Live data from Hacker News

Leaking the email of any YouTube user for $10k

brutecat.com

41–50 of 487 posts

Re: Leaking the email of any YouTube user for $10k

#41

Is it me or are all the dates in this timeline in the future? Isn’t it Feb 2025 now? Do you smell toast? EDIT: oh I see .. DD/MM/YY is a new one to me

Day-Month-Year is the standard everywhere in the world apart from the US. Big and little endian dates are the only way that makes sense I think. Doing it the US way where day is inexplicably between year and month just feels corrupted to my mind.

Not standard in China, Japan, Hungary, Mongolia, South Korea, Taiwan, and of course ISO 8601.

Re: Leaking the email of any YouTube user for $10k

#42

Earlier quoted context omitted.

Unfortunately with the number of users Google has, any deprecation will be met with cries of pain / I-rely-on-the-spacebar-to-heat-up-my-computer. See https://killedbygoogle.com/ .

Side note, what is that reference from? Searching "i rely on the spacebar to heat up my computer" directs me back to this comment (6 mins ago).

you're one of today's lucky 10,000

Re: Leaking the email of any YouTube user for $10k

#43

Is it me or are all the dates in this timeline in the future? Isn’t it Feb 2025 now? Do you smell toast? EDIT: oh I see .. DD/MM/YY is a new one to me

DMY is the most common format internationally. There's a growing move (and ISO standard) for YMD but its a slow change, I think it's only North America that uses MDY.

Re: Leaking the email of any YouTube user for $10k

#45
post #6

This is a puny payout IMO. If they poked around a bit more they may have found a better GAIA->Email vulnerability or perhaps could just use the one they found. A database of emails for every major youtube channel would be worth an awful lot.

Think this is puny — I found the ability to reveal emails in npmjs.org but as it hadn't been included in the new GitHub/Microsoft bug bounty scope yet, I was given a t-shirt and $1000.

Talk about puny!

Re: Leaking the email of any YouTube user for $10k

#46
post #2

Am I very naive expecting the payout to be significantly higher?

To me, that payout felt quite high; it's bigger than the average monthly salary for a senior IT professional where I live. To put it another way, that bounty alone would be like being paid for several months of full-time employment.

Re: Leaking the email of any YouTube user for $10k

#47
post #31

Earlier quoted context omitted.

That’s the date format used in the UK

Small correction: that's the date format used by most every country except the United States . https://en.wikipedia.org/wiki/List_of_date_formats_by_countr...

Why is it always americans who are caught with being seemingly unaware of the rest of the world? Is it because we all speak their language? I didn't ever see it with Britons or Australians.

Re: Leaking the email of any YouTube user for $10k

#48
post #44

I haven't gotten access to my YouTube channel since it migrated to Google account. If anyone can set me in contact with anyone who can help recover my account, it will be rewarded with karma for life

Haha a human at google. Good luck. My maps review are almost always blocked because reasons for years, Im still trying to reach a human there.

Re: Leaking the email of any YouTube user for $10k

#49

Very nice breakdown. But while 10,000 dollars seems like a decent sum, I expected more for a bug of this severity, if I'm being honest. Especially as they initially only awarded 3100. But I'm not sure how much is usual for such cases. Almost 150 days also seems kind of a long time for fixing it imho.

$10k is not a decent sum. The compensation reflects roughly 0.25-3 weeks of SWE costs in payout.

Industry-wide SWE compensation is somewhere in the $100k-$200k range. Typical Google SWE compensation is $350k. Top Google SWE salary is north of $1M. Increase by 60-100% for overhead, or somewhat more for consulting overhead.

The amount of work doing something like this is orders of magnitude more than the compensation:

1) Most security vulnerabilities investigated lead nowhere, were previously discovered, etc. That's lost time.

2) Working out something like this is much more than 0.25-3 weeks.

More critically, the black market value of most vulnerabilities is much more than Google pays out. A rational economic actor would sell something like this grey market or black market, rather than reporting.

The problem is none of the big companies take security seriously. The reason is that there are no economic damages to even serious data leaks, so what incentive is there for them to take data security seriously?

Many companies (including big ones like T-Mobile) have major security compromises every few months (and in the case of T-Mobile, have had so for decades) and simply don't care. I don't mean to pick on T-Mobile -- I like them as a company -- but they're pretty representative.

Post reply on HN