[HackerNotes Ep. 189] What Happened to HackerOne? with Joel Margolis

Nostalgia for the golden era, frustration with the AI mess, and the one problem worth fixing: why Joel thinks HackerOne lost the plot, and how it gets it back.

Hacker TL;DR

  • HackerOne's "golden era" ran on community and human effort, and a lot of that got traded for a cleaner sales machine

  • The AI problem is not "an AI read my report". It is the mixed messaging, the missing opt-out, and your original techniques getting reused with nothing coming back to you

  • Triage is the one problem worth fixing: the best triagers quit to go hack, so the whole thing is broken by design

  • The fix is simple and doable: put resources back on the hacker, ship the feedback fast, and remember the "one" in HackerOne

We do subs at $25, $10, and $5, premium subscribers get access to:

Hackalongs: live bug bounty hacking on real programs, VODs available
Live data streams, exploits, tools, scripts & un-redacted bug reports

Need a Pentest? We just launched CTBB Pentests!

Hack full time? Check out the Full-Time Hunter’s Guild!

Who's Joel Margolis

Joel Margolis (@0xteknogeek) is a former co-host and co-founder of Critical Thinking, a long-time HackerOne hacker who started on the platform back in mid-2017 right before H1-702, and a security engineer who now works at a crypto company.

The Golden Era Was Real

The whole story starts with a before and after. Back in 2017, HackerOne felt like a grassroots project. It pulled hackers out of the shadows, gave them a safe place to work, and turned live hacking events into the heart of the community. Justin and Joel actually met at one of those events, and CTBB exists to bring that same hacker-to-hacker energy back every week.

The best example is the Angry Blue posters. The early events had custom posters, silk-screen printed by hand, each one numbered by a real artist. Over the years that turned into cheap laser prints on cheap paper. It sounds tiny, but it says a lot. It is the difference between "we care about this" and "we just need something on the wall."

There is a fair point on the other side, though. Some of this is just what happens when a company grows up. We got in early, when the rules were loose and the team had room to be generous. Things change, and it is not fair to call every change a betrayal when there are people trying to keep the business alive.

The HSM Advantage

Here is the part that is hard to defend. Joel is in the Hacker Success Manager program, so he has someone inside HackerOne he can message any time who can "move mountains" for him. A brand new hacker with the exact same valid report and the exact same difficult program has no such person. Anyone who has used normal H1 support knows how big that gap really is.

So the fairness worry is real. But you also cannot give every hacker on the planet a personal contact, and it is a bad idea to feed the crowd that says it is impossible to break in. It is not impossible. SpaceRaccoon showed up after Justin was already established and shot straight to the top. XSSDoctor and plenty of others did the same in the last year or two. Write clear reports with solid PoCs, and the bounties and private invites come.

The thing everyone can agree on is simpler: feedback from top hackers should count as much as feedback from paying customers, maybe more. These are the people on the platform the most, doing the most work. When they flag something, it should get built, not just collect a few thumbs-up and die.

Pro Tip: The proving ground is real. If you are new, your edge is report quality, not access. Make the reproduction and the impact so clear that triage has nothing to argue with, and the invites follow.

Where Is the Engineering?

The core frustration is that the platform has barely changed in ten years, and almost every new feature lives in one box: AI. Joel once wanted a simple filter on a listing page. He built it himself with Tampermonkey in about an hour, back in the GPT-3 days. Two years later the official version still is not there. In a world where you can tell an AI "go add this" and get it in an afternoon, that silence is a lot harder to explain.

To be fair, one AI feature is genuinely good: the stats on your own submissions. You can ask where most of your reports land, what your average response time is, and it just answers instead of making someone build a chart. That is AI actually helping hackers and programs. The problem is that it feels like the one exception, not the plan.

There is a common excuse that power users are niche and not worth the effort. That excuse does not work here. On HackerOne a power user is just a normal user doing the same things more often. Their feedback is not some weird edge case, it is the main experience turned up to full volume.

The AI Report-Data Mess

This is the fight that spilled out in public. HackerOne said "we are not using researcher reports." Then it launched a product where the second bullet point was, more or less, using researcher report data to power the thing. Then it walked that back once people noticed. The line that made everyone laugh was an agent "sharpened by using context from HackerOne's 12 years of real world vulnerability data and your prior H1 findings."

The reasonable take is not "never touch my data." It is: give people a real opt-out, say clearly what you do, and tell people ahead of time. The damage comes from the mixed messages, the careful legal wording ("we are not training models, we are drawing conclusions from results on your reports"), and the fact that there is still no simple switch that says "do not use my reports for anything AI."

And the real worry is not that a model read your report. Most of us already paste our own reports into AI, and nobody is digging through your IDOR writeup for fun. The worry is your original techniques getting reused to make someone else money while you get nothing back. That is the part the "AI read my report equals bad" crowd keeps missing. For the fuller version of this whole AI story, go watch the episode with Alex Rice (Ep. 162).

Pro Tip: If report-data usage matters to you, screenshot the current policy and product copy. The wording keeps changing, and your screenshots are the only thing that survives a page getting quietly rewritten.

Sales vs Engineering, and the "Disposable" Feeling

The bigger read is that the focus moved to sales and left engineering behind, and that created side effects. The program directory fills up with thin programs (a few pages of scope, no real setup, a 3k crit on basically nothing) that still pay big yearly contracts. This is not an anti-sales rant. Every business needs money coming in, and Amazon losing money on the store while AWS pays the bills is the classic example of spreading your income out. The issue is balance. The sales team gets the trip to Turks and Caicos. The engineers who shipped the AI product do not. The hackers who create the value the whole platform sells do not either.

There is a useful gut check hiding in all this: are hackers actually suffering? Not really. You can wake up, pick any company, do zero marketing and zero accounting, send a report, and get paid. That is a great deal. So this is not a story about a broken platform. It is a story about a platform that drifted away from what made it special.

Still, one word sticks: disposable. When you stop feeling valued, there is always someone standing right behind you, ready to take your spot. Good for the platform. Not so good for the person.

Triage: The Impossible Problem

If you had to pick one problem in bug bounty worth solving, it is triage, and it might be close to impossible. It is a trap. By the time a triager is good enough to reliably reproduce reports, they can make more money just going and hacking themselves. So they leave. That leaves a small pool of people, a worse experience on both sides, and AI pushing report volume higher every month.

One idea worth stealing is Meta's FBDL (shout out to Ads Dawson). It is a structured way to describe a bug so reproduction is exact instead of vague. You define account A with these settings, account B with these settings, run the steps, and the bug reproduces. It will not fix everything, but it hits the exact pain point: the endless "I can't reproduce this" back-and-forth that wastes everyone's time. Whoever solves triage friction gets a real edge over the other platforms.

The Path Back

None of this means "fire the whole sales team." It means moving resources around. Put the center of gravity back on the hacker. Answer feedback with real timelines and tracking instead of dead thumbs-ups. And remember that paying programs hit the same wall: they ask for a feature, nothing happens, and the only reason they stay is that switching is a pain. Plenty of them have already built their own tools around the H1 inbox because they got tired of waiting.

There is also the founder-mode idea: the original founders stepping back in publicly, the way Brin got involved again with Gemini at Google. You lead this kind of thing differently when you actually lived through the golden era.

And after an hour of criticism, the real feeling underneath it all is gratitude. Bug bounty is a gift. Full flexibility, good money, no marketing, no accounting, just send the bug and get paid. The original mission got done. The ask is simple: HackerOne, keep winning, but remember who the "one" was always supposed to be.

Resources

That's it for the week, keep hacking!