Live data from Hacker News

Leaking the email of any YouTube user for $10k

brutecat.com

171–180 of 487 posts

Re: Leaking the email of any YouTube user for $10k

#171
post #97

Earlier quoted context omitted.

>Unmasking Google accounts? Could there be a business there? Sure, maybe. Is there one already? Presumably no. Absolutely, yes. Spam and targeted phishing attacks are in high demand. My understanding is that it is possible to retrieve every public youtube channel ID, if not also Google Maps/Play reviewers, quite easily. This exploit could have been used to create a massive near-complete database of every Google accou…

> This exploit could have been used to create a massive near-complete database of every Google account has automatically had a Youtube account created. Massive email databases are extremely cheap, often free. For this vulnerability to be worth more than $10k there would have to be something about it being a near-complete library of Google accounts (rather than just another massive mailing list). And that's assuming t…

>Massive email databases are extremely cheap, often free

There are different qualities of email databases. "Known real email by Youtube account holders" would be a high value database. Definitely not free.

This type of vulnerability is extremely valuable for private investigators, too. "Who uploaded this video which my client is extremely interested in?"

Re: Leaking the email of any YouTube user for $10k

#172
post #78

Breaking the email system so that it's not sent is the cherry on top. With companies as big as Google who have developed so many products, "security" feels fake. If every line of code is a possible vulnerability, with millions it's just inevitable. It feels like the only way is to keep things simple (e.g., deprecate the recorder site), but even then.

That's probably another reason why Google kills so many products that are successful, but not successful enough for Google's whole system to justify keeping them alive and secure.

Maybe Apple should do the same and kill their many half-baked software products.

Re: Leaking the email of any YouTube user for $10k

#173

Earlier quoted context omitted.

> Exploits need to plug into a business plan Or, you know, develop a new "business plan" around an exploit.

Nobody does this. It would be an insane proposition. The vulnerability is going to die very shortly into your attempt to capitalize on it. Businesses have startup costs they have to pay off.

[deleted]

Re: Leaking the email of any YouTube user for $10k

#174

Earlier quoted context omitted.

100%. Every product not a part of the core mission is attack surface area, ongoing maintenance to ensure it works with the rest of Google services and infra, and drag on the rest of the team and velocity. The part that sucks for consumers is that they often kill things that people like. I wish they had a better way of doing this. Bravo to brutecat for this excellent discovery, productionization, and writeup.

They could spin these products off into separate companies and cut the integration with the rest of the Google ecosystem.

Where is the profit for the individual product? There are a lot of services at every BigTech company that would not make sense as an individual product. But they make the overall ecosystem better or make money only because they are a part of the larger company.

That’s part of the stupidity of the DOJ trying to force Google to sell Chrome. Who would want it? And how would they profit from it?

Re: Leaking the email of any YouTube user for $10k

#175

Earlier quoted context omitted.

Honestly, that leaves straight up harassment of YouTubers by other YouTubers and fans off the table which by itself would motivate a few of them. Some of the same people who play in the black and grey hat worlds are the same people buying DDOS attacks and swatting streamers. They would have a party with their emails.

> which by itself would motivate a few of them Motivation in the abstract is not enough to counter GP's point—they have to have enough motivation that it's worth more than $10,000 to them and also have more than $10,000 to spend and also have the connections necessary to get in touch with someone who's able to sell a vulnerability like this and also be able to exploit it in a timely manner or at least think they can.

Or be a black hat. An incredibly common hat.

Re: Leaking the email of any YouTube user for $10k

#176

Earlier quoted context omitted.

Probably way too much effort. The apps aren't built for generic infra, but rather Google's internal weirdware. It wouldn't be possible to run it anywhere else without a rewrite.

I agree, and I like this term "internal weirdware". Real question: Why don't we see more start-ups try to clone old terminated Google services with a freemium model?

People don’t want to pay for things.

Re: Leaking the email of any YouTube user for $10k

#177
post #112

Earlier quoted context omitted.

I remember being upset about Google Reader for a few months after its death… before moving to one of its many, fuller-featured competitors and carrying on using RSS feeds exactly as before. What upsets me re RSS these days is how many people were apparently so reliant on one reader that they still publicly mourn every time it comes up, 12 years later. Who are these fair-weather feed followers who threw their hands in…

Killing Google Reader killed blogs. You personally can replace Google Reader as a product, but since most people didn't and just sort of moved on to closed platforms, there was less content produced on blogs and less discussion activity on the blog posts that were created after.

John Gruber of DaringFireball has said his blog has still not recovered completely from the Google Reader shutdown and he has the most popular blog in the Apple ecosystem

Re: Leaking the email of any YouTube user for $10k

#178
post #73

Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…

The bounty is not a market. It's a subsidized incentive to subvert the market, and to give greyhat hackers a reason to be white-tinged instead of black-tinged. I would conservatively guess this guy could have found at least 30 people willing to pay $500 for details on this exploit, and he would've netted $5000 more than Google paid him to do the right thing.

Probably the risk of going to jail outweighs the extra $5k, but if a company is serious about the bug bounty program, they would offer a reward that's competitive with what you could extract from the black market, and I don't think that's hard to do.

Re: Leaking the email of any YouTube user for $10k

#179
post #45

Earlier quoted context omitted.

Think this is puny — I found the ability to reveal emails in npmjs.org but as it hadn't been included in the new GitHub/Microsoft bug bounty scope yet, I was given a t-shirt and $1000. Talk about puny!

I was able to run JavaScript inside an email in the GMail app on Android (it required the user tap within the email body). I only got a Nexus 7 tablet.

I've discovered I can run JavaScript in the browser and I've got a job :(

Re: Leaking the email of any YouTube user for $10k

#180
post #138

Earlier quoted context omitted.

If you sell information about a vulnerability to someone that you know specifically is going to use it to break the law, you are an accessory to that lawbreaking. Ask Stephen Watt how this plays out.

Please read my posts more carefully. Virtually every response is non-responsive to what I wrote: I wrote: "unless you're dumb enough to ask questions about whom your selling to and have active knowledge you're assisting someone in breaking some law, selling to the black market is perfectly legal" You wrote: "If you sell information about a vulnerability to someone that you know specifically is going to use it to brea…

Someone gives you two kilos of cocaine, doesn’t tell you what’s in the box and tells you not to open it while you transport it across the border and when you get your the other side someone will pay you $20000.

You get caught by the DEA. Do you think it’s a valid defense “I didn’t ask what was in the box”?

Say the drug dealer you delivered it to got caught and then told authorities you delivered it to them, do you think you would have a valid defense?

Post reply on HN