Live data from Hacker News

The embedded YouTube player told me what you were watching

bugs.xdavidhu.me

101–110 of 112 posts

Re: The embedded YouTube player told me what you were watching

#101

Earlier quoted context omitted.

Ageist how? Who says you have to be a certain age to be a parent or grandparent? Sounds very ageist to me. And that is an example of how political correctness is an arms race.

> And that is an example of how political correctness is an arms race. Is it so hard to be nice?

It’s very easy to be nice. For example by saying that you shouldn’t just think about yourself, but also your parents and grandparents.

What isn’t nice is then to say that that is an ageist thing to say. Even though it is a perfectly valid thing to point out real people who are affected by certain online threats.

Re: The embedded YouTube player told me what you were watching

#102
post #42

Earlier quoted context omitted.

Ageist how? Who says you have to be a certain age to be a parent or grandparent? Sounds very ageist to me. And that is an example of how political correctness is an arms race.

You misunderstand: it's ageist to suggest that parents and grandparents are by definition not likely to be technical enough to use mitigations like containers and such. Which it is.

I think you misunderstand. Ageism is about discriminating on the basis of someone’s age.

The original comment was about grandparents and parents neither of which you need to have a certain age to be one. Assuming that it IS about age is in turn actually ageist because you are signaling that people should be parents at a certain point in their life.

To be clear, I don’t think your intentions are wrong: you are just trying to right a perceived wrong. I am just asking you to grant others a more favourable interpretation of their intentions as well. I do this by pointing out that your well intended call out of ageism is in turn also interpretable as something unwoke.

Hence arms race. There is always someone who can be more politically correct.

Re: The embedded YouTube player told me what you were watching

#103
post #99

Earlier quoted context omitted.

Probably not even worth the time he invested in looking for the bug or writing the post. And is basically nothing compared to the value of "exploiting" this bug. I would've expected at least a job offer or public praise for his offers. No wonders bug hunting is not attracting enough people.

> And is basically nothing compared to the value of "exploiting" this bug. Out of interest, how do you think you'd go about monetising this bug? I agree that the information leakage is definitely bad, but exploiting that to turn it in to cold hard cash seems tricky at best imo. I presume this factors in to Google's payout calculations.

Make a VPN service, market it in China, put this code into the control/account panel, sell data to Chinese government.

And no, how much it could be monetized certainly shouldn't factor into lowering the bounty. Maybe when raising it, since you need to be competing with the black market, but an exploit should be valued only on how much damage it could cause, and getting people disappeared for watching anti-government videos sounds like pretty big damage.

Re: The embedded YouTube player told me what you were watching

#104
post #70

I honestly feel like Google's award in this case is pathetic. This is an exploit which would be worth 100s of thousands, if not millions to the wrong people.

There is no entity that would pay anywhere near that amount of money for this. This is useless to black hats, and of course no legitimate service could pay to exploit this flaw. The last remotely plausible actor is like, various espionage agencies but good luck with that one.

China.

Re: The embedded YouTube player told me what you were watching

#105
post #8

$1,337 for watch history + liked videos + watch later disclosure? Requires user to visit a malicious site, yes, but still feels a bit skimpy.

Reminds me of when Google awarded me a whole Nexus 7 tablet for finding a way to run external JavaScript inside of Gmail for Android. The exploit required the user to tap on the email after opening it, which is why it didn't qualify for any money.

Wow. A whole $200 value

Re: The embedded YouTube player told me what you were watching

#106
post #70

I honestly feel like Google's award in this case is pathetic. This is an exploit which would be worth 100s of thousands, if not millions to the wrong people.

There is no entity that would pay anywhere near that amount of money for this. This is useless to black hats, and of course no legitimate service could pay to exploit this flaw. The last remotely plausible actor is like, various espionage agencies but good luck with that one.

It's worth a lot more than $1337 though. That sort of money is so low that it may not even be worth the time to white hats

Re: The embedded YouTube player told me what you were watching

#107
post #99

Earlier quoted context omitted.

> And is basically nothing compared to the value of "exploiting" this bug. Out of interest, how do you think you'd go about monetising this bug? I agree that the information leakage is definitely bad, but exploiting that to turn it in to cold hard cash seems tricky at best imo. I presume this factors in to Google's payout calculations.

Make a VPN service, market it in China, put this code into the control/account panel, sell data to Chinese government. And no, how much it could be monetized certainly shouldn't factor into lowering the bounty. Maybe when raising it, since you need to be competing with the black market, but an exploit should be valued only on how much damage it could cause, and getting people disappeared for watching anti-government…

> ...sell data to Chinese government.

I think this part is probably pretty hard and is certainly risky.

Re: The embedded YouTube player told me what you were watching

#108
post #107

Earlier quoted context omitted.

Make a VPN service, market it in China, put this code into the control/account panel, sell data to Chinese government. And no, how much it could be monetized certainly shouldn't factor into lowering the bounty. Maybe when raising it, since you need to be competing with the black market, but an exploit should be valued only on how much damage it could cause, and getting people disappeared for watching anti-government…

> ...sell data to Chinese government. I think this part is probably pretty hard and is certainly risky.

Or just sell the exploit on the dark net, where a Chinese state-sponsored hacker would surely find it and buy it. I'm certain China has a pile of crypto somewhere intended for just that.

Re: The embedded YouTube player told me what you were watching

#109
post #71
post #13

Earlier quoted context omitted.

> Requires user to visit a malicious site YouTube embeds are such universal things on the web, I doubt anyone would even think twice about security concerns coming from seeing that on a third-party site. Because it's Google, right? /s

Strangely, I almost never allow YouTube embeds (or for that matter any embeds) using uMatrix. I click the pop out link that appears in its place.

That's actually a really good idea, I should do that too.. Thanks!

Re: The embedded YouTube player told me what you were watching

#110

Earlier quoted context omitted.

>can't understand generics Is this really true? We learned about generics in college so I assumed that everyone knew it (especially if they work at Google).

As someone else noted, I am taking a swing at Go's lack of generics. More to the point, I am criticizing the reason for that. Designing a simple language is fine. I like simple languages a lot. Go was designed not because simple languages are good for some jobs but because Google decided their engineers aren't up to using more powerful tools. I don't know Go. I've only written about 200 lines of it. I don't pretend t…

> More to the point, I am criticizing the reason for that.

Go's lack of generics is not due to ideological reasons. The designers are not particularly against them and are open to adding them given a good proposal. They always said that generics may well be added at some point.

Post reply on HN