https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...
This one probably has the best summary:
https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...
This one probably has the best summary:
$5,000 is actually pretty normal for a critical. I think the most I received for one bug was around $10,000, but this is the exception.
AI has also ruined the market. I'm a security consultant (where I make most of my money) and stopped bug bounty once AI slop reports made it impossible to actually get anything triaged in a timely manner.
Something else many don't know is that with all of the major platforms, customers can see the bugs before they are even triaged by the platform team. Many companies are now taking advantage of the long triage times and fixing the bugs before the researcher can get paid. It's then marked as a duplicate and the researcher gets nothing.
Big companies who run these programs don’t use them as their only security. It’s a bonus program. They have internal employees and often third parties doing testing too.
> I'm surprised these programs aren't pushed harder, as the potential ROI seems fantastic.
I have some exposure to managing one of these programs, which was started by someone who left the company abruptly (right after it went on their resume as an achievement).
It’s a huge amount of work. We got an unbelievable number of bad reports before AI was available. Now it’s just a nightmare. The ratio of bad reports to actual payout-worthy reports was out of control.
Most submitters also tried to inflate the severity of their submission to get to the higher tiers. This created a problem where people were withholding small bugs while they’d try to find a way to chain it or elevate privileges. You could tell because as soon as you detected and closed their exploit, they would hurriedly submit a rushed report to try to claim it and then argue with you for not paying out because it was fixed before they submitted it.
We had payouts that went to larger numbers, but honestly I think it would have been better off if we didn’t. This makes bystanders irate, but honestly the incentives get bad when the payouts are large and everyone is spamming LLM bots at your service.
Isn’t that just a speedrun-encouragement for selling the exploit not to the one offering the product, but an attacker offering more (in this case, >$0 is not difficult to exceed) instead?