48 comments

[ 4.0 ms ] story [ 23.6 ms ] thread
All good things don't last forever. A organization or company lasting forever with the same goal/mission while using the same methods is a statistical anomaly.
> Co-founder Michiel Prins was allowed to leave the HackerOne dungeon to perform damage control with this absolute banger of an AI slop response: [...]

Wow, it's like he prompted for the most stereotypically AI response possible. There's a tired trope in every sentence going on for four whole paragraphs! I originally quoted it too but thought better and decided to snip it out because I'm pretty sure it would get my account flagged by HN's AI detection algorithm...

It got the executives it paid for
I'm surprised someone could get upset at AI triaging of bugs which would save everyone time.
(comment deleted)
Sending the sales team on a paid vacation to a tropical paradise while the engineering product flounders is such a perfect representation of corporate rot it sounds like something out of a Mike Judge movie
This one looks shocking on the outside indeed! It's however a sales HR practice: lower salary and commission, but use the alluring treat that top performers will have a special exclusive trip at the end of the year. Many are crazy for it.

It's more a reward for a competition-style work mindset.

It's because of the CEO: Kara Sprague. Just another Marissa Meyer story, nothing new. We all saw how Yahoo turned out in the end.
Completely standard for enterprise (and even commercial/etc) sales. It would be extremely surprising if they did not have it. Usually take top n% of reps by quota attainment, GP, or incentive/SPIFF hits.

Most (enterprise focused) companies, even outside of tech, has something like this. Called Club, P-club, presidents club, circle of excellence, etc.

HackerOne chose a sales-first culture and this is their way of rewarding that growth.

This is normal. Almost 3 decades in the industry and sales get very nice vacation to tropical paradise all the time. At best we go some decent conference.
Not only was there significant personal liability, but there had been multiple instances of hackers being criminally charged and sentenced to jail time for finding and reporting security vulnerabilities prior to this.

I don't think this is true, although it's a very commonly-held belief. Dan Goodin (I think?) wrote an article about this a long time ago, and was only able to come up with a few examples, and none of them fit this fact pattern.

https://news.ycombinator.com/item?id=16642155

What is true is that it is much less legally risky to test someone else's computer than it was 10-15 years ago. People forget that's what you're doing when you look for web vulns! The DOJ has had a norm over the past ~many years not to prosecute good-faith vulnerability research, even though strictly speaking it contravenes CFAA directly. But "risky on paper" is the most you could say about doing that kind of testing back in 2010.

I reported some exploits on hackerone.

Most got dismissed.

One of them, a remotely triggerable DoS vector got downgraded in severity. I got a token payment from the company, and 7 years later, it is still not marked as resolved.

I doubt my situation is unique.

One of my only bug bounty payouts was a DoS against a site via their customer query engine. I was quite proud of it, and was relieved when they actually paid out a token amount.

It took down the entire application for all users and tenants, not just the tenant submitting the poisoned query.

I don't remember how much I was paid, a token amount for sure, but I was happy with any amount because it was a hobby and any payment was good for the CV.

I reported a security bug, it was all processed very quickly and I got paid. I doubt my situation is unique.

I think it would be the individual companies slowing things down, not the platform.

I don't understand the controversy at the heart of this post. H1 stated they don't use reports to train LLMs. Then they revealed they were using LLMs to triage reports based on previous reports. These two facts are not necessarily incompatible. It's entirely possible to use an LLM with a db tool installed to triage reports without using the body of the reports as training fodder. The article doesn't give any evidence that this was not the case. It sounds to me more like the OP already disliked H1 (for its sales practices and general enshittification) and the LLM issue was a convenient excuse to make a clean break.
> To the companies: You don’t need HackerOne anymore. The tokens to build your own in-house platform cost less than single year of HackerOne.

You know, the biggest thing that HackerOne delivers is a universal payments system that requires absolutely no efforts from companies. Have you tried to manually pay hackers from around the world? It is a laborious process involving trying to find what providers are compatible and what forms of money go where. It is extremely taxing to handle this. HackerOne provides real, tangible value in not making people think about how precisely to pay a hacker and in what currency. No amount of tokens solve the accounting problem, and it is foolish to imply otherwise.

> universal payments system that requires absolutely no efforts from companies.

Indeed. I use a third party company (not HackerOne) to handle our bug bounty and the primary reason is so they handle all the payment hassles, I don't need to be involved. They also handle all the screening for false positives, which in the AI age are exploding. I also don't want to deal with that.

In general I lean towards building in-house, but this is one area I'm happy to oursource all the busywork.

Yep, spot on - this and some level of inbound filtering are the only reason we use an external platform.

That said, with the volume of inbound reports coming from LLMs, the signal-to-noise ratio has plummeted, and the time taken to triage has gone through the roof.

Literally just pay them in bitcoin. They're hackers, they'll be able to handle it.
Interesting. Do you think they are using something like Deel/Stripe to handle a lot of this ? i mean to figure out the "paying ppl around the world" complexity ... also local payment methods .. currencies .. compliance .. tax docs etc ?
This (money transfer) is one thing Pix would solve trivially.
This is a great example of a general trend, which is why I don't think SaaS is going anywhere. The bar may be raised, but it's not going anywhere. HackerOne and SaaS in general makes problems go away for money. If you use your own tokens and solve it yourself, it's still your problem. The deficiencies are your problem. The support and ongoing maintenance are your problem. Discovering some country split in two and now has to have currency handled in some other way is still your problem. And they never end.

I see some people with the idea that businesses are going to use AI to solve everything in their own one-off bespoke manners for everything, but I don't think it's going to happen. What's going to happen is that the SaaS providers are going to get even better at making yet more stuff go away than they were before and it'll actually be harder for a business to replicate it themselves then it used to be.

(Of course the "go away" isn't perfect, but clearly, neither is the idea that solving everything yourself with AI is either.)

p2p crypto transfer? 0% fees, instant
This is, in general, a good statement of a durable problem one can 'solve' profitably. Basically take a problem that is hard to do 1:1, systemize it such that you can easily tune the solution to "all" variants of that problem, and then sell that as a service taking a percentage which is still going to be less than the cost of the customer doing a one-off solution.
I'm sorry you don't know the difference between training, fine tuning, and context. But definitions matter especially in legalese.
Bug bounty programs were overrun with low-effort slop nearly a decade before LLMs were introduced; I can't imagine what they're like now...
You don't want to. It's exactly as bad as you think. I would say ~90% of reports are false now as opposed to ~40% before LLMs.
I am in this space. The reality is that the margins for a Bug Bounty Hunting platform are not good, triage is very expensive specially with all the AI slop that gets submitted now. You can hide it for a long time with VC money, but they need to diversify their product line to continue growing and compete against the AI pentest compagnies (which themselves will also diversify as AI pentest becomes a feature and not the whole product).
I agree. They have quality data to build an effective AI pentest product that is good enough, and they already have a good offering to bundle that into and satisfy enterprise demand.

Up and coming AI pentest companies need to have an exceptional product to get a chance to stand on their own and penetrate the enterprise market, otherwise their best scenario is an acquisition to get bundled into an established platform.

Honestly, you could sub the other big Bug Bounty platform for H1 in this post and you’d be still extremely accurate.
From the customer point of view: at a fortune500 I dealt a LOT with h1 (it was never H1) in the early days. Then we got a CISO who was mostly a showman. And at some point (which match the changes in leadership at h1 the article describes) the reports became all garbage and leadership (CISO and CTO) would talk about h1 hackathons with "top hackers flown from all over the world". Such a joke. The end result of those hackatons were 200 "internal host discovery" that were already reported internaly and teams always dismissed as "not worth fixing" and a single attack vector, usually from a brand new acquisition that was still going trhu onboarding. Pretty much never nothing relevant or actionable.
money happened. it corrupts all. once there is enough of it going around people lose all senses and just want more.
From the framing of the post, it sounds more like money didn't happen, at least by the expectations of investors. It was a corrupting influence from the start, just with a delayed impact.

> And to whoever is fired up: The market is ready for a disruption. The tools are in your hands. Build what HackerOne could have been.

This is a rallying cry that should echo across the entire tech industry. Build what * could have been.

I once interviewed there, and it was the weirdest interviews of my life.

They literally asked me to prepare on the company mission and values.

The first round was about generic stuff where nothing much was asked. And ironically, despite transparency being their core mission, they didn't tell me I was rejected until I emailed them about a week later.

Last time I reported a DoS bug to HackerOne, the company behind the bounty tried incite me to commit a crime against them by DoS'ing their servers using the hack I had reported in detail!

I literally showed them their server taking over a minute to respond to my request. I even showed how the delay increased proportionally to the message size... Clearly doing more processing; classic DoS vulnerability... Doesn't leave much to the imagination! But they said they would not pay me anything unless I actually proved that it scaled and caused disruption of their service!

It seemed like they were baiting me into incriminating myself for a crime that they wanted me to commit against them. It's not even the first time that I've been baited by a software company into committing a crime against themselves. I never took the bait though.

I know Joel well and think a lot here is both accurate and well written. I led the Yahoo bug bounty program from 2023-2024 and was involved in it from about 2021. A major event that this glosses over is Covid which also happened right around this time as well. Covid killed travel (and budget) which in turn made it impossible to do the live events. A lot of companies ended up shifting to virtual live events which just never delivered on the same value, scale, or impact.

When COVID restrictions were lifted, travel and t&e budgets just never returned. Layoffs started happening and what were lavish, expensive events just couldn’t happen anymore. Hackerone charged for and likely made a lot of money on these events. I think a lot of what is talked about in the article is true but I think Covid is a big part of the why that led to it.

human slop

tl;dr which begins 3,000 words in: employees were noticed to be leaving and it’s because a “fine tuning from user submissions” ai psychosis of yesteryear, except it’s amusingly happening in 2026 still. Investigation into the veracity of the claims.

They got corpo touched?
What happens even a company loses its original mission
I've disclosed vulns across just about every industry — banking, healthcare, oil & gas, government, cybersecurity, etc -- and to some of the largest companies in the world, OpenAI, Salesforce and Google. I've been doing this for nearly 20 years.

Most of my research starts with: _There is absolutely no way this works_. Then it works.

I've been thinking that a lot more lately.

Companies and hackers are both heavily incentivised to reduce the friction involved in vulnerability disclosure, particularly for large organisations. The platforms are good enough now. They're email in 2007: imperfect, occasionally frustrating, but substantially better than what came before.

They make SLAs possible. They provide structure and administration. Things still go wrong — companies stop responding, analysts drop the ball, hackers can be idiots — but the model basically works.

Decentralising disclosure again would make life significantly harder for individual hackers. We'd end up back on email, probably building email-powered bounty CRMs that consume a small country's worth of tokens just to keep track of everything.

For smaller organisations, though, I wouldn't touch a public bounty platform with a 10-foot pole. Run a private program first (through the platform). Having been on the receiving end of beg bounties, automated scanner output and increasingly AI-generated slop, most smaller security teams simply cannot scale to absorb the noise.

The more interesting way to think about these platforms is that they're becoming the LinkedIn of hacking.

For hackers, the path is fairly straightforward: build a rep through useful -- but oftentimes unsolicited disclosures, get invited onto private programs, and gradually establish a profile with a strong signal-to-noise ratio.

For companies, they're increasingly a recruiting and relationship-building tool.

And for the platforms, I think there's a much larger opportunity for them in community.

They should be significantly better at understanding hackers: what they're good at, what technologies interest them, which industries they understand, and where they're located. Today, that profiling is laughably poor, to the point the questionnaires on areas by these large platforms are out of date by several years.

Then use the data.

Run small, highly targeted events: state- or city-based meetups, lunch-and-learns, product launches, bounty program launches and technical briefings. They don't need huge sponsorship budgets or prize pools. They need the actual community involved. Pay for dinner, sponsor a talk.

A lot of existing events seem to start with companies, sponsorship packages and monetary amounts, then work backwards. I think that's backwards.

As a weekend hacker, I'm far more likely to spend time on a program because something about it is interesting: you're launching an AI feature, handling financial data in a new way, using Node/GCP/a TI-82 calculator, or exposing some weird technical surface I want to understand.

And I'm far more likely to build a useful relationship with a company if I can actually meet the people behind the program. Hackers can provide much better feedback than a semi-generated report, and companies can explain far more than a stale domain list and scope document — which, realistically, we'll be ignoring 99.99% of the time anyway.. Unless it's government. I quite like my freedom.