HNHacker News
TopNewBestAskShowJobs

martenmickos

14 karma · joined July 2, 2013

CEO of HackerOne. Formerly CEO of MySQL & Eucalyptus. Finn in Silicon Valley.
submissionscomments
martenmickos··on Introducing the Google Play Security Reward Program
Here is the announcement by Google: https://security.googleblog.com/2017/10/introducing-google-p...
martenmickos··on Ask HN: Do I need a bug bounty program? Feeling a bit threatened by HackerOne
Thanks for raising this issue.

HackerOne will NEVER threaten you or do anything to reduce your security. You can safely ignore our sales emails if that's what you want to do. We are just trying to be helpful.

But we do have the absolutely best set of programs for companies of all stripes. To start with, you can open a vulnerability disclosure program that costs you nothing. It will allow hackers to submit vulnerability reports to you. We run numerous programs of this type for startups and other companies.

Our mission is to empower the world to build a safer internet. That's it.

Marten HackerOne CEO

martenmickos··on Ask HN: How saturated is the market for offensive security/pentesting?
Sign up here: https://www.hackerone.com/resources/hack-learn-earn
martenmickos··on Google Bug Bounty – The $5k Error Page
Generally in the world of bug bounty programs, the signal-to-noise ratio (SNR) is around 10-20%.

Even at this low rate, it is not too bad. Let's say you receive 10 reports. You can relatively quickly identify the 8-9 noisy reports to find the 1-2 valid ones. Of course, a higher SNR is always better. It saves you time and effort.

On HackerOne, the average SNR across all programs is over 30%. The platform can automatically filter out certain reports that are duplicates or out of scope.

The platform maintains an average signal rating for each hacker (aka security researcher). Companies can limit access to their programs to hackers with a certain signal or higher. This will significantly increase SNR for the program.

Companies can also opt for a HackerOne program with triage included, in which case the SNR rises close to 100%.

martenmickos··on 10000$ by Hackerone for WannaCrypt “Killswitch”
Here is a great interview with MalwareTech: http://abcnews.go.com/Technology/wireStory/computer-expert-f...
martenmickos··on WordPress Now on HackerOne
Here is their bug bounty page for anyone who has found a vulnerability to report: https://hackerone.com/wordpress
martenmickos··on Ethical considerations of access to the HackerOne community
Thanks tetrep. I agree with your statement "would be a good time for HackerOne to write this stuff down".

We just discussed it this morning internally. If you have suggestions on how to formulate such a policy, please email me at marten@hackerone.com.

Thinking out loud, HackerOne stands for and supports the security and integrity of every piece of software code, for transparency and openness, for the sovereignty of each human being connected online, and for fair and equitable principles for all online activity. And probably some other aspects that I didn't think of this exact second.

If anyone has thoughts on this, we are all ears.

Marten

martenmickos··on HackerOne raises $40M in their C-round of funding
Sorry to hear this. Can you email us at support@hackerone.com or me marten@ so we can see what went wrong and where we dropped the ball. Thanks!
martenmickos··on HackerOne raises $40M in their C-round of funding
Good overview of HackerOne in The Verge: http://www.theverge.com/2017/2/8/14534738/hackerone-bounty-4...
martenmickos··on Ask HN: How was your experience hiring a white hat hacker?
The safest and most convenient way of hiring a white hat hacker (a.k.a. ethical hacker) is to run a bug bounty program and get the input of many of them.

HackerOne is the leading bug bounty platform.

martenmickos··on If OpenStack has won, then cloud computing has lost
Yup. And you can add Open Nebula to the list.

BTW, given that NIST uses Eucalyptus, you could argue that Eucalyptus meets not just the formal definition of cloud computing, but also the practical one.