Is it me or are all the dates in this timeline in the future? Isn’t it Feb 2025 now? Do you smell toast? EDIT: oh I see .. DD/MM/YY is a new one to me
MM/DD/YY is an exclusively American standard https://en.wikipedia.org/wiki/List_of_date_formats_by_countr... I have no idea why America settled on MM/DD/YY, which seems like absolutely the least intuitive permutation of D, M, and Y. Except perhaps MYD.
Leaking the email of any YouTube user for $10k
111–120 of 487 posts
Re: Leaking the email of any YouTube user for $10k
#112Earlier quoted context omitted.
They really aren't shy about massive breaking changes. I'm still upset about Google Reader. https://killedbygoogle.com/
I remember being upset about Google Reader for a few months after its death… before moving to one of its many, fuller-featured competitors and carrying on using RSS feeds exactly as before. What upsets me re RSS these days is how many people were apparently so reliant on one reader that they still publicly mourn every time it comes up, 12 years later. Who are these fair-weather feed followers who threw their hands in…
Re: Leaking the email of any YouTube user for $10k
#113Earlier quoted context omitted.
You’re significantly underestimating the value of dox-style exploits. Author could have partnered with a black hat vendor who would offer (for example) $25 per lookup. Or they could’ve done bulk scraping of YouTube channels to get emails and sold the dataset. It requires some legwork but they could’ve seen somewhere in the ballpark of 6 figures over 1 year if the exploit wasn’t patched. Oh, and if they had no ethics.
Does that black-hat vendor already exist? Do they already sell the service of taking $25 to unmask Google users? What calculation does that vendor do about how many customers they'll get before Google notices? Does the exploit developer get a 50% cut? The black-hat vendor is taking all the risk; seems unlikely. Arranging this whole thing is work; finding the "black hat vendor" is work; not getting caught in the proce…
Caught for what? If someone sells information about a vulnerability, what law are they breaking? In most jurisdictions, unless you're dumb enough to ask questions about whom your selling to and have active knowledge you're assisting someone in breaking some law, selling to the black market is perfectly legal, at least so long as you pay your taxes.
If you're doing grey market, it's even more legal. If a dictatorship wants to unmask a critic for assassination, and one is selling this information to a government security agency, it's legal by definition.
Re: Leaking the email of any YouTube user for $10k
#114> Some time ago, I was looking for a research target in Google and was digging through the Internal People API (Staging) discovery document Should... should this just be public: https://staging-people-pa.sandbox.googleapis.com/$discovery/...
Furthermore the discovery endpoint is publicly documented[0] and specifically meant for external users. Nobody internal would read the discovery endpoint: they would just pull up the .proto file through code search.
Another observation: from my experience at Google it took multiple weeks of effort fighting against the bureaucracy to be able to expose an API to the public. It's not like an AWS S3 bucket that could just be accidentally public. The team knew this is public and had fought the bureaucracy to make it public.
[0]: https://developers.google.com/discovery/v1/getting_started
Re: Leaking the email of any YouTube user for $10k
#115Earlier quoted context omitted.
$10k is not a decent sum. The compensation reflects roughly 0.25-3 weeks of SWE costs in payout. Industry-wide SWE compensation is somewhere in the $100k-$200k range. Typical Google SWE compensation is $350k. Top Google SWE salary is north of $1M. Increase by 60-100% for overhead, or somewhat more for consulting overhead. The amount of work doing something like this is orders of magnitude more than the compensation:…
Bug bounty payouts are not effort based. It does not matter how much time it took the discoverer to find the vulnerability. So discussing the amount of work involved is irrelevant; it's not like the kindergarten level "oh you tried so there's a consolation prize for effort". Comparing it against the fixed rate salary of a SWE is even more wrong, except that your argument shows it is more profitable for a hypothetical…
Re: Leaking the email of any YouTube user for $10k
#116Earlier quoted context omitted.
>Unmasking Google accounts? Could there be a business there? Sure, maybe. Is there one already? Presumably no. Absolutely, yes. Spam and targeted phishing attacks are in high demand. My understanding is that it is possible to retrieve every public youtube channel ID, if not also Google Maps/Play reviewers, quite easily. This exploit could have been used to create a massive near-complete database of every Google accou…
But then what? Given the number of accounts Google has, odds are that nearly every alphanumeric combo less than 8 or 10 characters plus “@gmail.com” is a google account. This vulnerability gets you other domains, but still not seeing it. Massive databases of email addresses are a dime a dozen. The only angle I can imagine is phishing for high profile creators, and at most this is a “makes it easier” and not a “create…
Re: Leaking the email of any YouTube user for $10k
#117Is it me or are all the dates in this timeline in the future? Isn’t it Feb 2025 now? Do you smell toast? EDIT: oh I see .. DD/MM/YY is a new one to me
MM/DD/YY is an exclusively American standard https://en.wikipedia.org/wiki/List_of_date_formats_by_countr... I have no idea why America settled on MM/DD/YY, which seems like absolutely the least intuitive permutation of D, M, and Y. Except perhaps MYD.
February Twelfth Two Thousand and Twenty Five
Feb 12 2025
02/12/2025
I know it's cool for Europeans ... and everyone else to hate on us for it but it does seem to make sense given the way we typically say the date.
Re: Leaking the email of any YouTube user for $10k
#118Earlier quoted context omitted.
It's an extraordinarily high sum for this kind of finding. Bounties are generally not a referendum on how clever the underlying work is. A full-chain iOS bug is worth hundreds of thousands of dollars because Apple competes with the grey market for it (and even then, it's an apples-oranges comparison and Apple pays substantially less than the rest of the market for structural reasons). Nobody competes for this bug; no…
My commentary was precisely about the state-of-the-practice. That $10k is "an extraordinarily high sum for" what was likely weeks of work on this bug, and probably months of work poking in other places, reflects the very, very low focus on security industry-wide. This is why we need significant civil -- or possibly occasionally criminal -- liability. Civil if it's simple negligence, and criminal if it's gross neglige…
Google is not going to pay you $200 if they leak your email address.
Google pays as much attention to security as Apple does.
If you want a world in which these kinds of security bugs create multimillion-dollar liabilities, you can advocate for the new statutes that will create that world; just be aware that only companies like Google will be able to afford to operate in that world.
Re: Leaking the email of any YouTube user for $10k
#119This is a puny payout IMO. If they poked around a bit more they may have found a better GAIA->Email vulnerability or perhaps could just use the one they found. A database of emails for every major youtube channel would be worth an awful lot.
Think this is puny — I found the ability to reveal emails in npmjs.org but as it hadn't been included in the new GitHub/Microsoft bug bounty scope yet, I was given a t-shirt and $1000. Talk about puny!