HackerOne Ends Anonymous Era for Bug Bounty Hunters with Mandatory ID Verification
HackerOne has ended its long-standing anonymous model for paid bug bounty programs. Researchers must now complete mandatory identity verification before submitting any reports to programs offering monetary rewards.
Compulsory Verification Becomes a Hard Requirement
Starting August 1, every hacker must finish identity verification before submitting vulnerabilities to any Bug Bounty Program. Unverified accounts cannot submit reports or receive payouts. The rule applies to all paid programs without exception. Vulnerability Disclosure Program (VDP) projects that offer no financial rewards remain open to unverified researchers.
Verification Process Handled by Veriff
Users access the ID Verification section in their profile, sign the Rules of Engagement document, and are redirected to Veriff, an Estonian identity verification provider. The process requires a live camera scan of a government-issued ID such as a passport, national ID, residence permit, or driver’s license, plus a real-time selfie for facial matching. Scanned copies and digital IDs are not accepted.
Several restrictions apply: VPNs, traffic anonymization tools, jailbroken devices, SDK emulators, and Apple Private Relay are all prohibited and trigger automatic rejection. Verification usually completes within three business days, with a maximum queue time of 48 hours. The verification must be renewed every year.
H1 Clear Adds Criminal Background Checks
H1 Clear represents a stricter tier that combines standard verification with criminal background screening. It targets a select group of elite researchers working on internal enterprise programs. Even Clear-status researchers must still complete the annual standard verification renewal.
Common Rejection Reasons and Preparation Tips
Most rejections stem from technical issues rather than identity fraud: blurry text on documents, missing machine-readable zones, cropped barcodes, expired IDs, or use of photocopies. HackerOne recommends good lighting, removal of glasses and headwear, and use of Chrome or Safari browsers.
Industry-Wide Shift Toward De-Anonymization
The change aligns with regulatory demands for anti-money laundering compliance and customer due diligence on cross-border payments. Similar verification requirements already exist on Bugcrowd and European platforms such as Intigriti. The policy affects new researchers, those in privacy-sensitive regions, and anyone hoping to participate in time-sensitive bounty competitions, as unverified accounts cannot submit reports immediately upon discovering a vulnerability.
Related articles
Telegram Briefly Removed from App Store After Apple Detects Child Sexual Abuse Material
Telegram was temporarily pulled from the App Store in multiple countries after Apple moderators identified content linked to child sexual abuse. The removal lasted roughly 20 minutes before the app was reinstated following Telegram's quick removal of the prohibited material and blocking of the responsible user. Apple cited strict App Store rules as the reason for the action. During the outage, already-installed copies continued to function normally while the app remained available via the Mac App Store and Google Play. Telegram responded on X with the quote “Rumors of my death have been greatly exaggerated” before Apple issued its official explanation. This marks at least the third documented instance of Telegram facing App Store removal, including a 2018 incident over unacceptable content and a 2024 removal from the Chinese store at the request of local regulators.
Russia's MinTsifry Proposes Hosting Providers Detect and Report Disguised VPN Services
The Russian Ministry of Digital Development is discussing measures to strengthen oversight of VPN services that mask themselves as legitimate websites and hide their IP addresses from official blocklists. Hosting providers would be required to independently identify suspicious IP addresses and report them to regulators for potential blocking. The proposal also introduces a tiered trust system for hosting clients based on the strength of their identity verification. Users authenticated only via phone or bank card could have services terminated within 30 minutes upon violations, while those verified through Gosuslugi or biometric systems would receive more time to resolve issues. Non-compliant hosting providers risk being labeled as unreliable, resulting in restrictions that limit client access to a narrow whitelist of approved resources such as government portals, banks, and marketplaces. Industry participants warn that these restrictions could worsen IPv4 address shortages and drive legitimate businesses toward foreign hosting providers.
Why Sending an MDM Command Does Not Mean It Has Been Executed
MDM operations such as policy assignment and device lock appear synchronous in the console but actually trigger complex asynchronous delivery chains involving backends, queues, vendor infrastructure, and device agents. The article explains that request acceptance, queue storage, external API confirmation, and actual device execution represent four distinct states that must be tracked separately. Aitera MDM implements an Outbox pattern to ensure transactional consistency between policy changes and command delivery while supporting at-least-once semantics with idempotency. Android Enterprise relies on the Android Management API and Google-controlled synchronization through Android Device Policy, whereas iOS uses APNs only for wake-up and pull-based command retrieval with statuses including Acknowledged, Error, and NotNow. The system maintains separate desired, delivery, and observed states to avoid misleading applied flags and provides detailed command history for administrators. Metrics focus on policy confirmation rates, queue age, and divergence between intended and actual device configurations rather than simple device counts.
Russia's FAS Opens Antitrust Case Against Apple for Failing to Pre-Install Domestic Software on iOS Devices
Russia's Federal Antimonopoly Service has initiated proceedings against Apple after the company failed to comply with a prior warning to pre-install Russian software on iPhones and iPads. The case stems from requirements under Russian law to offer domestic alternatives for search engines, messengers, and app stores. Apple had added support for a Russian search engine in a software update, but this did not satisfy regulators who also demanded the national messenger and domestic app store. Non-compliance could result in a fine reaching up to 4 billion rubles under the Code of Administrative Offenses. The government has already approved a mandatory list of Russian applications that must be pre-installed on smartphones and tablets starting January 1, 2027. The list includes RuStore, Max, Yandex Browser, Alice AI, VKontakte, Gosuslugi, Mir Pay, Mail.ru, and 2GIS among others.