Live data from Hacker News

Leaking the email of any YouTube user for $10k

brutecat.com

111–120 of 487 posts

Re: Leaking the email of any YouTube user for $10k

#111
post #29

Is it me or are all the dates in this timeline in the future? Isn’t it Feb 2025 now? Do you smell toast? EDIT: oh I see .. DD/MM/YY is a new one to me

MM/DD/YY is an exclusively American standard https://en.wikipedia.org/wiki/List_of_date_formats_by_countr... I have no idea why America settled on MM/DD/YY, which seems like absolutely the least intuitive permutation of D, M, and Y. Except perhaps MYD.

For a person born and raised in metric system, MM/DD/YY is just as bonkers as if someone decided that MM:HH:SS makes sense.

Re: Leaking the email of any YouTube user for $10k

#112
post #26

Earlier quoted context omitted.

They really aren't shy about massive breaking changes. I'm still upset about Google Reader. https://killedbygoogle.com/

I remember being upset about Google Reader for a few months after its death… before moving to one of its many, fuller-featured competitors and carrying on using RSS feeds exactly as before. What upsets me re RSS these days is how many people were apparently so reliant on one reader that they still publicly mourn every time it comes up, 12 years later. Who are these fair-weather feed followers who threw their hands in…

Killing Google Reader killed blogs. You personally can replace Google Reader as a product, but since most people didn't and just sort of moved on to closed platforms, there was less content produced on blogs and less discussion activity on the blog posts that were created after.

Re: Leaking the email of any YouTube user for $10k

#113
post #77

Earlier quoted context omitted.

You’re significantly underestimating the value of dox-style exploits. Author could have partnered with a black hat vendor who would offer (for example) $25 per lookup. Or they could’ve done bulk scraping of YouTube channels to get emails and sold the dataset. It requires some legwork but they could’ve seen somewhere in the ballpark of 6 figures over 1 year if the exploit wasn’t patched. Oh, and if they had no ethics.

Does that black-hat vendor already exist? Do they already sell the service of taking $25 to unmask Google users? What calculation does that vendor do about how many customers they'll get before Google notices? Does the exploit developer get a 50% cut? The black-hat vendor is taking all the risk; seems unlikely. Arranging this whole thing is work; finding the "black hat vendor" is work; not getting caught in the proce…

> not getting caught in the process is work

Caught for what? If someone sells information about a vulnerability, what law are they breaking? In most jurisdictions, unless you're dumb enough to ask questions about whom your selling to and have active knowledge you're assisting someone in breaking some law, selling to the black market is perfectly legal, at least so long as you pay your taxes.

If you're doing grey market, it's even more legal. If a dictatorship wants to unmask a critic for assassination, and one is selling this information to a government security agency, it's legal by definition.

Re: Leaking the email of any YouTube user for $10k

#114

> Some time ago, I was looking for a research target in Google and was digging through the Internal People API (Staging) discovery document Should... should this just be public: https://staging-people-pa.sandbox.googleapis.com/$discovery/...

It's just an automatically translated schema file from their internal .proto definition. Google relies on real cryptography not security through obscurity.

Furthermore the discovery endpoint is publicly documented[0] and specifically meant for external users. Nobody internal would read the discovery endpoint: they would just pull up the .proto file through code search.

Another observation: from my experience at Google it took multiple weeks of effort fighting against the bureaucracy to be able to expose an API to the public. It's not like an AWS S3 bucket that could just be accidentally public. The team knew this is public and had fought the bureaucracy to make it public.

[0]: https://developers.google.com/discovery/v1/getting_started

Re: Leaking the email of any YouTube user for $10k

#115
post #103
post #49

Earlier quoted context omitted.

$10k is not a decent sum. The compensation reflects roughly 0.25-3 weeks of SWE costs in payout. Industry-wide SWE compensation is somewhere in the $100k-$200k range. Typical Google SWE compensation is $350k. Top Google SWE salary is north of $1M. Increase by 60-100% for overhead, or somewhat more for consulting overhead. The amount of work doing something like this is orders of magnitude more than the compensation:…

Bug bounty payouts are not effort based. It does not matter how much time it took the discoverer to find the vulnerability. So discussing the amount of work involved is irrelevant; it's not like the kindergarten level "oh you tried so there's a consolation prize for effort". Comparing it against the fixed rate salary of a SWE is even more wrong, except that your argument shows it is more profitable for a hypothetical…

Unless you can stumble on Google vulnerabilities casually, it's showing quite the opposite -- how unprofitable it is to work from bug bounties.

Re: Leaking the email of any YouTube user for $10k

#116
post #97

Earlier quoted context omitted.

>Unmasking Google accounts? Could there be a business there? Sure, maybe. Is there one already? Presumably no. Absolutely, yes. Spam and targeted phishing attacks are in high demand. My understanding is that it is possible to retrieve every public youtube channel ID, if not also Google Maps/Play reviewers, quite easily. This exploit could have been used to create a massive near-complete database of every Google accou…

But then what? Given the number of accounts Google has, odds are that nearly every alphanumeric combo less than 8 or 10 characters plus “@gmail.com” is a google account. This vulnerability gets you other domains, but still not seeing it. Massive databases of email addresses are a dime a dozen. The only angle I can imagine is phishing for high profile creators, and at most this is a “makes it easier” and not a “create…

The back of an envelope can get you making silly claims quickly (ex. 26 ^ 8 is 208 billion)

Re: Leaking the email of any YouTube user for $10k

#117
post #29

Is it me or are all the dates in this timeline in the future? Isn’t it Feb 2025 now? Do you smell toast? EDIT: oh I see .. DD/MM/YY is a new one to me

MM/DD/YY is an exclusively American standard https://en.wikipedia.org/wiki/List_of_date_formats_by_countr... I have no idea why America settled on MM/DD/YY, which seems like absolutely the least intuitive permutation of D, M, and Y. Except perhaps MYD.

I've always thought it was because we say:

February Twelfth Two Thousand and Twenty Five

Feb 12 2025

02/12/2025

I know it's cool for Europeans ... and everyone else to hate on us for it but it does seem to make sense given the way we typically say the date.

Re: Leaking the email of any YouTube user for $10k

#118
post #110
post #59

Earlier quoted context omitted.

It's an extraordinarily high sum for this kind of finding. Bounties are generally not a referendum on how clever the underlying work is. A full-chain iOS bug is worth hundreds of thousands of dollars because Apple competes with the grey market for it (and even then, it's an apples-oranges comparison and Apple pays substantially less than the rest of the market for structural reasons). Nobody competes for this bug; no…

My commentary was precisely about the state-of-the-practice. That $10k is "an extraordinarily high sum for" what was likely weeks of work on this bug, and probably months of work poking in other places, reflects the very, very low focus on security industry-wide. This is why we need significant civil -- or possibly occasionally criminal -- liability. Civil if it's simple negligence, and criminal if it's gross neglige…

Google pays a piece rate. They pay the rate the market will bear, unless you impress them, like these people did, and then they pay a bit more. They do not compensate you for your working hours.

Google is not going to pay you $200 if they leak your email address.

Google pays as much attention to security as Apple does.

If you want a world in which these kinds of security bugs create multimillion-dollar liabilities, you can advocate for the new statutes that will create that world; just be aware that only companies like Google will be able to afford to operate in that world.

Re: Leaking the email of any YouTube user for $10k

#119
post #45
post #6

This is a puny payout IMO. If they poked around a bit more they may have found a better GAIA->Email vulnerability or perhaps could just use the one they found. A database of emails for every major youtube channel would be worth an awful lot.

Think this is puny — I found the ability to reveal emails in npmjs.org but as it hadn't been included in the new GitHub/Microsoft bug bounty scope yet, I was given a t-shirt and $1000. Talk about puny!

in an old company of mine they started an intranet but if you opened it as http instead of https you'd see raw codes inclusive sql passwords and everything ; i reported to them, to which they replied "yeah just open it with https like everyone else"
Post reply on HN