HackerOne
HackerOneExternal reviews
70 reviews
from
and
External reviews are not included in the AWS star rating for the product.
Best bug bounty platform
What do you like best about the product?
Hackerone host many programs for bug bounty and also provides good learning materials for web application hacking and mobile hacking. Hackeone traiger are the best.
What do you dislike about the product?
There is nothing I like about hackerone. It host bug bounty for many good programs to improvise their security. Hackerone's traiger are best triager with full of knowldege
What problems is the product solving and how is that benefiting you?
I used to do bug bounties in hackerone some years before. I had learnt application hacking by reading web application by hackerone. It also has mobile application hacking material too.
Top solution for managing bug bounty program
What do you like best about the product?
Well known in the security researchers community, you can get a lot of exposure through it. The UI is simple and effective.
What do you dislike about the product?
Paid plans are not idle for small companies and B2B products.
What problems is the product solving and how is that benefiting you?
One place to get reports of security issues in the company's products. Acknowledge, triage, are reward reports in a dedicated system instead of in emails. The app is also used to apply rewards for eligible reports.
Professional business partnership with the security researcher community
What do you like best about the product?
HackerOne is a great partner to us to help find security researchers for our bug bounty programs.
What do you dislike about the product?
As with most enterprise software the cost of the yearly subscription could be lower. There is an arbitrary discount associated with each annual renewal.
What problems is the product solving and how is that benefiting you?
Resolving security vulnerabilities in our software products.
Proactively Finding Vulnerabilities
What do you like best about the product?
HackerOne makes it safe and easy to have vulnerabilities found, reported and rewarded.
Dealing with hackers that have found vulnerabilities can be really stressful - deciding what awards are applicable for which vulnerabiliteis can be really tricky.
HackerOne makes that much easier - they manage which hackers are on your program so get much higher quality reports.
Also there is a standard for awarding and arguments can be sorted out by HackerOne staff.
They also work to keep your bounty program up to date and productive.
Dealing with hackers that have found vulnerabilities can be really stressful - deciding what awards are applicable for which vulnerabiliteis can be really tricky.
HackerOne makes that much easier - they manage which hackers are on your program so get much higher quality reports.
Also there is a standard for awarding and arguments can be sorted out by HackerOne staff.
They also work to keep your bounty program up to date and productive.
What do you dislike about the product?
Nothing stands out.
So far we haven't had any issues dealing with any of the HackerOne functionality.
So far we haven't had any issues dealing with any of the HackerOne functionality.
What problems is the product solving and how is that benefiting you?
With HackerOne we are proactively finding vulnerabilities before they are exploited.
This saves the company from financial exploitation as well as keeping user trust.
This saves the company from financial exploitation as well as keeping user trust.
Recommendations to others considering the product:
The managed program is a boon - they filter so many reports that we only deal with ones that really impact us.
Best tool for the job
What do you like best about the product?
HackerOne is by far the best place to find great security researchers to look at your product, and do this painlessly. It has clean, clear UI; easy setup; integration with SAML and task managers etc; and the best security researchers use the H1 platform. The triage/escalation team is great and HackerOne continues to do innovative stuff like SmartRewards, live hacking events, celebrating leading researchers and so on. There is a reason something like the US DoD as well as some of the best tech firms are on HackerOne.
What do you dislike about the product?
Triage team can sometimes need feedback to make sure they triage bugs the right way. Sometimes, a lot of the reports can be noisy; attracting the best talent is tricky.
What problems is the product solving and how is that benefiting you?
Great security testing coverage of SaaS applications. Found high quality security reports is probably the key benefit. We get continuous security testing rather than point in time assessments.
Great Tool For CbyerSecurity and Testing
What do you like best about the product?
Great Platform to create a Bug Bounty/Hunt program. It gives a platform to connect developers and testers which is a great deal as testing can be difficult and using this platform makes it easy. The website is also pretty easy to use. And the main great point is that Hacker One automatically creates reports based on the bugs submitted by the testers and give them bounty automatically. This can help you reduce Bugs and Attacks which your Application might be vulnerable to.
What do you dislike about the product?
The most thing I disliked about Hacker One was that It had duplicate bug reports which I myself found very irritation. Other than that Great Platform
What problems is the product solving and how is that benefiting you?
If you want to secure your applications against vulnerabilities, hackers, data leaks and want to make your application more secure, then HackerOne is for them. I realized that by using HackerOne I am improving the application's security and improve the vulnerabilities.
Recommendations to others considering the product:
I would advise everyone to use HackerOne as it's a great tool, and everyone should use it before deploying their apps to prod.
Triage Team Unexperienced
What do you like best about the product?
I like the vast number of companies that flock to this site. It is a standard for bug
Bounty hunting.
Bounty hunting.
What do you dislike about the product?
The triage team often time seems inexperienced. They want way more proof than needed. It seems like they want you to break safe harbor for your reports. Knowing things are possible is not enough. They want a full blown take down / hack before rewarding you or taking the bug serious. I’ve often seen bugs fixed that they write off as ‘informative’ and don’t pay the bounty. Often times the reports that you make as a template, will work the first time, until the triage team gets tired of doing their work and asks for more information. They often will not read your report and ask questions that are blatantly in the reports.
What problems is the product solving and how is that benefiting you?
I’m helping keep the internet secure. Helping deter black hats from taking advantage of holes in company security.
Recommendations to others considering the product:
Make sure you understand how hard it is to get an actual bounty before diving into this profession
Review For HackerOne
What do you like best about the product?
Good for cyber security,
Easy to use, trustworthy and efficient
Provides multiple channels to categorize a threat so that it can be reported efficiently
Gives an easy way to track threats
Easy to use, trustworthy and efficient
Provides multiple channels to categorize a threat so that it can be reported efficiently
Gives an easy way to track threats
What do you dislike about the product?
Sometimes the bugs reported aren't verified
The price is quite expensive
The price is quite expensive
What problems is the product solving and how is that benefiting you?
Used HackerOne to report and verify security related issues on my website and to check for
security vulnerabilities in my software
security vulnerabilities in my software
Recommendations to others considering the product:
Be patient
Great Application
What do you like best about the product?
HackerOne develops bug bounty solutions to help organizations reduce the risk of a security incident and that's what I like. The company itself is successful because we have an amazing product, great clients, and a wonderful team. Multiple ways to categorize an issue so that it can be reported efficiently.
What do you dislike about the product?
A lot of duplicate bugs get reported, although it does offer automatic suggestion of previously reported bugs that may be duplicates, it is far from perfect.
Anyone can report bugs, a lot of them are not verified before submission. This sometimes leads to a lot of time spent in verifying if the bug is really actionable.
Each submission has to be treated with equal potential, a lot of time, some time gets invested in vulnerabilities that aren't as important as some others.
Anyone can report bugs, a lot of them are not verified before submission. This sometimes leads to a lot of time spent in verifying if the bug is really actionable.
Each submission has to be treated with equal potential, a lot of time, some time gets invested in vulnerabilities that aren't as important as some others.
What problems is the product solving and how is that benefiting you?
Bug Bounty Programs
Joy with HackerOne
What do you like best about the product?
Easy to use
Multiple ways to categorize an issue so that it can be reported efficiently.
Gives an easy way to track issue and open issues again if they aren't resolved properly.
Multiple ways to categorize an issue so that it can be reported efficiently.
Gives an easy way to track issue and open issues again if they aren't resolved properly.
What do you dislike about the product?
I wish HackerOne's integrations were self-service and more fully-featured.
I'd love a way to set this up myself, and for that integration to go both ways,
I'd love a way to set this up myself, and for that integration to go both ways,
What problems is the product solving and how is that benefiting you?
HackerOne informed my team of a number of security vulnerabilities in our application which we were able to fix quickly and discreetly.
Recommendations to others considering the product:
It is one of the good platforms for security researchers to submit bugs and other vulnerabilities, it however, has some challenges, in terms of un-verified and duplicate submissions.
showing 61 - 70