Node.js changes bug bounty program due to AI clutter

Node.js changes bug bounty program due to AI clutter

The Node.js project is changing its bug bounty program after developers faced a surge of reports generated by artificial intelligence that are difficult to assess.

Now to submit vulnerability reports HackerOne the Node.js project requires a Signal score of 1.0 or higher.

The Node.js security team has seen a significant increase in low-quality reports. This trend has intensified over the past years, and during the holiday season, the influx exceeded our physical capabilities. From December 15 to January 15, we received more than 30 reports. Processing these takes time and effort that could be directed towards actual security work.

The minimum Signal score requirement ensures that reporters have a proven track record of submitting valid reports, while new researchers can still participate with a limited number of submissions.

Signal is a reputation metric on HackerOne that reflects the quality of an investigator's past reports. A high Signal indicates a history of valid and significant findings. This requirement helps prioritize reports from experts with proven experience and reduces the burden of filtering out invalid submissions.

Source: linux.org.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster