Article cover image

HackerOne's soul is in scope

Alex Rice
Alex Rice@senorarroz

Joel ("teknogeek") Margolis published a recent essay sharing a sentiment that I'm sure more than one member of this community has been feeling. It is long, it is specific, and it is written by someone who spent a decade here and now feels that HackerOne is losing its soul.

Some of it I disagree with. Some of it is right. The live hacking event posters used to be silkscreened by hand and numbered, and now they are not. A feature request that gets a thumbs up and then silence is worse than a no. Triage quality is the hardest scaling problem in this industry and we have not solved it. And our own words about AI have caused unnecessary frustration.

Has HackerOne changed? Yes. Do hackers still matter as much to our future as they did when we started? Definitely. Are we doing enough to make sure hackers feel that? Nope!

And then came AI. I spend a lot of time thinking about what AI means for security research and the people who have built livelihoods on it. I'm extremely optimistic about the technology. I'm less convinced by some of the very neat predictions about where it takes us.

Why we built HackerOne

Joel's telling of our early days is more flattering than the truth. HackerOne did not start as a mission to build the best possible thing for hackers. It was started to convince suits like me that you'd have to be brain-dead to ignore hackers.

Early in my career, before my prefrontal cortex had finished assembling itself, I received a cease and desist from Sony Online Entertainment. The details are a story for another time, but the impact stuck with me.

Over a decade later I found myself running product security at Facebook. One of the first things I helped do was launch our Whitehat program. We worked with Marcia Hofmann at the EFF to publish a formal legal safe harbor for security research. The hard part was getting Zuck and Sheryl to publicly commit that Facebook's lawyers would not go after the hacker community. They committed.

The program launched with modest ambitions and no money attached.

In parallel, we were spending millions of dollars a year on what we called continuous pentesting. More than forty third party firms, at least one engagement kicked off every week, always something in flight. By the standards of the day, it worked.

Then, alongside the kickoff of DEFCON-19, we attached bounties to the Whitehat program. The results from that first weekend eclipsed the entire prior year of continuous pentesting. We stumbled on a better way, and I have been obsessed ever since.

So I went back to our pentest vendors, most of the best firms in the world at the time, with the same pitch to each of them. I need more hacking, from more hackers, more often. I cannot pay your hourly rate 24/7. Hack me as often as you want and I will pay you per bug.

Every one of them said no.

Except one small Dutch pentest shop run by two guys named Jobert Abma and Michiel Prins, who could not have been more excited about it. My amazing co-founders.

That relationship is the founding of HackerOne. Not altruism. Not reverence for hacker culture, though we had plenty of it. Asking businesses to pay everyone by value instead of hours was an unequivocally better way to build a safer internet.

It is a mission we have not accomplished. Not close. The internet is not safe. Trustworthy technology is not the default. Every year we pay out more bounties, resolve more vulnerabilities, and hand more evidence to more security teams, now up 106% year over year. Yet the attack surface still grows faster than we close it.

The bet we made back then was that hackers were the best hope for a future full of safe and trustworthy technology. We still believe that. It is not nostalgia. It is the assumption everything else in our strategy rests on.

What I actually think AI does

I am an AI-pilled optimist with a deep skepticism of easy answers and silver bullets. Those are less contradictory than they sound. I use these tools constantly and I have watched them do things in my own hands I can barely believe.

AI is finding more vulnerabilities, earlier and faster. The most progressive security leaders we serve are putting frontier capability across their entire posture, discovery through remediation, and they are moving fast. That is a meaningful net positive for society.

Mission accomplished, right? We can all pack it up and go home?

I, for one, am not rushing to welcome our robot hacker overlords.

Only naive security leaders are celebrating an imminent victory. The ones I take seriously are doing two things at once. They are investing heavily in autonomous defense, and preparing for thousands of hackers each with thousands of agents.

That second half is the part most people skip in the hype. Security has never been about what your team knows. It has always been about what's possible by someone outside your walls.

That leaves only one future where hackers stop mattering. The one where nobody is capable of attacking you anymore. If we get there, wonderful.

But I predict the outside stays ahead thanks to the same diverse curiosity that has always driven the hacker community. Different brains, incentives, countries, obsessions, all poking at the same thing from angles nobody imagined. The end state is not a machine finding every problem while the rest of us sit back and relax. It is hackers and their agents running continuously against defenses that keep getting stronger.

What that means for hackers

High-volume, known-pattern work is becoming a commodity. That is real, it is happening now, and good people are feeling it. If a meaningful share of your income came from finding the same class of bug across a lot of targets, a rising floor does not feel like progress. It feels like the thing you were good at stopped being scarce.

The flip side is that the hard, creative work is worth more than it has ever been. If you are feeling behind, the people pulling ahead are documenting how they do it.

Ads (0xMoose) Dawson grew his submissions roughly sixfold last year while the share closed without reward fell from 32% to 24%. That is true craft and he walks through the entire loop.

Joseph (rez0) Thacker and JD (xssdoctor) published their whole hackbot build, celebrating what worked but also what did not. Showing the failures is a gift to everyone coming behind them.

Luke (hakluke) Stephens wrote the guide for anyone coming back cold. His point that stuck with me: everyone has the same one-line prompt now, so aiming yours where everyone else aims theirs earns you their duplicates.

Hackers and AI are not mutually exclusive and one becoming obsolete is not what the data says today. HackerOne customers have paid hackers $91M in the past year, growing faster than at any other point in our history. Hackers earning six figures on the platform grew by nearly a quarter over last year.

While AI raises the floor, hackers keep raising the ceiling.

Why we do NOT train generative AI on your reports

I fully acknowledge that line doesn't solve every problem caused by AI, but I still value it very much. Early on we adopted this stance for several reasons, including at least one durable strategic reason.

Every frontier lab, dozens of fresh VC-fueled AI pentesting startups, and a lot of serious hackers are racing to build the best AI hacker. That capability is here and it is only going to get better. But that story does not end with one corporate superintelligence finding and fixing every problem.

Throwing yet another AI hacker onto the stack is not and was never our strategy. Security teams need outside perspective, adversarial and unbounded by their assumptions, arriving continuously. Our job is to get the bugs from the best hackers in the world fixed as quickly as possible.

One more thing, because it is the honest answer to a complaint I hear. AI has accelerated our release velocity significantly but most of what we have shipped this year has not been hacker-facing. Our top priority has been building AI-native infrastructure for validating and remediating everything this community produces. If you have been waiting on a feature request while we did that, I am sorry.

We went there deliberately. The bottleneck on your work has never really been the finding. Most of you know this intuitively from every time one of your bugs has taken longer to fix than it did to find. How fast it gets validated, how fast it gets fixed, whether the program on the other end can keep pace. That is the most valuable thing we can build for this community, and it is a wicked problem. We are far enough now to see it working. Machine-speed validation and remediation is what unlocks the full potential of everything you find.

Soul searching

This is a genuinely uncertain moment and I don't know how all of it lands. I don’t know what a full-time hacker's week looks like in three years. I don’t know how to replace the pure human joy that came from hand-crafted research. I don’t know which of the skills people spent a decade building will still be the scarce ones. I know some people are going to get hurt by this transition, because it is not fair or evenly distributed. That is a real cost, and I don’t have a clean answer for it yet.

What I am confident about is the direction. The mission is unchanged and unfinished. Empower the world to build a safer internet. That mission needs hackers more now than it did in 2012, and more than it did in 2017, because what we are up against is accelerating. The soul of this community lives in the people who keep showing up to break things and tell the world about it. That part is not ours to lose and from where I sit it is very much alive.