Live data from Hacker News

Leaking the email of any YouTube user for $10k

brutecat.com

121–130 of 487 posts

Re: Leaking the email of any YouTube user for $10k

#121
post #113
post #77

Earlier quoted context omitted.

Does that black-hat vendor already exist? Do they already sell the service of taking $25 to unmask Google users? What calculation does that vendor do about how many customers they'll get before Google notices? Does the exploit developer get a 50% cut? The black-hat vendor is taking all the risk; seems unlikely. Arranging this whole thing is work; finding the "black hat vendor" is work; not getting caught in the proce…

> not getting caught in the process is work Caught for what? If someone sells information about a vulnerability, what law are they breaking? In most jurisdictions, unless you're dumb enough to ask questions about whom your selling to and have active knowledge you're assisting someone in breaking some law, selling to the black market is perfectly legal, at least so long as you pay your taxes. If you're doing grey mark…

If you sell information about a vulnerability to someone that you know specifically is going to use it to break the law, you are an accessory to that lawbreaking. Ask Stephen Watt how this plays out.

Re: Leaking the email of any YouTube user for $10k

#122

Earlier quoted context omitted.

But then what? Given the number of accounts Google has, odds are that nearly every alphanumeric combo less than 8 or 10 characters plus “@gmail.com” is a google account. This vulnerability gets you other domains, but still not seeing it. Massive databases of email addresses are a dime a dozen. The only angle I can imagine is phishing for high profile creators, and at most this is a “makes it easier” and not a “create…

The back of an envelope can get you making silly claims quickly (ex. 26 ^ 8 is 208 billion)

I think you might be off by a factor of 10. Alphanumeric would be at least 36 characters, which would imply 2.8 trillion combininations (36 ^ 8).

Re: Leaking the email of any YouTube user for $10k

#123
post #78

Earlier quoted context omitted.

That's probably another reason why Google kills so many products that are successful, but not successful enough for Google's whole system to justify keeping them alive and secure.

100%. Every product not a part of the core mission is attack surface area, ongoing maintenance to ensure it works with the rest of Google services and infra, and drag on the rest of the team and velocity. The part that sucks for consumers is that they often kill things that people like. I wish they had a better way of doing this. Bravo to brutecat for this excellent discovery, productionization, and writeup.

They could spin these products off into separate companies and cut the integration with the rest of the Google ecosystem.

Re: Leaking the email of any YouTube user for $10k

#124
post #97

Earlier quoted context omitted.

>Unmasking Google accounts? Could there be a business there? Sure, maybe. Is there one already? Presumably no. Absolutely, yes. Spam and targeted phishing attacks are in high demand. My understanding is that it is possible to retrieve every public youtube channel ID, if not also Google Maps/Play reviewers, quite easily. This exploit could have been used to create a massive near-complete database of every Google accou…

And then what? Exploits need to plug into a business plan. Like any business plan there has to be somewhere that money gets extracted and that money needs to be more than the exploit cost & infrastructure costs & a risk premium. If you can’t trivially say how the exploit explicitly gets turned into cash you probably are on the wrong track. Doubly so if it’s not a known standard and commoditized way that’s happened be…

There is often phishing campaigns targeting larger channels on YT, trying to trick someone with access to it into opening malicious e-mail attachments, with the end-goal of taking over the channel. Usually the attackers then put a livestream on it and push some crypto scam. It must make enough money, given that it keeps happening.

Most recent example I've seen: https://www.youtube.com/watch?v=EnVxWK6DfMQ

Re: Leaking the email of any YouTube user for $10k

#125
post #49

Very nice breakdown. But while 10,000 dollars seems like a decent sum, I expected more for a bug of this severity, if I'm being honest. Especially as they initially only awarded 3100. But I'm not sure how much is usual for such cases. Almost 150 days also seems kind of a long time for fixing it imho.

$10k is not a decent sum. The compensation reflects roughly 0.25-3 weeks of SWE costs in payout. Industry-wide SWE compensation is somewhere in the $100k-$200k range. Typical Google SWE compensation is $350k. Top Google SWE salary is north of $1M. Increase by 60-100% for overhead, or somewhat more for consulting overhead. The amount of work doing something like this is orders of magnitude more than the compensation:…

salary and compensation are not synonyms, you used them interchangeably

Re: Leaking the email of any YouTube user for $10k

#126

Earlier quoted context omitted.

100%. Every product not a part of the core mission is attack surface area, ongoing maintenance to ensure it works with the rest of Google services and infra, and drag on the rest of the team and velocity. The part that sucks for consumers is that they often kill things that people like. I wish they had a better way of doing this. Bravo to brutecat for this excellent discovery, productionization, and writeup.

They could spin these products off into separate companies and cut the integration with the rest of the Google ecosystem.

Probably way too much effort. The apps aren't built for generic infra, but rather Google's internal weirdware. It wouldn't be possible to run it anywhere else without a rewrite.

Re: Leaking the email of any YouTube user for $10k

#127
post #97
post #73

Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…

>Unmasking Google accounts? Could there be a business there? Sure, maybe. Is there one already? Presumably no. Absolutely, yes. Spam and targeted phishing attacks are in high demand. My understanding is that it is possible to retrieve every public youtube channel ID, if not also Google Maps/Play reviewers, quite easily. This exploit could have been used to create a massive near-complete database of every Google accou…

Honestly, that leaves straight up harassment of YouTubers by other YouTubers and fans off the table which by itself would motivate a few of them. Some of the same people who play in the black and grey hat worlds are the same people buying DDOS attacks and swatting streamers. They would have a party with their emails.

Re: Leaking the email of any YouTube user for $10k

#128
post #110
post #59

Earlier quoted context omitted.

It's an extraordinarily high sum for this kind of finding. Bounties are generally not a referendum on how clever the underlying work is. A full-chain iOS bug is worth hundreds of thousands of dollars because Apple competes with the grey market for it (and even then, it's an apples-oranges comparison and Apple pays substantially less than the rest of the market for structural reasons). Nobody competes for this bug; no…

My commentary was precisely about the state-of-the-practice. That $10k is "an extraordinarily high sum for" what was likely weeks of work on this bug, and probably months of work poking in other places, reflects the very, very low focus on security industry-wide. This is why we need significant civil -- or possibly occasionally criminal -- liability. Civil if it's simple negligence, and criminal if it's gross neglige…

I think you're looking at this wrong.

Security is hard. Incredibly hard. Unlike most things in business which are positive-sum, security isn't - it's adversarial. If we make companies pay huge civil fines for things that are so hard to protect against, we're stifling a ton of innovation.

I usually analogize a large company to a bank. A bank is supposed to keep your money secure, and for sure you'd have a legitimate beef if a bank robber could waltz in and steal your money easily because it's not kept in a vault.

But what if it is kept in a vault? What if the bank isn't attacked by a random group of bank robbers, but rather by the armed forces of a hostile nation? We don't expect banks to protect against armies - that's what we have states for! They provide centralized protection against threats that are far too large for any individual entity to take on by themselves.

This is the same, albeit out of sight, situation with large companies. You can have thousands, tens of thousands of people around the world poking at everything your company does for years, looking for any vulnerability. No company can truly withstand that kind of scrutiny - and I don't think making civil penalties higher will change that. And on top of criminal or opportunistic actors, companies also have to be worried about state actors too.

The only way is for the state to take on an active role in security. I don't see any other way that gets real security for anyone.

Re: Leaking the email of any YouTube user for $10k

#130
post #115
post #103

Earlier quoted context omitted.

Bug bounty payouts are not effort based. It does not matter how much time it took the discoverer to find the vulnerability. So discussing the amount of work involved is irrelevant; it's not like the kindergarten level "oh you tried so there's a consolation prize for effort". Comparing it against the fixed rate salary of a SWE is even more wrong, except that your argument shows it is more profitable for a hypothetical…

Unless you can stumble on Google vulnerabilities casually, it's showing quite the opposite -- how unprofitable it is to work from bug bounties.

It's not the opposite. We are in fact not disagreeing. It's unprofitable to work from bug bounties. It is better off for the person to become an internal red teamer.
Post reply on HN