Live data from Hacker News

Leaking the email of any YouTube user for $10k

brutecat.com

71–80 of 487 posts

Re: Leaking the email of any YouTube user for $10k

#71
post #59
post #49

Earlier quoted context omitted.

$10k is not a decent sum. The compensation reflects roughly 0.25-3 weeks of SWE costs in payout. Industry-wide SWE compensation is somewhere in the $100k-$200k range. Typical Google SWE compensation is $350k. Top Google SWE salary is north of $1M. Increase by 60-100% for overhead, or somewhat more for consulting overhead. The amount of work doing something like this is orders of magnitude more than the compensation:…

It's an extraordinarily high sum for this kind of finding. Bounties are generally not a referendum on how clever the underlying work is. A full-chain iOS bug is worth hundreds of thousands of dollars because Apple competes with the grey market for it (and even then, it's an apples-oranges comparison and Apple pays substantially less than the rest of the market for structural reasons). Nobody competes for this bug; no…

You’re significantly underestimating the value of dox-style exploits. Author could have partnered with a black hat vendor who would offer (for example) $25 per lookup. Or they could’ve done bulk scraping of YouTube channels to get emails and sold the dataset.

It requires some legwork but they could’ve seen somewhere in the ballpark of 6 figures over 1 year if the exploit wasn’t patched.

Oh, and if they had no ethics.

Re: Leaking the email of any YouTube user for $10k

#72
post #26

Earlier quoted context omitted.

Unfortunately with the number of users Google has, any deprecation will be met with cries of pain / I-rely-on-the-spacebar-to-heat-up-my-computer. See https://killedbygoogle.com/ .

They really aren't shy about massive breaking changes. I'm still upset about Google Reader. https://killedbygoogle.com/

I didn't use Reader. What was so special about it? Iirc it was an RSS aggregator, which sounds pretty simple to replace. Nobody has an open source equivalent?

Re: Leaking the email of any YouTube user for $10k

#73
Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations:

* Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneously, that has effectively no half-life once discovered, and whose exploitation will generate reliable telemetry from the target.

* Similarly, bugs like full-chain Android/Chrome go for hundreds of thousands of dollars because Google competes with a well-established grey market; a firm can take that bug and sell it to potentially 6 different agencies at a single European country.

* Even then, bounty vs. grey market is an apples-oranges comparison. Google will pay substantially less than the grey market, because Google doesn't need a reliable exploit (just proof that one can be written) and doesn't need to pay maintenance. The rest of the market will pay a total amount that is heavily tranched and subject to risk; Google can offer a lump-sum payment which is attractive even if discounted.

* Threat actors buy vulnerabilities that fit into existing business processes. They do not, as a general rule, speculate on all the cool things they might do with some new kind of vulnerability and all the ways they might make money with it. Collecting payment information? Racking up thousands of machines for a botnet? Existing business processes. Unmasking Google accounts? Could there be a business there? Sure, maybe. Is there one already? Presumably no.

A bounty payout is not generally a referendum on how clever or exciting a bug is. Here, it kind of is, though, because $10,000 feels extraordinarily high for a server-side web bug.

For people who make their nut finding these kinds of bugs, the business strategy is to get good at finding lots of them. It's not like iOS exploit development, where you might sink months into a single reliable exploit.

This is closer to the kind of vulnerability research I've done recently in my career than a lot of other vuln work, so I'm reasonably confident. But there are people on HN who actually full-time do this kind of bounty work, and I'd be thrilled to be corrected by any of them.

Re: Leaking the email of any YouTube user for $10k

#74
post #72
post #26

Earlier quoted context omitted.

They really aren't shy about massive breaking changes. I'm still upset about Google Reader. https://killedbygoogle.com/

I didn't use Reader. What was so special about it? Iirc it was an RSS aggregator, which sounds pretty simple to replace. Nobody has an open source equivalent?

Great and simple UI, synced across all your devices (which is what ended up killing RSS in f.ex. Thunderbird for me).

Re: Leaking the email of any YouTube user for $10k

#75
post #26

Earlier quoted context omitted.

Unfortunately with the number of users Google has, any deprecation will be met with cries of pain / I-rely-on-the-spacebar-to-heat-up-my-computer. See https://killedbygoogle.com/ .

They really aren't shy about massive breaking changes. I'm still upset about Google Reader. https://killedbygoogle.com/

I remember being upset about Google Reader for a few months after its death… before moving to one of its many, fuller-featured competitors and carrying on using RSS feeds exactly as before.

What upsets me re RSS these days is how many people were apparently so reliant on one reader that they still publicly mourn every time it comes up, 12 years later. Who are these fair-weather feed followers who threw their hands in the air with the loss of exactly one product?

Re: Leaking the email of any YouTube user for $10k

#76
post #64
post #45

Earlier quoted context omitted.

Think this is puny — I found the ability to reveal emails in npmjs.org but as it hadn't been included in the new GitHub/Microsoft bug bounty scope yet, I was given a t-shirt and $1000. Talk about puny!

I think this is puny: I was able to take over accounts on a cybersecurity platform just by knowing their account email and was only paid $200

I think this is puny; I can take down almost any site on the internet just by knowing the DNS name, and in exchange all I get is threats of criminal prosecution under anti-DDoS laws

Re: Leaking the email of any YouTube user for $10k

#77
post #59

Earlier quoted context omitted.

It's an extraordinarily high sum for this kind of finding. Bounties are generally not a referendum on how clever the underlying work is. A full-chain iOS bug is worth hundreds of thousands of dollars because Apple competes with the grey market for it (and even then, it's an apples-oranges comparison and Apple pays substantially less than the rest of the market for structural reasons). Nobody competes for this bug; no…

You’re significantly underestimating the value of dox-style exploits. Author could have partnered with a black hat vendor who would offer (for example) $25 per lookup. Or they could’ve done bulk scraping of YouTube channels to get emails and sold the dataset. It requires some legwork but they could’ve seen somewhere in the ballpark of 6 figures over 1 year if the exploit wasn’t patched. Oh, and if they had no ethics.

Does that black-hat vendor already exist? Do they already sell the service of taking $25 to unmask Google users? What calculation does that vendor do about how many customers they'll get before Google notices? Does the exploit developer get a 50% cut? The black-hat vendor is taking all the risk; seems unlikely. Arranging this whole thing is work; finding the "black hat vendor" is work; not getting caught in the process is work; not getting screwed by your partner is work. You pencil out the numbers and this gets less and less plausible as a way to beat a $10,000 lump sum payment.

I think the reality though is just that there's literally no buyer for this.

You could sell the service yourself! I bet you could make a couple thousand bucks before you and your customers got indicted.

Re: Leaking the email of any YouTube user for $10k

#78

Breaking the email system so that it's not sent is the cherry on top. With companies as big as Google who have developed so many products, "security" feels fake. If every line of code is a possible vulnerability, with millions it's just inevitable. It feels like the only way is to keep things simple (e.g., deprecate the recorder site), but even then.

That's probably another reason why Google kills so many products that are successful, but not successful enough for Google's whole system to justify keeping them alive and secure.

Re: Leaking the email of any YouTube user for $10k

#79
post #26

Earlier quoted context omitted.

Unfortunately with the number of users Google has, any deprecation will be met with cries of pain / I-rely-on-the-spacebar-to-heat-up-my-computer. See https://killedbygoogle.com/ .

They really aren't shy about massive breaking changes. I'm still upset about Google Reader. https://killedbygoogle.com/

+1 for Google Reader

That marks my coming of age on the enshittified web. The killing of Google Reader was a watershed moment. It marks the moment in time when the tide turned from the open Web to closed social media gardens.

Re: Leaking the email of any YouTube user for $10k

#80
post #23

Earlier quoted context omitted.

You're essentially suggesting a Drake equation [1] equivalent for the number of security vulnerabilities based on NLoC. What other factors would be part of this equation? [1] https://en.wikipedia.org/wiki/Drake_equation

How close to the Balmer peak the programmer was when he wrote the code.

Correlated or inversely correlated?
Post reply on HN