logoalt Hacker News

jamessinghalyesterday at 6:51 PM2 repliesview on HN

Their success rates on HackerOne seem widely varying.

  22/24 (Valid / Closed) for Walt Disney

  3/43 (Valid / Closed) for AT&T

Replies

pclmulqdqyesterday at 8:27 PM

Walt Disney doesn't pay bug bounties. AT&T's bounties go up to $5k, which is decent but still not much. It's possible that the market for bugs is efficient.

show 1 reply
thaumasiotesyesterday at 6:53 PM

> Their success rate on HackerOne seems widely varying.

Some of that is likely down to company policies; Snapchat's policy, for example, is that nothing is ever marked invalid.

show 1 reply