logoalt Hacker News

Restructuring GitHub's bug bounty program

18 pointsby soheilprotoday at 2:28 AM9 commentsview on HN

Comments

dinkelbergtoday at 2:54 AM

So if the "wrong" person finds a critical vulnerability in GitHub, the payout is capped at $10,000. Might reduce the likelihood of it being submitted to the bug bounty program.

show 2 replies
saagarjhatoday at 4:03 AM

I wonder if this incentivizes people to form groups that self-vet for quality submissions to enhance their reputation.

fragmedetoday at 4:06 AM

That's a weird way to do it. Yes, there's a wave of low quality reports, but a vuln is a vuln. The filter mechanism shouldn't affect the payout amount. What if we just give people who are white a higher payout because they are white? That seems fair, right?

applfanboysbgontoday at 4:04 AM

I mean, this is just a "fuck you", right? "Because there's a lot of LLM spam, we've decided that some researchers will get 1/4th as much pay for reporting the same bug as others, even if they didn't use LLMs". If anything this will have the opposite of the intended effect -- this strongly discourages humans who aren't part of the VIP program from reporting bugs they find to Github, so you'll probably see a higher ratio of LLM spam in the future. And don't be surprised if those bugs get sold elsewhere...