AUTO-UPDATED

What Happened to HackerOne?

HackerOne faces growing criticism from the security research community over claims that its AI-driven triage and testing tools are utilizing proprietary vulnerability data to improve platform automation.

Key Points

  • Long-time researchers allege that HackerOne has shifted from a hacker-centric community to a profit-driven, sales-focused corporate entity.
  • The platform’s "Hai" AI assistant and new "Continuous Testing" product have sparked concerns regarding the potential use of researcher submissions for model training.
  • Despite official denials from leadership, internal documentation and marketing materials have caused confusion about how "contextual learning" impacts future automated triage.
  • Critics argue that the platform’s feature development has stagnated, leading to a decline in user experience and a lack of transparency regarding data usage.
  • Co-founders have engaged in damage control, promising that no model training occurs while acknowledging the need for better communication and incentive structures.

Why it Matters

The controversy highlights a deepening rift between bug bounty platforms and the ethical hackers who power them, raising questions about data ownership in the age of AI. As platforms prioritize automated efficiency and B2B sales, they risk alienating the security experts necessary for identifying critical vulnerabilities.
Teknogeek.io Published by Joel Margolis
Read original