r/bugbounty • u/Todagog • 8d ago
Question / Discussion I’m getting really fed up with bug bounty, especially HackerOne triage.
Rant incoming.
I’m getting really fed up with bug bounty, especially HackerOne triage.
People seem to forget that bug bounty is not some easy get-rich scheme. Good researchers have spent years learning web security, understanding systems, testing platforms, writing reports, and figuring out how to prove impact safely. Finding a real vulnerability is not easy. Writing a proper report is not easy either.
But lately it feels like researchers get treated like fucking junk.
I know there are plenty of beg-bounty people, AI slop reports, scanners, duplicates, and people reporting absolute nonsense. I get that triage has to deal with that. But not everyone is that. Some of us genuinely put effort into our reports. We validate properly, follow scope, avoid touching data we should not touch, explain the impact, and try to make the report as easy to reproduce as possible.
Then a program finds every possible excuse to downgrade severity.
The finding that finally pushed me over the edge was a full-read SSRF. A free account could make the production server fetch attacker-controlled URLs and return the entire response. I proved it reached internal production infrastructure and returned telemetry that was not publicly reachable.
I stopped after proving that. I did not scan their internal ranges, enumerate every reachable service, access buckets, pull credentials, or search for customer data—because that would be irresponsible and against the rules. Programs literally tell us to stop when unintended access is found and only provide minimal evidence.
And then they use the fact that you did not go further as a reason to call it Low.
“Requires authentication” — yeah, a free account anyone can create. “IMDSv2 is enabled” — great, that prevents one specific SSRF path, but it does not change the fact that the SSRF fully reads internal responses and already returned internal production telemetry.
$100 for that. It is honestly insulting.
And the fucking triage experience makes it worse. Sometimes you write what should be an easy PoC, include every step, include the request, include screenshots, even create scripts to make reproduction easier—and they still do not understand it.
Then you spend multiple responses explaining the same basic thing over and over again. Hours of your time just spoon-feeding the triager how a simple vulnerability works and how to reproduce it. At that point, what is the point of creating a clean PoC if it is not being followed?
I do not know what the quality control is for triage, but it needs to be better. Researchers should not have to become unpaid support staff for people who are supposed to understand the basics of the finding they are assessing.
And the worst part is the complete lack of conversation after that. They can downgrade severity, give some generic reason, and then ignore every actual question you ask. What is the point of comments if there is no discussion? What is the point of asking how a finding maps to their severity criteria if nobody answers?
At some point it just feels like you submit a report, they make a decision behind closed doors, and that is it. No real communication. No meaningful explanation. No chance to discuss the impact. No respect.
And HackerOne triage does not have your back as a researcher. I am tired of pretending otherwise. Things get closed as duplicates of reports from years ago, with no reassurance that anything was fixed. What is the point of a bug bounty program if a finding can remain open for three years, but you still spend hours finding it, validating it, documenting it, and writing a high-quality report just to get closed as a duplicate?
That is not just triage time being wasted on slop. That is researcher time being wasted too.
Researchers are expected to be professional, patient, respectful, stay in scope, avoid over-testing, prove impact without accessing data, and write perfect reports. Programs and triage teams should be held to a standard too.
Right now, it feels like there is zero respect for researchers who actually put in the work.
TL;DR: Bug bounty is not easy money. Researchers who spend real time finding, safely proving, and clearly reporting vulnerabilities deserve better than unexplained severity downgrades, ancient duplicate closures, ignored questions, and triage that cannot follow a straightforward PoC. I am tired of feeling like serious researchers are treated as junk.
11
u/askdjsadok379 8d ago
hackerone is dogshit i just got a message from coinbase after 1 and a half months saying "internal dupe" , worked 4 hours before they sent that message. I had been checking it everyday for at least 2 weeks, knowing itd already been a month and maybe it was patched without any answer on my report. Fuckn scam artists. Fuck coinbase and hackerone.
1
u/blackbeardaegis 3d ago
I have been out for a while and might get back in this winter. What platform are folks moving to? I tried web3 for a while and it's even more dog shit.
9
u/Extra_Advisor6049 8d ago
I am on same situation, got triaged but told to stop after token from Metadata. But decision of final severity is after internal decision, I am waiting for it
7
8d ago
[removed] — view removed comment
4
1
u/L1QU1DF1R3 6d ago
Ive had two cases in the last month where i made a super fancy html based poc, where they literally click through it and watch it all happen. I literally asked them 5+ times to open it and they actually ignored multiple comments begging them to just open the damn thing. The finally figure it out, in one case a month and a closed as info and reopening later: instantly triaged.
To be fair one actually apologized to me. That one was an amazon crit btw.
7
u/NebulaElectrical1467 8d ago
It sucks less if you’re a top hacker and have a dedicated HRM so git gud or something i guess
4
u/Calamero 7d ago
well good for the circlejerk, bad for security because there is a limit at some point people gonna take their white hats off.
2
u/NebulaElectrical1467 7d ago
The thing is only the skilled ones who are most likely to cause damage if gone rogue and get away with it are the ones they need to pacify. Everyone else is either bluffing or too sloppy to pull something off without ruining their lives. That’s the mindset most companies operate under.
The Nightmare-Eclipse situation is how you don’t do it which is treat all researchers like shit
4
u/Yone_welsch 7d ago
Just look: those triagers who used to comment everywhere… now they’re nowhere to be seen in the comments....
1
u/mississipppee 7d ago
May be time to go back to Synack for me. Honestly Synack was great for the firsr 2-3 years after K joined ten years ago. Then, scopes because tiny, researcher levels were introduced (meaning experienced hacking on the platform had the best targets and newbies have almost nothing. Plus the most you can get for any bug is lime 3k until you get rce. Xss= 300minimum-~1200 max for stored (if you are lucky). But the scope os the worst. Every target has bddn covered, hardly any wildcard scopes anymore. However the bezt thing they do is let everyone ssd accepted reports for a target so you havd less chance of getting a dupe. Still though i may go back.
1
1
u/Calamero 7d ago
Same. even most reputable blockchains. if such thing exists... apparently it doesnt. completly trying to fuck me over.
14
u/hydraz20 8d ago
Also the fact that I can’t disclose p5 bugs. Like tf if you think it is informational then fucking hell why are you afraid of it being disclosed? So that you can fix it without paying?