安全客•August 4, 2026•🇨🇳Translated from Chinese

HackerOne Ends Anonymous Era for Bug Bounty Hunters with Mandatory ID Verification

HackerOne has ended its long-standing anonymous model for paid bug bounty programs. Researchers must now complete mandatory identity verification before submitting any reports to programs offering monetary rewards.

Compulsory Verification Becomes a Hard Requirement

Starting August 1, every hacker must finish identity verification before submitting vulnerabilities to any Bug Bounty Program. Unverified accounts cannot submit reports or receive payouts. The rule applies to all paid programs without exception. Vulnerability Disclosure Program (VDP) projects that offer no financial rewards remain open to unverified researchers.

Verification Process Handled by Veriff

Users access the ID Verification section in their profile, sign the Rules of Engagement document, and are redirected to Veriff, an Estonian identity verification provider. The process requires a live camera scan of a government-issued ID such as a passport, national ID, residence permit, or driver’s license, plus a real-time selfie for facial matching. Scanned copies and digital IDs are not accepted.

Several restrictions apply: VPNs, traffic anonymization tools, jailbroken devices, SDK emulators, and Apple Private Relay are all prohibited and trigger automatic rejection. Verification usually completes within three business days, with a maximum queue time of 48 hours. The verification must be renewed every year.

H1 Clear Adds Criminal Background Checks

H1 Clear represents a stricter tier that combines standard verification with criminal background screening. It targets a select group of elite researchers working on internal enterprise programs. Even Clear-status researchers must still complete the annual standard verification renewal.

Common Rejection Reasons and Preparation Tips

Most rejections stem from technical issues rather than identity fraud: blurry text on documents, missing machine-readable zones, cropped barcodes, expired IDs, or use of photocopies. HackerOne recommends good lighting, removal of glasses and headwear, and use of Chrome or Safari browsers.

Industry-Wide Shift Toward De-Anonymization

The change aligns with regulatory demands for anti-money laundering compliance and customer due diligence on cross-border payments. Similar verification requirements already exist on Bugcrowd and European platforms such as Intigriti. The policy affects new researchers, those in privacy-sensitive regions, and anyone hoping to participate in time-sensitive bounty competitions, as unverified accounts cannot submit reports immediately upon discovering a vulnerability.

Related articles

Habr•Policy & Regulation

How to Complete the Roskomnadzor Personal Data Notification Form in 2026: Field-by-Field Analysis

The article provides a detailed walkthrough of the current Roskomnadzor notification form for operators processing personal data under Russian law. It explains that the form is an extract from existing internal documents rather than a questionnaire, requiring operators to reference their data processing policy, inventory results, appointment orders, and protection level acts. Key prerequisites include confirming that notification is mandatory after the 2022 amendments removed most exemptions, preparing five core documents, and understanding that the form pulls data directly from those records. The guide covers every section, from operator identification and processing regions to data categories, protection measures, geography, and post-submission obligations. It also addresses common mistakes, the option to save drafts, auto-population features, and liability for non-compliance or inaccurate information. The piece concludes with a checklist mapping each form field to its source document.

Habr•Policy & Regulation

OBEP Raids on Russian IT Firms: How to Safeguard Source Code, Servers and Blockchain Assets During Searches

Russian IT companies, Web3 projects and fintech services now face frequent visits from OBEP operatives conducting pre-investigative checks or searches under criminal cases. The article details the legal distinction between operational-search measures and formal searches, emphasizing article 164.1 of the UPK RF that prohibits seizure of physical servers in economic crime investigations. It explains how companies can demand data mirroring instead of hardware removal and how to invoke article 51 of the RF Constitution when pressured for encryption keys. Commercial secret regimes are presented as a tool to raise criminal liability for leaks and to request closed court proceedings. Practical checklists cover document verification, staff instructions, password retention and immediate calls to specialized criminal counsel. The guidance aims to prevent business paralysis while preserving evidence integrity during raids.

Habr•Policy & Regulation

RWB Deploys Enterprise-Wide Database Access Control with Trino and Open Policy Agent

RWB has replaced fragmented manual database access processes with a centralized architecture built on Trino as the single entry point and Open Policy Agent for policy enforcement. The system enforces least-privilege access, mandatory auditing, and automated revocation tied to HR records while eliminating anonymous and password-based logins. Access requests now complete in 3–10 minutes instead of an average of four days, with 92 percent handled automatically. Key components include Keycloak for OIDC authentication, Vault for secrets, Kafka for security event streaming to SOC, and Kubernetes orchestration. Responsibility is split across AI & Data Security, Core DevOps, Access Management, SOC, and Trust & Safety teams. More than 1,250 PostgreSQL clusters and 90 projects are now connected, with real-time dashboards tracking adoption and policy health.

AntiMalware•Policy & Regulation

Russia Moves to Allow Biometric Data Processing for Suspects and Convicts Without Consent

Russian law enforcement agencies may soon gain the legal right to process biometric data of suspects, accused individuals, and convicted persons without requiring their personal consent. A corresponding draft bill has already been submitted to the government and is scheduled for review at the next cabinet meeting, according to TASS. The measure covers fingerprints, facial images, voice recordings, and other physiological or behavioral characteristics used for identification. If approved, prior permission from the individual will no longer be needed when biometrics are used in criminal proceedings. The change applies not only to those already convicted but also to suspects and accused persons whose guilt has not yet been established by a court. For ordinary citizens, enrollment in the Unified Biometric System remains voluntary and is used for remote identity verification when accessing financial and government services.