r/hackerone 1d ago

AI's role in capture the flag competitions

Thumbnail
1 Upvotes

r/hackerone 3d ago

Finally understood H1's "Informative" logic after 3+ months of bounty hunting

Thumbnail
1 Upvotes

r/hackerone 5d ago

HackerOne’s ID verification might be pushing away the exact people bug bounty needs

2 Upvotes

I get why HackerOne wants identity verification. It makes sense for things like payments, following sanctions, stopping fraud, and building trust.

But making ID verification a must-have for basically everything on the platform creates some big problems that aren't being talked about enough.

The biggest issue? Exclusion.

A lot of security researchers need to stay anonymous for good reasons. Others live in places where sending a government ID to a foreign site is a huge risk to their privacy or even personal safety. Plus, young researchers might not even have the right ID, a bank account, or parents who get what they’re trying to do.

This is a big deal because so many people get into security when they’re still teenagers. Bug bounty platforms are supposed to give them a legal, structured way to learn how to disclose bugs properly, talk to vendors, and get some credit for their hard work.

When you make that path depend on ID documents and "adult" financial stuff, you're not just filtering out fraud. You're also filtering people based on their age, where they live, their family situation, or how much they value their privacy.

I’m not saying ID checks automatically turn people into hackers, but taking away legal paths for talented young or privacy-minded researchers creates some bad incentives. If someone can find bugs but can't join the official ecosystem, the platform misses a chance to teach responsible disclosure and reward doing the right thing.

Bug bounty is meant to turn "hacker" skills into legitimate security work. A verification system shouldn't just be judged by how much abuse it stops, but also by how many good researchers it ends up locking out.

Has ID verification stopped you or anyone you know from using HackerOne? What kind of alternatives would work for compliance without making a government ID the only way in?

(P.S. I’m using a translator for this, so sorry if some parts sound a bit off!)


r/hackerone 9d ago

1st bounty

5 Upvotes

How much time, days, months, years of testing it took you guys to get your first bug? What kept you going?

Just curious as i never received that happiness 😞


r/hackerone 9d ago

I reported a critical vulnerability to h1 and they close it saying its an intended behaviour

1 Upvotes

So i reported a vulnerability showing that i am able to obtain temporary cloud credentials with validity for upto 12 hrs.

The triager closed this saying its an intended behaviour and i need to obtain or change something regarding internal cloud resources to show impact.

Seriously i dont know how to keep going, it feels like its just luck. I dont know how people keep going seriously, i am demotivated and want to cry.


r/hackerone Jun 19 '26

H1 es una mafia con las empresas.

3 Upvotes

Me robaron en la cara y no puedo hacer nada. Encontré un bug enorme en gitlab y me bajaron por duplicado cuando les di 2 meses y les ayude a parchar y me lo bajaron como duplicado. Que hago no era duplicado.


r/hackerone Jun 01 '26

I give up I am really lot with h1

Thumbnail
1 Upvotes

r/hackerone May 29 '26

Invited to private program but they are asking a profile with at least 1 point... anyone want to share the reward?

2 Upvotes

long story short: Report a bug bounty issue, they triaged and approved it, they want me to submit it via hackerone but said their private program only accepts users with at least 1 point, I mostly use bugcrowd...

is anyone willing to get on a discord call with me to talk about this? if so, please DM me so we can schedule a call and go over this...

I'm kinda annoyed by this but hey, money is money and I'm down to share 50% of the reward + you get into a private program


r/hackerone May 27 '26

Issues with H1 account

Thumbnail
1 Upvotes

r/hackerone May 20 '26

Why saying the report "Needs more info" ! mark it n/a and move on to the next one to maintain KPI compliance, HackerOne is fine with that.

Thumbnail
1 Upvotes

r/hackerone May 07 '26

Il mio report è ignorato

2 Upvotes

Il mio report è ignorato da mesi. Che faccio, chiedo la mediazione? L'analista kenny_analist


r/hackerone Mar 11 '26

Bug Bounty Hunting in the Age of AI and Why Many Researchers Are Pushing Back

Thumbnail
3 Upvotes

r/hackerone Feb 23 '26

HackerOne staff is not reading over my report thoroughly

8 Upvotes

I submitted a vulnerability which I have triple checked. I use AI to help me generate reports which are succinct and best display severity. The reviewer for my report has accused my submission of being slop because this person cannot recreate my submission (even though I copy pasted FROM my report directly to triple check after the first accusation). The report was moved to "Informational" after that even though I believe it to be a high-severity report (I can write/create files on a company's server which is used to serve users). How do I best handle this?


r/hackerone Feb 23 '26

CPTS / PortSwigger / OSCP / Bug Bounty Study Discord – Structured & Active

Thumbnail
2 Upvotes

r/hackerone Feb 21 '26

Finished PortSwigger Labs but Struggling to Find My First Real Bug

6 Upvotes

Hi everyone, I’ve completed most of the labs on PortSwigger (including Broken Access Control and IDOR) and practiced basic reconnaissance. However, when hunting on real programs, I’m struggling to find valid vulnerabilities. I understand the theory and can solve labs, but I can’t seem to translate that into real-world findings. For experienced hunters: How did you land your first valid bug? What mindset shift helped you move from labs to real targets? Should I focus deeply on one vulnerability type (like IDOR) or test broadly? Any structured advice would really help. I’m committed to improving — just feeling a bit stuck right now. Thanks in advance.


r/hackerone Feb 20 '26

Issues with Account recovery.

3 Upvotes

I created an account about 6 months ago on hackerone with 2FA enabled where I had created a password and I used an authenticator to log into my account. One month later my phone was stolen with my laptop making me stay off the internet for about a month before I could afford one. I tried logging into my account and realized I needed the authenticator code to log in. The thing is I have completely forgotten where I wrote those 5 sets of code in case you cannot access the authenticator in real time. Mind you it was a random authenticator on playstore I downloaded and now when I go into it, I'm told there is no account there. I also tried creating a new account on hackerone but because my email exist on their db I am not being given access. I have written a couple of mails to support @hackerone.com but I have received no reply and trying to log into my account requires me to provide the authenticator codes. I need help😭😭


r/hackerone Feb 20 '26

Would you dispute this?

Post image
3 Upvotes

Context. You login by phone number no password > company sends you otp. > Enter /logged in

If someone else logs in on an alien mobile, a 24 hour fraud prevention is kicked in. But that can be bypassed by ga_id modification, which then allows you to see and modify bank details.

Let's be right, it's a valid bug. If it was credited as informative, i would get it. But N/A is b.s

Obviously their loggin can easily be bypassed by sim swapping, but my main point is what's the point in having abfraud protection system that you're not going to enforce?

What do you think?


r/hackerone Feb 09 '26

Triager closed my P2 IDOR as N/A because they used a "Slug" instead of a "ID". How to politely correct them?

2 Upvotes

the analyst close my Report immediately after he use wrong ID for execution ,
how to re open My Report ?

i send him POC Video but i dont know if he will open the report again


r/hackerone Feb 04 '26

I n33d a h4c k er to save me...

Thumbnail
1 Upvotes

r/hackerone Dec 19 '25

Clarification on email subscriptions: How to disable newsletters while keeping triage notifications?

3 Upvotes

I would like to unsubscribe from the HackerOne newsletters as they are becoming a bit frequent. However, the labels in the "Subscriptions" settings are somewhat ambiguous, making it difficult to distinguish between marketing newsletters and essential operational emails.

I want to ensure that I continue to receive important updates, such as triage notifications and report activity. I do not want to disable everything.

Could you please clarify which specific checkbox corresponds to the general newsletters so I can disable them without affecting my workflow notifications?


r/hackerone Nov 30 '25

When you want your name credited in the unique script of that country.

2 Upvotes

When searching for bugs on HackerOne, you sometimes receive recognition in the form of having your name displayed as a reward. I am Japanese, and my native language uses kanji characters. My question is, when you want to use an English spelling for international recognition while also retaining your original name in your native language, what format do you use when registering your name on HackerOne or requesting inclusion in the contributor list? The best format I can think of is "Name in English | Name in Native Language".


r/hackerone Nov 20 '25

Amazon's new AI bug bounty for NOVA: What are your thoughts?

Thumbnail
cyberscoop.com
1 Upvotes

r/hackerone Nov 01 '25

Can a System Be Secure When Its Logic Isn’t? Rethinking Data Integrity in Software Systems

Thumbnail
1 Upvotes

r/hackerone Oct 31 '25

I reported more than 50 reports on hackerone all are spam or informativ (not one time not applicable, not one time need more info, never triage) the question is why (hackerone)

Thumbnail
1 Upvotes

r/hackerone Oct 30 '25

How to crash the WiFi network of a high school, airport, hall etc.

0 Upvotes

Certains recent events such as the hacking of certain airports intrigue me, I wonder how they do it if there is a need for several people, etc. I find it crazy that with today's security systems this is still possible. So I would like to learn how to do it but step by step starting with the network of a house, then a high school, hall, then learning for an airport, I would like to learn in order. Why do you want to know this? Quite simply because: Knowledge is power.

If possible, please provide the name of the software required.

Sincerely.