frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

When Startups Ask for Free Security Work

6•hdue•3h ago
A few weeks ago, I explored [redacted], a YC-backed AI backend platform. Like many security researchers, I tend to poke at new tools to see how they handle common attack vectors.

It didn’t take long to find issues, both in security and user experience.

## The Vulnerabilities

*Authorization Flaw*: [redacted] limits free users to 3 items, with a paywall for more. But their API doesn’t enforce this. Anyone can bypass the frontend and call the API directly.

This classic flaw means free users can generate unlimited content, paid tiers lose value, and the business model collapses.

*UX Problems*: The platform also has confusing navigation, inconsistent design, poor hierarchy, clunky workflows, and unclear onboarding. When the product experience feels this raw, security flaws are just another sign of neglect.

## The Response

I asked in their community channel about their disclosure process. The founder replied:

“hi [name], i just saw your message on the general channel. right now, we are not hiring, but people are helping improving the platform and this is a good test for the future, when we will hire people. if you want to contribute, feel free to report bugs or security issues to us. if security related, it's best on private dms rather than on general channel”

Translation: Please do free security work for us. Maybe we’ll hire you someday.

## Why I Didn’t Disclose

I withheld details because: - No bug bounty or acknowledgment system - Security research framed as "free testing" - Vague promise of future consideration, not present compensation - No disclosure policy or timeline - Overall lack of professionalism

Finding and responsibly reporting vulnerabilities takes skill. Expecting researchers to do it for free, especially from a funded startup, is unacceptable.

## The Broader Problem

This reflects a larger startup issue: wanting community help without paying for it. Companies routinely ask for unpaid QA, security audits, bug reports, and UX feedback while raising millions.

## What Good Companies Do

The best companies have: - Clear disclosure policies with defined timelines - Bug bounty programs (even small ones show respect) - Professional communication with researchers - Public acknowledgment for responsible disclosure

It doesn’t take much. Even a $10 gift card and a thank-you matter.

## Current Status

A month later, the vulnerability is still unfixed, and UX remains rough.

For users, this means inaccurate usage tracking, broken economics, possible deeper issues, and ongoing frustration. For the company, it reveals a culture where security, UX, and respect are afterthoughts.

## Lessons for Founders

*Security basics*: - Enforce all limits server-side. Never trust the frontend. - Publish a simple disclosure policy. - Respect researchers, we’re trying to help.

*Cultural basics*: - Don’t ask for free labor. - Treat feedback as valuable, not free QA. - Remember that first impressions last.

The security community wants to help, but not at the cost of undervaluing expertise.

Build secure products. Create intuitive experiences. Respect those who help you improve. Security debt compounds quickly, but UX debt kills adoption even faster.

---

Have you had similar experiences with AI startups expecting free security work? How do you handle companies that dismiss security?

Firms will hesitate to invest in US after raid – S Korea president

https://www.bbc.com/news/articles/cly0e4k750go
1•belter•38s ago•0 comments

Panda and the New iPhone Air Adventure

https://pandacomic.com/2025/09/11/📱🐼-panda-and-the-new-iphone-air-adventure/
1•ifeelbits•1m ago•0 comments

Ask HN: Is MSFT hotmail down for you?

1•markus_zhang•1m ago•0 comments

This Nomadic Eccentric Was the Most Prolific Mathematician in History

https://www.scientificamerican.com/article/this-nomadic-eccentric-was-the-most-prolific-mathemati...
1•jruohonen•1m ago•0 comments

Polymorphic symmetric multiple dispatch with variance

https://dl.acm.org/doi/10.1145/3290324
1•andsoitis•3m ago•0 comments

AlbumentationsX: Next-generation Albumentations for image augmentations

https://github.com/albumentations-team/AlbumentationsX
1•ashvardanian•4m ago•1 comments

Bypassing WAFs for Fun and JavaScript Injection with Parameter Pollution

https://blog.ethiack.com/blog/bypassing-wafs-for-fun-and-js-injection-with-parameter-pollution
1•speckx•5m ago•0 comments

The One-Line Prompt That Cut Token Usage by 37.91%

https://modgo.org/the-one-line-prompt-that-cut-token-usage-by-37-91/
1•hexpeek•8m ago•0 comments

Global Replication Made Easy

https://www.tigrisdata.com/blog/talks/2025/global-replication/
1•ianopolous•8m ago•0 comments

GrapheneOS and Forensic Extraction of Data

https://discuss.grapheneos.org/d/13107-grapheneos-and-forensic-extraction-of-data
16•SoKamil•13m ago•0 comments

Show HN: Rule34dle – A Higher-or-Lower Game Based on Character Popularity

https://rule34dle.app/
1•virusyu•17m ago•0 comments

Daniel Day-Lewis says he 'never intended to retire, really'

https://www.theguardian.com/film/2025/sep/11/daniel-day-lewis-says-he-never-intended-to-retire-re...
3•mykowebhn•18m ago•0 comments

Ireland will not participate in Eurovision if Israel takes part

https://www.rte.ie/entertainment/2025/0911/1532957-rte-eurovision/
44•a_paddy•18m ago•5 comments

Lessons in Disabling RC4 in Active Directory

https://syfuhs.net/lessons-in-disabling-rc4-in-active-directory
3•speckx•19m ago•0 comments

Behind the Scenes of Bun Install

https://bun.com/blog/behind-the-scenes-of-bun-install
10•Bogdanp•20m ago•1 comments

Show HN: SARE, a Hybrid Post-Quantum Encryption System Implemented in Rust

https://github.com/SareProject/sare
2•znano•20m ago•0 comments

Show HN: TrustGlance – See any business's trust level in seconds

https://trustglance.com:443/
1•aaronkn•26m ago•0 comments

Verifying LLM Output, Sorta, Kinda

https://theaiunderwriter.substack.com/p/false-confidence
2•participant1138•26m ago•0 comments

CPI for all items rises 0.4% in August, 2.9% YoY; shelter and food up

https://www.bls.gov/news.release/archives/cpi_09112025.htm
1•impish9208•27m ago•0 comments

Shop Now at Ecofriek 100% Organic Food Products Delivered Fresh from Farm

https://ecofriek.com/
1•rashunain•27m ago•1 comments

Web Desktops

https://github.com/syxanash/awesome-web-desktops
2•southwindcg•27m ago•0 comments

Tricks from OpenAI GPT-OSS you can use with transformers

https://huggingface.co/blog/faster-transformers
4•soheilpro•28m ago•0 comments

Experts Scrutinized Ofcom's Online Safety Act Governance. They're Concerned

https://www.theregister.com/2025/09/11/concern_and_sympathy_as_experts/
2•rntn•29m ago•0 comments

The Erdös Number Project

https://sites.google.com/oakland.edu/grossman/home/the-erdoes-number-project
2•jruohonen•30m ago•0 comments

PauseR – Open-Source Plugin: Pause Minority Mode for RabbitMQ with Khepri

https://seventhstate.io/seventh-state-pauser-plugin/
2•SeventhState•30m ago•1 comments

Show HN: Speech-to-text CLI in Rust with Nvidia Parakeet-local, fast, extensible

https://elvin.engineering/blog/2025/09-10-para-speak-cli/
2•elvin_d•34m ago•0 comments

How Bloomberg News Vetted the Epstein Emails

https://www.bloomberg.com/news/features/2025-09-11/how-bloomberg-news-vetted-the-jeffrey-epstein-...
3•danso•34m ago•1 comments

UK fires ambassador to US Peter Mandelson over Epstein links

https://www.cnn.com/2025/09/11/uk/peter-mandelson-uk-ambassador-fired-intl
7•belter•37m ago•0 comments

Pokémon Cards CSS Holographic Effect

https://poke-holo.simey.me
2•speckx•37m ago•0 comments

Learning Lens Blur Fields

https://blur-fields.github.io/
1•bookofjoe•38m ago•0 comments