logoalt Hacker News

omoikane • today at 6:18 PM • 1 reply • view on HN

Every HN post regarding security exploits inevitably results in some comment saying the bounty is too low. I find it helpful to read previous comments by tptacek regarding bug bounties and market values:

https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...

This one probably has the best summary:

https://news.ycombinator.com/item?id=43025038


Replies

elmer2 • today at 6:27 PM

This is correct. I've made well over six figures over the last couple of years through bug bounty programs. I wouldn't spend months finding one bug. It's usually days or a week or two max.

$5,000 is actually pretty normal for a critical. I think the most I received for one bug was around $10,000, but this is the exception.

AI has also ruined the market. I'm a security consultant (where I make most of my money) and stopped bug bounty once AI slop reports made it impossible to actually get anything triaged in a timely manner.

Something else many don't know is that with all of the major platforms, customers can see the bugs before they are even triaged by the platform team. Many companies are now taking advantage of the long triage times and fixing the bugs before the researcher can get paid. It's then marked as a duplicate and the researcher gets nothing.

➕ show 2 replies