Great platform for Bug Bounty
What do you like best about the product?
I have been working on HackerOne Bounty propgram since last 5 years and I must say, it is platform and services provided by HackerOne team.
What do you dislike about the product?
I feel the triaging feature can be improve more.
What problems is the product solving and how is that benefiting you?
HackerOne help us as organisation to findout external attacks and remediating those before any incident
Extremely competent and well run pentesting offering
What do you like best about the product?
We have been working with HackerOne for pentesting for a few years now and are very happy with all aspects of this program.
The researchers we have worked with are very competent, ask great questions, and generate well written reports.
We’ve worked with a few different pentesting/bounty programs and HackerOne’s pentesting offering is by far our favorite and one we will continue to use in the future.
If this were an eBay review they’d get an A+++++++.
What do you dislike about the product?
One of the hardest things about any sort of pentesting (HackerOne included) is knowing if the researchers are going to find most of your vulnerabilities. Hacking is hard and sometimes pentesters won't get everything. This is true for bounty programs as well and other pentesting companies.
What problems is the product solving and how is that benefiting you?
They are helping close the gap between what vulnerabilities we have outstanding but are unware of.
Long time, happy HackerOne customer
What do you like best about the product?
Triage services, program description and award table assistance, useful metricson program performance, good account management and roadmap access.
What do you dislike about the product?
Account management changes about yearly so less long term relationships.
What problems is the product solving and how is that benefiting you?
HackerOne is our premier bug bounty program and vulnerability disclosure program platform.
Offers bug bounty opportunities and helps to earn extra money
What is our primary use case?
I use the tool for hacking, practicing, and doing responsible vulnerability disclosure.
What is most valuable?
I don't use the tool in my day-to-day work. It's more for freelancing. I search for open platforms where I can do penetration testing on websites. If I find any bugs or vulnerabilities, I get paid. So, I do it as a freelancing activity, and it's really helpful.
Apart from getting all the bug bounty opportunities, we also get the chance to practice in a safe environment, like a demo setup. These features are great for beginners who want to explore bug bounties in the future.
What needs improvement?
One issue I've experienced is traffic. Many people try to participate when an opportunity with a bounty of around 1,000-15,000 dollars comes up. In this case, the first person to report the vulnerability gets the bounty. If a second person reports the same vulnerability, they are marked as duplicated instead of receiving some recognition. The second person also invested time finding the issue, so I think this can be improved.
For how long have I used the solution?
I have been using the product for three to four years.
What do I think about the stability of the solution?
How are customer service and support?
I haven't contacted the tool's technical support yet.
Which solution did I use previously and why did I switch?
I decided to go with HackerOne because I have experience with three bug bounty platforms: HackerOne and Bugcrowd. With Bugcrowd, you have to search for opportunities. In contrast, HackerOne presents opportunities directly when you log in. Additionally, other platforms' server response time and reporting methods are longer compared to HackerOne. HackerOne's reporting process is straightforward, with dropdown options for selecting the website and type of vulnerability.
How was the initial setup?
The solution doesn't need an installation since it's a SaaS model. It's very easy to use. When you log in for the first time, you'll directly see the opportunities page, where companies are ready for you to hack. The opportunities are right before you, so you don't have to search for them like on other platforms.
What's my experience with pricing, setup cost, and licensing?
The tool is open-source and free for bug bounty hunters.
What other advice do I have?
In college, I started using HackerOne and taught my 10-20 juniors how to use it. I'm sure they might still be using it in their lives right now. The biggest challenge integrating HackerOne into my existing security protocols has been on my side, not the tool's. I need to take the time out to use and practice with it, but currently, I'm unable to give it the time I used to. There's no issue from the application side.
To use the tool, you first need a basic knowledge of cybersecurity terms, like exploits and vulnerabilities, and how to identify them. Once familiar with these basics, you can learn more from the resources and platforms HackerOne provides. They offer tickets and guides to help you understand the methods for finding and exploiting vulnerabilities.
Before deciding to use the solution in your organization, consider the purpose. HackerOne is a multi-platform. If the goal is to spread awareness about cybersecurity or to make the security team more active in learning about hacking methods and new vulnerabilities, then it can be very effective. It allows the team to earn extra money while learning and exploring new vulnerabilities in the market, potentially even finding zero-day vulnerabilities.
I would rate HackerOne around an eight to nine out of ten. The application is simple to use, offering numerous opportunities and scopes for exploration. It covers many platforms, including web, Android, and iOS applications. However, the high traffic can sometimes be a drawback. If they manage this issue by implementing features like consolidation pricing for duplicate vulnerabilities, it could easily be a ten out of ten.
Securing the Digital Realm: Insights from HackerOne
What do you like best about the product?
Being the first in the business, hackerone has the largest community, covering various expected fortune 500 companies in their bounty programs.
What do you dislike about the product?
The support team usually take long time to resolve the tickets, in some cases they close they even closed the ticket without resolving the query.
What problems is the product solving and how is that benefiting you?
In the digital realm, bad attackers are continuously targeting companies to hack them illegally and threatening their reputation and integrity among customers, and clients. Selling their valuables on the DarkWeb. HackerOne enables ethical hackers to collaborate with registered companies to patch the maximum possible vulnerabilities that could allow a black hat to exploit the system.
Great platform to raise requests and get solution for cyber security
What do you like best about the product?
It gives me clear status report on time for the request raised. Opportunities are mentioned to work. My dashboard is also very nice. It gives me a report based on percentile. Hacktivity is great option for see all the activity does my me and shows the progress.
What do you dislike about the product?
Testing takes a little time to show the results.
What problems is the product solving and how is that benefiting you?
It keeps the cyberspace secure for the company. Cybersecurity is one of the most important aspects for us since we deal in user money directly.
Best Bug Bounty Platform
What do you like best about the product?
The best bug-hunting platform is HackerOne. Here, security experts attempt to uncover vulnerabilities on numerous websites and are rewarded for doing so.
What do you dislike about the product?
I currently have no complaints regarding hackerone. Hackerone offers some free resources to help novice security professionals get started with mobile and online application security.
What problems is the product solving and how is that benefiting you?
For many security researchers, Hackerone is their main source of income. People get paid here. I used to work as a part-time bug bounty hunter. Additionally, Hackerone offers great goodies. HackerOne changed my lifes
Very nice platform with lots of companies hosting there bug bounty program
What do you like best about the product?
There are many big and amazing companies listed hosting their bug bounty programs with amazing payouts
What do you dislike about the product?
Sometimes triager takes more time to validate the bug but that's not a big issue
What problems is the product solving and how is that benefiting you?
I am a bug bounty hunter and the platform help me to use my talent to earn good bounties bug reporting bugs
Perfect bug hunting platform
What do you like best about the product?
Hackerone is the best bug hunting platform. Here security researchers try to find vulnerability on many websites and get rewards for finding valid vulnerability
What do you dislike about the product?
Nothing so far I dislike about hackerone. Hackerone has some free stuffs which helps new security person to get started into web application security and mobile security.
What problems is the product solving and how is that benefiting you?
Hackerone is the source of income for many security researchers. Here persons get paid. I use to do part time bug bounty for income. Hackerone also provides cool swags.
Bug Bounty Beast
What do you like best about the product?
Hackerone hosts multiple websites to let the security researchers do bug bounty i.e. find vulnerabilities in their website and get rewards if vulnerabilities gets valid
What do you dislike about the product?
There is no such thing I dislike about hackerone. It is one of the source for security researchers to earn money by doing bug bounties. It has many web application which provides bounty.
What problems is the product solving and how is that benefiting you?
Hackerone has hackerone university in which one can learn about the basics of web, mobile security. A security researcher can hunt bugs on any public hackerone program and get paid or get swags