Comments
Hacker News
by poly2it
Anyone can point an LLM to a code base and ask to find a vulnerability - and the initial set of findings is going to be rather lame.
Encouraging researchers to stick to a target and to report 7 lows before getting in will probably make their contributions more valuable.
by darkamaul
by Klaster_1
by saagarjha
Why take the lower offer by going directly.
That sounds like a win for everyone involved.
by dinkelberg
> VIP program bounty table:
Severity Payout
-------- --------
Low $1,000
Medium $7,500
High $20,000
Critical $30,000+
> We are adjusting our public program rates to accommodate this shift in focus towards quality of relationships and findings over quantity of reports. We are also updating to static payouts—a single, clear number per severity level, rather than a wide range.> Our new public program bounty table:
Severity Payout
-------- -------
Low $250
Medium $2,000
High $5,000
Critical $10,000
> To reduce the volume of low-effort and AI-generated reports, we’re implementing a HackerOne signal requirement on the public program.by wxw
Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- Does this reflect new pricing in the black (hat) market?by poly2it
- I believe the changes here make a lot of sense because, most of the time, your best bugs are not your first ones
Anyone can point an LLM to a code base and ask to find a vulnerability - and the initial set of findings is going to be rather lame.
Encouraging researchers to stick to a target and to report 7 lows before getting in will probably make their contributions more valuable.
by darkamaul - by Klaster_1
- I mean, this is just a "fuck you", right? "Because there's a lot of LLM spam, we've decided that some researchers will get 1/4th as much pay for reporting the same bug as others, even if they didn't use LLMs". If anything this will have the opposite of the intended effect -- this strongly discourages humans who aren't part of the VIP program from reporting bugs they find to Github, so you'll probably see a higher ratio of LLM spam in the future. And don't be surprised if those bugs get sold elsewhere...
- I wonder if this incentivizes people to form groups that self-vet for quality submissions to enhance their reputation.by saagarjha
- Seems to me like the game theory here is un-credentialed reporters need to submit their reports through credentialed folks who will vet and take a cut on the way through.
Why take the lower offer by going directly.
That sounds like a win for everyone involved.
- So if the "wrong" person finds a critical vulnerability in GitHub, the payout is capped at $10,000. Might reduce the likelihood of it being submitted to the bug bounty program.by dinkelberg
- > We’re formalizing a permanent private/invite-only VIP program for qualified researchers who consistently deliver high-quality, high-impact work.
> VIP program bounty table:
> We are adjusting our public program rates to accommodate this shift in focus towards quality of relationships and findings over quantity of reports. We are also updating to static payouts—a single, clear number per severity level, rather than a wide range.Severity Payout -------- -------- Low $1,000 Medium $7,500 High $20,000 Critical $30,000+> Our new public program bounty table:
> To reduce the volume of low-effort and AI-generated reports, we’re implementing a HackerOne signal requirement on the public program.Severity Payout -------- ------- Low $250 Medium $2,000 High $5,000 Critical $10,000by wxw