Chris Evans (@scarybeasts) 's Twitter Profile
Chris Evans

@scarybeasts

CISO and Chief Hacking Officer at HackerOne. Past: Founded {vsftpd, Chrome security, Google Project Zero}; Tesla; Dropbox. Hacker / Researcher. beebjit.

ID: 38752792

linkhttps://scarybeastsecurity.blogspot.com/ calendar_today09-05-2009 00:10:51

3,3K Tweet

25,25K Followers

202 Following

Jobert Abma (@jobertabma) 's Twitter Profile Photo

Hackers, good news: we’ve launched the ability to pause your payments and setting a minimum amount for a small group of hackers — and it’s looking good! We expect to make this available for the entire community in the second half of May.

Chris Evans (@scarybeasts) 's Twitter Profile Photo

Great hacking MUST be celebrated! Yes, with robust bounties of course. But also with praise when a hacker's creativity finds something unusual, or deeply hidden, or clever, or unexpected, or just downright impactful, or difficult, or ... ! I commit to giving more Testimonials.

Chris Evans (@scarybeasts) 's Twitter Profile Photo

Every Bug Bounty Program has areas for improvement. IMHO, the mark of a Gold Standard BBP is accepting feedback with humility and making updates. In this instance, we had a bounty table inconsistency. I approved $60,000 in retroactive payouts and we straightened out the table.

Chris Evans (@scarybeasts) 's Twitter Profile Photo

Hackers, I think this one's important. You deserve transparency as a matter of fairness and platform integrity. It is now mandatory for programs to always show time-to-bounty related statistics. (Example is from a leading program.)

Hackers, I think this one's important. You deserve transparency as a matter of fairness and platform integrity. It is now mandatory for programs to always show time-to-bounty related statistics. (Example is from a leading program.)
Chris Evans (@scarybeasts) 's Twitter Profile Photo

Hackers, the new payment controls (pause, thresholds) have been released to all accounts. Thanks for all the feedback that helped us to prioritize this.

Hackers, the new payment controls (pause, thresholds) have been released to all accounts. Thanks for all the feedback that helped us to prioritize this.
Jobert Abma (@jobertabma) 's Twitter Profile Photo

Hackers, today we’re announcing Spot Checks for all; a new way to help organizations all over the world by testing specific areas of their systems. Spot Checks vary in size and often pay out quickly (we’ve seen $500 within minutes). Opportunities show up on HackerOne and in

Chris Evans (@scarybeasts) 's Twitter Profile Photo

Hackers, thanks for the feedback on bounty table transparency enhancements. Glad it's useful! Why do this? See screenshot of great program. You deserve to know a program honors its bounty table, uses the extent of any ranges, and is generous with High / Critical severities.

Hackers, thanks for the feedback on bounty table transparency enhancements. Glad it's useful! Why do this? See screenshot of great program. You deserve to know a program honors its bounty table, uses the extent of any ranges, and is generous with High / Critical severities.
Chris Evans (@scarybeasts) 's Twitter Profile Photo

I'm very excited about Spot Checks. It's a new way for hackers and enterprises to connect, to build relationships, and generate the same spectacular results they always do.

Mårten Mickos (@martenmickos) 's Twitter Profile Photo

The massive Ambassador World Cup is starting again, with 700 hackers competing in 40 teams. Last year, one of our major customers said it was the best thing they ever did.

The massive Ambassador World Cup is starting again, with 700 hackers competing in 40 teams. 
Last year, one of our major customers said it was the best thing they ever did.
Chris Evans (@scarybeasts) 's Twitter Profile Photo

Thanks Nagli for the feedback. There is no new policy but there was a documentation error, which is now fixed. Keep the feedback coming!

Mårten Mickos (@martenmickos) 's Twitter Profile Photo

HackerOne Ambassador World Cup in full swing with over $30,000 paid in bounties in these first days alone. How is your country faring? Bookmark the leaderboard so you can follow! leaderboards.hackerone.live/awc2024

Chris Evans (@scarybeasts) 's Twitter Profile Photo

Hackers, there's now a better UI for programs to give you testimonials on your public profile. As Chief Hacking Officer, it's my expectation that any top-tier or world-class program uses this to celebrate the best reports. Share with your friends who operate programs!

Hackers, there's now a better UI for programs to give you testimonials on your public profile. As Chief Hacking Officer, it's my expectation that any top-tier or world-class program uses this to celebrate the best reports. Share with your friends who operate programs!
Chris Evans (@scarybeasts) 's Twitter Profile Photo

Hackers, based on feedback, we're planning to separate out and make BBP reputation the primary measure on profiles and leaderboards. Further iterations likely to follow -- feedback welcome as always.

Hackers, based on feedback, we're planning to separate out and make BBP reputation the primary measure on profiles and leaderboards. Further iterations likely to follow -- feedback welcome as always.
Chris Evans (@scarybeasts) 's Twitter Profile Photo

Hackers, thanks as always for the on-point feedback! The missing tags, e.g. "Managed by HackerOne", are coming back. See screenshot. In the interim, it's still possible to search on them. And the new ones. I'm excited for programs to respect you by committing to "Fast Payment".

Hackers, thanks as always for the on-point feedback! The missing tags, e.g. "Managed by HackerOne", are coming back. See screenshot. In the interim, it's still possible to search on them. And the new ones. I'm excited for programs to respect you by committing to "Fast Payment".
Jobert Abma (@jobertabma) 's Twitter Profile Photo

Collaboration yields more vulnerabilities and typically higher severities! Go hang out with (internet) friends and hack together!

Jobert Abma (@jobertabma) 's Twitter Profile Photo

Hackers, we’re running a beta with payouts directly to BTC and USDC wallets without needing a Coinbase account. No ETA on general availability but this is now live for the first 300 hackers to test it out.

Chris Evans (@scarybeasts) 's Twitter Profile Photo

Hackers, there's a new per-asset type leaderboard. Here are the current titans of the quarter for AI Model / AI Red Team assets. hackerone.com/leaderboard/as…

Hackers, there's a new per-asset type leaderboard. Here are the current titans of the quarter for AI Model / AI Red Team assets. hackerone.com/leaderboard/as…