Live data from Hacker News

Leaking the email of any YouTube user for $10k

brutecat.com

191–200 of 487 posts

Re: Leaking the email of any YouTube user for $10k

#191
post #78

Earlier quoted context omitted.

That's probably another reason why Google kills so many products that are successful, but not successful enough for Google's whole system to justify keeping them alive and secure.

Maybe Apple should do the same and kill their many half-baked software products.

Which ones? In my experience, a lot of Apples products have incredible longevity. Notes, Calendar, Pages all just get better and better.

Re: Leaking the email of any YouTube user for $10k

#192
post #73

Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…

It does not make sense to value these kind of (web) bugs by their potential price on the grey market. I think its better to value these bugs by their potential impact, although that is hard to express in money.

In this case there were 4 billion email addresses on the line from being scraped, imagine if this was exploited and the data was leaked. The news would hit the headliners which would definitely be bad for Google's reputation and stock price.

However, the impact of the leak is not that high as it only consists of a channel email address mapping, and therefore I think 10k is a fair price

Re: Leaking the email of any YouTube user for $10k

#193
post #183
post #73

Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…

> Threat actors buy vulnerabilities that fit into existing business processes Selling crazy stories to the media is as old as time. This vuln would give you a lookup table from email->YT SELECT * FROM table WHERE email LIKE “%.gov”

And? So what. You can spam them?

Come on.

Re: Leaking the email of any YouTube user for $10k

#194
post #96

Earlier quoted context omitted.

Some malicious mail that grants remote access to the employees device? Its not that hard to understand.

Actually it is hard to understand because that employee's device isn't an attack vector.

It absolutely is. Every connection to your app also is a attack vector.

Re: Leaking the email of any YouTube user for $10k

#195
post #46
post #2

Am I very naive expecting the payout to be significantly higher?

To me, that payout felt quite high; it's bigger than the average monthly salary for a senior IT professional where I live. To put it another way, that bounty alone would be like being paid for several months of full-time employment.

[deleted]

Re: Leaking the email of any YouTube user for $10k

#196
post #153

After reading the article top to bottom I still had to come to the comments to find out what the "for $10,000" was about. It's the payout for a bug bounty.

Bottom of the article:

> Timeline

> 05/11/24 - Panel awards $3,133.

> 12/12/24 - Panel awards an additional $7,500.

Re: Leaking the email of any YouTube user for $10k

#197
post #189
post #73

Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…

I hate how this HN thread is mostly about discussing the amount of bounty, but I'm afraid it's only natural. Most commenters here are working in the software industry and they want to normalize extremely high bounties. It's an extra income source for them. They want higher bug bounties much like they want SWEs to be a highly compensated profession. It's only natural for workers to demand higher pay for their own prof…

[flagged]

Re: Leaking the email of any YouTube user for $10k

#198
post #73

Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…

It sounds like a standard threat-risk assessment applies.

How big of a threat is it/what impact will it have on business/reputation/etc.?

How likely is it to be exploited and how widely would it be considered useful to the market of threat actors?

Re: Leaking the email of any YouTube user for $10k

#199
post #185
post #73

Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…

Most other fields of endeavor aren’t compensated based on the black market value of the thing that’s being produced. If we apply your analysis to other things, we’ll find that the upper bound price for a new car stereo or bike is ~ $100, and the price of any copyrighted good is bounded by the cost of transferring it over the network. I think it is more useful to divide the amount Google paid by the number of hours sp…

Bug bounty programs are not the only (or even primary) way that security researchers get paid. Google pays employees salaries to find vulns. Bounty programs are a pretty recent development and the idea that they should be scalable and stable well paying employment for a lot of people is a bit strange to me.

If security researchers want to have stable employment doing this sort of work, there's oodles of job applications they can send out.

Re: Leaking the email of any YouTube user for $10k

#200
post #190
post #73

Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…

> because $10,000 feels extraordinarily high for a server-side web bug. Am I misunderstanding the bug? In my reading, this bug translates to "a list of the top 1,000 Youtube accounts' email addresses (or as many as you can get until Google detects it and shuts it down)." Why isn't that conceivably worth more than $10,000?

Perhaps because email addresses are kinda/sorta PII (business emails are categorically not) but not quite comparable to home addresses, tax/payment information, etc..

Our emails get leaked all the time in data breaches, sometimes alongside much more important information such as home addresses etc..

This was certainly a bad leak that could be used to further dox people by connecting the email to other leaked info or other sources, but from Google's perspective, all they did was leak the email.

It was a privacy breach for sure.

But further doxxing based on the email would be "not their problem" I suspect they would say.

Post reply on HN