Live data from Hacker News

Leaking the email of any YouTube user for $10k

brutecat.com

141–150 of 487 posts

Re: Leaking the email of any YouTube user for $10k

#141
post #97

Earlier quoted context omitted.

>Unmasking Google accounts? Could there be a business there? Sure, maybe. Is there one already? Presumably no. Absolutely, yes. Spam and targeted phishing attacks are in high demand. My understanding is that it is possible to retrieve every public youtube channel ID, if not also Google Maps/Play reviewers, quite easily. This exploit could have been used to create a massive near-complete database of every Google accou…

Honestly, that leaves straight up harassment of YouTubers by other YouTubers and fans off the table which by itself would motivate a few of them. Some of the same people who play in the black and grey hat worlds are the same people buying DDOS attacks and swatting streamers. They would have a party with their emails.

> which by itself would motivate a few of them

Motivation in the abstract is not enough to counter GP's point—they have to have enough motivation that it's worth more than $10,000 to them and also have more than $10,000 to spend and also have the connections necessary to get in touch with someone who's able to sell a vulnerability like this and also be able to exploit it in a timely manner or at least think they can.

Re: Leaking the email of any YouTube user for $10k

#142

Is it me or are all the dates in this timeline in the future? Isn’t it Feb 2025 now? Do you smell toast? EDIT: oh I see .. DD/MM/YY is a new one to me

Day-Month-Year is the standard everywhere in the world apart from the US. Big and little endian dates are the only way that makes sense I think. Doing it the US way where day is inexplicably between year and month just feels corrupted to my mind.

> Day-Month-Year is the standard everywhere in the world apart from the US

Nope, the standards are day.month.year, year-month-day, or month/day/year. The problem happens when the delimiter doesn't match the ordering.

Re: Leaking the email of any YouTube user for $10k

#143

Earlier quoted context omitted.

The motivation isn't financial but the impact to some of Google's biggest earners would be significant. Never mind the PR when Mr Beast and SSSniperwolf's personal details leak online.

You mean, "mrbeastcompanyofficial@gmail.com"?

https://www.wired.com/story/youtube-bitcoin-scam-account-hij...

Re: Leaking the email of any YouTube user for $10k

#144
post #96
post #94

Earlier quoted context omitted.

I'm totally not understanding what you're saying then. > Im just saying that all it takes is one employee to click onto the wrong URL to breach your apps security Pretend I'm a signal employee. What link can I click that breaches the app's security? They don't store unencrypted data, pushing source code changes requires review, releases are signed and a single employee can't compromise the release process, so I'm mis…

Some malicious mail that grants remote access to the employees device? Its not that hard to understand.

Actually it is hard to understand because that employee's device isn't an attack vector.

Re: Leaking the email of any YouTube user for $10k

#145

I’d misunderstood the title to refer to $10k of GPU compute or something like that. Unfortunately I suspect there’ll be tens or hundreds of occurrences of this bug given that they just picked one old Google product and immediately found a hole.

I misunderstood it to mean they are selling any YouTuber’s email address for $10k

Re: Leaking the email of any YouTube user for $10k

#146
post #97
post #73

Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…

>Unmasking Google accounts? Could there be a business there? Sure, maybe. Is there one already? Presumably no. Absolutely, yes. Spam and targeted phishing attacks are in high demand. My understanding is that it is possible to retrieve every public youtube channel ID, if not also Google Maps/Play reviewers, quite easily. This exploit could have been used to create a massive near-complete database of every Google accou…

> This exploit could have been used to create a massive near-complete database of every Google account has automatically had a Youtube account created.

Massive email databases are extremely cheap, often free. For this vulnerability to be worth more than $10k there would have to be something about it being a near-complete library of Google accounts (rather than just another massive mailing list).

And that's assuming the prospective buyer believed that they could exploit this vulnerability in full before discovery. If I'm reading this exploit right, each email recovered requires two requests, one of which needs to make one of the fields 2.5 million characters long in order to error out the notification email sent to the victim. Presumably that email sending error would show up in a log somewhere, so the prospective attacker would have to send billions of requests fast enough that Google can't block them as suspicious or patch the vulnerability, all the while knowing full well that they're filling up an error log somewhere and leaving an extremely suspicious pattern of megabyte-sized request bodies on a route that normally doesn't even reach kilobytes.

I'm honestly not seeing how you could make an email list out of this that is anywhere near complete, and even if you could I'm not sure where the value to it would be.

Re: Leaking the email of any YouTube user for $10k

#147

Earlier quoted context omitted.

Draw up a straw-man business plan for this, with SWAG numbers.

The motivation isn't financial but the impact to some of Google's biggest earners would be significant. Never mind the PR when Mr Beast and SSSniperwolf's personal details leak online.

Major channels typically would be using a YouTube brand account, not a single normal Google account. (This is so that they can e.g. delegate parts of the channel management to multiple people without sharing a single login). The email address for a brand account is totally worthless.

Re: Leaking the email of any YouTube user for $10k

#148
post #73

Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…

> Threat actors buy vulnerabilities that fit into existing business processes

Isn't there a market for this? For example, "Reveal who is behind this account that's criticizing our sketchy company/government, so we can neutralize them".

I'll also argue there's separate incentives, than the market value to threat actors... Although a violent stalker of an online personality might not be a lucrative market for a zero-day exploit for this "threat actor" market, the vulnerability is still a liability (and ethical) risk for the company that could negligently disclose the identity of target to violent stalker.

IMHO, if you're paying well a gazillion Leetcode performance artists, to churn out massive amounts of code with imperfect attention to security, then you should also pay well the people who help you catch and fix their gazillion mistakes, before bad things happens.

Re: Leaking the email of any YouTube user for $10k

#149
post #97

Earlier quoted context omitted.

>Unmasking Google accounts? Could there be a business there? Sure, maybe. Is there one already? Presumably no. Absolutely, yes. Spam and targeted phishing attacks are in high demand. My understanding is that it is possible to retrieve every public youtube channel ID, if not also Google Maps/Play reviewers, quite easily. This exploit could have been used to create a massive near-complete database of every Google accou…

And then what? Exploits need to plug into a business plan. Like any business plan there has to be somewhere that money gets extracted and that money needs to be more than the exploit cost & infrastructure costs & a risk premium. If you can’t trivially say how the exploit explicitly gets turned into cash you probably are on the wrong track. Doubly so if it’s not a known standard and commoditized way that’s happened be…

> Exploits need to plug into a business plan

Or, you know, develop a new "business plan" around an exploit.

Re: Leaking the email of any YouTube user for $10k

#150
post #148
post #73

Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…

> Threat actors buy vulnerabilities that fit into existing business processes Isn't there a market for this? For example, "Reveal who is behind this account that's criticizing our sketchy company/government, so we can neutralize them". I'll also argue there's separate incentives, than the market value to threat actors... Although a violent stalker of an online personality might not be a lucrative market for a zero-da…

> then you should also pay well the people who help you catch and fix their gazillion mistakes before bad things happens.

You missed their point about the business model of the security researchers here: their business model is finding a large number of small value vulnerabilities. Those who are good at this are very very good at this.

My company has a bug bounty program and some of the researchers participating in it make double or more my salary off of our program, but we never pay out more than this for a single report. And it's not like we're particularly vulnerable, we just get a steady stream of very small issues and we pay accordingly.

Post reply on HN