upvote
> I don't understand the controversy at the heart of this post.

Did you miss this part from the article:

> They switched from talking about bug bounty programs, live hacking events, and how they could help you stay secure, to promoting their in-house AI security product and continuous security monitoring tool.

notably the in-house AI security product is trained on existing bug bounty reports.

> It sounds to me more like the OP already disliked H1 (for its sales practices and general enshittification) and the LLM issue was a convenient excuse to make a clean break.

that's pretty harsh to say when OP provided some very valid reasons, imho speaking as someone who's used HackerOne for over a decade.

link to H1's "continuous monitoring tool" for the curious: https://www.hackerone.com/product/h1-continuous-testing

reply
And also the idea that H1 "training" models based on bug bounty reports is kind of a silly concern; frontier models have commoditized most of what was reported on H1, even at higher quality levels. H1 itself is a nonfactor.
reply