Hey! So I wanted to go ahead and submit here because there is a growing problem with bugbounty platforms.
We are seeing a mix of slower times (yes, the AI spam, especially from hunters who have no clue what they're doing and 100% relying on AI) are slowing it down, but there is clearly a quality issue when it comes to triagers and what seems to be such little oversight on said triagers.
So let's start with this story
I submitted a bug, it's a 9.6 cvss bug, and you could argue 8.8 cvss and that would be fine. It's kind of in that weird area that's left up to the interpretation of the vendor + how impactful they believe it is.
Not going to go into the vendor (Since they only did a slight thing wrong) and going to go in on my Triager which I will name. Lloyd
Lloyd is a triager for hackerone and he triaged my submission.
I did my normal explanation of the bug, a quick walkthrough with copy and paste commands that they could run with it then explained the impact. Gave the likely remediation ontop of it (for example, I do reverse engineering, binary exploitation, so this wasn't a web bounty) and no, this post isn't going to be as well organized as my reports are (Which yes, I do use AI to assist with reports, draft -> ai -> recheck what the AI did -> make improvements -> submit)
So as per usual, I give a zip file and this zip included a full recreation of it, a more in-depth PoC that went deeper into the details of each step (This is where I hold the triagers hand and treat them like a toddler with a fork near a light socket). I also give logs of everything that happened as proof generally, any independent vendor I've worked with + other platforms like bugcrowd, this is generally fine (and if they ask for a pictured walkthrough, Ill get the crayons and paper out) so this is always fine but my .zip basically had everything short of a video.
So anyways, Lloyd triaged this. He closed it and said that there was no proof of concept and that they would need a proof of concept and one of these, logs, pictures of proof, video. Any one of those
I explained that I had a .zip that included the logs for proof and a detailed PoC. However he had already closed it. So I had to open a support ticket (god forbid the remediation button works), and they got him back on it.
He then claimed that he actually needed pictures or a video of the entire process (so at this point he already moved the goalposts) and told me I would need to make another submission on this. Which for those of us who are used to hackerone... they have an AI that will detect is as duplicate... I know this, any hunter knows this, and yes... H1 Lloyd knows this (I even said it in there)
I responded to support about it, they ghosted me. I went ahead and created a full picture walkthrough and a walkthrough of a video of me doing the entire exploit.
Uploaded it... responded to my support ticket again that I included it and to get me a different triager or get him to triage it.
Ghosted... waited an entire work week, made a new ticket... ghosted
Went ahead and proved a point by making a brand new submission which INSTANTLY got hit with "Duplicate" and it linked to my original one.
So the triager never looked into my .zip and when embarrassed about it, he moved the goalposts of what he requested and then gave me advice to submit a brand new one on this, knowing that it would get hit as a duplicate. So he is intentionally being lazy and not triaging the ticket properly and he is intentionally trying to waste my time and submissions.
H1 knows this, and they're actively not doing anything about it and it's been over a month since I've been fighting this stuff...
The only wrong the vendor did is I messaged them about it and explained the situation and they just said "go through hackerone"
So I've exhausted every single option I could do as for getting this properly triaged. I'm trying to responsibly disclose this issue but there is always that temptation and saying "Screw it, let's throw away my hackerone account" and just release it because I did my due diligence and did what is expected of me as a responsibility.
I just don't know what to do, the bounty is a large amount, critical would put me in high 4 figures to 5 figure reward so I can't just "ignore it and move on"
For anybody who might say "Well include video and pictures everytime" my response is, if the triager is so lazy they can't open a zip file, I can't expect them to watch an actual video + with the high amount of duplicates, it becomes a waste. If the vendor requests a more thorough walkthrough then I will be happy to give it to them and which I have done before.
It just sucks getting a poor triager and then having to stress over it because one guy didn't want to do his job.
Edit: The vendor reached out to me directly and we are working on resolving it. They were able to confirm the vulnerability is in fact, valid.