6 ms·
What Happened to HackerOne?
- sudo_cowsay 2mo agoAll good things don't last forever. A organization or company lasting forever with the same goal/mission while using the same methods is a statistical anomaly.
- wahnfrieden 2mo agoWhat is the corrupting force?
- mgiampapa 2mo agoUsually money.
- shermantanktop 2mo agoOften preceded by the waning of the passion and self sacrifice that enables things to happen without money. It’s sad when it’s asymmetric - founders lose their idealism and sell out while early employees fail to notice the game has changed. But dreams are rarely enough to keep things going. And VCs know just what to say to make it seem like the dream and the money can coexist.
- bigiain 2mo agoYep. It can be power - see Reddit and Wikipedia mods - but it's usually money. And once VC fundraising is involved, it's pretty much always money.
- tptacek 2mo agoWhich is another way to say "viability".
- doc_ick 2mo agoNot always.
- sudo_cowsay 2mo agoThe joy/energy and human element being reduced. Or sometimes it's profit greed. Or it could just be due to economic conditions at the time. There are lots of ways for organizations to fall. Pick your poison.
- strictnein 2mo agoThe people who cared leave and are replaced by people who just want a job.
- DonHopkins 2mo ago"You can divide our industry into two kinds of people: those who want to go work for a company to make it successful, and those who want to go work for a successful company." -- Jamie Zawinski
- natmaka 2mo agoBureaucracy is a major one, as it tends to dissipate more and more resources to sustain its own infrastructure, neglecting the core mission (J. Pournelle's Law).
- dbspin 2mo agoThe investors.
- movpasd 2mo agoIt's just economics. VCs dump large amounts of money into early-stage platforms with the express purpose of exploiting it later. This is an inevitable part of the lifecycle of high capital, low margin industries with strong network effects. This is not VCs being evil and corrupting a pristine engineer- or hacker-defined concept of true value. The VCs are all following the rules and are trying to make money off of risky investments (it's "venture" capital, after all). But the incentive structure just forces the market into either an oligopoly of largely extractive services (or into everything being free: that's why open source is also a stable point for software). My hope is that in time, basic software services, like for communication, socialising, community hosting, and so on, will eventually become seen as core social infrastructure. I don't really think this can happen via existing institutions, even open source, because the fixed costs of making software are really high. You really need _tax_ to support this. But it's very difficult to do because the internet cuts across borders.
- inigyou 2mo agoEntropy. Game theory.
- cindyllm 2mo ago[dead]
- momojo 2mo agoThe brokenness of man? Sin?
- applfanboysbgon 2mo ago> Co-founder Michiel Prins was allowed to leave the HackerOne dungeon to perform damage control with this absolute banger of an AI slop response: [...] Wow, it's like he prompted for the most stereotypically AI response possible. There's a tired trope in every sentence going on for four whole paragraphs! I originally quoted it too but thought better and decided to snip it out because I'm pretty sure it would get my account flagged by HN's AI detection algorithm...
- bigiain 2mo agoI wonder if that's the golden handcuffed founder equivalent of blinking out SOS in morse code?
- cookiengineer 2mo agoImagine doing this article as a thorough writeup to provide feedback, rewriting this for like an hour before you post it. And then you get an AI slop response like that in return where you can't even tell whether it was just a CEO not giving a damn...or a standard dumb chat bot with a stupid response. I'm not sure if founders are aware that these are tipping points in customer care where the people that care about your product and ecosystem will leave your company for good, and you're irreparably damaging your own reputation. If I were OP I'd never ever touch anything with a 10ft pole that the founders will build in their lifetime, and I'd warn everyone I know in the community about it. That's the damage they're doing with these AI optimizations to themselves. There's a reason why everyone starts to hate your company right after your stupid chatbot was introduced.
- abofh 2mo agoIt got the executives it paid for
- charcircuit 2mo agoI'm surprised someone could get upset at AI triaging of bugs which would save everyone time.
- wahnfrieden 2mo agoYou’re surprised that workers don’t like their work being used to remove the need to pay them for it in the future? Your idea of time saved for the worker is for them to lose their livelihood without compensation
- deleted 2mo ago[deleted]
- mapmeld 2mo agoFrom what I've seen in the bounty-related subreddits, AI is flooding bug bounty inboxes with low-value or meaningless reports, or straight-up hallucinations when people use smaller models (to turn a profit, you make lots of low-value bug reports and see who pays out). This has a negative effect on humans doing their work with or without LLMs: curl shut down their bounty program, and GitHub just announced they're "restructuring" theirs. The author of this post also makes a case that HackerOne hasn't been honest about LLM training and use, either to hackers or to their own staff.
- charcircuit 2mo agoDoesn't that problem benefit from having automatic bug triage that can avoid fast tracking these bad reports?
- iepathos 2mo agoAn LLM finds a dubious bug, an LLM turns it into a convincing report, and now the proposed solution is to have an LLM triage it? There are a lot of turtles holding up this approach and the circular logic seems hard to miss. Automated triage can filter obvious spam, which was already fast and easy for humans to do. The hard part is independently reproducing a plausible finding and assessing its actual impact. If LLMs could already do that reliably, then the slop report problem wouldn't exist in the first place.
- deleted 2mo ago[deleted]
- paradox460 2mo agoSending the sales team on a paid vacation to a tropical paradise while the engineering product flounders is such a perfect representation of corporate rot it sounds like something out of a Mike Judge movie
- ralph84 2mo agoPresidents club is a standard way to reward top performing sales reps across many industries. It doesn't indicate anything other than the company is trying to reward and retain their top sales reps. Engineers who find it distasteful should be happy to know engineers typically get way more equity than sales reps.
- onion2k 2mo agoEngineers who find it distasteful should be happy to know engineers typically get way more equity than sales reps. That isn't true. Early sales employees ('customer success', 'technical sales', 'growth', maybe product roles) get just as much equity as engineers who join at a similar time. The difference is that engineers often join earlier, with the commensurate risk that comes with. Also equity rarely pays out so you'd need to be comparing the probability of an exit that actually rewards the share class that engineers get, whether or not they've been diluted to nothing, whether there's a secondary market to sell on before an exit event, etc. It also depends on whether someone even wants the potential reward equity gives them over the more tangible rewards of money and perks. Comparing this stuff is hard. The point here though, is that the company is rewarding sales people at a time when the product is doing poorly, which implies the leadership team care more about selling a bad product than turning it into a good product. I hope that's not the case because it used to be a good platform.
- icantevenhold 2mo agoTechnical sales and customer growth also don’t get the cut of sales that usually the actual sales reps do. In general i think sales reps make more money overall but have a much more stressful job and can get axed whenever they underperform for a quarter etc
- tptacek 2mo agoNot only was there significant personal liability, but there had been multiple instances of hackers being criminally charged and sentenced to jail time for finding and reporting security vulnerabilities prior to this. I don't think this is true, although it's a very commonly-held belief. Dan Goodin (I think?) wrote an article about this a long time ago, and was only able to come up with a few examples, and none of them fit this fact pattern. https://news.ycombinator.com/item?id=16642155 https://news.ycombinator.com/item?id=16642155 What is true is that it is much less legally risky to test someone else's computer than it was 10-15 years ago. People forget that's what you're doing when you look for web vulns! The DOJ has had a norm over the past ~many years not to prosecute good-faith vulnerability research, even though strictly speaking it contravenes CFAA directly. But "risky on paper" is the most you could say about doing that kind of testing back in 2010.
- doc_ick 2mo agoDoubt, I’d argue it’s the opposite given the term “vulnerability research” is being overloaded to include things such as F12 on a school website.
- arcwhite 2mo agohttps://m.slashdot.org/story/159162-- https://m.slashdot.org/story/159162-- example circa 2011 I can think of 4-5 other situations from around that era (~2012) where people were at least charged and needed a lot of help to navigate the legal proceedings to avoid jail time. In 2010 it was more than risky on paper. 2017-2018 is well into the established era and probably even the golden age of bug bounties when a lot of corporate and judicial thinking re: white hat cybersecurity had been shifted.
- tptacek 2mo agoIt's true that I'm speaking entirely in an American context.
- furst-blumier 2mo agoMaybe in the US but see eg germany: https://binsec.wiki/en/pentesting-guidelines/pt-legal-framework/pt-germany/ https://binsec.wiki/en/pentesting-guidelines/pt-legal-framew...
- codexon 2mo agoI reported some exploits on hackerone. Most got dismissed. One of them, a remotely triggerable DoS vector got downgraded in severity. I got a token payment from the company, and 7 years later, it is still not marked as resolved. I doubt my situation is unique.
- tptacek 2mo agoMost bounty programs won't pay for DoS at all.
- codexon 2mo agoit isn't simple request flooding, it is application level resource exhaustion
- tptacek 2mo agoYeah, I figured that's what you meant, and most bounty programs won't pay out for stuff like that. Every application has those bugs; on a software pentest, we'd sev:lo them.
- EraYaN 2mo agoSome of them can have 1 rpi take down a full 100 node cluster, so sure sev:lo but the cyber insurance often want them fixed anyway. But it will probably take it happening before C-suite decides that 0 revenue is a problem.
- nicce 2mo ago> Every application has those bugs; on a software pentest, we'd sev:lo them. Every application has a bug that can bring the whole application down for every user without owning a botnet? That comes often with a significant business cost, if someone exploits it. Many companies take them seriously. I have reported many as high and business has agreed. Not with HackerOne thought. If there is a bug where someone can make your whole product down with a single laptop isn't really something you can just ignore.
- simpaticoder 2mo agoI don't understand the controversy at the heart of this post. H1 stated they don't use reports to train LLMs. Then they revealed they were using LLMs to triage reports based on previous reports. These two facts are not necessarily incompatible. It's entirely possible to use an LLM with a db tool installed to triage reports without using the body of the reports as training fodder. The article doesn't give any evidence that this was not the case. It sounds to me more like the OP already disliked H1 (for its sales practices and general enshittification) and the LLM issue was a convenient excuse to make a clean break.
- update 2mo ago> I don't understand the controversy at the heart of this post. Did you miss this part from the article: > They switched from talking about bug bounty programs, live hacking events, and how they could help you stay secure, to promoting their in-house AI security product and continuous security monitoring tool. notably the in-house AI security product is trained on existing bug bounty reports. > It sounds to me more like the OP already disliked H1 (for its sales practices and general enshittification) and the LLM issue was a convenient excuse to make a clean break. that's pretty harsh to say when OP provided some very valid reasons, imho speaking as someone who's used HackerOne for over a decade. link to H1's "continuous monitoring tool" for the curious: https://www.hackerone.com/product/h1-continuous-testing https://www.hackerone.com/product/h1-continuous-testing
- simpaticoder 2mo agoNo I don't think I missed that part of the article that was covered in my statement that the op seem to really not like H1 for lots of other reasons.
- tptacek 2mo agoAnd also the idea that H1 "training" models based on bug bounty reports is kind of a silly concern; frontier models have commoditized most of what was reported on H1, even at higher quality levels. H1 itself is a nonfactor.
- Shank 2mo ago> To the companies: You don’t need HackerOne anymore. The tokens to build your own in-house platform cost less than single year of HackerOne. You know, the biggest thing that HackerOne delivers is a universal payments system that requires absolutely no efforts from companies. Have you tried to manually pay hackers from around the world? It is a laborious process involving trying to find what providers are compatible and what forms of money go where. It is extremely taxing to handle this. HackerOne provides real, tangible value in not making people think about how precisely to pay a hacker and in what currency. No amount of tokens solve the accounting problem, and it is foolish to imply otherwise.
- rjzzleep 2mo agoMany solutions nowadays. https://www.payoneer.com/ https://www.payoneer.com/ is one of them. Of course this one is a bit racist depending on which contry you were born in.
- weird-eye-issue 2mo agoRace and country of origin are not the same
- AustinDev 2mo agoJust pay them in stable coins. That's a solved problem.
- MikeNotThePope 2mo agoBuying stable coins is a mild pain because so many banks think crypto is radioactive. Then you have to wait for your deposited funds to completely settle before you can withdraw the crypto from your account and send it elsewhere. Doable, sure. Easy & convenient, not so much. I wouldn't call it a solved problem in the same way you can hand someone cash, tap to pay with your phone, or pay by scanning a QR Code.
- Jommi 2mo ago
- grogenaut 2mo agoI'm sorry you don't know the difference between training, fine tuning, and context. But definitions matter especially in legalese.
- vladsiu 2mo ago[dead]
- dualvariable 2mo agoBug bounty programs were overrun with low-effort slop nearly a decade before LLMs were introduced; I can't imagine what they're like now...
- H4lcyon 2mo agoYou don't want to. It's exactly as bad as you think. I would say ~90% of reports are false now as opposed to ~40% before LLMs.
- Sytten 2mo agoI am in this space. The reality is that the margins for a Bug Bounty Hunting platform are not good, triage is very expensive specially with all the AI slop that gets submitted now. You can hide it for a long time with VC money, but they need to diversify their product line to continue growing and compete against the AI pentest compagnies (which themselves will also diversify as AI pentest becomes a feature and not the whole product).
- gbrindisi 2mo agoI agree. They have quality data to build an effective AI pentest product that is good enough, and they already have a good offering to bundle that into and satisfy enterprise demand. Up and coming AI pentest companies need to have an exceptional product to get a chance to stand on their own and penetrate the enterprise market, otherwise their best scenario is an acquisition to get bundled into an established platform.
- d0ublespeak 2mo agoHonestly, you could sub the other big Bug Bounty platform for H1 in this post and you’d be still extremely accurate.
- iririririr 2mo agoFrom the customer point of view: at a fortune500 I dealt a LOT with h1 (it was never H1) in the early days. Then we got a CISO who was mostly a showman. And at some point (which match the changes in leadership at h1 the article describes) the reports became all garbage and leadership (CISO and CTO) would talk about h1 hackathons with "top hackers flown from all over the world". Such a joke. The end result of those hackatons were 200 "internal host discovery" that were already reported internaly and teams always dismissed as "not worth fixing" and a single attack vector, usually from a brand new acquisition that was still going trhu onboarding. Pretty much never nothing relevant or actionable.
- saidnooneever 2mo agomoney happened. it corrupts all. once there is enough of it going around people lose all senses and just want more.
- aa-jv 2mo agoSee also, the influx of spooks into various hackerspaces during the Snowden/Assange era. I truly believe there was an effort to subvert these communities, and thats what happened.
- doginasuit 2mo agoFrom the framing of the post, it sounds more like money didn't happen, at least by the expectations of investors. It was a corrupting influence from the start, just with a delayed impact. > And to whoever is fired up: The market is ready for a disruption. The tools are in your hands. Build what HackerOne could have been. This is a rallying cry that should echo across the entire tech industry. Build what * could have been.
- thewhitetulip 2mo agoI once interviewed there, and it was the weirdest interviews of my life. They literally asked me to prepare on the company mission and values. The first round was about generic stuff where nothing much was asked. And ironically, despite transparency being their core mission, they didn't tell me I was rejected until I emailed them about a week later.
- nc55g3g 2mo ago[dead]
- jongjong 2mo agoLast time I reported a DoS bug to HackerOne, the company behind the bounty tried incite me to commit a crime against them by DoS'ing their servers using the hack I had reported in detail! I literally showed them their server taking over a minute to respond to my request. I even showed how the delay increased proportionally to the message size... Clearly doing more processing; classic DoS vulnerability... Doesn't leave much to the imagination! But they said they would not pay me anything unless I actually proved that it scaled and caused disruption of their service! It seemed like they were baiting me into incriminating myself for a crime that they wanted me to commit against them. It's not even the first time that I've been baited by a software company into committing a crime against themselves. I never took the bait though.
- jaccola 2mo agoTo be fair “we will compensate you if you do X” sounds a lot like a contract so you’d probably be just fine in court. (Though likely wise to avoid the chance of a legal headache)
- jongjong 2mo agoI don't trust the legal system. They could cover up the evidence, get me blocked on HackerOne, claim that my screenshots are AI-generated, hire top lawyers then make the judge to charge me for the lawyers' bill. The big company always wins. The legal system is pure fiction at this point. What lawyer would stand against the big companies? Permanently destroying all their future career prospects. Erin Brockovich? That's a corporate propaganda movie. Reality is more like what happened to Julian Assange or Steven Donziger. And they had support from some powerful groups. If they didn't, we wouldn't even have heard of them. That would have been my situation. Not worth the $200 bounty.
- olelele 2mo agoThe Steven Donziger story is so insane.
- jrozner 2mo agoI know Joel well and think a lot here is both accurate and well written. I led the Yahoo bug bounty program from 2023-2024 and was involved in it from about 2021. A major event that this glosses over is Covid which also happened right around this time as well. Covid killed travel (and budget) which in turn made it impossible to do the live events. A lot of companies ended up shifting to virtual live events which just never delivered on the same value, scale, or impact. When COVID restrictions were lifted, travel and t&e budgets just never returned. Layoffs started happening and what were lavish, expensive events just couldn’t happen anymore. Hackerone charged for and likely made a lot of money on these events. I think a lot of what is talked about in the article is true but I think Covid is a big part of the why that led to it.
- traceroute66 2mo ago> travel and t&e budgets just never returned. It is also worth remembering that the cost of travel itself, and the cost of venues itself has also increased substantially. As well as associated costs such as catering and insurance. So in-person events have issues from both sides, those attending and those hosting. You also do not mention corporate policies. Under pressure from investors, their employees and sometimes their home-countries, many corporates have also introduced environmental policies. So if you want the company to pay for your flight, you not only have to justify it financially, but you have to justify it environmentally too.
- yieldcrv 2mo agohuman slop tl;dr which begins 3,000 words in: employees were noticed to be leaving and it’s because a “fine tuning from user submissions” ai psychosis of yesteryear, except it’s amusingly happening in 2026 still. Investigation into the veracity of the claims.
- bullpen 2mo agoThey got corpo touched?
- vladmk 2mo agoWhat happens even a company loses its original mission
- apimade 2mo agoI've disclosed vulns across just about every industry — banking, healthcare, oil & gas, government, cybersecurity, etc -- and to some of the largest companies in the world, OpenAI, Salesforce and Google. I've been doing this for nearly 20 years. Most of my research starts with: _There is absolutely no way this works_. Then it works. I've been thinking that a lot more lately. Companies and hackers are both heavily incentivised to reduce the friction involved in vulnerability disclosure, particularly for large organisations. The platforms are good enough now. They're email in 2007: imperfect, occasionally frustrating, but substantially better than what came before. They make SLAs possible. They provide structure and administration. Things still go wrong — companies stop responding, analysts drop the ball, hackers can be idiots — but the model basically works. Decentralising disclosure again would make life significantly harder for individual hackers. We'd end up back on email, probably building email-powered bounty CRMs that consume a small country's worth of tokens just to keep track of everything. For smaller organisations, though, I wouldn't touch a public bounty platform with a 10-foot pole. Run a private program first (through the platform). Having been on the receiving end of beg bounties, automated scanner output and increasingly AI-generated slop, most smaller security teams simply cannot scale to absorb the noise. The more interesting way to think about these platforms is that they're becoming the LinkedIn of hacking. For hackers, the path is fairly straightforward: build a rep through useful -- but oftentimes unsolicited disclosures, get invited onto private programs, and gradually establish a profile with a strong signal-to-noise ratio. For companies, they're increasingly a recruiting and relationship-building tool. And for the platforms, I think there's a much larger opportunity for them in community. They should be significantly better at understanding hackers: what they're good at, what technologies interest them, which industries they understand, and where they're located. Today, that profiling is laughably poor, to the point the questionnaires on areas by these large platforms are out of date by several years. Then use the data. Run small, highly targeted events: state- or city-based meetups, lunch-and-learns, product launches, bounty program launches and technical briefings. They don't need huge sponsorship budgets or prize pools. They need the actual community involved. Pay for dinner, sponsor a talk. A lot of existing events seem to start with companies, sponsorship packages and monetary amounts, then work backwards. I think that's backwards. As a weekend hacker, I'm far more likely to spend time on a program because something about it is interesting: you're launching an AI feature, handling financial data in a new way, using Node/GCP/a TI-82 calculator, or exposing some weird technical surface I want to understand. And I'm far more likely to build a useful relationship with a company if I can actually meet the people behind the program. Hackers can provide much better feedback than a semi-generated report, and companies can explain far more than a stale domain list and scope document — which, realistically, we'll be ignoring 99.99% of the time anyway.. Unless it's government. I quite like my freedom.
- taude 2mo agoThis same tale could likely be applied to a lot of VC Funded SaaS....
- flaburgan 2mo agoVCs are a plague much more than they are an opportunity.
- yan_solo42 2mo agoI have 7.00 signal on HackerOne (the highest it can be), I've never filed a report that was closed as not applicable or spam, and I consistently report highs and critical severity issues which make up just over 70% of my reports. Yet I still find it next to impossible to get issues resolved. I'm a software engineer / tech bro by trade, and hacking and CTFs have always been a part time hobby for me, and thus I'm not part of the "elite" who get special treatment in the form of account managers and priority support. I can't help but feel like I'm becoming an even smaller cog in this corporate machine than before - if you look at H1's website, the hacker community is now just 1/6th of their supposed offering, alongside all of the AI pentesting services. The hacker community is precisely what this company was built on. The trajectory that they're on, and the positioning that they're adopting, makes me feel like they're eager to "move on" to something beyond it. The financial incentive is certainly there.
- zingababba 2mo agoThey absolutely are and they are also sitting on a goldmine of data they are using to enable them to do just that. If you doubt this just ask them for a demo of their agentic capabilities and start talking to them about roadmap, they are full steam ahead with fucking over the people that made them what they are.
- che_shirecat 2mo agoH1 has probably one of the most incompetent series of CEO's in SV startup history, pretty staggering how poorly the business is run
- vivzkestrel 2mo ago- we need another post from this dude - "What happened to HackerNews?" - why is it only AI, LLM, GPT stuff on the all the pages now?
- red-iron-pine 2mo agowhy do 50% of posts on some subreddits get removed?
- acaloiar 2mo agoI'm not so sure anyone was let out of the dungeon. All the "co-founder" statements read exactly like Claude drivel. If I were a betting man, I'd bet HackerOne simply wired LLMs up to post as Alex and Michiel.