Live data from Hacker News

Leaking the email of any YouTube user for $10k

brutecat.com

21–30 of 487 posts

Re: Leaking the email of any YouTube user for $10k

#21

Earlier quoted context omitted.

Unfortunately with the number of users Google has, any deprecation will be met with cries of pain / I-rely-on-the-spacebar-to-heat-up-my-computer. See https://killedbygoogle.com/ .

Side note, what is that reference from? Searching "i rely on the spacebar to heat up my computer" directs me back to this comment (6 mins ago).

[deleted]

Re: Leaking the email of any YouTube user for $10k

#22

Earlier quoted context omitted.

Unfortunately with the number of users Google has, any deprecation will be met with cries of pain / I-rely-on-the-spacebar-to-heat-up-my-computer. See https://killedbygoogle.com/ .

Side note, what is that reference from? Searching "i rely on the spacebar to heat up my computer" directs me back to this comment (6 mins ago).

https://xkcd.com/1172/

Re: Leaking the email of any YouTube user for $10k

#23

Breaking the email system so that it's not sent is the cherry on top. With companies as big as Google who have developed so many products, "security" feels fake. If every line of code is a possible vulnerability, with millions it's just inevitable. It feels like the only way is to keep things simple (e.g., deprecate the recorder site), but even then.

You're essentially suggesting a Drake equation [1] equivalent for the number of security vulnerabilities based on NLoC. What other factors would be part of this equation?

[1] https://en.wikipedia.org/wiki/Drake_equation

Re: Leaking the email of any YouTube user for $10k

#24

Earlier quoted context omitted.

Unfortunately with the number of users Google has, any deprecation will be met with cries of pain / I-rely-on-the-spacebar-to-heat-up-my-computer. See https://killedbygoogle.com/ .

Side note, what is that reference from? Searching "i rely on the spacebar to heat up my computer" directs me back to this comment (6 mins ago).

https://xkcd.com/1172/

Re: Leaking the email of any YouTube user for $10k

#25
post #6

This is a puny payout IMO. If they poked around a bit more they may have found a better GAIA->Email vulnerability or perhaps could just use the one they found. A database of emails for every major youtube channel would be worth an awful lot.

Major YouTube channels are typically managed by multiple people through the channel management features and brand accounts. I don't think it's possible to even log in to the brand account (which has a generated email address like channel-000000000000000000000@pages.plusgoogle.com) instead it can only be accessed through an authorized user's account (which are distinct from the channel, i.e: it's not the email address that would be surfaced by this attack). Granted, things have changed over the years, so there may be old channels lingering with Google account linked email addresses, but from what I can tell, all channels were converted a while back.

https://support.google.com/youtube/answer/7001996?hl=en-GB

edit: My hunch is that the channels the OP's attack was able to target are not actual channels but rather YouTube users (who have a "channel" because that's how YouTube represents users): so "YouTube User" is the correct description of this attack, which is distinct from what you're thinking of as a channel.

Re: Leaking the email of any YouTube user for $10k

#26

Breaking the email system so that it's not sent is the cherry on top. With companies as big as Google who have developed so many products, "security" feels fake. If every line of code is a possible vulnerability, with millions it's just inevitable. It feels like the only way is to keep things simple (e.g., deprecate the recorder site), but even then.

Unfortunately with the number of users Google has, any deprecation will be met with cries of pain / I-rely-on-the-spacebar-to-heat-up-my-computer. See https://killedbygoogle.com/ .

They really aren't shy about massive breaking changes.

I'm still upset about Google Reader.

https://killedbygoogle.com/

Re: Leaking the email of any YouTube user for $10k

#27
“Applied 1 downgrade from the base amount due to complexity of attack chain required” I’ve only participated in a few vulnerability programs, and most of them reward less if the security flaw is stupidly simple (but serious) such as revealing user emails in the page source.

Re: Leaking the email of any YouTube user for $10k

#29

Is it me or are all the dates in this timeline in the future? Isn’t it Feb 2025 now? Do you smell toast? EDIT: oh I see .. DD/MM/YY is a new one to me

MM/DD/YY is an exclusively American standard

https://en.wikipedia.org/wiki/List_of_date_formats_by_countr...

I have no idea why America settled on MM/DD/YY, which seems like absolutely the least intuitive permutation of D, M, and Y. Except perhaps MYD.

Re: Leaking the email of any YouTube user for $10k

#30
> That params is nothing more than just base64 encoded protobuf, which is a common encoding format used throughout Google.

Pour one out for the google dev in charge of b64 encoding their fancy binary message format so it can be jammed inside a JSON blob. If you want a vision of the future, imagine a boot with "worse is better" imprinted on the sole stomping on an engineer's face, forever.

Post reply on HN