Turso 用 AI 替代白帽赏金计划
推荐指数 57.0 NO. 017 · 2026.05.16
发布2026/05/15Score330Comments242
为什么值得看
数据库公司 Turso 宣布关闭运行多年的漏洞赏金计划,全面转向 AI 驱动的安全检测。这暗示 AI 已能覆盖传统人工渗透测试的核心场景,对安全行业人力结构有标志性影响。
媒体预览
编辑判断
Turso 不是第一家用 AI 做安全扫描的公司,但它是首个高调关闭赏金计划、把 AI 作为替代方案写进公告的。这个决策的底气可能来自内部测试数据——如果 AI 的漏报率和误报率已经低于初级白帽,继续支付赏金就是负 ROI。
对安全从业者来说,纯靠挖漏洞变现的路径在收窄,但高级红队、AI 安全对齐、模型越狱防御这类需要创造性思维的岗位反而更值钱。对创业公司而言,Turso 的做法提供了一个成本锚点:如果你的安全预算里赏金占比超过 30%,现在就该评估 AI 替代的可行性。
社区反馈
负面 182 条评论
核心争论:AI生成低质量漏洞报告淹没赏金计划,人工审核成本失控,关闭计划是无奈之举还是技术倒退
Isn't there some alternative approach? I.e when someone submit ai slop they get a strike. Three strikes and you are suspended from submitting to the bug bounty for x months/years? *Edit - I get it. It seems like the authentication is a challenge.
They mentioned they had identified alternatives but it would be costly to implement them. One can imagine that ban evading by generating a new user account would be easy for an LLM agent. It's going to be a long, long game if whack-a-mole.
you still need to spend effort reviewing the code to figure out when you can give a strike. Thrice for an actual ban. This would still waste precious maintainer time.