14 comments

[ 0.19 ms ] story [ 10.4 ms ] thread
So if the "wrong" person finds a critical vulnerability in GitHub, the payout is capped at $10,000. Might reduce the likelihood of it being submitted to the bug bounty program.
I wonder if this incentivizes people to form groups that self-vet for quality submissions to enhance their reputation.
i mean; that sounds like a win for GH right?
I mean, this is just a "fuck you", right? "Because there's a lot of LLM spam, we've decided that some researchers will get 1/4th as much pay for reporting the same bug as others, even if they didn't use LLMs". If anything this will have the opposite of the intended effect -- this strongly discourages humans who aren't part of the VIP program from reporting bugs they find to Github, so you'll probably see a higher ratio of LLM spam in the future. And don't be surprised if those bugs get sold elsewhere...
> We’re formalizing a permanent private/invite-only VIP program for qualified researchers who consistently deliver high-quality, high-impact work.

> VIP program bounty table:

  Severity  Payout
  --------  --------
  Low       $1,000
  Medium    $7,500
  High      $20,000
  Critical  $30,000+
> We are adjusting our public program rates to accommodate this shift in focus towards quality of relationships and findings over quantity of reports. We are also updating to static payouts—a single, clear number per severity level, rather than a wide range.

> Our new public program bounty table:

  Severity  Payout
  --------  -------
  Low       $250
  Medium    $2,000
  High      $5,000
  Critical  $10,000

> To reduce the volume of low-effort and AI-generated reports, we’re implementing a HackerOne signal requirement on the public program.
It is much harder to refute bullshit than to make up bullshit. As harsh or unfair as it might seem, this makes sense.
I believe the changes here make a lot of sense because, most of the time, your best bugs are not your first ones

Anyone can point an LLM to a code base and ask to find a vulnerability - and the initial set of findings is going to be rather lame.

Encouraging researchers to stick to a target and to report 7 lows before getting in will probably make their contributions more valuable.

Does this reflect new pricing in the black (hat) market?
Another reason why LLMs suck. So far cons > pros
Seems to me like the game theory here is un-credentialed reporters need to submit their reports through credentialed folks who will vet and take a cut on the way through.

Why take the lower offer by going directly.

That sounds like a win for everyone involved.

still removing work from github.

this is formalizing some very enterprise-esque processes for security research, software resellers anyone?