<p><span style="background-color: transparent;">Episode 162: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joseph sit down with HackerOne </span>Founder &amp; CTO Alex Rice to discuss concerns of Using Hacker Data for AI and decreasing bounties.</p><p><br></p><p><span style="background-color: transparent;">Follow us on twitter at: </span><a href="https://x.com/ctbbpodcast" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://x.com/ctbbpodcast</a></p><p><span style="background-color: transparent;">Got any ideas and suggestions? Feel free to send us any feedback here: </span><a href="mailto:info@criticalthinkingpodcast.io" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">info@criticalthinkingpodcast.io</a></p><p><span style="background-color: transparent;">Shoutout to</span><a href="https://twitter.com/realytcracker" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);"> YTCracker</a><span style="background-color: transparent;"> for the awesome intro music!</span></p><p><br></p><p><br></p><p><span style="background-color: transparent;">====== Links ======</span></p><p><span style="background-color: transparent;">Follow your hosts Rhynorater, rez0 and gr3pme on X:&nbsp;</span></p><p><a href="https://x.com/Rhynorater" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://x.com/Rhynorater</a></p><p><a href="https://x.com/rez0__" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://x.com/rez0__</a></p><p><a href="https://x.com/gr3pme" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://x.com/gr3pme</a></p><p><br></p><p><span style="background-color: transparent;">Critical Research Lab:</span></p><p><a href="https://lab.ctbb.show/" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://lab.ctbb.show/</a><span style="background-color: transparent;">&nbsp;</span></p><p><br></p><p><span style="background-color: transparent;">====== Ways to Support CTBBPodcast ======</span></p><p><span style="background-color: transparent;">Hop on the CTBB Discord at </span><a href="https://ctbb.show/discord" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://ctbb.show/discord</a><span style="background-color: transparent;">!</span></p><p><br></p><p><span style="background-color: transparent;">We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.</span></p><p><br></p><p><span style="background-color: transparent;">You can also find some hacker swag at </span><a href="https://ctbb.show/merch" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://ctbb.show/merch</a><span style="background-color: transparent;">!</span></p><p><br></p><p><span style="background-color: transparent;">Today's Sponsor: Join Justin at Zero Trust World in March and get $200 off registration with Code </span><strong style="background-color: transparent;">ZTWCTBB26</strong></p><p><a href="https://ztw.com/" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://ztw.com/</a></p><p><br></p><p><span style="background-color: transparent;">Today’s Guest: </span><a href="https://x.com/senorarroz" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://x.com/senorarroz</a></p><p><br></p><p><span style="background-color: transparent;">====== This Week in Bug Bounty ======</span></p><p><br></p><p><span style="background-color: transparent;">XML external entity: The ultimate Bug Bounty guide to exploiting XXE vulnerabilities</span></p><p><a href="https://www.yeswehack.com/learn-bug-bounty/xml-external-entity-guide-xxe?utm_source=Critical_Thinking&amp;utm_medium=Youtube&amp;utm_campaign=XXE_Critical_Thinking&amp;utm_id=XXE_CT" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://www.yeswehack.com/learn-bug-bounty/xml-external-entity-guide-xxe?utm_source=Critical_Thinking&amp;utm_medium=Youtube&amp;utm_campaign=XXE_Critical_Thinking&amp;utm_id=XXE_CT</a></p><p><br></p><p><span style="background-color: transparent;">Bug Bounty Maturity Framework</span></p><p><a href="https://bugbountymaturity.com/" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://bugbountymaturity.com/</a></p><p><br></p><p><span style="background-color: transparent;">====== Resources ======</span></p><p><span style="background-color: transparent;">Confidential Information and Confidentiality Obligations</span></p><p><a href="https://www.hackerone.com/terms/general#:~:text=HackerOne%20may%20use%20Confidential%20Information%20to%20develop%20and/or%20improve%20its%20Services%20(for%20example%2C%20to%20identify%20trends%2C%20and%20to%20train%20AI%20models)%20provided%20such%20use%20does%20not%20result%20in%20disclosure%20of%20Confidential%20Information%20to%20unauthorized%20third%20parties" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://www.hackerone.com/terms/general#:~:text=HackerOne%20may%20use%20Confidential%20Information%20to%20develop%20and/or%20improve%20its%20Services%20(for%20example%2C%20to%20identify%20trends%2C%20and%20to%20train%20AI%20models)%20provided%20such%20use%20does%20not%20result%20in%20disclosure%20of%20Confidential%20Information%20to%20unauthorized%20third%20parties</a></p><p><br></p><p><span style="background-color: transparent;">Ownership and Licenses</span></p><p><a href="https://www.hackerone.com/terms/community#:~:text=8.%20Ownership%20and%20Licenses" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://www.hackerone.com/terms/community#:~:text=8.%20Ownership%20and%20Licenses</a></p><p><br></p><p><span style="background-color: transparent;">I argued with an AI regarding HackerOne using Hacker reports to train PtaaS</span></p><p><a href="https://bugbounty.forum/post/183ff0fc-eb9e-47f8-991d-c0aa5b0bba71" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://bugbounty.forum/post/183ff0fc-eb9e-47f8-991d-c0aa5b0bba71</a></p><p><br></p><p><span style="background-color: transparent;">HackerOne PTaaS (likely training their AI on private reports data)</span></p><p><a href="https://www.reddit.com/r/bugbounty/comments/1r5hixk/hackerone_ptaas_likely_training_their_ai_on/" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://www.reddit.com/r/bugbounty/comments/1r5hixk/hackerone_ptaas_likely_training_their_ai_on/</a></p><p><br></p><p><span style="background-color: transparent;">What Makes Agentic PTaaS Different in Real Environments</span></p><p><a href="https://www.hackerone.com/blog/agentic-penetration-testing-as-a-service#:~:text=Our%20agents%20are,real%20enterprise%20constraints" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://www.hackerone.com/blog/agentic-penetration-testing-as-a-service#:~:text=Our%20agents%20are,real%20enterprise%20constraints</a></p><p><br></p><p><span style="background-color: transparent;">====== Timestamps ======</span></p><p><span style="background-color: transparent;">(00:00:00) Introduction</span></p><p><span style="background-color: transparent;">(00:08:44) HackerOne AI Terms of Service&nbsp;</span></p><p><span style="background-color: transparent;">(00:24:56) Agentic PTaaS</span></p><p><span style="background-color: transparent;">(00:38:09) Selling data</span></p><p><span style="background-color: transparent;">(00:43:49) Decrease in Bounties</span></p>

Critical Thinking - Bug Bounty Podcast

[email protected] (Justin Gardner (Rhynorater), Joseph Thacker (Rez0), & Brandyn Murtagh (gr3pme))

Episode 162: HackerOne Training AI on Bug Bounty Data?

FEB 19, 202653 MIN
Critical Thinking - Bug Bounty Podcast

Episode 162: HackerOne Training AI on Bug Bounty Data?

FEB 19, 202653 MIN

Description

Episode 162: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joseph sit down with HackerOne Founder & CTO Alex Rice to discuss concerns of Using Hacker Data for AI and decreasing bounties.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: [email protected] to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ ====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Today's Sponsor: Join Justin at Zero Trust World in March and get $200 off registration with Code ZTWCTBB26https://ztw.com/Today’s Guest: https://x.com/senorarroz====== This Week in Bug Bounty ======XML external entity: The ultimate Bug Bounty guide to exploiting XXE vulnerabilitieshttps://www.yeswehack.com/learn-bug-bounty/xml-external-entity-guide-xxe?utm_source=Critical_Thinking&utm_medium=Youtube&utm_campaign=XXE_Critical_Thinking&utm_id=XXE_CTBug Bounty Maturity Frameworkhttps://bugbountymaturity.com/====== Resources ======Confidential Information and Confidentiality Obligationshttps://www.hackerone.com/terms/general#:~:text=HackerOne%20may%20use%20Confidential%20Information%20to%20develop%20and/or%20improve%20its%20Services%20(for%20example%2C%20to%20identify%20trends%2C%20and%20to%20train%20AI%20models)%20provided%20such%20use%20does%20not%20result%20in%20disclosure%20of%20Confidential%20Information%20to%20unauthorized%20third%20partiesOwnership and Licenseshttps://www.hackerone.com/terms/community#:~:text=8.%20Ownership%20and%20LicensesI argued with an AI regarding HackerOne using Hacker reports to train PtaaShttps://bugbounty.forum/post/183ff0fc-eb9e-47f8-991d-c0aa5b0bba71HackerOne PTaaS (likely training their AI on private reports data)https://www.reddit.com/r/bugbounty/comments/1r5hixk/hackerone_ptaas_likely_training_their_ai_on/What Makes Agentic PTaaS Different in Real Environmentshttps://www.hackerone.com/blog/agentic-penetration-testing-as-a-service#:~:text=Our%20agents%20are,real%20enterprise%20constraints====== Timestamps ======(00:00:00) Introduction(00:08:44) HackerOne AI Terms of Service (00:24:56) Agentic PTaaS(00:38:09) Selling data(00:43:49) Decrease in Bounties