What Happened to HackerOne? (blog.teknogeek.io)
84 points by hipparchus 2 hours ago
paradox460 36 minutes ago
Sending the sales team on a paid vacation to a tropical paradise while the engineering product flounders is such a perfect representation of corporate rot it sounds like something out of a Mike Judge movie
tptacek 35 minutes ago
Not only was there significant personal liability, but there had been multiple instances of hackers being criminally charged and sentenced to jail time for finding and reporting security vulnerabilities prior to this.
I don't think this is true, although it's a very commonly-held belief. Dan Goodin (I think?) wrote an article about this a long time ago, and was only able to come up with a few examples, and none of them fit this fact pattern.
https://news.ycombinator.com/item?id=16642155
What is true is that it is much less legally risky to test someone else's computer than it was 10-15 years ago. People forget that's what you're doing when you look for web vulns! The DOJ has had a norm over the past ~many years not to prosecute good-faith vulnerability research, even though strictly speaking it contravenes CFAA directly. But "risky on paper" is the most you could say about doing that kind of testing back in 2010.
simpaticoder 3 minutes ago
I don't understand the controversy at the heart of this post. H1 stated they don't use reports to train LLMs. Then they revealed they were using LLMs to triage reports based on previous reports. These two facts are not necessarily incompatible. It's entirely possible to use an LLM with a db tool installed to triage reports without using the body of the reports as training fodder. The article doesn't give any evidence that this was not the case. It sounds to me more like the OP already disliked H1 (for its sales practices and general enshittification) and the LLM issue was a convenient excuse to make a clean break.
codexon 35 minutes ago
I reported some exploits on hackerone.
Most got dismissed.
One of them, a remotely triggerable DoS vector got downgraded in severity. I got a token payment from the company, and 7 years later, it is still not marked as resolved.
I doubt my situation is unique.
tptacek 28 minutes ago
Most bounty programs won't pay for DoS at all.
codexon 23 minutes ago
it isn't simple request flooding, it is application level resource exhaustion
tptacek 13 minutes ago
sudo_cowsay an hour ago
All good things don't last forever. A organization or company lasting forever with the same goal/mission while using the same methods is a statistical anomaly.
wahnfrieden an hour ago
What is the corrupting force?
sudo_cowsay an hour ago
The joy/energy and human element being reduced. Or sometimes it's profit greed. Or it could just be due to economic conditions at the time. There are lots of ways for organizations to fall. Pick your poison.
strictnein an hour ago
The people who cared leave and are replaced by people who just want a job.
mgiampapa an hour ago
Usually money.
shermantanktop an hour ago
bigiain 38 minutes ago
tptacek 28 minutes ago
abofh an hour ago
It got the executives it paid for
charcircuit an hour ago
I'm surprised someone could get upset at AI triaging of bugs which would save everyone time.
mapmeld 43 minutes ago
From what I've seen in the bounty-related subreddits, AI is flooding bug bounty inboxes with low-value or meaningless reports, or straight-up hallucinations when people use smaller models (to turn a profit, you make lots of low-value bug reports and see who pays out).
This has a negative effect on humans doing their work with or without LLMs: curl shut down their bounty program, and GitHub just announced they're "restructuring" theirs. The author of this post also makes a case that HackerOne hasn't been honest about LLM training and use, either to hackers or to their own staff.
charcircuit 8 minutes ago
Doesn't that problem benefit from having automatic bug triage that can avoid fast tracking these bad reports?
wahnfrieden an hour ago
You’re surprised that workers don’t like their work being used to remove the need to pay them for it in the future? Your idea of time saved for the worker is for them to lose their livelihood without compensation
add-sub-mul-div 32 minutes ago
I can understand coming down on either side of the question of whether these AI reports save or waste time. I cannot understand being surprised or ignorant about the existence or high level beliefs of either side.
applfanboysbgon an hour ago
> Co-founder Michiel Prins was allowed to leave the HackerOne dungeon to perform damage control with this absolute banger of an AI slop response: [...]
Wow, it's like he prompted for the most stereotypically AI response possible. There's a tired trope in every sentence going on for four whole paragraphs! I originally quoted it too but thought better and decided to snip it out because I'm pretty sure it would get my account flagged by HN's AI detection algorithm...
bigiain 36 minutes ago
I wonder if that's the golden handcuffed founder equivalent of blinking out SOS in morse code?
cookiengineer 14 minutes ago
Imagine doing this article as a thorough writeup to provide feedback, rewriting this for like an hour before you post it.
And then you get an AI slop response like that in return where you can't even tell whether it was just a CEO not giving a damn...or a standard dumb chat bot with a stupid response.
I'm not sure if founders are aware that these are tipping points in customer care where the people that care about your product and ecosystem will leave your company for good, and you're irreparably damaging your own reputation.
If I were OP I'd never ever touch anything with a 10ft pole that the founders will build in their lifetime, and I'd warn everyone I know in the community about it.
That's the damage they're doing with these AI optimizations to themselves.
There's a reason why everyone starts to hate your company right after your stupid chatbot was introduced.