frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Ask HN: Anyone Using a Mac Studio for Local AI/LLM?

48•UmYeahNo•1d ago•30 comments

Discuss – Do AI agents deserve all the hype they are getting?

4•MicroWagie•6h ago•1 comments

Ask HN: Ideas for small ways to make the world a better place

19•jlmcgraw•23h ago•21 comments

Ask HN: Non AI-obsessed tech forums

32•nanocat•21h ago•28 comments

LLMs are powerful, but enterprises are deterministic by nature

4•prateekdalal•10h ago•7 comments

Ask HN: 10 months since the Llama-4 release: what happened to Meta AI?

44•Invictus0•1d ago•11 comments

Ask HN: Who wants to be hired? (February 2026)

139•whoishiring•5d ago•520 comments

Ask HN: Who is hiring? (February 2026)

313•whoishiring•5d ago•514 comments

AI Regex Scientist: A self-improving regex solver

7•PranoyP•1d ago•1 comments

Ask HN: Non-profit, volunteers run org needs CRM. Is Odoo Community a good sol.?

2•netfortius•18h ago•1 comments

Tell HN: Another round of Zendesk email spam

104•Philpax•3d ago•54 comments

Ask HN: Is Connecting via SSH Risky?

19•atrevbot•2d ago•37 comments

Ask HN: Has your whole engineering team gone big into AI coding? How's it going?

18•jchung•2d ago•14 comments

Ask HN: Why LLM providers sell access instead of consulting services?

5•pera•1d ago•13 comments

Ask HN: How does ChatGPT decide which websites to recommend?

5•nworley•1d ago•11 comments

Ask HN: What is the most complicated Algorithm you came up with yourself?

3•meffmadd•1d ago•7 comments

Ask HN: Is there anyone here who still uses slide rules?

123•blenderob•4d ago•122 comments

Ask HN: Mem0 stores memories, but doesn't learn user patterns

9•fliellerjulian•2d ago•6 comments

Ask HN: Is it just me or are most businesses insane?

8•justenough•1d ago•7 comments

Kernighan on Programming

170•chrisjj•5d ago•61 comments

Ask HN: Anyone Seeing YT ads related to chats on ChatGPT?

2•guhsnamih•1d ago•4 comments

Ask HN: Does global decoupling from the USA signal comeback of the desktop app?

5•wewewedxfgdf•1d ago•3 comments

We built a serverless GPU inference platform with predictable latency

5•QubridAI•2d ago•1 comments

Ask HN: Does a good "read it later" app exist?

8•buchanae•3d ago•18 comments

Ask HN: Any International Job Boards for International Workers?

2•15charslong•20h ago•2 comments

Ask HN: Have you been fired because of AI?

17•s-stude•4d ago•15 comments

Ask HN: Anyone have a "sovereign" solution for phone calls?

12•kldg•4d ago•1 comments

Ask HN: Cheap laptop for Linux without GUI (for writing)

15•locusofself•3d ago•16 comments

Ask HN: How Did You Validate?

4•haute_cuisine•2d ago•6 comments

GitHub Actions Have "Major Outage"

53•graton•4d ago•17 comments
Open in hackernews

Tell HN: Internet Bug Bounty (IBB) on HackerOne Appears Dead, CVEs Unpaid

11•irke882•1mo ago
I figured out this might be a good place to ask/raise this.

This is about the IBB program:

https://hackerone.com/ibb

A few months back, I reported two vulnerabilities that should get a $8000 payout or so. They got CVE numbers and got fixed months back.

It seems like the program is dead. Last report has been resolved 8 months ago. I have tried repeatedly to contact HackerOne through different channels, but got no response. This includes e-mailing the official IBB e-mail, e-mailing HackerOne people directly, reaching out through their forms and using mediation. There's total silence.

I searched social media for any mentions of this, but didn't see any communications.

It looks like the program is dead. The bounties are still being promised, but the reports are ignored - even for published CVE's that clearly do qualify for payouts according to the rules.

Does anyone know more about the situation? What shall be done here? Is the program dead?

Comments

whatamidoingyo•1mo ago
That's why I stopped going to HackerOne. My first 3 reports were marked as duplicate. The last report on there was an auth bypass, essentially. They replied: "But you need to show what can be done beyond this". Like, wat? You want me to do some real damage before accepting it (hackerone managed)?

Those were my only reports on the platform before I gave up. Then I went to BugCrowd, submitted a report and it was accepted.

jll088•1mo ago
I'm cybersecurity editor at The Register and would like to hear more about what happened - can you get in touch via email (jessica.lyons@theregister.com) or signal jess.825