

Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- Another reason why LLMs suck. So far cons > prosby sdevonoes
- Most definitely, yeah.by frizlab
- > So far cons > pros
Lets say 80% of the world's population decides the cons outweight the pros, now what? Put the genie back in the bottle, something that is famously easy and trivial to do?
- It is much harder to refute bullshit than to make up bullshit. As harsh or unfair as it might seem, this makes sense.by Schnitz
- Does this reflect new pricing in the black (hat) market?by poly2it
- I believe the changes here make a lot of sense because, most of the time, your best bugs are not your first ones
Anyone can point an LLM to a code base and ask to find a vulnerability - and the initial set of findings is going to be rather lame.
Encouraging researchers to stick to a target and to report 7 lows before getting in will probably make their contributions more valuable.
by darkamaul - by Klaster_1
- I mean, this is just a "fuck you", right? "Because there's a lot of LLM spam, we've decided that some researchers will get 1/4th as much pay for reporting the same bug as others, even if they didn't use LLMs". If anything this will have the opposite of the intended effect -- this strongly discourages humans who aren't part of the VIP program from reporting bugs they find to Github, so you'll probably see a higher ratio of LLM spam in the future. And don't be surprised if those bugs get sold elsewhere...
- I wonder if this incentivizes people to form groups that self-vet for quality submissions to enhance their reputation.by saagarjha
- i mean; that sounds like a win for GH right?by w0m
- Seems to me like the game theory here is un-credentialed reporters need to submit their reports through credentialed folks who will vet and take a cut on the way through.
Why take the lower offer by going directly.
That sounds like a win for everyone involved.
- still removing work from github.
this is formalizing some very enterprise-esque processes for security research, software resellers anyone?
by htrp - So if the "wrong" person finds a critical vulnerability in GitHub, the payout is capped at $10,000. Might reduce the likelihood of it being submitted to the bug bounty program.by dinkelberg
- I find it quite offensive that there is a payout difference for major vulnerabilities when the outcome is the end in the end.
If it was me finding such a vulnerability, this discrimination would offend me so much that I would prefer to sell it to semi-legal actors that would pay multiple of that...
by greatgib - It might, but as someone who has to review public vulnerability reports for a much less popular website, I completely understand why they’re building a vouch program to dissuade slop reports. One would presume their internal team is using frontier models for red team agent scanning against potential attack surface, and so this is a potential risk they’re willing to take.
Tragedy of the commons that someone who hasn’t passed the filter yet might have their payout limited.
Vouch - https://news.ycombinator.com/item?id=46930961 - February 2026 (486 comments)
by toomuchtodo - > We’re formalizing a permanent private/invite-only VIP program for qualified researchers who consistently deliver high-quality, high-impact work.
> VIP program bounty table:
> We are adjusting our public program rates to accommodate this shift in focus towards quality of relationships and findings over quantity of reports. We are also updating to static payouts—a single, clear number per severity level, rather than a wide range.Severity Payout -------- -------- Low $1,000 Medium $7,500 High $20,000 Critical $30,000+> Our new public program bounty table:
> To reduce the volume of low-effort and AI-generated reports, we’re implementing a HackerOne signal requirement on the public program.Severity Payout -------- ------- Low $250 Medium $2,000 High $5,000 Critical $10,000by wxw - > VIP program for qualified researchers who consistently deliver high-quality, high-impact work.
Almost as though they want the quality and consistency of hired labor but not the cost
by cobertos