Live data from Hacker News

Leaking the email of any YouTube user for $10k

brutecat.com

181–190 of 487 posts

Re: Leaking the email of any YouTube user for $10k

#181

Earlier quoted context omitted.

> Exploits need to plug into a business plan Or, you know, develop a new "business plan" around an exploit.

Nobody does this. It would be an insane proposition. The vulnerability is going to die very shortly into your attempt to capitalize on it. Businesses have startup costs they have to pay off.

You could dump all the data over a matter of weeks, then you’re sitting on a treasure trove that will pay out over 5+ years.

You could sell it non-exclusively to every data broker

Re: Leaking the email of any YouTube user for $10k

#183
post #73

Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…

> Threat actors buy vulnerabilities that fit into existing business processes

Selling crazy stories to the media is as old as time.

This vuln would give you a lookup table from email->YT

SELECT * FROM table WHERE email LIKE “%.gov”

Re: Leaking the email of any YouTube user for $10k

#184
post #43

Is it me or are all the dates in this timeline in the future? Isn’t it Feb 2025 now? Do you smell toast? EDIT: oh I see .. DD/MM/YY is a new one to me

DMY is the most common format internationally. There's a growing move (and ISO standard) for YMD but its a slow change, I think it's only North America that uses MDY.

ISO 8601 was set in 1988:

https://xkcd.com/1179/

Re: Leaking the email of any YouTube user for $10k

#185
post #73

Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…

Most other fields of endeavor aren’t compensated based on the black market value of the thing that’s being produced.

If we apply your analysis to other things, we’ll find that the upper bound price for a new car stereo or bike is ~ $100, and the price of any copyrighted good is bounded by the cost of transferring it over the network.

I think it is more useful to divide the amount Google paid by the number of hours spent on this and any unsuccessful exploit attempts since the last bounty was paid.

I’d guess that the vast majority of people in this space are making less than US minimum wage for their efforts, with a six figure per year opportunity cost.

That tells you exactly how much Google values the security and preserving the privacy of its end users. The number is significantly lower than what they pay other engineers orders of magnitude more to steal personal information from the same group of people.

Re: Leaking the email of any YouTube user for $10k

#186

“Applied 1 downgrade from the base amount due to complexity of attack chain required” I’ve only participated in a few vulnerability programs, and most of them reward less if the security flaw is stupidly simple (but serious) such as revealing user emails in the page source.

Yeah, this seems backwards. It should be upgraded from the base amount because they effectively found 2 bugs!

Re: Leaking the email of any YouTube user for $10k

#187

Earlier quoted context omitted.

And then what? Exploits need to plug into a business plan. Like any business plan there has to be somewhere that money gets extracted and that money needs to be more than the exploit cost & infrastructure costs & a risk premium. If you can’t trivially say how the exploit explicitly gets turned into cash you probably are on the wrong track. Doubly so if it’s not a known standard and commoditized way that’s happened be…

> Exploits need to plug into a business plan Or, you know, develop a new "business plan" around an exploit.

Even if that did happen, it would drive down the price of the exploit and especially so for server side novel ones.

Re: Leaking the email of any YouTube user for $10k

#188
post #148

Earlier quoted context omitted.

> Threat actors buy vulnerabilities that fit into existing business processes Isn't there a market for this? For example, "Reveal who is behind this account that's criticizing our sketchy company/government, so we can neutralize them". I'll also argue there's separate incentives, than the market value to threat actors... Although a violent stalker of an online personality might not be a lucrative market for a zero-da…

You are imagining a market that doesn’t exist. First there are only very few gobs/companies that are sketchy enough to do this - and for those a huge number of non-anonymous people exist with huge reach that are very critical for years. If such a market would exist they would assassinate all those first - you don’t need the email if you have the face, voice, and name - since that is not happening they just don’t care…

There’s 100% an active market for this, and I think tptacek is simply wrong on this point (the others are valid)

The likes of Cambridge Analytica didn’t go away, they exist and absolutely go hunting for data like this.

The ability to map between different identifiers and pieces of content on the internet is central to so many things - why do you think adtech tries to join so many datapoints? Let alone things like influence campaigns for political purposes.

I’m not talking about assasination plots, but more mundane data mining. This is why so much effort in the EU has gone into preventing companies from joining data sources across products - that’s embedded in DMA

Re: Leaking the email of any YouTube user for $10k

#189
post #73

Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…

I hate how this HN thread is mostly about discussing the amount of bounty, but I'm afraid it's only natural. Most commenters here are working in the software industry and they want to normalize extremely high bounties. It's an extra income source for them. They want higher bug bounties much like they want SWEs to be a highly compensated profession. It's only natural for workers to demand higher pay for their own profession. No amount of rationalization will change that instinct.

Re: Leaking the email of any YouTube user for $10k

#190
post #73

Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…

> because $10,000 feels extraordinarily high for a server-side web bug.

Am I misunderstanding the bug? In my reading, this bug translates to "a list of the top 1,000 Youtube accounts' email addresses (or as many as you can get until Google detects it and shuts it down)." Why isn't that conceivably worth more than $10,000?

Post reply on HN