HackerOne's Bug Bounty Program: A Tale of Reduced Rewards and AI's Impact
The world of bug bounty hunting is undergoing a significant transformation, and HackerOne, a prominent platform in this domain, is at the center of this shift. The recent reduction in rewards for vulnerability reports has sparked intense debate among security researchers and project maintainers alike.
The Changing Landscape of Bug Bounty Rewards
HackerOne's Internet Bug Bounty (IBB) program, once a lucrative avenue for bug hunters, has seen a dramatic decrease in reward amounts. For instance, a medium-severity vulnerability that previously fetched $1,843 now earns a meager $297. Critical vulnerabilities, once rewarded with $9,250, now attract $2,257, while high-severity bugs have seen their payouts slashed from $4,429 to $1,009. Even low-severity bugs, once a lucrative find, now only yield $68.
This drastic reduction in rewards has left many researchers feeling disheartened and questioning the sustainability of their efforts. The trust between researchers and bug bounty programs is at an all-time low, as the rules of the game seem to change after the work is already done.
The AI Factor
One of the most intriguing aspects of this transformation is the role of AI-generated reports. Until recently, AI slop, or low-quality bug reports generated by AI, was dismissed as a minor issue. However, as AI models have become exponentially better at writing code and exploits, the situation has taken a turn.
Open source projects are now struggling to keep up with the influx of AI-generated reports, which still require human evaluation. This has led to a shift in the dynamics of the bug bounty landscape. Daniel Stenberg, the founder and lead developer of curl, famously stated that the project has stopped receiving AI slop reports, instead welcoming a surge of high-quality security reports, many of which are AI-assisted.
The Linux Kernel Conundrum
The Linux kernel community has been particularly affected by the rise of AI-assisted bug hunting. Linux kernel maintainer Greg Kroah-Hartman noted that AI-generated reports contain less slop and more valid concerns. However, the sheer volume of these reports has overwhelmed the project's security mailing list, making it almost unmanageable.
Linus Torvalds, the iconic Linux kernel boss, declared that the security mailing list has become almost entirely unmanageable due to the flood of duplicate reports from AI-assisted bug hunters. This situation highlights the double-edged sword of AI in bug bounty hunting.
The Human Element in Bug Bounty Hunting
At the heart of this debate is the human element in bug bounty hunting. Jakub Ciolek, a hacker who reported two denial-of-service bugs in Argo CD, found himself in a similar situation as Stenberg and Kroah-Hartman. He reported the bugs last fall, expecting a reward of around $8,500. However, HackerOne's delay in processing his report and the subsequent reduction in rewards left him feeling frustrated.
Ciolek argues that the economics of vulnerability reporting are changing rapidly. He believes that the discovery-first bug bounty model is becoming obsolete, as finding plausible bugs is becoming cheaper, and generating reports is easy to scale. The expensive part, he emphasizes, is still very human: verification, deduplication, impact assessment, coordination, and getting safe fixes shipped.
The Trust Issue and the Way Forward
The trust issue between researchers and bug bounty programs is a critical concern. Ciolek points out that the change in reward amounts was applied long after the work was completed, fixed, and publicly credited under different expectations. This unpredictability undermines the principles of responsible disclosure, which rely on researchers believing in a predictable process.
As a result, serious researchers are pricing in this risk, or even stopping their participation in bug bounty programs. Ciolek, for one, has ceased active bug bounty research, choosing to report serious issues as they arise, with a focus on verification and impact.
In conclusion, the reduction in bug bounty rewards and the rise of AI-assisted reports have sparked a reevaluation of the bug bounty model. The future of bug bounty hunting lies in rewarding more of the remediation cycle, not just the discovery phase. As the landscape continues to evolve, the human element in bug bounty hunting remains crucial, ensuring the sustainability and integrity of this vital practice in the open-source ecosystem.