Live data from Hacker News

Leaking the email of any YouTube user for $10k

brutecat.com

101–110 of 487 posts

Re: Leaking the email of any YouTube user for $10k

#101
post #95
post #73

Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…

Also, Google can monitor the grey/black market and buy these exploits under false identities. For less urgent vulnerabilities (such as the YT email hack), this severely caps the bounty size.

My guess was that people selling vulnerabilities generally know who they’re selling to. Is there a big market for people selling exploits to unknown/anonymous customers?

Re: Leaking the email of any YouTube user for $10k

#102
post #64
post #45

Earlier quoted context omitted.

Think this is puny — I found the ability to reveal emails in npmjs.org but as it hadn't been included in the new GitHub/Microsoft bug bounty scope yet, I was given a t-shirt and $1000. Talk about puny!

I think this is puny: I was able to take over accounts on a cybersecurity platform just by knowing their account email and was only paid $200

Do you mind sharing which platform?

Re: Leaking the email of any YouTube user for $10k

#103
post #49

Very nice breakdown. But while 10,000 dollars seems like a decent sum, I expected more for a bug of this severity, if I'm being honest. Especially as they initially only awarded 3100. But I'm not sure how much is usual for such cases. Almost 150 days also seems kind of a long time for fixing it imho.

$10k is not a decent sum. The compensation reflects roughly 0.25-3 weeks of SWE costs in payout. Industry-wide SWE compensation is somewhere in the $100k-$200k range. Typical Google SWE compensation is $350k. Top Google SWE salary is north of $1M. Increase by 60-100% for overhead, or somewhat more for consulting overhead. The amount of work doing something like this is orders of magnitude more than the compensation:…

Bug bounty payouts are not effort based. It does not matter how much time it took the discoverer to find the vulnerability. So discussing the amount of work involved is irrelevant; it's not like the kindergarten level "oh you tried so there's a consolation prize for effort". Comparing it against the fixed rate salary of a SWE is even more wrong, except that your argument shows it is more profitable for a hypothetical person relying on bug bounty income to instead join Google as an internal red teamer.

The other comment has already addressed the market value question.

Re: Leaking the email of any YouTube user for $10k

#104
post #97
post #73

Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…

>Unmasking Google accounts? Could there be a business there? Sure, maybe. Is there one already? Presumably no. Absolutely, yes. Spam and targeted phishing attacks are in high demand. My understanding is that it is possible to retrieve every public youtube channel ID, if not also Google Maps/Play reviewers, quite easily. This exploit could have been used to create a massive near-complete database of every Google accou…

But then what? Given the number of accounts Google has, odds are that nearly every alphanumeric combo less than 8 or 10 characters plus “@gmail.com” is a google account. This vulnerability gets you other domains, but still not seeing it. Massive databases of email addresses are a dime a dozen.

The only angle I can imagine is phishing for high profile creators, and at most this is a “makes it easier” and not a “creates the problem” bug.

Re: Leaking the email of any YouTube user for $10k

#105
post #90
post #26

Earlier quoted context omitted.

They really aren't shy about massive breaking changes. I'm still upset about Google Reader. https://killedbygoogle.com/

I realized I was reading too many websites and decided to switch to RSS, only to find out that Google had killed Reader a month earlier. Years later, I came across Artifact, created by the founders of Instagram, and thought it was an interesting idea. The problem was I was reading its shutdown announcement. Sometimes I think products are killed way too early. Look at twitch, it boomed after years of stagnation.

Twitch has found some not-amazing niches to bulk up its revenue. A service needs to be profitable to work, and I don't think anyone wanted to pay for RSS. Or not enough.

Re: Leaking the email of any YouTube user for $10k

#106
post #72
post #26

Earlier quoted context omitted.

They really aren't shy about massive breaking changes. I'm still upset about Google Reader. https://killedbygoogle.com/

I didn't use Reader. What was so special about it? Iirc it was an RSS aggregator, which sounds pretty simple to replace. Nobody has an open source equivalent?

See: https://news.ycombinator.com/item?id=5371725

Re: Leaking the email of any YouTube user for $10k

#107
post #97
post #73

Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…

>Unmasking Google accounts? Could there be a business there? Sure, maybe. Is there one already? Presumably no. Absolutely, yes. Spam and targeted phishing attacks are in high demand. My understanding is that it is possible to retrieve every public youtube channel ID, if not also Google Maps/Play reviewers, quite easily. This exploit could have been used to create a massive near-complete database of every Google accou…

And then what?

Exploits need to plug into a business plan. Like any business plan there has to be somewhere that money gets extracted and that money needs to be more than the exploit cost & infrastructure costs & a risk premium.

If you can’t trivially say how the exploit explicitly gets turned into cash you probably are on the wrong track. Doubly so if it’s not a known standard and commoditized way that’s happened before.

Re: Leaking the email of any YouTube user for $10k

#108
post #78

Breaking the email system so that it's not sent is the cherry on top. With companies as big as Google who have developed so many products, "security" feels fake. If every line of code is a possible vulnerability, with millions it's just inevitable. It feels like the only way is to keep things simple (e.g., deprecate the recorder site), but even then.

That's probably another reason why Google kills so many products that are successful, but not successful enough for Google's whole system to justify keeping them alive and secure.

100%. Every product not a part of the core mission is attack surface area, ongoing maintenance to ensure it works with the rest of Google services and infra, and drag on the rest of the team and velocity.

The part that sucks for consumers is that they often kill things that people like. I wish they had a better way of doing this.

Bravo to brutecat for this excellent discovery, productionization, and writeup.

Re: Leaking the email of any YouTube user for $10k

#109
post #95

Earlier quoted context omitted.

Also, Google can monitor the grey/black market and buy these exploits under false identities. For less urgent vulnerabilities (such as the YT email hack), this severely caps the bounty size.

My guess was that people selling vulnerabilities generally know who they’re selling to. Is there a big market for people selling exploits to unknown/anonymous customers?

It's a pretty big part of most black markets that vendors don't ask too many questions about the buyer.

Do you really want to know what the FSB plans to do with your exploit?

Re: Leaking the email of any YouTube user for $10k

#110
post #59
post #49

Earlier quoted context omitted.

$10k is not a decent sum. The compensation reflects roughly 0.25-3 weeks of SWE costs in payout. Industry-wide SWE compensation is somewhere in the $100k-$200k range. Typical Google SWE compensation is $350k. Top Google SWE salary is north of $1M. Increase by 60-100% for overhead, or somewhat more for consulting overhead. The amount of work doing something like this is orders of magnitude more than the compensation:…

It's an extraordinarily high sum for this kind of finding. Bounties are generally not a referendum on how clever the underlying work is. A full-chain iOS bug is worth hundreds of thousands of dollars because Apple competes with the grey market for it (and even then, it's an apples-oranges comparison and Apple pays substantially less than the rest of the market for structural reasons). Nobody competes for this bug; no…

My commentary was precisely about the state-of-the-practice.

That $10k is "an extraordinarily high sum for" what was likely weeks of work on this bug, and probably months of work poking in other places, reflects the very, very low focus on security industry-wide. This is why we need significant civil -- or possibly occasionally criminal -- liability. Civil if it's simple negligence, and criminal if it's gross negligence leading to harm.

If Google were to pay me $200 if it leaked my data, that would:

- Be worth much less than my privacy

- Amount to damages of $400B worldwide if there were a compromise impacting all $2B users (although, realistically, damages would be lower in middle and low income countries)

This would represent a 20% fall in Google's market cap, which feels about right.

At that point, I expect the bug bounties would be set many orders of magnitude higher. Security bugs should be rare. They're common. This is a problem, and one created by our market incentive structures.

You are correct that Apple is an exception, and seems to mind security.

Post reply on HN