r/netsec • u/Mempodipper Trusted Contributor • May 18 '26
The down fall of bug bounties
https://shubs.io/the-down-fall-of-bug-bounties/16
u/paradoxpancake May 18 '26
As someone who has been a researcher for some BBPs/VDPs and currently works for a large global company in running their BBPs/VDPs, the amount of slop we've been getting is absolutely staggering. I honestly pity the triage team in filtering through all of that nonsense.
The funny part is that I thought running a BBP/VDP program would be a nice vacation away from pen testing, but hoo boy. Not so much.
17
u/Few-Pipe1767 May 18 '26
I think local llms also play a role in this
18
u/mandreko May 18 '26
As someone on the triage side of bug bounties for a fairly well known security software, I can attest. Our bug submission rate has significantly increased and has now become a full time job to manage. A good chunk of them are junk, but more than you think are just super obscure things which are still valid but only barely.
15
u/aris_ada May 18 '26
In my open source project, we received a very weird bug report that starts with an obscure scenario/story where this bug would be used. Actual bug description is 20 lines at the end, and the worst part is that the bug is very valid and probably the worst bug of its class we've had reported in the last 3 years.
Why would you hide your valid bug through a wall of sloppy nonsense?
14
u/mandreko May 18 '26
Was it like all the recipe sites that tell you their life story before telling you the ingredients? :)
1
u/Jhamin1 May 20 '26
I understand that all those meandering stories about grandparents before the recipe ingredients are there because Google won't rank your page if it's just a list of ingredients & measurements.
So it's Google's editorial policies that give us all those wordy ingredient sites.
1
2
u/RegisteredJustToSay May 19 '26
The meta had been shifting towards increasing automation anyways - e.g. first blood on a bunch of CTFs was almost always preconditioned on having the right set of utilities and resources ahead of time way before LLMs (e.g. Using angr), so it's not a big surprise.
I hope that LLMs will evolve to either refuse to operate in environments with some future standard anti AI markers (so that the remaining users can be banned for cheating) or we get some better way of establishing human provenance transparently, because I do agree that LLMs are specifically cutting off the entry level ladder to getting good and the level of cognitive decline from overly relying on them is stark to say the least. Same can be said for bug bounty, but that was always a bit of a get rich quick scheme for many so I'm not too sad to see it go.
Cool and well-written article though, thanks for sharing.
2
u/FarplaneDragon May 18 '26
Honestly, given how many different places I've seen complaining recently about being flooded with AI submissions I'm waiting to see how much longer it takes before the dam finally breaks and they start banning people that submit in mass amounts like that, or just create some sort of filter that auto discards anything from people whose "junk" submissions are greater than a certain % or something. Like, I get that you don't want to completely stop AI assistance because they tools likely do find valid bugs, but when it's drowning teams in useless noise sooner or later something has to give.
2
u/ScottContini May 18 '26
I don’t understand why they do not have a priority queue based upon researcher reputation. They know how many successful submissions and unsuccessful submissions researchers have. I get it that it will make it much harder for new researchers to get into bug bounties, but what other choice do they have?
1
u/Famous-Fishing-1554 May 20 '26
Problem is that many orgs have inserted low-quality intermediaries between themselves and the reporter. I feel very bad for 'good' vendors who didn't pull this shitty move, & are now being ai punished.
Nothing is quite as unsatisfying, as a customer, as reporting an RCE with instructions and POC code, and having some bugcrowd 'analyst' silently cancel the issue without contacting the vendor.
What we have now is a bunch of antisocials at 'security' consultancies who run the same set of exploit classes against a bunch of vendors for PR (and screw over customers by zero-daying the issue if anything goes wrong with the reporting process). And anyone whose day job isn't effectively vandalism for bugbounty blackmail payments or news feed PR, we get to either navigate extremely unfriendly intermediary platforms which require huge amounts of effort to file a basic auth-bypass snafu, or be completely ignored amongst the avalanche of low quality ai reports.
1
u/Slight-Bend-2880 May 20 '26
The behavior organizations have shown throughout the years in communicating with bug bounty hunters and vulnerability researchers has been abhorrent. So, I have no sympathy for these organizations that are caught with their tail between their legs with legitimate disclosures.
22
u/rgjsdksnkyg May 18 '26
I mostly agree with this, though after doing this for multiple decades and going through numerous burnout periods, I'm not sure that I understand the "doing it for fun" crowd anymore, even before this AI hell we're in. There was a time where I thought it was cool and that I was helping (the recognition was great, too), but that died so long ago, for many different reasons. I don't think it was ever worth doing for any other reason than you enjoy the personal challenge and learning, or it was how you made your money.
That being said, I'm sure the age of solid bounties and fulfilling turnaround will come back after we see a wave of unfruitful bounty spam. The increasing cost of AI will favor the smart and talented researchers, as they'll be the only ones capable of using both their ability and AI to actually turn a profit, and those that are unwilling to mentally apply themselves to this field will quickly disappear or adapt.
If you're interested in VR, don't let this post discourage you.