Comments

Hacker News

Does this reflect new pricing in the black (hat) market?

by poly2it

I believe the changes here make a lot of sense because, most of the time, your best bugs are not your first ones

Anyone can point an LLM to a code base and ask to find a vulnerability - and the initial set of findings is going to be rather lame.

Encouraging researchers to stick to a target and to report 7 lows before getting in will probably make their contributions more valuable.

by darkamaul

I mean, this is just a "fuck you", right? "Because there's a lot of LLM spam, we've decided that some researchers will get 1/4th as much pay for reporting the same bug as others, even if they didn't use LLMs". If anything this will have the opposite of the intended effect -- this strongly discourages humans who aren't part of the VIP program from reporting bugs they find to Github, so you'll probably see a higher ratio of LLM spam in the future. And don't be surprised if those bugs get sold elsewhere...

by applfanboysbgon

I wonder if this incentivizes people to form groups that self-vet for quality submissions to enhance their reputation.

by saagarjha

Seems to me like the game theory here is un-credentialed reporters need to submit their reports through credentialed folks who will vet and take a cut on the way through.

Why take the lower offer by going directly.

That sounds like a win for everyone involved.

by everfrustrated

So if the "wrong" person finds a critical vulnerability in GitHub, the payout is capped at $10,000. Might reduce the likelihood of it being submitted to the bug bounty program.

by dinkelberg

> We’re formalizing a permanent private/invite-only VIP program for qualified researchers who consistently deliver high-quality, high-impact work.

> VIP program bounty table:

  Severity  Payout
  --------  --------
  Low       $1,000
  Medium    $7,500
  High      $20,000
  Critical  $30,000+
> We are adjusting our public program rates to accommodate this shift in focus towards quality of relationships and findings over quantity of reports. We are also updating to static payouts—a single, clear number per severity level, rather than a wide range.

> Our new public program bounty table:

  Severity  Payout
  --------  -------
  Low       $250
  Medium    $2,000
  High      $5,000
  Critical  $10,000

> To reduce the volume of low-effort and AI-generated reports, we’re implementing a HackerOne signal requirement on the public program.

by wxw

Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • Does this reflect new pricing in the black (hat) market?
  • I believe the changes here make a lot of sense because, most of the time, your best bugs are not your first ones

    Anyone can point an LLM to a code base and ask to find a vulnerability - and the initial set of findings is going to be rather lame.

    Encouraging researchers to stick to a target and to report 7 lows before getting in will probably make their contributions more valuable.

  • I mean, this is just a "fuck you", right? "Because there's a lot of LLM spam, we've decided that some researchers will get 1/4th as much pay for reporting the same bug as others, even if they didn't use LLMs". If anything this will have the opposite of the intended effect -- this strongly discourages humans who aren't part of the VIP program from reporting bugs they find to Github, so you'll probably see a higher ratio of LLM spam in the future. And don't be surprised if those bugs get sold elsewhere...
  • I wonder if this incentivizes people to form groups that self-vet for quality submissions to enhance their reputation.
  • Seems to me like the game theory here is un-credentialed reporters need to submit their reports through credentialed folks who will vet and take a cut on the way through.

    Why take the lower offer by going directly.

    That sounds like a win for everyone involved.

  • So if the "wrong" person finds a critical vulnerability in GitHub, the payout is capped at $10,000. Might reduce the likelihood of it being submitted to the bug bounty program.
  • > We’re formalizing a permanent private/invite-only VIP program for qualified researchers who consistently deliver high-quality, high-impact work.

    > VIP program bounty table:

      Severity  Payout
      --------  --------
      Low       $1,000
      Medium    $7,500
      High      $20,000
      Critical  $30,000+
    
    > We are adjusting our public program rates to accommodate this shift in focus towards quality of relationships and findings over quantity of reports. We are also updating to static payouts—a single, clear number per severity level, rather than a wide range.

    > Our new public program bounty table:

      Severity  Payout
      --------  -------
      Low       $250
      Medium    $2,000
      High      $5,000
      Critical  $10,000
    
    
    > To reduce the volume of low-effort and AI-generated reports, we’re implementing a HackerOne signal requirement on the public program.
    by wxw