Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Commit 70499d0

Browse files
committed
Update hacker-mediation.md
1 parent 1d0338f commit 70499d0

File tree

1 file changed

+9
-8
lines changed

1 file changed

+9
-8
lines changed

docs/hackers/hacker-mediation.md

Lines changed: 9 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -8,17 +8,16 @@ id: "hackers/hacker-mediation"
88
Hackers can request assistance from HackerOne in cases when discussions with the program have been attempted and there has been no satisfactory resolution. Vice versa, programs can also request mediation when the Code of Conduct has been violated.
99

1010
Hacker Mediation can be requested for the following reasons:
11-
12-
A program's decision is inconsistent with broad industry standards.
13-
A program does not honor a commitment made on their Security Page.
14-
A program promises to reply within a certain time period on their Security Page but fails to do so.
15-
A program claims a domain is in scope on their Security Page, then makes a last-minute change to pull it out of scope based on your report.
16-
A program clearly outlines a vulnerability in a particular domain as being worth a minimum bounty, but then awards less than that amount or no bounty at all without explanation.
17-
Etc.
18-
11+
* A program's decision is inconsistent with broad industry standards.
12+
* A program does not honor a commitment made on their Security Page.
13+
* A program promises to reply within a certain time period on their Security Page but fails to do so.
14+
* A program claims a domain is in scope on their Security Page, then makes a last-minute change to pull it out of scope based on your report.
15+
* A program clearly outlines a vulnerability in a particular domain as being worth a minimum bounty, but then awards less than that amount or no bounty at all without explanation.
16+
* Etc.
1917

2018
Hacker mediation is used to raise concerns about reports to security teams and facilitate discussions between hackers and customers to enable a more favorable outcome for everyone involved. Please keep in mind that if a program is not managed or triaged by HackerOne, then the time to fully resolve the mediation might take longer than usual.
2119

20+
2221
### Requesting Hacker Mediation
2322
To request mediation:
2423

@@ -40,6 +39,7 @@ In most cases, HackerOne will not be able to mediate for reports that have been
4039

4140
Finally, keep in mind that HackerOne is no longer able to add external researchers to original report submissions due to security and privacy concerns related to doing so.
4241

42+
4343
### Hacker Mediation Triggers
4444
Requesting hacker mediation triggers the following actions:
4545

@@ -60,5 +60,6 @@ Two-factor authentication resets | Unresponsiveness (e.g.: The triage team or th
6060
Account deletion |
6161
General questions |
6262

63+
6364
**The Make It Right Fund**
6465
There may be cases where HackerOne may believe a hacker’s submission has been handled incorrectly. We want to make sure hackers are awarded for their efforts in such cases. After extensive backend reviews are completed of the specific report, the hacker may be considered for a discretionary correction from the HackerOne Make It Right Fund. Please keep in mind that not every report is eligible for Make It Right and the decision to recommend or consider a Make It Right award belongs to HackerOne. Usage of Make It Right may be noted in the report’s record for transparency.

0 commit comments

Comments
 (0)