frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

We ran a security bounty for our tiny bootstrap startup. Here's what happened

2•momciloo•17h ago
We're a team of five, bootstrapped, building BCMS, a headless CMS. A year ago we launched a security bounty. Rewards were between $100 and $700... basically what we could afford. Surprisingly, that didn't stop people. Hunters still flooded in. Several a day. The issue wasn’t the size of the payouts, it was the kind of behaviour it attracted.

I expected people to try breaking into user data, finding crazy privilege escalations, or discovering ways to dump entire databases. What actually happened was… different.

We got reports about: - Creative ways to inject JavaScript into HTML through weird embedding edge cases. - Strange file upload pitfalls we hadn't thought of. - Tons of tiny UX bugs filed as "security." - And the most time-consuming one: things that worked exactly as designed, but looked like bugs to outsiders.

Example: in our CMS, you can use an "entry pointer" to select related content. A blog editor with no permissions for “products” should still be able to select products to recommend, but not open/edit/delete them. To make that UX work, our API returns product titles even if you don’t technically have product access. This is by design. We had to spend hours explaining this again and again to bounty hunters convinced it was a data-leak.

What we hoped: our existing users would feel encouraged to report issues. What we got: bounty hunters who’d never heard of us, hammering the API.

Another surprise: the program didn’t really motivate our existing users to report bugs. Instead, we suddenly got a wave of people who literally searched Google for

inurl:security "reward" "cms" bug bounty bug bounty reward $100

and landed on us. No genuine conversations, just transactional hunting. For a few months, 30% of all site visitors came from that one Google query. Our Sentry lit up from random API fuzzing, exceptions everywhere, onboarding metrics tanked.

So yes, the bounty helped. We did patch dozens of real issues that would have been painful later. We ended up paying out ~$5k total, and several reports led to meaningful patches. So even with small rewards, we got serious contributions. But it also forced us to “fix” things that weren’t broken (just to stop getting the submissions about them haha), drained time explaining design decisions, and buried real user issues.

We eventually shut it down. For us right now, it’s more valuable to understand how new users onboard, where they get stuck, and what makes them stay.

So, if you’re considering creating a bug bounty, be ready for bounty hunters to outnumber your real users. If you want signal from your actual users, maybe wait until you can afford the noise.

Comments

asadeddin•17h ago
Very interesting. Thanks for sharing the insights!

Would've it made more sense to separate this testing out to a different instance of your product? This would've probably helped distinguish between real and bounty users.

Google admits the open web is in 'rapid decline'

https://www.theverge.com/news/773928/google-open-web-rapid-decline
1•pseudolus•5m ago•0 comments

How to Become a Pure Mathematician (Or Statistician)

http://hbpms.blogspot.com/
1•ipnon•6m ago•0 comments

A Billionaire Owner Brought Turmoil and Trouble to Sotheby's

https://www.newyorker.com/magazine/2025/09/01/how-a-billionaire-owner-brought-turmoil-and-trouble...
1•FinnLobsien•9m ago•0 comments

Running a Root DNS Server on FreeBSD from Alpha to Now by Daniel Mahoney

https://toobnix.org/w/hL5BvuZsy5B3PSeW4YzeNa
1•rodrigo975•14m ago•0 comments

Show HN: PDFGate

https://pdfgate.com/
3•byteforge•22m ago•2 comments

ASML and Mistral agree €1.3B blockbuster European AI deal

https://www.ft.com/content/98e78f6b-0ebf-4546-b25f-bf7621e26c8b
1•jamesblonde•24m ago•0 comments

Mistral AI raises €1.7B to accelerate technological progress with AI

https://mistral.ai/news/mistral-ai-raises-1-7-b-to-accelerate-technological-progress-with-ai
2•kgwgk•27m ago•0 comments

Meta hid harms to children from VR products, whistleblowers allege

https://www.theguardian.com/technology/2025/sep/08/meta-virtual-reality-whistleblowers
1•beardyw•27m ago•0 comments

19 Dead in Kathmandu Social Media ban protests

https://kathmandupost.com/national/2025/09/08/nepal-s-gen-z-uprising-explained
1•schmudde•29m ago•0 comments

Jobseekers from Africa being tricked into slavery in Asia's cyberscam compounds

https://www.theguardian.com/global-development/2025/sep/09/cyberslavery-kenya-uganda-ethiopia-sou...
2•beardyw•29m ago•0 comments

David Sacks' rules for success in Trump's Washington

https://www.semafor.com/article/09/08/2025/david-sacks-rules-for-success-in-trumps-washington
1•aspenmayer•31m ago•1 comments

New parametric CAD BREP kernel attempt

https://github.com/mmiscool/BREP
1•mmiscool•32m ago•0 comments

Lea Ypi: How to think about surveillance

https://www.ft.com/content/9e7372b7-002e-41db-823c-7a70ab8d888d
1•bcye•33m ago•0 comments

DeepWiki of Twitter's Recommendation Algorithm

https://deepwiki.com/twitter/the-algorithm
1•spdling2•35m ago•0 comments

Launching QuickDID – Fast, Open Handle Resolution for the AT Protocol

https://ngerakines.leaflet.pub/3lyea5xnhhc2w
1•g0xA52A2A•37m ago•0 comments

Driftsort: An efficient, generic and robust stable sort implementation

https://github.com/Voultapher/sort-research-rs/blob/main/writeup/driftsort_introduction/text.md
1•g0xA52A2A•38m ago•0 comments

Ask HN: Let's find out who is from which country?

1•Forgret•48m ago•2 comments

The Center for Human-Compatible Artificial Intelligence Is Hiring

https://humancompatible.ai/jobs#chai-internship
1•chai-admin•49m ago•1 comments

Norway's Labour party wins election after seeing off populist surge

https://www.theguardian.com/world/2025/sep/08/norways-labour-party-holds-narrow-lead-in-early-ele...
2•mtlmtlmtlmtl•52m ago•0 comments

Show HN: AuctionHubIndia – Discover Bank Auction Properties Across India

https://www.auctionhubindia.com/
1•raooll•53m ago•0 comments

Tanstack: Headless, type-safe and powerful utilities for Web Applications

https://tanstack.com/
1•chabad360•54m ago•0 comments

Compiling a Functional Language to LLVM

https://danieljharvey.github.io/posts/2023-02-08-llvm-compiler-part-1.html
3•Bogdanp•55m ago•0 comments

Free Video Blur Tool – WuMask

https://wumask.com/
1•EtudusMax•1h ago•1 comments

ASML, Mistral AI enter strategic partnership

https://www.asml.com/en/news/press-releases/2025/asml-mistral-ai-enter-strategic-partnership
3•TechTechTech•1h ago•0 comments

The Army Behind the Army (1919)

https://gutenberg.org/cache/epub/76843/pg76843-images.html
2•petethomas•1h ago•0 comments

Google Launches Preferred News Source

https://blog.google/products/search/preferred-sources/
1•firefoxd•1h ago•0 comments

Show HN: AI Toolbox – a free collection of tiny web utilities

https://www.ellipselabs.tech/
1•Prit44421•1h ago•1 comments

Rethinking Analytical Processing in the GPU Era

https://arxiv.org/abs/2508.04701
3•matt_d•1h ago•0 comments

The next chapter for Atlassian and our customers

https://www.atlassian.com/blog/announcements/atlassian-ascend
1•eastbound•1h ago•1 comments

LockMeOut: Time-lock your phone, computer or social media accounts

https://lockmeout.online/
1•AbuAssar•1h ago•0 comments