TrustRadius: an HG Insights company

HackerOne

Score7.6 out of 10

12 Reviews and Ratings

What is HackerOne?

HackerOne is a hacker-powered security platform, helping organizations find and fix critical vulnerabilities before they can be exploited, from the company of the same name in San Francisco. The service is used for vulnerability location, pen testing, bug bounty, and vulnerability triage services.

Good consolidation and frees up my time

Pros

  • Filter for spammy bug reports
  • Nice central interface
  • Payment/reward system is nice

Cons

  • I'd like to see a way for the end-user to set a minimum standard so those reporting are better vetted

Most Important Features

  • Customer support
  • Customizability

Return on Investment

  • More time for my team to address concerns and big filter though several things

Alternatives Considered

Bugcrowd

Other Software Used

Bugcrowd

HackerOne experience.

Pros

  • Easy to use
  • Multiple ways to categorize an issue so that it can be reported efficiently.
  • Gives an easy way to track issue and open issues again if they aren't resolved properly.

Cons

  • A lot of duplicate bugs get reported, although it does offer automatic suggestion of previously reported bugs that may be duplicates, it is far from perfect.
  • Anyone can report bugs, a lot of them are not verified before submission. This sometimes leads to a lot of time spent in verifying if the bug is really actionable.
  • Each submission has to be treated with equal potential, a lot of time, some time gets invested in vulnerabilities that aren't as important as some others.

Return on Investment

  • Bugs that can't be tracked internally are submitted by external researchers, which is an important factor for security vulnerabilities.
  • Even if the bugs reported are duplicates, there still is provision to award reputation points, that keep the researchers engaged.
  • It also requires a lot of verification and validation, as a lot of the submissions are unverified to begin with.

Other Software Used

Visual Studio.NET, Dynatrace