Is there not a single thing that 'AI' isn't enshittifying?
Bug bounties: The good, the bad, and the frankly ridiculous ways to do it
Thirty years ago, Netscape kicked off the first commercial bug bounty program. Since then, companies large and small have bought into the idea, with mixed results. Bug bounties seem simple: a flaw finder spots a vulnerability, responsibly discloses it, and then gets a reward for their labor. But over the past decades, they've …
COMMENTS
-
-
Sunday 24th August 2025 19:56 GMT DS999
They just need to require better reports
Make them provide a few screenshots and/or log files that demonstrate the bug being exploited, not just a text writeup "if you do these steps then you get root" or whatever. For a real report that isn't much of a hurdle, but if AI is hallucinating bugs it would also have to fabricate screenshots and log files. Not sure about log files but AI is demonstrably terrible at image generation that includes text. The text is often garbled or meaningless, even for easy stuff like "generate a map of the US including the names of each state".
If people submit stuff that includes obviously AI generated slop just blacklist them from doing bug reports.
-
Sunday 24th August 2025 10:42 GMT Blazde
'AI moderation'
I'm never going to use a bounty platform that's known to use AI moderation (at least where it operates like a brick wall you can't easily appeal your way past - looking at you Google). It's frustrating enough when unscrupulous or ignorant humans reject a vulnerability report you've spent hours working on, but at least you can blame an individual in that case. A senseless 'computer says no' response is a process failure and proof you're wasting your time dealing with the entire company. More AI slop is not the answer to AI slop. It's a b.s. solution and they know it is.
-
Sunday 24th August 2025 12:04 GMT tyrfing
"no, I don't look for criticals at all, they're too hard and take too long. I go for automation to get more efficient low- and medium-severity bugs.' The mediums are the sweet spot, because they pay more.."
Just like with taxes. Taxing the billionaires might get you lots on an individual basis, but you get less overall because there just aren't that many of them.
And taxing them more is really hard.
-
Sunday 24th August 2025 19:30 GMT jake
The flaw in your logic is that a country is supposed to tax billionaires AS WELL AS the ordinary people, in a proportional manor.
Right now here in the US, the billionaires aren't being proportionally taxed. In fact, most of the fuckers are freeloading.
"Quand le peuple n'aura plus rien à manger, il mangera le riche." —Jean-Jacques Rousseau
-
-
Monday 25th August 2025 21:02 GMT MashedPotato
Beg Bounty
We are plagued by these extortionists who weekly assert that they have found a critical vulnerability, which is nothing more than an SPF compliant issue, or disabled DMARC or perhaps reflected cross site scripting. None of which is important in our systems, all of which generates noise. Inevitably the initial email asks for money "in line with industry good practice. And then the threat that in order to protect personal data if we don't pay up the extortionist will have to go to the information commissioner to ensure full public disclosure.
The only people worse are the extortionist ratings companies that provide no value to anyone, yet tick an audit box and squeeze fees from unsuspecting clients. "oh you have RDP, we don't think RDP is good practice therefore we rate you D+, you need to remove it". I think we know best whether FTP, RDP, or whatever other specious protocol they decide they don't like is suitable for our environment, our risks and our business needs.
A plague on all their houses.