextzck 10 hours ago
      Yeah I reported a j-frog vulnerability to Anthropic. It was downgraded to “informative” and they asked me to prove that I could exfiltrate data. I replied that exfiltrating data is against their program’s safe harbor policy and they just never responded. 2 months later the claude code source code leaked.
      • apimade 3 hours ago
        In my experience, program requirements are mostly there for the lawyers.

        If you act in good faith, communicate clearly, and conduct yourself reasonably, most companies will work with you — even when you've technically wandered outside the neat boundaries of their risk-appropriate, regulatory-reviewed policy.

        That isn't protection, of course. Eventually you'll encounter a bounty program run primarily by lawyers, procurement, or someone optimising a graph trend-line.

        And we know what tends to happen next.

        Those programs, and organisations, develop reputations. Researchers talk. Companies get discussed at conferences, in private groups and across the community, and some become informally blacklisted.

        Microsoft is a useful recent example: researchers have publicly walked away from five-figure bounties to make a point. There are excellent people working there, but organisationally Microsoft has repeatedly struggled to engage with the security community in a way that feels collaborative, rather than adversarial. Unless you're one of their paid partners, intermingled in their ecosystem.

        A lot of that seems to come down to incentives: somebody, somewhere, wants the numbers to look better.

        That doesn't work particularly well in an industry that, like most industries, ultimately runs on relationships, trust and specialisation.

        If a company marks something critical as informational, sometimes the most effective response is a CVSS parameter argument. It's a snarky comment:

        "Okay — so if I find a way to abuse your own infrastructure to message your customers, trigger a major incident and create regulatory problems for your clients, you'd prefer I treat that as informational too, and instead just report it to regulators?"

        Surprisingly often, that gets the issue reconsidered.

        Have you annoyed an analyst? Maybe. Does it matter? Probably not. Neither of you will remember the exchange a week later, but you might have corrected a bad risk decision on their side and you'll see a positive outcome on your side. Mistakes happen.

        I generally advise companies and hackers alike to follow Kiwicon's #1 rule.

      • inigyou 5 hours ago
        Hacking someone who asks you to hack them is legally safe even if not written in their default policy
    • xnorswap 7 hours ago
      One of my only bug bounty payouts was a DoS against a site via their customer query engine. I was quite proud of it, and was relieved when they actually paid out a token amount.

      It took down the entire application for all users and tenants, not just the tenant submitting the poisoned query.

      I don't remember how much I was paid, a token amount for sure, but I was happy with any amount because it was a hobby and any payment was good for the CV.

    • tptacek 11 hours ago
      Most bounty programs won't pay for DoS at all.
      • codexon 11 hours ago
        it isn't simple request flooding, it is application level resource exhaustion
        • tptacek 11 hours ago
          Yeah, I figured that's what you meant, and most bounty programs won't pay out for stuff like that. Every application has those bugs; on a software pentest, we'd sev:lo them.
          • nicce 4 hours ago
            > Every application has those bugs; on a software pentest, we'd sev:lo them.

            Every application has a bug that can bring the whole application down for every user without owning a botnet? That comes often with a significant business cost, if someone exploits it. Many companies take them seriously. I have reported many as high and business has agreed. Not with HackerOne thought. If there is a bug where someone can make your whole product down with a single laptop isn't really something you can just ignore.

            • tptacek 2 hours ago
              You can report a self-XSS sev:hi (and bounty hunters do) and get many orgs to take them seriously, because they don't have serious security practices. But DoS is generally sev:lo.
              • nicce 1 hour ago
                > You can report a self-XSS sev:hi (and bounty hunters do) and get many orgs to take them seriously, because they don't have serious security practices.

                Which can be definitely high, if it can be triggered by giving specific URL, for example.

                I think there is too much generalization happening here.

          • EraYaN 6 hours ago
            Some of them can have 1 rpi take down a full 100 node cluster, so sure sev:lo but the cyber insurance often want them fixed anyway. But it will probably take it happening before C-suite decides that 0 revenue is a problem.
    • rplnt 6 hours ago
      I reported a security bug, it was all processed very quickly and I got paid. I doubt my situation is unique.

      I think it would be the individual companies slowing things down, not the platform.

  • tptacek 11 hours ago
    Not only was there significant personal liability, but there had been multiple instances of hackers being criminally charged and sentenced to jail time for finding and reporting security vulnerabilities prior to this.

    I don't think this is true, although it's a very commonly-held belief. Dan Goodin (I think?) wrote an article about this a long time ago, and was only able to come up with a few examples, and none of them fit this fact pattern.

    https://news.ycombinator.com/item?id=16642155

    What is true is that it is much less legally risky to test someone else's computer than it was 10-15 years ago. People forget that's what you're doing when you look for web vulns! The DOJ has had a norm over the past ~many years not to prosecute good-faith vulnerability research, even though strictly speaking it contravenes CFAA directly. But "risky on paper" is the most you could say about doing that kind of testing back in 2010.

    • arcwhite 8 hours ago
      https://m.slashdot.org/story/159162-- example circa 2011

      I can think of 4-5 other situations from around that era (~2012) where people were at least charged and needed a lot of help to navigate the legal proceedings to avoid jail time.

      In 2010 it was more than risky on paper.

      2017-2018 is well into the established era and probably even the golden age of bug bounties when a lot of corporate and judicial thinking re: white hat cybersecurity had been shifted.

      • tptacek 2 hours ago
        It's true that I'm speaking entirely in an American context.
    • doc_ick 10 hours ago
      Doubt, I’d argue it’s the opposite given the term “vulnerability research” is being overloaded to include things such as F12 on a school website.
    • furst-blumier 8 hours ago
  • yan_solo42 2 hours ago
    I have 7.00 signal on HackerOne (the highest it can be), I've never filed a report that was closed as not applicable or spam, and I consistently report highs and critical severity issues which make up just over 70% of my reports.

    Yet I still find it next to impossible to get issues resolved.

    I'm a software engineer / tech bro by trade, and hacking and CTFs have always been a part time hobby for me, and thus I'm not part of the "elite" who get special treatment in the form of account managers and priority support.

    I can't help but feel like I'm becoming an even smaller cog in this corporate machine than before - if you look at H1's website, the hacker community is now just 1/6th of their supposed offering, alongside all of the AI pentesting services.

    The hacker community is precisely what this company was built on.

    The trajectory that they're on, and the positioning that they're adopting, makes me feel like they're eager to "move on" to something beyond it. The financial incentive is certainly there.

    • zingababba 51 minutes ago
      They absolutely are and they are also sitting on a goldmine of data they are using to enable them to do just that. If you doubt this just ask them for a demo of their agentic capabilities and start talking to them about roadmap, they are full steam ahead with fucking over the people that made them what they are.
  • che_shirecat 2 hours ago
    H1 has probably one of the most incompetent series of CEO's in SV startup history, pretty staggering how poorly the business is run
  • sudo_cowsay 12 hours ago
    All good things don't last forever. A organization or company lasting forever with the same goal/mission while using the same methods is a statistical anomaly.
    • wahnfrieden 12 hours ago
      What is the corrupting force?
      • movpasd 2 hours ago
        It's just economics. VCs dump large amounts of money into early-stage platforms with the express purpose of exploiting it later. This is an inevitable part of the lifecycle of high capital, low margin industries with strong network effects.

        This is not VCs being evil and corrupting a pristine engineer- or hacker-defined concept of true value. The VCs are all following the rules and are trying to make money off of risky investments (it's "venture" capital, after all). But the incentive structure just forces the market into either an oligopoly of largely extractive services (or into everything being free: that's why open source is also a stable point for software).

        My hope is that in time, basic software services, like for communication, socialising, community hosting, and so on, will eventually become seen as core social infrastructure. I don't really think this can happen via existing institutions, even open source, because the fixed costs of making software are really high. You really need _tax_ to support this. But it's very difficult to do because the internet cuts across borders.

      • sudo_cowsay 12 hours ago
        The joy/energy and human element being reduced. Or sometimes it's profit greed. Or it could just be due to economic conditions at the time. There are lots of ways for organizations to fall. Pick your poison.
      • strictnein 12 hours ago
        The people who cared leave and are replaced by people who just want a job.
      • natmaka 9 hours ago
        Bureaucracy is a major one, as it tends to dissipate more and more resources to sustain its own infrastructure, neglecting the core mission (J. Pournelle's Law).
      • mgiampapa 12 hours ago
        Usually money.
        • shermantanktop 12 hours ago
          Often preceded by the waning of the passion and self sacrifice that enables things to happen without money.

          It’s sad when it’s asymmetric - founders lose their idealism and sell out while early employees fail to notice the game has changed.

          But dreams are rarely enough to keep things going. And VCs know just what to say to make it seem like the dream and the money can coexist.

        • bigiain 12 hours ago
          Yep.

          It can be power - see Reddit and Wikipedia mods - but it's usually money. And once VC fundraising is involved, it's pretty much always money.

        • tptacek 11 hours ago
          Which is another way to say "viability".
      • dbspin 4 hours ago
        The investors.
      • DonHopkins 9 hours ago
        "You can divide our industry into two kinds of people: those who want to go work for a company to make it successful, and those who want to go work for a successful company." -- Jamie Zawinski
  • abofh 12 hours ago
    It got the executives it paid for
  • taude 3 hours ago
    This same tale could likely be applied to a lot of VC Funded SaaS....
    • flaburgan 19 minutes ago
      VCs are a plague much more than they are an opportunity.
  • Sytten 10 hours ago
    I am in this space. The reality is that the margins for a Bug Bounty Hunting platform are not good, triage is very expensive specially with all the AI slop that gets submitted now. You can hide it for a long time with VC money, but they need to diversify their product line to continue growing and compete against the AI pentest compagnies (which themselves will also diversify as AI pentest becomes a feature and not the whole product).
    • gbrindisi 6 hours ago
      I agree. They have quality data to build an effective AI pentest product that is good enough, and they already have a good offering to bundle that into and satisfy enterprise demand.

      Up and coming AI pentest companies need to have an exceptional product to get a chance to stand on their own and penetrate the enterprise market, otherwise their best scenario is an acquisition to get bundled into an established platform.

  • dualvariable 10 hours ago
    Bug bounty programs were overrun with low-effort slop nearly a decade before LLMs were introduced; I can't imagine what they're like now...
    • H4lcyon 6 hours ago
      You don't want to. It's exactly as bad as you think. I would say ~90% of reports are false now as opposed to ~40% before LLMs.
  • vladmk 4 hours ago
    What happens even a company loses its original mission
  • bullpen 5 hours ago
    They got corpo touched?
  • saidnooneever 8 hours ago
    money happened. it corrupts all. once there is enough of it going around people lose all senses and just want more.
    • doginasuit 3 hours ago
      From the framing of the post, it sounds more like money didn't happen, at least by the expectations of investors. It was a corrupting influence from the start, just with a delayed impact.

      > And to whoever is fired up: The market is ready for a disruption. The tools are in your hands. Build what HackerOne could have been.

      This is a rallying cry that should echo across the entire tech industry. Build what * could have been.

    • aa-jv 8 hours ago
      See also, the influx of spooks into various hackerspaces during the Snowden/Assange era. I truly believe there was an effort to subvert these communities, and thats what happened.
  • thewhitetulip 8 hours ago
    I once interviewed there, and it was the weirdest interviews of my life.

    They literally asked me to prepare on the company mission and values.

    The first round was about generic stuff where nothing much was asked. And ironically, despite transparency being their core mission, they didn't tell me I was rejected until I emailed them about a week later.

  • d0ublespeak 10 hours ago
    Honestly, you could sub the other big Bug Bounty platform for H1 in this post and you’d be still extremely accurate.
  • simpaticoder 11 hours ago
    I don't understand the controversy at the heart of this post. H1 stated they don't use reports to train LLMs. Then they revealed they were using LLMs to triage reports based on previous reports. These two facts are not necessarily incompatible. It's entirely possible to use an LLM with a db tool installed to triage reports without using the body of the reports as training fodder. The article doesn't give any evidence that this was not the case. It sounds to me more like the OP already disliked H1 (for its sales practices and general enshittification) and the LLM issue was a convenient excuse to make a clean break.
    • update 11 hours ago
      > I don't understand the controversy at the heart of this post.

      Did you miss this part from the article:

      > They switched from talking about bug bounty programs, live hacking events, and how they could help you stay secure, to promoting their in-house AI security product and continuous security monitoring tool.

      notably the in-house AI security product is trained on existing bug bounty reports.

      > It sounds to me more like the OP already disliked H1 (for its sales practices and general enshittification) and the LLM issue was a convenient excuse to make a clean break.

      that's pretty harsh to say when OP provided some very valid reasons, imho speaking as someone who's used HackerOne for over a decade.

      link to H1's "continuous monitoring tool" for the curious: https://www.hackerone.com/product/h1-continuous-testing

      • simpaticoder 1 hour ago
        No I don't think I missed that part of the article that was covered in my statement that the op seem to really not like H1 for lots of other reasons.
    • tptacek 10 hours ago
      And also the idea that H1 "training" models based on bug bounty reports is kind of a silly concern; frontier models have commoditized most of what was reported on H1, even at higher quality levels. H1 itself is a nonfactor.
  • iririririr 9 hours ago
    From the customer point of view: at a fortune500 I dealt a LOT with h1 (it was never H1) in the early days. Then we got a CISO who was mostly a showman. And at some point (which match the changes in leadership at h1 the article describes) the reports became all garbage and leadership (CISO and CTO) would talk about h1 hackathons with "top hackers flown from all over the world". Such a joke. The end result of those hackatons were 200 "internal host discovery" that were already reported internaly and teams always dismissed as "not worth fixing" and a single attack vector, usually from a brand new acquisition that was still going trhu onboarding. Pretty much never nothing relevant or actionable.
  • applfanboysbgon 12 hours ago
    > Co-founder Michiel Prins was allowed to leave the HackerOne dungeon to perform damage control with this absolute banger of an AI slop response: [...]

    Wow, it's like he prompted for the most stereotypically AI response possible. There's a tired trope in every sentence going on for four whole paragraphs! I originally quoted it too but thought better and decided to snip it out because I'm pretty sure it would get my account flagged by HN's AI detection algorithm...

    • bigiain 12 hours ago
      I wonder if that's the golden handcuffed founder equivalent of blinking out SOS in morse code?
    • cookiengineer 11 hours ago
      Imagine doing this article as a thorough writeup to provide feedback, rewriting this for like an hour before you post it.

      And then you get an AI slop response like that in return where you can't even tell whether it was just a CEO not giving a damn...or a standard dumb chat bot with a stupid response.

      I'm not sure if founders are aware that these are tipping points in customer care where the people that care about your product and ecosystem will leave your company for good, and you're irreparably damaging your own reputation.

      If I were OP I'd never ever touch anything with a 10ft pole that the founders will build in their lifetime, and I'd warn everyone I know in the community about it.

      That's the damage they're doing with these AI optimizations to themselves.

      There's a reason why everyone starts to hate your company right after your stupid chatbot was introduced.

  • jongjong 7 hours ago
    Last time I reported a DoS bug to HackerOne, the company behind the bounty tried incite me to commit a crime against them by DoS'ing their servers using the hack I had reported in detail!

    I literally showed them their server taking over a minute to respond to my request. I even showed how the delay increased proportionally to the message size... Clearly doing more processing; classic DoS vulnerability... Doesn't leave much to the imagination! But they said they would not pay me anything unless I actually proved that it scaled and caused disruption of their service!

    It seemed like they were baiting me into incriminating myself for a crime that they wanted me to commit against them. It's not even the first time that I've been baited by a software company into committing a crime against themselves. I never took the bait though.

    • jaccola 7 hours ago
      To be fair “we will compensate you if you do X” sounds a lot like a contract so you’d probably be just fine in court. (Though likely wise to avoid the chance of a legal headache)
      • jongjong 7 hours ago
        I don't trust the legal system. They could cover up the evidence, get me blocked on HackerOne, claim that my screenshots are AI-generated, hire top lawyers then make the judge to charge me for the lawyers' bill.

        The big company always wins. The legal system is pure fiction at this point. What lawyer would stand against the big companies? Permanently destroying all their future career prospects.

        Erin Brockovich? That's a corporate propaganda movie.

        Reality is more like what happened to Julian Assange or Steven Donziger. And they had support from some powerful groups. If they didn't, we wouldn't even have heard of them. That would have been my situation. Not worth the $200 bounty.

        • olelele 5 hours ago
          The Steven Donziger story is so insane.
  • apimade 4 hours ago
    I've disclosed vulns across just about every industry — banking, healthcare, oil & gas, government, cybersecurity, etc -- and to some of the largest companies in the world, OpenAI, Salesforce and Google. I've been doing this for nearly 20 years.

    Most of my research starts with: _There is absolutely no way this works_. Then it works.

    I've been thinking that a lot more lately.

    Companies and hackers are both heavily incentivised to reduce the friction involved in vulnerability disclosure, particularly for large organisations. The platforms are good enough now. They're email in 2007: imperfect, occasionally frustrating, but substantially better than what came before.

    They make SLAs possible. They provide structure and administration. Things still go wrong — companies stop responding, analysts drop the ball, hackers can be idiots — but the model basically works.

    Decentralising disclosure again would make life significantly harder for individual hackers. We'd end up back on email, probably building email-powered bounty CRMs that consume a small country's worth of tokens just to keep track of everything.

    For smaller organisations, though, I wouldn't touch a public bounty platform with a 10-foot pole. Run a private program first (through the platform). Having been on the receiving end of beg bounties, automated scanner output and increasingly AI-generated slop, most smaller security teams simply cannot scale to absorb the noise.

    The more interesting way to think about these platforms is that they're becoming the LinkedIn of hacking.

    For hackers, the path is fairly straightforward: build a rep through useful -- but oftentimes unsolicited disclosures, get invited onto private programs, and gradually establish a profile with a strong signal-to-noise ratio.

    For companies, they're increasingly a recruiting and relationship-building tool.

    And for the platforms, I think there's a much larger opportunity for them in community.

    They should be significantly better at understanding hackers: what they're good at, what technologies interest them, which industries they understand, and where they're located. Today, that profiling is laughably poor, to the point the questionnaires on areas by these large platforms are out of date by several years.

    Then use the data.

    Run small, highly targeted events: state- or city-based meetups, lunch-and-learns, product launches, bounty program launches and technical briefings. They don't need huge sponsorship budgets or prize pools. They need the actual community involved. Pay for dinner, sponsor a talk.

    A lot of existing events seem to start with companies, sponsorship packages and monetary amounts, then work backwards. I think that's backwards.

    As a weekend hacker, I'm far more likely to spend time on a program because something about it is interesting: you're launching an AI feature, handling financial data in a new way, using Node/GCP/a TI-82 calculator, or exposing some weird technical surface I want to understand.

    And I'm far more likely to build a useful relationship with a company if I can actually meet the people behind the program. Hackers can provide much better feedback than a semi-generated report, and companies can explain far more than a stale domain list and scope document — which, realistically, we'll be ignoring 99.99% of the time anyway.. Unless it's government. I quite like my freedom.

  • yieldcrv 6 hours ago
    human slop

    tl;dr which begins 3,000 words in: employees were noticed to be leaving and it’s because a “fine tuning from user submissions” ai psychosis of yesteryear, except it’s amusingly happening in 2026 still. Investigation into the veracity of the claims.

  • vladsiu 10 hours ago
    [dead]
  • nc55g3g 8 hours ago
    [dead]
  • charcircuit 12 hours ago
    I'm surprised someone could get upset at AI triaging of bugs which would save everyone time.
    • mapmeld 12 hours ago
      From what I've seen in the bounty-related subreddits, AI is flooding bug bounty inboxes with low-value or meaningless reports, or straight-up hallucinations when people use smaller models (to turn a profit, you make lots of low-value bug reports and see who pays out).

      This has a negative effect on humans doing their work with or without LLMs: curl shut down their bounty program, and GitHub just announced they're "restructuring" theirs. The author of this post also makes a case that HackerOne hasn't been honest about LLM training and use, either to hackers or to their own staff.

      • uqers 11 hours ago
        Didn't Daniel later report that curl recently started getting mostly high-quality LLM reports on their bounty program? I can imagine that there would definitely be a few "bounty spammers" trying to get hits, but it seems like most of them are doing good work.

        I'd say instead that the problem is that a lot of people don't care anymore about the quality of the work being done, and LLMs are accelerating it. Bounty programs have shifted from ways for people to report security bugs to ways for people to try to make money.

      • charcircuit 11 hours ago
        Doesn't that problem benefit from having automatic bug triage that can avoid fast tracking these bad reports?
        • iepathos 8 hours ago
          An LLM finds a dubious bug, an LLM turns it into a convincing report, and now the proposed solution is to have an LLM triage it? There are a lot of turtles holding up this approach and the circular logic seems hard to miss.

          Automated triage can filter obvious spam, which was already fast and easy for humans to do. The hard part is independently reproducing a plausible finding and assessing its actual impact. If LLMs could already do that reliably, then the slop report problem wouldn't exist in the first place.

          • charcircuit 6 hours ago
            >If you could build the thing they wanted to build it would fix the slop problem

            It sounds like a reason to try and build it than a reason to not build it.

            • H4lcyon 6 hours ago
              I tried to build it (kind of). My team is going to use it to alert us to the most critical issues so we can hop on them before waiting for triage. It's decent at figuring out criticality but it's TERRIBLE at actually doing triage and assessing whether the report is plausibly or implausibly true. Security can be really nuanced, and from my experience so far with the model I'm using it's really bad at being skeptical enough to actually figure out if something is a legit issue with impact or not. I agree though, it would be awesome if we could get AI triage that worked.
    • wahnfrieden 12 hours ago
      You’re surprised that workers don’t like their work being used to remove the need to pay them for it in the future? Your idea of time saved for the worker is for them to lose their livelihood without compensation
    • add-sub-mul-div 11 hours ago
      I can understand coming down on either side of the question of whether these AI reports save or waste time. I cannot understand being surprised or ignorant about the existence or high level beliefs of either side.
  • grogenaut 11 hours ago
    I'm sorry you don't know the difference between training, fine tuning, and context. But definitions matter especially in legalese.