5 ms·
> To the companies: You don’t need HackerOne anymore. The tokens to build your own in-house platform cost less than single year of HackerOne. You know, the big
by Shank 2mo ago
> To the companies: You don’t need HackerOne anymore. The tokens to build your own in-house platform cost less than single year of HackerOne.
You know, the biggest thing that HackerOne delivers is a universal payments system that requires absolutely no efforts from companies. Have you tried to manually pay hackers from around the world? It is a laborious process involving trying to find what providers are compatible and what forms of money go where. It is extremely taxing to handle this. HackerOne provides real, tangible value in not making people think about how precisely to pay a hacker and in what currency. No amount of tokens solve the accounting problem, and it is foolish to imply otherwise.
- rjzzleep 2mo agoMany solutions nowadays. https://www.payoneer.com/ https://www.payoneer.com/ is one of them. Of course this one is a bit racist depending on which contry you were born in.
- weird-eye-issue 2mo agoRace and country of origin are not the same
- AustinDev 2mo agoJust pay them in stable coins. That's a solved problem.
- MikeNotThePope 2mo agoBuying stable coins is a mild pain because so many banks think crypto is radioactive. Then you have to wait for your deposited funds to completely settle before you can withdraw the crypto from your account and send it elsewhere. Doable, sure. Easy & convenient, not so much. I wouldn't call it a solved problem in the same way you can hand someone cash, tap to pay with your phone, or pay by scanning a QR Code.
- Jommi 2mo agoNot anymore! Most places allow this very easily now.
- rvz 2mo agoExactly. Revolut is a bank that allows cryptocurrencies. HN really is living in their own bubble.
- stavros 2mo agoNo it doesn't. You can gamble with it, but it doesn't let you own or send it.
- rvz 2mo ago> No it doesn't. Yes it does. > You can gamble with it, but it doesn't let you own or send it. You can deposit (receive) and withdraw (send) cryptocurrencies there. "Owning" is a matter at the private key level which of course you use a self-hosted wallet for "true" ownership. But no argument was made on ownership. My point still stands that Revolut is a bank that allows cryptocurrencies.
- interactivecode 2mo agoRevolut does not have a banking license in the US. At the moment they are a front for another bank. Don't be gullible and believe blindly what the marketing departments tell you.
- victorbjorklund 2mo agoPITA for a large company to handle stable coins etc with accounting, etc
- fuomag9 2mo agoAlso PITA for people as well, we have a 33% tax on crypto selling here in Italy on profits…
- tonyhart7 2mo agowhy its fucking high ??
- bdavbdav 2mo agoSame in a lot of countries - he said profits - it’s a taxable gain like any other asset or holding.
- reddalo 2mo agoI don't know. It used to be 26%, like capital gains from shares, securities, etc. but since 1st January 2026 crypto is taxed at 33% unless it's euro stablecoins (still 26%). At this point, I think most crypto investors in Italy will just evade taxes altogether.
- michaelt 2mo agoItaly has progressive taxes on salary, with marginal rates from 23% to 43%. The latter on income above €50k And if you've got taxes like that on earned income - shouldn't people with unearned income pay just as much? If your tax on investment gains is too small, you end up with an economy where the salaried worker renting a house pays more tax than their landlord, who owns ten houses.
- freeone3000 2mo agoI think America’s tax policy and redistribution scheme have made it the country where private individuals have the most money in the world - and that saying the landlord should pay just as much tax disincentivizes wealth concentration!
- DonHopkins 2mo agoSkip the crypto, cut out the middle man, and just pay the hackers in cocaine directly from the board of director's supply.
- olelele 2mo agoProbably a similar ecological footprint to Bitcoin too...
- _trampeltier 2mo agoYou got downvoted, but sadly we have 2026 and it's still not easy to send money to any bank in the world. You can say a lot of bad things about the crypto world, but thats a problem Bitcoin solved two decades ago.
- tonyhart7 2mo agobitcoin is neither cheap and stable
- reddalo 2mo agoNor safe. Good luck recalling a wrong crpyto transaction.
- rvz 2mo ago> Good luck recalling a wrong crpyto transaction. No better than recalling a wrong bank transfer or Zelle transaction.
- ShinyLeftPad 2mo agoWrong bank transfers can't get recalled? I know I disputed a debit card transaction and got my money back the other month
- Hugsbox 2mo agoIn Canada, every bank has Interac e-Transfer, essentially we can easily email or text either other money. It's really wicked, and I'm always amazed other places like America don't have it built into their bank accounts and have to use 3rd-party apps to handle sending money to each other. But anyway, the point is that it tells you every single time you send a transfer that way to be careful, because you can't undo a transfer after it's been sent. I'm assuming it's the same for most methods of bank transfer? I mean, debit transactions are surely a different beast.
- michaelt 2mo agoIt's not just the transfer of cash. It's also complying with tax and employment laws in the country the hacker is in, to the satisfaction of your legal and finance teams. Sure, in western-style legal systems you can call them a contractor and they can pay their own tax. Just don't employ them full time for long enough to trigger 'sham contract' rules that would make them employees. But your corporate legal team doesn't have anyone trained and licensed to give advice on Tajikistan tax and employment law, so they can't approve this proposed contract without hiring an outside legal expert. And of course all suppliers, regardless of country, must agree to our anti-slave-labour policy which permits audits of... One might say "skip that nonsense, just send the money" - but the larger the company, the more their in-house infosec becomes a load of uptight squares who love compliance and audit. And the kind of companies that can pay out five-figure bounties tend to be pretty large.
- inigyou 2mo agoWhy would you or anyone in your American company care about complying with Tajikistan law?
- ofjcihen 2mo agoLess about that. More about “not accidentally funding terrorism” (or, more realistically, not giving money to sanctioned countries which can have significant consequences).
- michaelt 2mo agoCISO: "We're going to invite random strangers from all around the globe to hack us, and pay them for their findings" CEO: "I'm not sure I like the idea of us inviting people to hack us - or paying a 'bounty' to hackers holding a knife to our throat. Will they at least agree to a binding NDA and terms of engagement, in advance?" CISO: "No, they won't." CEO: "Well, at least if the hackers are in poor countries, a $500 payout for a critical bug will be plenty, right?" CISO: "No, critical issues will be 10-100x that" CEO: "Well will the average quality of these reports better than those we get from our hired pentesters?" CISO: "On average these will be the lowest quality reports you've ever seen. But 0.1% might be gold. Oh, and I need to hire 3 more guys to sift through these terrible reports. Also our sifters might miss the gold." CEO: "Oh. Well at least we won't be breaking the law though, right?" CISO: "Uh, about that..."
- icantevenhold 2mo agoThis and the pre-triage are the only reasons we even use a bug bounty platform. If paying out bounties was easy I would do it all via email; but as you said it’s almost impossible to do (unless you are maybe bigcorp and have a team just for that)
- maccard 2mo agoI worked at a big corp and we paid out randoms for a program (not bug bounty). It was an absolute minefield, people would lie to us about where they were located only for us to find out they’re in <insert sanctioned country here> and then legal tells us we have to pay them but we’re not allowed to at the same time. Outsourcing all that mess is a great use of money.
- icantevenhold 2mo agoYea we also handled it ourselves the first couple years but it was so painful. Literally the same thing you described happened - as well spending weeks+ how we need to file it as tax when we pay bounty to someone in Pakistan etc.
- weird-eye-issue 2mo agoAre you in the US? You simply collect a W8 from them that you keep on file and then the payment would be counted as an expense on taxes. We do payout to hundreds o f affiliates every year and this is how we handle it, it's really not complicated. The actual payments are done via Wise batch payments which just requires their email address.
- bhg45g34 2mo ago[dead]
- kay_o 2mo agoMy largest problem with H1 is how braindead scripted/AI their triage is. - Starting scenario: no way to contact a company outside of H1 (or some other managed programme) - The company is compromised, their customer support has no idea what this means, they have no security.txt or any other security contact - I have explicitly told H1 to just forward it with no bounty, I don't want a bounty, only remediation, I do not care about a bounty or any reward - H1 closes as "not eligible" and tells me to not submit stuff I can't prove it's my compromise by putting my username on it - Corporate server is still compromised and being used as a proxy to brute force my services
- jjav 2mo ago> universal payments system that requires absolutely no efforts from companies. Indeed. I use a third party company (not HackerOne) to handle our bug bounty and the primary reason is so they handle all the payment hassles, I don't need to be involved. They also handle all the screening for false positives, which in the AI age are exploding. I also don't want to deal with that. In general I lean towards building in-house, but this is one area I'm happy to oursource all the busywork.
- snapcaster 2mo agoMind sharing which company you use for this?
- jjav 2mo agoThere are many options, probably mostly equivalent, just depends where you can negotiate a price agreeable to your budget. But to answer the question, currently using Inspectiv.
- GeneticGenesis 2mo agoYep, spot on - this and some level of inbound filtering are the only reason we use an external platform. That said, with the volume of inbound reports coming from LLMs, the signal-to-noise ratio has plummeted, and the time taken to triage has gone through the roof.
- inigyou 2mo agoLiterally just pay them in bitcoin. They're hackers, they'll be able to handle it.
- StilesCrisis 2mo agoThat solves the literal "how to pay" but so does an envelope full of cash via FedEx. That's not the actual complicated part of legally paying someone for contract work in a foreign possibly-hostile nation.
- inigyou 2mo agoI'm pretty sure the legal way to pay someone in a sanctioned country is: you can't. Full stop. Especially not for hacking services.
- StilesCrisis 2mo agoI'm not actually sure how HackerOne skirts around this.
- inigyou 2mo agoAccountability firewalls, probably. They won't pay a sanctioned country, but they'll turn a blind enough eye to anyone who says they're from a different one.
- zulln 2mo agoIn the early days Meta (Facebook back then) used to pay bounties by physically mailing pre-paid debit cards, so you are not far off with the idea of envelopes full of cash.
- gyanchawdhary 2mo agoInteresting. Do you think they are using something like Deel/Stripe to handle a lot of this ? i mean to figure out the "paying ppl around the world" complexity ... also local payment methods .. currencies .. compliance .. tax docs etc ?
- gchamonlive 2mo agoThis (money transfer) is one thing Pix would solve trivially.
- nonethewiser 2mo agoAny universal system would. The problem is there isnt a universal system.
- gchamonlive 2mo agoThat's untrue because it assumes all systems are interchangeable just because they are centralized and global, but intention matters and how you operate them creates hidden incentives that can alter how these systems evolve over time. Pix in Brazil, unlike other solutions, is entirely state-run and shouldn't suffer from investor pressure. It can still potentially suffer from service quality degradation and lack of transparency, but enshitification and anti-consumer practices are also very much present in private-owned initiatives, so it's not exclusive to this project.
- inigyou 2mo agoYeah, but it only works in Brazil. There's no political will for the US to adopt a Brazilian payment system, and plenty of political will for that to not happen. The same is true in every country. Europe has the SEPA system (often incorrectly called the IBAN system), but you can't use SEPA to transfer to a US account. When the Ukraine war broke out and Ukraine sought donations, they were asking people to donate to a Deutsche Bank account with SEPA, or a JPMorgan Chase account with ACH, or an Australian National Bank account with whatever system they use in Australia.
- gchamonlive 2mo agoHence the "would solve", but as you identified the US prefers to favor their internal ancient financial structures that aren't fit for current global needs. And it's not like it's doing so in order to prevent someone to acquire strategic leverage, because this tech would benefit everyone equally, but to maintain its stronghold over the world's financial systems (like hackerone) just to extract profit. This is very Roman of the Americans, we gotta admit.
- jerf 2mo agoThis is a great example of a general trend, which is why I don't think SaaS is going anywhere. The bar may be raised, but it's not going anywhere. HackerOne and SaaS in general makes problems go away for money. If you use your own tokens and solve it yourself, it's still your problem. The deficiencies are your problem. The support and ongoing maintenance are your problem. Discovering some country split in two and now has to have currency handled in some other way is still your problem. And they never end. I see some people with the idea that businesses are going to use AI to solve everything in their own one-off bespoke manners for everything, but I don't think it's going to happen. What's going to happen is that the SaaS providers are going to get even better at making yet more stuff go away than they were before and it'll actually be harder for a business to replicate it themselves then it used to be. (Of course the "go away" isn't perfect, but clearly, neither is the idea that solving everything yourself with AI is either.)
- ceejayoz 2mo ago> If you use your own tokens and solve it yourself, it's still your problem. The flip side, of course, is that I can fix my problem - which may be unique and not something a large SaaS will ever do - on my timeline.
- jerf 2mo agoThat's not a new flip side, though. That's always been with us. SaaS will be more able to take on more requirements then they used to be but no one SaaS will ever be able to take on everything. And the decision between "roll our own and own it forever versus buy this one service that almost does everything we need, but not quite, but maybe it's worth living with it because it's still better than rolling it ourselves" isn't going anywhere either. I would not want to be a SaaS that offers some really simple service that can be replicated in a heartbeat, though. Something like "how do I pay people all over the world" is already very complicated, and over the next decades as governments start writing laws with the understanding that AIs can implement them in code no matter how complicated they are, it's likely these problems will become even more complicated and even more important to just buy a service that can deal with them. (I'm not celebrating that, merely predicting it.) But I sure wouldn't want to be selling some super simple scheduled reminder service or something else really small. In the worst case, envision a world where home owner associations or townships or whatever other local governmental division of just perhaps a few hundred people start levying sales taxes, with their own complicated exclusions and offsets and conditions, because LLMs make it possible to handle the code for all of the literally hundreds of thousands or millions of such jurisdictions. Even if you can throw tokens at that problem to solve it yourself, you probably don't want to. And again... I'm not celebrating that. More a world-weary bowing to the inevitable despite it being an obviously bad idea.
- stellamariesays 2mo ago[flagged]
- pbkompasz 2mo agop2p crypto transfer? 0% fees, instant
- ChuckMcM 2mo agoThis is, in general, a good statement of a durable problem one can 'solve' profitably. Basically take a problem that is hard to do 1:1, systemize it such that you can easily tune the solution to "all" variants of that problem, and then sell that as a service taking a percentage which is still going to be less than the cost of the customer doing a one-off solution.