What Happened to HackerOne?
What Happened to HackerOne?
HackerOne 怎么了?
So…what’s going on at HackerOne lately? It might be time for a wellness check. If you are new to the bug bounty space (1-3 years), you might not have any idea what I’m talking about. But as a properly washed-up bug bounty hunter who lived through the golden era of HackerOne, I think it’s time to address the elephant in the room. 那么……最近 HackerOne 到底发生了什么?或许是时候给它做个“健康检查”了。如果你是漏洞赏金领域的新人(入行 1-3 年),你可能完全不知道我在说什么。但作为一个亲历过 HackerOne 黄金时代、如今已“退隐江湖”的漏洞赏金猎人,我觉得是时候谈谈这个显而易见的问题了。
For some context, I started as a hacker on HackerOne in 2017. When I began working in tech, that hands-on experience was extremely useful for managing a bug bounty program, since I knew what researchers wanted, and how to interact with them. As a result, I have managed multiple large bug bounty programs on HackerOne across various companies from 2018 to 2025 and I’ve been on both sides of the equation. What I’m about to talk about comes from first-hand experience, both as a researcher and as a bug bounty program manager, and many, many years of direct conversations with HackerOne, both publicly and privately. 简单交代一下背景:我于 2017 年开始在 HackerOne 上以黑客身份活动。当我进入科技行业工作时,那段实战经验在管理漏洞赏金项目时非常有用,因为我深知研究人员的需求以及如何与他们互动。因此,从 2018 年到 2025 年,我曾管理过多家公司在 HackerOne 上的多个大型漏洞赏金项目,可以说我身处过这一生态的两端。我接下来要谈的内容均源于我的第一手经验——既作为研究人员,也作为项目经理——以及多年来与 HackerOne 之间无数次公开和私下的直接交流。
Background
背景
To start, I think it’s important to realize what HackerOne was originally designed to be. In 2011, two ethical hackers, Jobert Abma and Michiel Prins, set out to find security vulnerabilities in 100 of the largest tech companies. They succeeded and found bugs in Google, Facebook, Apple, Microsoft, Twitter, and many others. At this point in time, the landscape for ethical security research was risky, legally dubious, and very scary for security researchers. Not only was there significant personal liability, but there had been multiple instances of hackers being criminally charged and sentenced to jail time for finding and reporting security vulnerabilities prior to this. Much of this was due to specific arbitrary lines drawn in the sand which, if crossed, made you a bad actor, but if not crossed, made you a potentially bad actor but technically not one. 首先,我认为有必要了解 HackerOne 最初的设计初衷。2011 年,两位白帽黑客 Jobert Abma 和 Michiel Prins 着手寻找全球 100 家大型科技公司的安全漏洞。他们成功了,并在谷歌、Facebook、苹果、微软、Twitter 等公司发现了漏洞。在当时,白帽安全研究的环境充满风险,法律地位模糊,对研究人员来说非常可怕。不仅存在巨大的个人法律责任,而且在此之前,已经发生过多起黑客因发现并报告安全漏洞而被刑事起诉甚至判刑的案例。这很大程度上是因为当时存在一些武断的界限:越界了,你就是“坏人”;没越界,你虽然看起来像个坏人,但技术上还算清白。
Bug Bounty Platforms like HackerOne were designed to directly address this issue. It created a safe mutual space for companies and hackers to connect, and it paved the way for ethical hackers to submit security vulnerabilities to companies, with full consent, and get paid for that work. This was a huge milestone. You no longer had to worry about getting dragged to court (or jail) for finding an IDOR that leaked customer data. Instead, you got a “thank you” and a cash payout for making everyone a little safer. This operating model was the foundation for bug bounty and remained that way for the next 5+ years. 像 HackerOne 这样的漏洞赏金平台正是为了直接解决这一问题而设计的。它为公司和黑客建立了一个安全的互动空间,为白帽黑客在获得完全授权的情况下向公司提交漏洞并获得报酬铺平了道路。这是一个巨大的里程碑。你不再需要担心因为发现一个导致客户数据泄露的 IDOR(不安全直接对象引用)漏洞而被送上法庭(或监狱)。相反,你因为让世界变得更安全而获得了一句“谢谢”和现金奖励。这种运营模式是漏洞赏金计划的基石,并在随后的五年多时间里一直保持不变。
The Golden Age of HackerOne and Live Hacking Events
HackerOne 的黄金时代与现场黑客活动 (LHE)
During this period, there was a very strong and explicit focus for the business: how do we make this the best possible product for hackers? The people running the business day-to-day were hackers, hacker-adjacent, and most (if not all) were face-to-face with hackers on a regular basis. From 2017 to 2020, HackerOne was doing Live Hacking Events (LHEs) every few months. These were exclusive events where the top bug bounty researchers around the world would fly into a location, be given a target, and go absolutely ham finding critical vulnerabilities. 在此期间,该业务有一个非常明确的核心重点:如何为黑客打造最好的产品?当时负责日常运营的人员要么是黑客,要么与黑客圈子紧密相关,且大多数(如果不是全部)人都会定期与黑客面对面交流。从 2017 年到 2020 年,HackerOne 每隔几个月就会举办一次现场黑客活动 (LHE)。这些活动非常高端,全球顶尖的漏洞赏金研究人员会飞往指定地点,针对特定目标进行“疯狂”的漏洞挖掘。
LHEs were a huge value prop for programs. During a 1-3 day period, you would get more high and critical security reports than you would have received for the whole year otherwise. Every event had a 1-of-1 custom designed poster with graphics, hacker usernames, stickers and challenge coins. It’s hard to overstate what an incredible and productive period this was for HackerOne and their top programs. These events were exclusive and highly coveted; invites and +1s were practically their own currency. And the environment at these events was surreal. You would be given free flights and hotels around the world, and spend a few days surrounded by the best and most skilled bug bounty hunters in the world. LHE 对项目方来说具有巨大的价值。在 1-3 天的时间里,项目方收到的高危和严重安全报告数量,往往超过了平时一整年的总和。每场活动都有独一无二的定制海报,上面印有图形、黑客用户名、贴纸和挑战币。很难夸大这段时期对 HackerOne 及其顶级项目来说是多么不可思议且富有成效。这些活动具有排他性且令人垂涎;邀请函和随行名额几乎成了硬通货。活动现场的氛围更是超现实:你不仅能获得全球范围内的免费机票和酒店,还能在几天内与世界上最优秀、技术最精湛的漏洞赏金猎人共处。
These researchers would regularly find some of the most impactful bugs using their own novel techniques, and all while sharing tips and tricks in one-off conversations that could not be replicated anywhere else. Prior to the advent of live hacking events, most security researcher circles were small, isolated, and sharing information publicly was practically unheard of. LHEs created a way for security researchers to connect with each other, and essentially created a whole new community within infosec. Most of my closest friends nowadays are people who I met through the live hacking scene, and I am extremely grateful to HackerOne for that. 这些研究人员经常利用自己独创的技术发现最具影响力的漏洞,同时在私下交流中分享那些在其他任何地方都无法获得的技巧。在现场黑客活动出现之前,大多数安全研究圈子都很小且封闭,公开分享信息几乎是闻所未闻的。LHE 为安全研究人员提供了一种相互联系的方式,本质上在信息安全领域创造了一个全新的社区。我如今最亲密的朋友大多是在现场黑客活动中结识的,对此我非常感谢 HackerOne。
LHEs were not the only area where HackerOne was building and establish a community for security researchers. They created a HackerOne Community space to organize meetups, online events, workshops, and CTFs. They created regional clubs, and appointed hackers who lived there as ambassadors to help foster and grow local researcher communities all around the world. But slowly but surely, things began to change. The community groups and events lost momentum and fizzled out. The custom designed silkscreen LHE posters became cheap low-effort laser prints. The people who had dedicated years to creating and running incredible events were laid off or left. The LHE invitation and scoring systems became (even more) exclusive, gamified, and exceedingly calculated. So one by one, the dominoes began to fall. LHE 并不是 HackerOne 构建安全研究社区的唯一领域。他们创建了 HackerOne 社区空间,用于组织聚会、在线活动、研讨会和 CTF 比赛。他们还建立了区域俱乐部,并任命当地黑客担任大使,以帮助培育和发展全球各地的本地研究人员社区。但慢慢地,事情开始发生变化。社区团体和活动失去了动力,逐渐消亡。定制的丝网印刷 LHE 海报变成了廉价、粗糙的激光打印品。那些多年来致力于策划和运营精彩活动的人员被裁员或离职。LHE 的邀请和评分系统变得(更加)排他、游戏化且充满了算计。于是,多米诺骨牌开始一张接一张地倒下。
The Profit Problem
盈利难题
Before going further, I think it’s important to get into the “why” behind these changes that started happening. Sometime around 2020 or 2021, HackerOne was forced to come face-to-face with a very important question that every business must ask itself at some point: “How do we make money?” To understand how HackerOne even was able to survive as a business, you have to first know that HackerOne was basically running entirely on VC money for the first 10 years of its existence. Between 2014 and 2022, the company did a seed round almost every 2 years, raising a total of $160M. If a company is self-sustaining, there is little-to-no reason to continue raising money unless you have an incredibly high burn-rate, which would be odd fo 在深入探讨之前,我认为有必要弄清楚这些变化背后的“原因”。大约在 2020 年或 2021 年左右,HackerOne 被迫面对每个企业在某个阶段都必须回答的一个重要问题:“我们如何赚钱?”要理解 HackerOne 作为一家企业是如何生存下来的,你首先必须知道,在成立的前 10 年里,HackerOne 基本上完全依靠风险投资(VC)资金运营。在 2014 年到 2022 年间,该公司几乎每两年进行一轮融资,总共筹集了 1.6 亿美元。如果一家公司能够自给自足,除非烧钱速度极快(这对于一家公司来说很奇怪),否则几乎没有理由继续融资。