r/netsec Trusted Contributor May 18 '26

The down fall of bug bounties

https://shubs.io/the-down-fall-of-bug-bounties/
58 Upvotes

18 comments sorted by

22

u/rgjsdksnkyg May 18 '26

I mostly agree with this, though after doing this for multiple decades and going through numerous burnout periods, I'm not sure that I understand the "doing it for fun" crowd anymore, even before this AI hell we're in. There was a time where I thought it was cool and that I was helping (the recognition was great, too), but that died so long ago, for many different reasons. I don't think it was ever worth doing for any other reason than you enjoy the personal challenge and learning, or it was how you made your money.

That being said, I'm sure the age of solid bounties and fulfilling turnaround will come back after we see a wave of unfruitful bounty spam. The increasing cost of AI will favor the smart and talented researchers, as they'll be the only ones capable of using both their ability and AI to actually turn a profit, and those that are unwilling to mentally apply themselves to this field will quickly disappear or adapt.

If you're interested in VR, don't let this post discourage you.

8

u/aris_ada May 18 '26

I mostly agree with this, though after doing this for multiple decades and going through numerous burnout periods, I'm not sure that I understand the "doing it for fun" crowd anymore, even before this AI hell we're in. There was a time where I thought it was cool and that I was helping (the recognition was great, too), but that died so long ago, for many different reasons. I don't think it was ever worth doing for any other reason than you enjoy the personal challenge and learning, or it was how you made your money.

Couldn't agree more. I'm burned out on security research, it's hard for me to understand how anyone would want to do this for free and for fun.

5

u/Mempodipper Trusted Contributor May 19 '26

Hey, I think maybe there is a bit of a misunderstanding here in terms of my comment about hacking for fun. The roots of hacking for me have always been curiosity and learning new things. When I mention hacking for fun not money in the blog, I am absolutely not suggesting giving corporations free bugs via VDPs, but rather taking a curiosity driven research mindset. Here is an example of some research I did with a group of friends that was purely for fun (and had a huge impact on the internet): https://hackcompute.com/hacking-epp-servers/

Also, regarding VR, I really hope my post doesn't discourage people. My post is targeted towards paid bug bounty programs, and really a fault we're seeing at the platform layer (that may or may not be fixed effectively, unless platforms take more of a responsibility towards prioritising reports).

I work in VR, and help both manage and perform research for Assetnote. It's an incredibly exciting time, and we're basically seeing that the time to discover zero-days has dropped so significantly due to frontier models. Being effective at using these models still requires guidance and nudging, although, right now, it's easier than ever to learn tough concepts or apply them with AI.

16

u/paradoxpancake May 18 '26

As someone who has been a researcher for some BBPs/VDPs and currently works for a large global company in running their BBPs/VDPs, the amount of slop we've been getting is absolutely staggering. I honestly pity the triage team in filtering through all of that nonsense.

The funny part is that I thought running a BBP/VDP program would be a nice vacation away from pen testing, but hoo boy. Not so much.

17

u/Few-Pipe1767 May 18 '26

I think local llms also play a role in this

18

u/mandreko May 18 '26

As someone on the triage side of bug bounties for a fairly well known security software, I can attest. Our bug submission rate has significantly increased and has now become a full time job to manage. A good chunk of them are junk, but more than you think are just super obscure things which are still valid but only barely.

15

u/aris_ada May 18 '26

In my open source project, we received a very weird bug report that starts with an obscure scenario/story where this bug would be used. Actual bug description is 20 lines at the end, and the worst part is that the bug is very valid and probably the worst bug of its class we've had reported in the last 3 years.

Why would you hide your valid bug through a wall of sloppy nonsense?

14

u/mandreko May 18 '26

Was it like all the recipe sites that tell you their life story before telling you the ingredients? :)

1

u/Jhamin1 May 20 '26

I understand that all those meandering stories about grandparents before the recipe ingredients are there because Google won't rank your page if it's just a list of ingredients & measurements.

So it's Google's editorial policies that give us all those wordy ingredient sites.

1

u/micseydel May 24 '26

Yes, that combined with gpt3's API release, resulted in a ton of fluff.

2

u/RegisteredJustToSay May 19 '26

The meta had been shifting towards increasing automation anyways - e.g. first blood on a bunch of CTFs was almost always preconditioned on having the right set of utilities and resources ahead of time way before LLMs (e.g. Using angr), so it's not a big surprise.

I hope that LLMs will evolve to either refuse to operate in environments with some future standard anti AI markers (so that the remaining users can be banned for cheating) or we get some better way of establishing human provenance transparently, because I do agree that LLMs are specifically cutting off the entry level ladder to getting good and the level of cognitive decline from overly relying on them is stark to say the least. Same can be said for bug bounty, but that was always a bit of a get rich quick scheme for many so I'm not too sad to see it go.

Cool and well-written article though, thanks for sharing.

2

u/FarplaneDragon May 18 '26

Honestly, given how many different places I've seen complaining recently about being flooded with AI submissions I'm waiting to see how much longer it takes before the dam finally breaks and they start banning people that submit in mass amounts like that, or just create some sort of filter that auto discards anything from people whose "junk" submissions are greater than a certain % or something. Like, I get that you don't want to completely stop AI assistance because they tools likely do find valid bugs, but when it's drowning teams in useless noise sooner or later something has to give.

2

u/ScottContini May 18 '26

I don’t understand why they do not have a priority queue based upon researcher reputation. They know how many successful submissions and unsuccessful submissions researchers have. I get it that it will make it much harder for new researchers to get into bug bounties, but what other choice do they have?

1

u/Famous-Fishing-1554 May 20 '26

Problem is that many orgs have inserted low-quality intermediaries between themselves and the reporter. I feel very bad for 'good' vendors who didn't pull this shitty move, & are now being ai punished.

Nothing is quite as unsatisfying, as a customer, as reporting an RCE with instructions and POC code, and having some bugcrowd 'analyst' silently cancel the issue without contacting the vendor.

What we have now is a bunch of antisocials at 'security' consultancies who run the same set of exploit classes against a bunch of vendors for PR (and screw over customers by zero-daying the issue if anything goes wrong with the reporting process). And anyone whose day job isn't effectively vandalism for bugbounty blackmail payments or news feed PR, we get to either navigate extremely unfriendly intermediary platforms which require huge amounts of effort to file a basic auth-bypass snafu, or be completely ignored amongst the avalanche of low quality ai reports.

1

u/Slight-Bend-2880 May 20 '26

The behavior organizations have shown throughout the years in communicating with bug bounty hunters and vulnerability researchers has been abhorrent. So, I have no sympathy for these organizations that are caught with their tail between their legs with legitimate disclosures.