Every researcher I talk to reinforces the same insight, bug bounty's problem isn't technical, it's trust.
Protocols hate spam, AI reports, and noise.
SRs hate opaque duplicates, vague closures, and being unheard.
Adding friction isn't the answer. Building trust systems is.
@fwrnr Then researcher mistreatment is just bt a symptom. The cause to all these is fear and programs have happily leveraged on it.
Let's see who gets the last laugh.
@fwrnr How could achieving a balanced accountability frm self hosted programs be possible? Easy for crits to be downgraded to mediums and there nothing a researcher could do about it.
@fwrnr I predict we still have a year of runway before majority of the programs enact AI-Triage at scale. As fr self-hosted programs, this is what I'm hoping to spend more time in the coming months, the ROI from hunting on major platforms no longer maths up.
You think you're upset at bug bounty platforms and their natural use of leverage they have and the market incentives for them to use that leverage.
You fail to realize that you're actually upset at the hacker community, who have failed to make use of the leverage they have.
Security research teaches patience in the strangest ways.
Wait for contests. Wait for judging. Wait for escalations. Wait for payouts. Wait for protocol responses.😂💔
WAGMI...
@monkehack@jeremiahg I have done away with good/bad here, and think it's biased and unreasonable to use 'allow' to describe platforms allowing customers to mistreat hackers, but then not mentioning that hackers have historically 'allowed' this to take place, too. Not exactly fair is it.
We reported a security issue to one of the biggest password managers and exactly how to fix it (they couldn't find the solution). It took them more than 100 days to fix it. They will not include it for a bug bounty. In return they will give us $10 of credit in our account.
This is not a joke. 🤡
@shreyas_chavhan This is the same question i keep asking myself. Are they skipping my finding coz its complex to reproduce!! is the queue really that long...
AI will kill bug bounties NOT because it’s better than human hunters.
It’ll kill them because platforms are failing at handing triage queues and unable to distinguish legit bugs from AI Slops.
Once you hit about a 20-point IQ gap, communication starts to completely break down.
It's not that the lower IQ person is "stupid" (although that can often be the case) or the higher one is arrogant, it's that you're literally operating on different systems.
A 20 point difference (roughly 1.3 standard deviations) means:
Vocabulary and abstraction levels diverge sharply. What feels like crystal clear logic to one side sounds like vague, pretentious word salad to the other. Jokes land flat. Metaphors get taken literally. Complex cause and effect chains get simplified into "this good, that bad."
Different time horizons and pattern recognition. One person thinks in months or years and sees systems, the other is locked into days or immediate rewards. Trying to explain second order effects feels like speaking another language.
Also, processing speed and working memory gaps. The higher IQ person is already three steps ahead, getting impatient. The lower IQ person feels talked down to or overwhelmed.
Both walk away frustrated.
Both have wasted each others time.
Being attractive but neurodivergent is such a weird experience because people become fascinated with your appearance. Then uncomfortable when they realize you require depth, honesty, reassurance, patience, and emotional intelligence.