Live data from Hacker News

Leaking the email of any YouTube user for $10k

brutecat.com

81–90 of 487 posts

Re: Leaking the email of any YouTube user for $10k

#82
post #72
post #26

Earlier quoted context omitted.

They really aren't shy about massive breaking changes. I'm still upset about Google Reader. https://killedbygoogle.com/

I didn't use Reader. What was so special about it? Iirc it was an RSS aggregator, which sounds pretty simple to replace. Nobody has an open source equivalent?

There wasn't an equivalent when it was deprecated. It downloaded the contents and they were archived in your account.

https://news.ycombinator.com/item?id=5371982

Re: Leaking the email of any YouTube user for $10k

#83
post #26

Earlier quoted context omitted.

Unfortunately with the number of users Google has, any deprecation will be met with cries of pain / I-rely-on-the-spacebar-to-heat-up-my-computer. See https://killedbygoogle.com/ .

They really aren't shy about massive breaking changes. I'm still upset about Google Reader. https://killedbygoogle.com/

I'm still upset about the "I've Got A Bad Feeling About This" button.

https://www.youtube.com/watch?v=4Z4RKRLaSug

Re: Leaking the email of any YouTube user for $10k

#84
post #45
post #6

This is a puny payout IMO. If they poked around a bit more they may have found a better GAIA->Email vulnerability or perhaps could just use the one they found. A database of emails for every major youtube channel would be worth an awful lot.

Think this is puny — I found the ability to reveal emails in npmjs.org but as it hadn't been included in the new GitHub/Microsoft bug bounty scope yet, I was given a t-shirt and $1000. Talk about puny!

I was able to run JavaScript inside an email in the GMail app on Android (it required the user tap within the email body). I only got a Nexus 7 tablet.

Re: Leaking the email of any YouTube user for $10k

#85
post #59
post #49

Earlier quoted context omitted.

$10k is not a decent sum. The compensation reflects roughly 0.25-3 weeks of SWE costs in payout. Industry-wide SWE compensation is somewhere in the $100k-$200k range. Typical Google SWE compensation is $350k. Top Google SWE salary is north of $1M. Increase by 60-100% for overhead, or somewhat more for consulting overhead. The amount of work doing something like this is orders of magnitude more than the compensation:…

It's an extraordinarily high sum for this kind of finding. Bounties are generally not a referendum on how clever the underlying work is. A full-chain iOS bug is worth hundreds of thousands of dollars because Apple competes with the grey market for it (and even then, it's an apples-oranges comparison and Apple pays substantially less than the rest of the market for structural reasons). Nobody competes for this bug; no…

Just because companies are paying X doesn't mean that X isn't a low sum.

Calling 10k an "extraordinarily high sum" is accurate to some and inaccurate to others.

I would bet the groups would differ by perceived personal cost more than the opinion of Google, Apple, and the like. These groups would also probably show distinction where people have been victimized by "identity theft."

The opinions of those bearing the cost are more important here, in my opinion.

Re: Leaking the email of any YouTube user for $10k

#86
post #26

Earlier quoted context omitted.

They really aren't shy about massive breaking changes. I'm still upset about Google Reader. https://killedbygoogle.com/

I remember being upset about Google Reader for a few months after its death… before moving to one of its many, fuller-featured competitors and carrying on using RSS feeds exactly as before. What upsets me re RSS these days is how many people were apparently so reliant on one reader that they still publicly mourn every time it comes up, 12 years later. Who are these fair-weather feed followers who threw their hands in…

GR had some primitive social features that none of the competitors, as far as I know, could replicate. Side-effect of being the largest. Even an exact clone wouldn't behave the same. It was the core of the blogging ecosystem, and IMO its removal was the main cause of blogging falling apart.

All so they could clear the way for Google Plus. And look how that turned out.

So yeah, watershed moment, the point where the scales fell from my eyes, still justifiably pissed, fool me twice, etc etc etc

(Still using RSS daily, though I lapsed for a while).

Re: Leaking the email of any YouTube user for $10k

#87

Breaking the email system so that it's not sent is the cherry on top. With companies as big as Google who have developed so many products, "security" feels fake. If every line of code is a possible vulnerability, with millions it's just inevitable. It feels like the only way is to keep things simple (e.g., deprecate the recorder site), but even then.

I would challenge you to give me examples where security feels "real" and how does that help.

Most software products rely on very complex software stacks, and if you trust 100% all the libraries and the OS you use I would say it's a wrong mindset. There were bugs even in the processor (meltdown). Security is a continuous battle and you never know if you won, only (sometimes) if you loose.

Re: Leaking the email of any YouTube user for $10k

#88
post #70
post #61

Earlier quoted context omitted.

The point is: security is fake. No app is truly secure. You can spend millions on app security and all it takes to breach that is one slip up of a human user.

I'd take away "security is complicated and multi-faceted", not "fake". It's not a black and white of "an app is truly secure" or "an app is truly insecure", but rather a continuum from "secure enough in practice for this threat model and purpose" to "an insecure mess". Like, plenty of websites and apps have launched, existed for years, and then shutdown without a single security incident. In those cases, surely the a…

Im just saying that all it takes is one employee to click onto the wrong URL to breach your apps security. I am not talking about the app itself. You can have all the security implemented the world has to offer and yet you cant get rid of human errors.

Re: Leaking the email of any YouTube user for $10k

#89
post #26

Earlier quoted context omitted.

They really aren't shy about massive breaking changes. I'm still upset about Google Reader. https://killedbygoogle.com/

I remember being upset about Google Reader for a few months after its death… before moving to one of its many, fuller-featured competitors and carrying on using RSS feeds exactly as before. What upsets me re RSS these days is how many people were apparently so reliant on one reader that they still publicly mourn every time it comes up, 12 years later. Who are these fair-weather feed followers who threw their hands in…

There still is no replacement for Google Reader. The difference is that there was a community around Reader’s social features. That only really works with wide adoption, and it’s a lot easier for people to adopt a Google product than a random company x one. Today, there are many replacements with the mechanical features of browsing & sync, but the community will never come back.

The other problem was that Google killing Reader was a signal to the broader web to move away from RSS. RSS has kind of limped along since then.

Re: Leaking the email of any YouTube user for $10k

#90
post #26

Earlier quoted context omitted.

Unfortunately with the number of users Google has, any deprecation will be met with cries of pain / I-rely-on-the-spacebar-to-heat-up-my-computer. See https://killedbygoogle.com/ .

They really aren't shy about massive breaking changes. I'm still upset about Google Reader. https://killedbygoogle.com/

I realized I was reading too many websites and decided to switch to RSS, only to find out that Google had killed Reader a month earlier.

Years later, I came across Artifact, created by the founders of Instagram, and thought it was an interesting idea. The problem was I was reading its shutdown announcement.

Sometimes I think products are killed way too early. Look at twitch, it boomed after years of stagnation.

Post reply on HN