Some things that happened to me while doing Bug Bounty: 1. Downgrading the score of a vulnerability that was previously reported twice and rated as "Medium". 2. Reporting to a open source project, they see the bug, they remove all the files from their Github, bumped up the version, then, told me that I've found the vulnerability in an older version. 3. The program imported all the existing bugs into the platform, afterwards, marked them as duplicate once they got reported. And the list goes on, the lesson is simple, never hack for free. All the best for you and your family, Jason.
@official.sirhaxalot2 ай бұрын
I got repeatedly fisted doing bb. Wrote a blog about it if you're interested?
@incognitoworth12052 ай бұрын
This is f*cking true
@trevermcbride40412 ай бұрын
I reported a vulnerability once that was currently working on the platform that allowed you to bypass mfa, and was told its a duplicate vulnerability from a internal bulletin a year before I submitted it to them.
@bgorortayber2 ай бұрын
@@trevermcbride4041 Name and shame!
@Studio23Media2 ай бұрын
@@trevermcbride4041 YIKES!! That's embarrassing for them to admit. 😂
@asurhacks2 ай бұрын
This kinda guy is worshipped by everyone in their respective field. Someone who speaks up against the odd. Mad respect to boss haddix the legend.
@effsixteenblock502 ай бұрын
Mad respect to Haddix for this truth telling. No doubt he's been conflicted about this stuff for a long time and is finally in a position where he feels like he can talk about it. Something else that needs to be addressed is that when researchers are continuously facing these BS practices, many of them might just opt to sell their P-1 / 0 days to a buyer that pays way more and with much less friction than the programs.
@huzaifamuhammad80442 ай бұрын
I'm afraid some might even turn into the other side (black hat)
@handle_your_set2 ай бұрын
@@huzaifamuhammad8044 IMO, that would be the appropriate response to corporate consolidation and research theft.
@youreabigguy2 ай бұрын
@@huzaifamuhammad8044 This happens frequently, I know this for a fact
@detecht2 ай бұрын
Seeing you speak on this, makes the rest of us feel like we can too. Thank you for having the courage to say what we've all been thinking. We love you, jHaddix ❤
@manufaleschini2 ай бұрын
I love this talk and have the highest respekt of Jason. He is one of the most brilliant minds in the Bug Bounty scene and such a wonderful human being. He doesn't have to fight for this community, he does it at will. I admire your support for the "nonames" and new hunters in the field. May god bless you and your wife. 🙏🏻
@WarmEmpanada2 ай бұрын
Wishing the best for you and your family Jason ❤
@TimHerbert509Ай бұрын
Thanks for helping us up and comers! Prayers for your family.
@elite_fitness20 күн бұрын
Jhaddix you the man. You took big risks doing this but you did what is right and we appreciate you.
@brunoeligiopavesi69872 ай бұрын
As usual Jason's talks are always very interesting.
@youreabigguy2 ай бұрын
It should be well known by now, never to short, be stingy with, get over on or underestimate your hackers... When very talented researchers get screwed over they begin to thinking and being a legitimate researcher isn't worth it, and go from reporting bugs to selling exploits on the black market.
@theodorekorehonenАй бұрын
If the suits that run these ticketing systems think the people that generate the revenue used to pay their salaries should simp for them and on top of that, be thankful for the privilege to work for them, I think marketplaces for bugs on the non clearnet might just grow in popularity. Greedy people seem to manage to ruin everything
@devz9530Ай бұрын
yes I think this will be the next step for the bug bounty scene and corporates will be forced to react, either by bidding on the exploits themselves on the black market, or creating a better marketplace solution that favors us hackers
@zerocewl2 ай бұрын
Awesome talk by jason haddix thanks, And Prayers to your family jason 🙏
@matt57212 ай бұрын
Wow that's nuts about the traffic being monitored for the top 250. It would be petty cash to them AND create competition by paying those 250, but they discourage them instead.
@AlexbongoKurban2 ай бұрын
Why do you think in the programs they request or require you to put a custom header with your username of the bug bounty program?
@matt57212 ай бұрын
@@AlexbongoKurban so you just commented without watching? They're stealing from the top 250
@sithrebel1548Ай бұрын
@@matt5721 cry harder
@XtremuZ22 күн бұрын
@@sithrebel1548 whenever some of them become rogue, let's see who cries harder
@Thiccolo2 ай бұрын
This needs to be put out there even more
@almc84452 ай бұрын
Almost all of the issues here seem like they come from the same reason we have unions for regular employees… Hackers union anyone?
@TESTA-CCАй бұрын
We Have a Hackers Union....it's called Code!
@almc8445Ай бұрын
@ Code doesn’t stop a race to the bottom for wages. That’s exactly my point…
@PixelPulse_Playbook2 ай бұрын
Some hackers create informative content, and that's a good thing. However, I believe that sometimes you need to stand up for your community. It's great content, and I respect you, bro.
@tobias8933Ай бұрын
Thanks for speaking up! I've discovered a high severity vulnerability in a well-known social media platform a couple months ago. The triaging process was an absolutely ridiculous shit show. It took 6 months, included two interventions from the platform's support team and right before the payout, they decreased the severity rating reducing the payout by 90%. 0/5 Never again.
@theodorekorehonenАй бұрын
I'm assuming there's some forced arbitration thing so they can tell you to GFY whenever they pull their scam?
@evilcorp30372 ай бұрын
Wow, really eye opening! Thank you very much
@shmo9943Ай бұрын
Pissing off hackers is a very bold move
@official.sirhaxalot2 ай бұрын
Putting personal shit to one side to work is the epitome of a professional. Excellent talk. I hope your wife recovers.
@2rx_bni2 ай бұрын
No it's deranged they should have given him an out. Don't do this. It's unhinged.
@galloe2 ай бұрын
@@2rx_bniYeah, fuck that. A talk over my wife, there's no way in hell I'd ever do that.
@trustedsecurity60392 ай бұрын
@@2rx_bni totally!!! The worst is his "my kids are watching my others kids" WTF!!! Kids must be sas for their mom and this guy isnt even there for them... Bad Parents really!!!
@emarbeats68962 ай бұрын
@@trustedsecurity6039seems like hes working pretty hard to provide for his family.
@johnandmeghАй бұрын
Setting aside whatever their family dynamics might be, which might make it totally ok in his particular case…the caveat given at the beginning tacitly encourages the behavior of “I’d rather push myself past the normal point and do a worse job, than take time away for me and my family”, which I believe is negative for most people.
@jhaddixP2 ай бұрын
❤
@michaelr.37992 ай бұрын
Thank you for doing this, wishing your wife a speedy recovery.
@mohamedmater12302 ай бұрын
wishing your wife a speedy recovery Thanks JHaddix
@comosaycomosah2 ай бұрын
very hard to navigate appreciate you advocating for the little guy always
@tallst12 ай бұрын
Glorified ticketing system
@EarthWalkerOne2 ай бұрын
Bug Bounty is the same as the BetterBusinessBurreau. Started by bad businesses to limit the number of lawsuits they receive...
@alextravine94222 ай бұрын
It would appear to me that the bug bounty program is corrupted and should not be something to participate in.
@EarthWalkerOne2 ай бұрын
Seems like all that really needs to happen is companies and especially Platforms being taught a lesson. Bounty platforms should also be anonymous, there should be no room for celebrity/favoritism or targeted monitoring. If we're in this to make things more secure and get paid, then bug bounty programs and platforms should really try to incentivize white hat behavior. If I'm not going to get paid either way, the world will become more secure by forcing companies to listen and practice security if their vulns given away in alternative markets. If they're going to make getting compensated fairly difficult, you can just name your price elsewhere...
@SimonCasАй бұрын
They want to play a game, we like playing games 😊
@robertbruce7686Ай бұрын
Another excellent talk!!
@trailer-g1118Ай бұрын
I have learnt something but also discouraged, whether to start bug bounty or something else........please advice..
@ak1t4hax0r82 ай бұрын
Amazing talk! thanks for sharing Jason!
@joygatewood802820 күн бұрын
Question - at 4:03 Jason mentions that AI is being used to train on attack traffic and to build services out of it. Is it possible that AI is being used to become bounty hunters themselves?
@danishbhat15362 ай бұрын
A wise man says wise things
@elite_fitnessАй бұрын
3 times bugcrowd has said that my report was a dupe and a year later the vuln is still there. I also think a triager took my vulns and brushed me off
@grakka72Ай бұрын
Welcome to the WESTERN WORLD of capatilisme. You deserve more credit for your work.
@jmz80862 ай бұрын
amazing presentation. thank you!
@archkittensАй бұрын
How can the contract bind you re: the submission if you received no money(consideration) for the submission? It is not illegal to sell unregulated information, and it’s definitely not illegal to share unregulated information for free, the platforms and ultimately the customers are buying your right to do those things, and if they choose not to buy it your rights should be unchanged.
@TripleA6792 ай бұрын
This is why some would rather sell their discoveries on the dark web.
@TomPotato-f7vАй бұрын
I'd drop everything to be at my wife's side, instead of worrying about using mild swear words at a talk that certainly won't change the world. but that's just me. all the best to you and yours, mr haddix
@elite_fitness20 күн бұрын
I smell a little animosity, perhaps Jason was at the conference, hours from home and she had to go get stitches.. Hes not a Dr . Have you been doing this dirty crap or something?
@0xbeven4622 ай бұрын
🎉 great talk , though it maybe underrvalued your illustrated valuable insights into shady platforms and shit loads that occur to bug hunters, misrepresentation etc, nice talk
@mohamednasseribrahem2 ай бұрын
I am starting hunting nowadays but I am a little afraid of this question Will bug hunt decline or end with the rise of the AI?
@TheStarcaliburАй бұрын
They most probalbly think "thats their passion. They do it anyway, why should we pay for this?!" That is on so many sides just wrong and abusive. But i think its also a hint about who these people are. And think about if the hacking comunity should not branch out and make their own Bug bounty site. They have all the expertise. Dear .... If you read this idea and start doing it. Reach out to me and take me on board for sparking that process :) In a few years i will do it, bringing the right people together :)
@24bkdoorАй бұрын
There are also organizations that wait for you to publicly disclose vulnerabilities and intentionally ignore your reports so you do so, platforms that suggest bugs are not shared with customers but are. The struggle they are face with are the legal implications of not protecting their systems. Lately the pros of ethical reporting are outweighed by the cons. I hope your talk inspires change.
@shadowuniferАй бұрын
This is why I’m extremely paranoid about how I submit bugs and tend to sell them instead. My time and skills are valuable.
@cosmin91ro2 ай бұрын
you have my respects man, but I was expecting mentioning about wanna be hackers that throws shitty reports and spams both platform triagers and programs' security teams, hoping to full them to get a 100$ bounty
@pcguy619Ай бұрын
For real… or CVEs rated at high 9s that claim “code execution is possible” but are at most only memory corruption. POC or GTFO!
@nullvoid35452 ай бұрын
Why not make A but bounty "union" that instead acts as an intermediary between hunters and the platforms taking the contracts for bug bounties. If the platforms wont take your bugs because you didn't sign A contract, then you now have A barrier for negotiating. The bugs can be sent to either regulators(Does threatening to report A crime count as extortion?) or the company themselves with the advantage that A group representative has A larger megaphone to(responsibly) disclose publicly that this company would not pay you under this more equitable arrangement. Best I got. But I think it's A better plan than hoping they simply choose to be less exploitative.(On the internet?)
@mattf.214225 күн бұрын
This is the reason I didn't pursue these platforms. I literally signed up, and found an XSS attack on a site. It took me like 10 minutes. And I couldn't believe it. But when I submitted the report, they said it was already found. It probably was, as it was so easy. But why wasn't it fixed? And there's no proof. Fook that.
@AlexFlores-o5b2 ай бұрын
Where can I sign up? Can’t be worst than AT&T
@sysadmin1350Ай бұрын
Great talk
@dosesandmimoses2 ай бұрын
I brought this topic up to Dr. Hinton respectfully..
@monh9642 ай бұрын
This is sad, i thnk the black market is better
@regular3dguy8302 ай бұрын
Great talk!
@itsmemyme2 ай бұрын
lets implment some decentralized id or attachment which can trace out for found instances and properly pay for percentage to hunter
@zak68202 ай бұрын
wow respect to jasson haddix
@JoeRogansForeheadАй бұрын
I thought bug crowd was when more than 4 gay people formed a line?
@mwebsec25 күн бұрын
🔥🔥🔥
@slussssy012 ай бұрын
Love you haddix
@biz1MАй бұрын
Have seen BC employees stealing research (0day) then claiming the bounty on other targets leveraging the same tech stack. Repulsive behavior and blacklisted. Also seen employed hackers within firms share a 0day within the firm with strict instructions do duh, DO NOT LEAK to then be abused/leaked by said "future" employee who even went as far as asking on twitter for some bypasses for this very specific vector. BB is a scam.
@eyezikandexploits2 ай бұрын
This is kinda messed up
@bughunter9766Ай бұрын
3rd party shit happened to me,, with full access to cloud read and write,, with all the employees data.
@eshayz2 ай бұрын
Hackers being replaced by AI before GTA 6
@dosesandmimoses2 ай бұрын
Also- the court systems - online.
@Zarnubius24 күн бұрын
he should have named it "how to hack the hacking community"
@LewisCowles2 ай бұрын
Very interesting, and definitely food for thought. Doesn't sound very realistic though. "Shitty customers" feels like "anyone who doesn't do what I'd advise".
@theodorekorehonenАй бұрын
Do you work for one of these companies? Your comment really has this "I'm a middle manager whose only task is to throw a wrench in the works and feel self important" energy. Or perhaps you're just someone whose personally trends towards the bootlicking side?
@myfaveyoutubeАй бұрын
my dude
@jnycАй бұрын
STOP HELPING THEM!! LET THEM EAT THE BUGS!
@AndreeaCeАй бұрын
(Better now?) American Magnet ;))
@ruckica19 күн бұрын
youre not getting any cash thats for one
@usamaarshad17662 ай бұрын
Rep++
@netbin2 ай бұрын
/notes
@mrluke826421 күн бұрын
Microsoft the biggest ip thief
@k0ns0l2 ай бұрын
YOLO :p
@0x5001Ай бұрын
bug bounty is scam :)
@cyb0rgh4kr2 ай бұрын
Freakin Jason HaddiX! best wishes to your FAM bro @jasonhaddix