What Happened to HackerOne?
Discussion 193 comments
That isn't true. Early sales employees ('customer success', 'technical sales', 'growth', maybe product roles) get just as much equity as engineers who join at a similar time. The difference is that engineers often join earlier, with the commensurate risk that comes with.
Also equity rarely pays out so you'd need to be comparing the probability of an exit that actually rewards the share class that engineers get, whether or not they've been diluted to nothing, whether there's a secondary market to sell on before an exit event, etc. It also depends on whether someone even wants the potential reward equity gives them over the more tangible rewards of money and perks.
Comparing this stuff is hard.
The point here though, is that the company is rewarding sales people at a time when the product is doing poorly, which implies the leadership team care more about selling a bad product than turning it into a good product. I hope that's not the case because it used to be a good platform.
In general i think sales reps make more money overall but have a much more stressful job and can get axed whenever they underperform for a quarter etc
Engineers can also be axed at any time for performance. They're fortunate that most companies are bad at measuring that, but they're also subject to things like stack ranking at very bad companies (fire worst 10% every year) so it's certainly not better to be in eng rather than sales.
Ultimately all roles have aspects of them that suck, so you need to find the one that sucks least for you.
I never seen this on my 30+ years on the job, other than being an early joiner to startups, equity isn't a thing.
> Engineers who find it distasteful should be happy to know engineers typically get way more equity than sales reps.
At very best, some companies might offer some kind of fixed bonus, if you over delivered as part of the KPI/OKR/whatever goals for the year, or the profits were nice enough that everyone gets a cut.
Even without the equity part i think most engineers should be thankful for not having to hit their kpis to get full paycheck
Someone outside the company who was thinking of joining a B2B sales team, and who likes tropical vacations, might react positively to this post.
Or a potential investor might be impressed to see the company has a mature sales pipeline and plenty of revenue to reward its top salespeople.
Most (enterprise focused) companies, even outside of tech, has something like this. Called Club, P-club, presidents club, circle of excellence, etc.
HackerOne chose a sales-first culture and this is their way of rewarding that growth.
It's more a reward for a competition-style work mindset.
When COVID restrictions were lifted, travel and t&e budgets just never returned. Layoffs started happening and what were lavish, expensive events just couldn’t happen anymore. Hackerone charged for and likely made a lot of money on these events. I think a lot of what is talked about in the article is true but I think Covid is a big part of the why that led to it.
It is also worth remembering that the cost of travel itself, and the cost of venues itself has also increased substantially. As well as associated costs such as catering and insurance.
So in-person events have issues from both sides, those attending and those hosting.
You also do not mention corporate policies. Under pressure from investors, their employees and sometimes their home-countries, many corporates have also introduced environmental policies. So if you want the company to pay for your flight, you not only have to justify it financially, but you have to justify it environmentally too.
You can find many examples like this.
Most got dismissed.
One of them, a remotely triggerable DoS vector got downgraded in severity. I got a token payment from the company, and 7 years later, it is still not marked as resolved.
I doubt my situation is unique.
If you act in good faith, communicate clearly, and conduct yourself reasonably, most companies will work with you — even when you've technically wandered outside the neat boundaries of their risk-appropriate, regulatory-reviewed policy.
That isn't protection, of course. Eventually you'll encounter a bounty program run primarily by lawyers, procurement, or someone optimising a graph trend-line.
And we know what tends to happen next.
Those programs, and organisations, develop reputations. Researchers talk. Companies get discussed at conferences, in private groups and across the community, and some become informally blacklisted.
Microsoft is a useful recent example: researchers have publicly walked away from five-figure bounties to make a point. There are excellent people working there, but organisationally Microsoft has repeatedly struggled to engage with the security community in a way that feels collaborative, rather than adversarial. Unless you're one of their paid partners, intermingled in their ecosystem.
A lot of that seems to come down to incentives: somebody, somewhere, wants the numbers to look better.
That doesn't work particularly well in an industry that, like most industries, ultimately runs on relationships, trust and specialisation.
If a company marks something critical as informational, sometimes the most effective response is a CVSS parameter argument. It's a snarky comment:
"Okay — so if I find a way to abuse your own infrastructure to message your customers, trigger a major incident and create regulatory problems for your clients, you'd prefer I treat that as informational too, and instead just report it to regulators?"
Surprisingly often, that gets the issue reconsidered.
Have you annoyed an analyst? Maybe. Does it matter? Probably not. Neither of you will remember the exchange a week later, but you might have corrected a bad risk decision on their side and you'll see a positive outcome on your side. Mistakes happen.
I generally advise companies and hackers alike to follow Kiwicon's #1 rule.
It took down the entire application for all users and tenants, not just the tenant submitting the poisoned query.
I don't remember how much I was paid, a token amount for sure, but I was happy with any amount because it was a hobby and any payment was good for the CV.
Every application has a bug that can bring the whole application down for every user without owning a botnet? That comes often with a significant business cost, if someone exploits it. Many companies take them seriously. I have reported many as high and business has agreed. Not with HackerOne thought. If there is a bug where someone can make your whole product down with a single laptop isn't really something you can just ignore.
I think it would be the individual companies slowing things down, not the platform.
And they have hackerone employees pre-screen submissions and I had to tell them multiple times why my submission was valid.
I don't think this is true, although it's a very commonly-held belief. Dan Goodin (I think?) wrote an article about this a long time ago, and was only able to come up with a few examples, and none of them fit this fact pattern.
https://news.ycombinator.com/item?id=16642155
What is true is that it is much less legally risky to test someone else's computer than it was 10-15 years ago. People forget that's what you're doing when you look for web vulns! The DOJ has had a norm over the past ~many years not to prosecute good-faith vulnerability research, even though strictly speaking it contravenes CFAA directly. But "risky on paper" is the most you could say about doing that kind of testing back in 2010.
I can think of 4-5 other situations from around that era (~2012) where people were at least charged and needed a lot of help to navigate the legal proceedings to avoid jail time.
In 2010 it was more than risky on paper.
2017-2018 is well into the established era and probably even the golden age of bug bounties when a lot of corporate and judicial thinking re: white hat cybersecurity had been shifted.
Yet I still find it next to impossible to get issues resolved.
I'm a software engineer / tech bro by trade, and hacking and CTFs have always been a part time hobby for me, and thus I'm not part of the "elite" who get special treatment in the form of account managers and priority support.
I can't help but feel like I'm becoming an even smaller cog in this corporate machine than before - if you look at H1's website, the hacker community is now just 1/6th of their supposed offering, alongside all of the AI pentesting services.
The hacker community is precisely what this company was built on.
The trajectory that they're on, and the positioning that they're adopting, makes me feel like they're eager to "move on" to something beyond it. The financial incentive is certainly there.
This is not VCs being evil and corrupting a pristine engineer- or hacker-defined concept of true value. The VCs are all following the rules and are trying to make money off of risky investments (it's "venture" capital, after all). But the incentive structure just forces the market into either an oligopoly of largely extractive services (or into everything being free: that's why open source is also a stable point for software).
My hope is that in time, basic software services, like for communication, socialising, community hosting, and so on, will eventually become seen as core social infrastructure. I don't really think this can happen via existing institutions, even open source, because the fixed costs of making software are really high. You really need _tax_ to support this. But it's very difficult to do because the internet cuts across borders.
It’s sad when it’s asymmetric - founders lose their idealism and sell out while early employees fail to notice the game has changed.
But dreams are rarely enough to keep things going. And VCs know just what to say to make it seem like the dream and the money can coexist.
It can be power - see Reddit and Wikipedia mods - but it's usually money. And once VC fundraising is involved, it's pretty much always money.
If I were a betting man, I'd bet HackerOne simply wired LLMs up to post as Alex and Michiel.
Up and coming AI pentest companies need to have an exceptional product to get a chance to stand on their own and penetrate the enterprise market, otherwise their best scenario is an acquisition to get bundled into an established platform.
They literally asked me to prepare on the company mission and values.
The first round was about generic stuff where nothing much was asked. And ironically, despite transparency being their core mission, they didn't tell me I was rejected until I emailed them about a week later.
> And to whoever is fired up: The market is ready for a disruption. The tools are in your hands. Build what HackerOne could have been.
This is a rallying cry that should echo across the entire tech industry. Build what * could have been.
Did you miss this part from the article:
> They switched from talking about bug bounty programs, live hacking events, and how they could help you stay secure, to promoting their in-house AI security product and continuous security monitoring tool.
notably the in-house AI security product is trained on existing bug bounty reports.
> It sounds to me more like the OP already disliked H1 (for its sales practices and general enshittification) and the LLM issue was a convenient excuse to make a clean break.
that's pretty harsh to say when OP provided some very valid reasons, imho speaking as someone who's used HackerOne for over a decade.
link to H1's "continuous monitoring tool" for the curious: https://www.hackerone.com/product/h1-continuous-testing
Wow, it's like he prompted for the most stereotypically AI response possible. There's a tired trope in every sentence going on for four whole paragraphs! I originally quoted it too but thought better and decided to snip it out because I'm pretty sure it would get my account flagged by HN's AI detection algorithm...
And then you get an AI slop response like that in return where you can't even tell whether it was just a CEO not giving a damn...or a standard dumb chat bot with a stupid response.
I'm not sure if founders are aware that these are tipping points in customer care where the people that care about your product and ecosystem will leave your company for good, and you're irreparably damaging your own reputation.
If I were OP I'd never ever touch anything with a 10ft pole that the founders will build in their lifetime, and I'd warn everyone I know in the community about it.
That's the damage they're doing with these AI optimizations to themselves.
There's a reason why everyone starts to hate your company right after your stupid chatbot was introduced.
- "What happened to HackerNews?"
- why is it only AI, LLM, GPT stuff on the all the pages now?
I literally showed them their server taking over a minute to respond to my request. I even showed how the delay increased proportionally to the message size... Clearly doing more processing; classic DoS vulnerability... Doesn't leave much to the imagination! But they said they would not pay me anything unless I actually proved that it scaled and caused disruption of their service!
It seemed like they were baiting me into incriminating myself for a crime that they wanted me to commit against them. It's not even the first time that I've been baited by a software company into committing a crime against themselves. I never took the bait though.
The big company always wins. The legal system is pure fiction at this point. What lawyer would stand against the big companies? Permanently destroying all their future career prospects.
Erin Brockovich? That's a corporate propaganda movie.
Reality is more like what happened to Julian Assange or Steven Donziger. And they had support from some powerful groups. If they didn't, we wouldn't even have heard of them. That would have been my situation. Not worth the $200 bounty.
Most of my research starts with: _There is absolutely no way this works_. Then it works.
I've been thinking that a lot more lately.
Companies and hackers are both heavily incentivised to reduce the friction involved in vulnerability disclosure, particularly for large organisations. The platforms are good enough now. They're email in 2007: imperfect, occasionally frustrating, but substantially better than what came before.
They make SLAs possible. They provide structure and administration. Things still go wrong — companies stop responding, analysts drop the ball, hackers can be idiots — but the model basically works.
Decentralising disclosure again would make life significantly harder for individual hackers. We'd end up back on email, probably building email-powered bounty CRMs that consume a small country's worth of tokens just to keep track of everything.
For smaller organisations, though, I wouldn't touch a public bounty platform with a 10-foot pole. Run a private program first (through the platform). Having been on the receiving end of beg bounties, automated scanner output and increasingly AI-generated slop, most smaller security teams simply cannot scale to absorb the noise.
The more interesting way to think about these platforms is that they're becoming the LinkedIn of hacking.
For hackers, the path is fairly straightforward: build a rep through useful -- but oftentimes unsolicited disclosures, get invited onto private programs, and gradually establish a profile with a strong signal-to-noise ratio.
For companies, they're increasingly a recruiting and relationship-building tool.
And for the platforms, I think there's a much larger opportunity for them in community.
They should be significantly better at understanding hackers: what they're good at, what technologies interest them, which industries they understand, and where they're located. Today, that profiling is laughably poor, to the point the questionnaires on areas by these large platforms are out of date by several years.
Then use the data.
Run small, highly targeted events: state- or city-based meetups, lunch-and-learns, product launches, bounty program launches and technical briefings. They don't need huge sponsorship budgets or prize pools. They need the actual community involved. Pay for dinner, sponsor a talk.
A lot of existing events seem to start with companies, sponsorship packages and monetary amounts, then work backwards. I think that's backwards.
As a weekend hacker, I'm far more likely to spend time on a program because something about it is interesting: you're launching an AI feature, handling financial data in a new way, using Node/GCP/a TI-82 calculator, or exposing some weird technical surface I want to understand.
And I'm far more likely to build a useful relationship with a company if I can actually meet the people behind the program. Hackers can provide much better feedback than a semi-generated report, and companies can explain far more than a stale domain list and scope document — which, realistically, we'll be ignoring 99.99% of the time anyway.. Unless it's government. I quite like my freedom.
tl;dr which begins 3,000 words in: employees were noticed to be leaving and it’s because a “fine tuning from user submissions” ai psychosis of yesteryear, except it’s amusingly happening in 2026 still. Investigation into the veracity of the claims.
This has a negative effect on humans doing their work with or without LLMs: curl shut down their bounty program, and GitHub just announced they're "restructuring" theirs. The author of this post also makes a case that HackerOne hasn't been honest about LLM training and use, either to hackers or to their own staff.
I'd say instead that the problem is that a lot of people don't care anymore about the quality of the work being done, and LLMs are accelerating it. Bounty programs have shifted from ways for people to report security bugs to ways for people to try to make money.
Automated triage can filter obvious spam, which was already fast and easy for humans to do. The hard part is independently reproducing a plausible finding and assessing its actual impact. If LLMs could already do that reliably, then the slop report problem wouldn't exist in the first place.
It sounds like a reason to try and build it than a reason to not build it.
You know, the biggest thing that HackerOne delivers is a universal payments system that requires absolutely no efforts from companies. Have you tried to manually pay hackers from around the world? It is a laborious process involving trying to find what providers are compatible and what forms of money go where. It is extremely taxing to handle this. HackerOne provides real, tangible value in not making people think about how precisely to pay a hacker and in what currency. No amount of tokens solve the accounting problem, and it is foolish to imply otherwise.
I see some people with the idea that businesses are going to use AI to solve everything in their own one-off bespoke manners for everything, but I don't think it's going to happen. What's going to happen is that the SaaS providers are going to get even better at making yet more stuff go away than they were before and it'll actually be harder for a business to replicate it themselves then it used to be.
(Of course the "go away" isn't perfect, but clearly, neither is the idea that solving everything yourself with AI is either.)
One learning I can share from the indie game industry is copycats become dime a dozen when a particular game becomes successful. With execution becoming nearly cheap, tasty products and their behaviour will be copied and competition will rise substantially.
But the simple truth is 100 programmers with AI are going to do a lot more work than 1 or 2 programmers with AI. All the usual considerations for communication overhead and all the old reasons why 100 programmers aren't necessarily 100 times as productive as 1 are in play... but so are all the reasons why that group of 100 programmers is going to outdo that 1 no matter how hard that 1 works.
We are probably in roughly the middle phase of the time period when we're still learning to harness AIs at all, and seeing simply some modest accelerations of process. Eventually we're going to progress to getting significantly enhanced productivity from them for pretty much everybody. And then what will happen is not that the SaaS market crashes, but what constitutes an entry-level SaaS product will rise up to meet the increased programming firepower. Find me a SaaS whose current two-year roadmap is "Eh, don't do anything, really, we're set" and I'll show you the SaaS company who probably ought to be really, really worried about AI eliminating their entire niche. I'm sure there are some out there, but it's not the usual SaaS company experience.
You can argue that games are derivative, but I think most revenue still goes to premier titles, not knock offs.
The flip side, of course, is that I can fix my problem - which may be unique and not something a large SaaS will ever do - on my timeline.
I would not want to be a SaaS that offers some really simple service that can be replicated in a heartbeat, though. Something like "how do I pay people all over the world" is already very complicated, and over the next decades as governments start writing laws with the understanding that AIs can implement them in code no matter how complicated they are, it's likely these problems will become even more complicated and even more important to just buy a service that can deal with them. (I'm not celebrating that, merely predicting it.) But I sure wouldn't want to be selling some super simple scheduled reminder service or something else really small.
In the worst case, envision a world where home owner associations or townships or whatever other local governmental division of just perhaps a few hundred people start levying sales taxes, with their own complicated exclusions and offsets and conditions, because LLMs make it possible to handle the code for all of the literally hundreds of thousands or millions of such jurisdictions. Even if you can throw tokens at that problem to solve it yourself, you probably don't want to. And again... I'm not celebrating that. More a world-weary bowing to the inevitable despite it being an obviously bad idea.
I think there might be space for "source available" enterprise software where you can use an LLM to modify it in a way that is cheap to continue reintegrating in new releases.
It may also be reasonable to send your prompts to the vendor and see if it is a feature they are willing to maintain.
But the ability to meaningfully make a personal implementation has changed.
Indeed. I use a third party company (not HackerOne) to handle our bug bounty and the primary reason is so they handle all the payment hassles, I don't need to be involved. They also handle all the screening for false positives, which in the AI age are exploding. I also don't want to deal with that.
In general I lean towards building in-house, but this is one area I'm happy to oursource all the busywork.
But to answer the question, currently using Inspectiv.
That said, with the volume of inbound reports coming from LLMs, the signal-to-noise ratio has plummeted, and the time taken to triage has gone through the roof.
If paying out bounties was easy I would do it all via email; but as you said it’s almost impossible to do (unless you are maybe bigcorp and have a team just for that)
Outsourcing all that mess is a great use of money.
- Starting scenario: no way to contact a company outside of H1 (or some other managed programme)
- The company is compromised, their customer support has no idea what this means, they have no security.txt or any other security contact
- I have explicitly told H1 to just forward it with no bounty, I don't want a bounty, only remediation, I do not care about a bounty or any reward
- H1 closes as "not eligible" and tells me to not submit stuff I can't prove it's my compromise by putting my username on it
- Corporate server is still compromised and being used as a proxy to brute force my services
The closest we have is cryptocurrency, but it doesn't scale.