HackerOne has announced a policy change requiring hackers to undergo identity verification before they can submit reports to any bug bounty program on its platform. This adjustment aligns with regulatory demands, distinguishing these programs from vulnerability disclosure programs (VDPs), which remain accessible to unverified researchers due to the absence of financial incentives.
Understanding the Verification Process
To initiate the verification, users must navigate to their User profile page and select the ID Verification section. Here, they are required to agree to HackerOne’s Rules of Engagement, which outlines terms related to increased access and credentials for verified users.
Upon accepting these terms, users can start the verification process through Veriff, HackerOne’s identity partner. This process involves real-time image capture, where applicants photograph a valid government ID and typically take a live selfie for comparison.
Technical Requirements and Document Guidelines
HackerOne’s verification process emphasizes environmental integrity, prohibiting the use of VPNs, traffic anonymizers, jailbroken devices, SDK emulators, or Apple’s private relay, as their use results in automatic rejection. Accepted ID forms include passports, national IDs, residence permits, and driver’s licenses, although eligibility varies by country and must be physical copies.
Once completed, HackerOne generally confirms verification within three business days, with initial reviews potentially taking up to 48 hours. Verification is not permanent and requires annual renewal to maintain access to verification-dependent programs.
Maintaining Compliance in the Bug Bounty Ecosystem
HackerOne distinguishes its standard ID Verification from the more comprehensive H1 Clear program, which includes additional background checks for a select group of hackers. Rejections often occur due to technical issues like poor-quality images or expired documents rather than identity fraud.
For optimal results, HackerOne advises using good lighting, removing obstructions like glasses, and utilizing supported browsers. As the vulnerability disclosure industry faces increasing compliance demands, researchers should incorporate the verification timeline into their planning.
This regulatory shift underscores the growing expectations for compliance in the cybersecurity domain, affecting how ethical hackers engage with enterprise programs.
