Leaking the email of any YouTube user for $10k
81–90 of 487 posts
Re: Leaking the email of any YouTube user for $10k
#82Earlier quoted context omitted.
They really aren't shy about massive breaking changes. I'm still upset about Google Reader. https://killedbygoogle.com/
I didn't use Reader. What was so special about it? Iirc it was an RSS aggregator, which sounds pretty simple to replace. Nobody has an open source equivalent?
Re: Leaking the email of any YouTube user for $10k
#83Earlier quoted context omitted.
Unfortunately with the number of users Google has, any deprecation will be met with cries of pain / I-rely-on-the-spacebar-to-heat-up-my-computer. See https://killedbygoogle.com/ .
They really aren't shy about massive breaking changes. I'm still upset about Google Reader. https://killedbygoogle.com/
Re: Leaking the email of any YouTube user for $10k
#84This is a puny payout IMO. If they poked around a bit more they may have found a better GAIA->Email vulnerability or perhaps could just use the one they found. A database of emails for every major youtube channel would be worth an awful lot.
Think this is puny — I found the ability to reveal emails in npmjs.org but as it hadn't been included in the new GitHub/Microsoft bug bounty scope yet, I was given a t-shirt and $1000. Talk about puny!
Re: Leaking the email of any YouTube user for $10k
#85Earlier quoted context omitted.
$10k is not a decent sum. The compensation reflects roughly 0.25-3 weeks of SWE costs in payout. Industry-wide SWE compensation is somewhere in the $100k-$200k range. Typical Google SWE compensation is $350k. Top Google SWE salary is north of $1M. Increase by 60-100% for overhead, or somewhat more for consulting overhead. The amount of work doing something like this is orders of magnitude more than the compensation:…
It's an extraordinarily high sum for this kind of finding. Bounties are generally not a referendum on how clever the underlying work is. A full-chain iOS bug is worth hundreds of thousands of dollars because Apple competes with the grey market for it (and even then, it's an apples-oranges comparison and Apple pays substantially less than the rest of the market for structural reasons). Nobody competes for this bug; no…
Calling 10k an "extraordinarily high sum" is accurate to some and inaccurate to others.
I would bet the groups would differ by perceived personal cost more than the opinion of Google, Apple, and the like. These groups would also probably show distinction where people have been victimized by "identity theft."
The opinions of those bearing the cost are more important here, in my opinion.
Re: Leaking the email of any YouTube user for $10k
#86Earlier quoted context omitted.
They really aren't shy about massive breaking changes. I'm still upset about Google Reader. https://killedbygoogle.com/
I remember being upset about Google Reader for a few months after its death… before moving to one of its many, fuller-featured competitors and carrying on using RSS feeds exactly as before. What upsets me re RSS these days is how many people were apparently so reliant on one reader that they still publicly mourn every time it comes up, 12 years later. Who are these fair-weather feed followers who threw their hands in…
All so they could clear the way for Google Plus. And look how that turned out.
So yeah, watershed moment, the point where the scales fell from my eyes, still justifiably pissed, fool me twice, etc etc etc
(Still using RSS daily, though I lapsed for a while).
Re: Leaking the email of any YouTube user for $10k
#87Breaking the email system so that it's not sent is the cherry on top. With companies as big as Google who have developed so many products, "security" feels fake. If every line of code is a possible vulnerability, with millions it's just inevitable. It feels like the only way is to keep things simple (e.g., deprecate the recorder site), but even then.
Most software products rely on very complex software stacks, and if you trust 100% all the libraries and the OS you use I would say it's a wrong mindset. There were bugs even in the processor (meltdown). Security is a continuous battle and you never know if you won, only (sometimes) if you loose.
Re: Leaking the email of any YouTube user for $10k
#88Earlier quoted context omitted.
The point is: security is fake. No app is truly secure. You can spend millions on app security and all it takes to breach that is one slip up of a human user.
I'd take away "security is complicated and multi-faceted", not "fake". It's not a black and white of "an app is truly secure" or "an app is truly insecure", but rather a continuum from "secure enough in practice for this threat model and purpose" to "an insecure mess". Like, plenty of websites and apps have launched, existed for years, and then shutdown without a single security incident. In those cases, surely the a…
Re: Leaking the email of any YouTube user for $10k
#89Earlier quoted context omitted.
They really aren't shy about massive breaking changes. I'm still upset about Google Reader. https://killedbygoogle.com/
I remember being upset about Google Reader for a few months after its death… before moving to one of its many, fuller-featured competitors and carrying on using RSS feeds exactly as before. What upsets me re RSS these days is how many people were apparently so reliant on one reader that they still publicly mourn every time it comes up, 12 years later. Who are these fair-weather feed followers who threw their hands in…
The other problem was that Google killing Reader was a signal to the broader web to move away from RSS. RSS has kind of limped along since then.
Re: Leaking the email of any YouTube user for $10k
#90Earlier quoted context omitted.
Unfortunately with the number of users Google has, any deprecation will be met with cries of pain / I-rely-on-the-spacebar-to-heat-up-my-computer. See https://killedbygoogle.com/ .
They really aren't shy about massive breaking changes. I'm still upset about Google Reader. https://killedbygoogle.com/
Years later, I came across Artifact, created by the founders of Instagram, and thought it was an interesting idea. The problem was I was reading its shutdown announcement.
Sometimes I think products are killed way too early. Look at twitch, it boomed after years of stagnation.