Hacker News new | ask | show | jobs
by dinkelberg 6 days ago
So if the "wrong" person finds a critical vulnerability in GitHub, the payout is capped at $10,000. Might reduce the likelihood of it being submitted to the bug bounty program.
2 comments

It might, but as someone who has to review public vulnerability reports for a much less popular website, I completely understand why they’re building a vouch program to dissuade slop reports. One would presume their internal team is using frontier models for red team agent scanning against potential attack surface, and so this is a potential risk they’re willing to take.

Tragedy of the commons that someone who hasn’t passed the filter yet might have their payout limited.

Vouch - https://news.ycombinator.com/item?id=46930961 - February 2026 (486 comments)

vouch programs where other users put their trust in you are a good thing. this is a centralized vip program where membership can be added or removed from anyone for no reason. there is no guaranteed way to get in. its a private club not a trust system.
tbh hackerone should just implement a +/- reputation points feature on researcher profiles. Like, the researcher submits a slop report to GitHub via H1, GitHub looks at it and identifies it as slop, GitHub presses the -rep button on reaearcher profile which bans them from submitting to GitHub on H1 again and makes their rep points minus 1. Companies should be able to configure you need at least 10 rep points to receive payouts. Only specific (by H1 chosen) companies can +/- rep.

So, researchers first need to collect some positive rep. But the rep points are global, so once you have fixed a few bugs for Google, you've gotten enough +rep that you can also receive stuff at GitHub.

Oh, and ID check when signing up at H1.

Long term all beg bounty submitters would be banned for pretty much all of tech.

I think they do that already, there are signal ratios
Signal and Reputation already do these things but public programs are…well public.
How does decreasing pay for humans discourage slop reports, exactly?
It discourages all reports, so you get the reduced slop reports for free.
To my mind, it encourages more reports because that way you're more likely to have some of them slip through and get approved, meaning your future reports are worth more.
Does it, though? It discourages humans from putting in effort because their time will not be rewarded. But the slop reports were not the result of time nor effort. I'd rather expect changing a payout from $1k to $250 doesn't meaningfully move the needle on someone spending two minutes prompting their OpenClaw to spam bug bounties. Especially since the reports you actually want to filter out are the sub-50-IQ reports that were always going to get $0 either way.
You're forgetting that GitHub aka Microsoft is one of the big slop peddlers. They made the problem but now don't want to pay for it.
"one of the big" is an understatement. They own OpenAI, which created and popularized the whole field.
Saying they “own” OpenAI is a massive stretch, considering their stake is less than 30%, post-recapitalization into a PBC.
Large organizations are complex machines. The security team responsible for triaging these reports is very likely not the same as the one peddling slop. The nuance and irony is not lost on me.
I find it quite offensive that there is a payout difference for major vulnerabilities when the outcome is the end in the end.

If it was me finding such a vulnerability, this discrimination would offend me so much that I would prefer to sell it to semi-legal actors that would pay multiple of that...