Live data from Hacker News

Leaking the email of any YouTube user for $10k

brutecat.com

211–220 of 487 posts

Re: Leaking the email of any YouTube user for $10k

#211
post #185

Earlier quoted context omitted.

Most other fields of endeavor aren’t compensated based on the black market value of the thing that’s being produced. If we apply your analysis to other things, we’ll find that the upper bound price for a new car stereo or bike is ~ $100, and the price of any copyrighted good is bounded by the cost of transferring it over the network. I think it is more useful to divide the amount Google paid by the number of hours sp…

Bug bounty programs are not the only (or even primary) way that security researchers get paid. Google pays employees salaries to find vulns. Bounty programs are a pretty recent development and the idea that they should be scalable and stable well paying employment for a lot of people is a bit strange to me. If security researchers want to have stable employment doing this sort of work, there's oodles of job applicati…

> Bounty programs are a pretty recent development and the idea that they should be scalable and stable well paying employment for a lot of people is a bit strange to me.

So, the value to the researcher of having a found bug has a floor of the black market value.

The value to Google is whatever the costs of exploitation are: reputational, cleanup, etc.

A sane value is somewhere between these two, depending on bargaining power, of course. Now, Google has all the bargaining power. On the other hand, at some point there's the point where you feel like you're being cheated and you'd rather just deal with the bad guys instead.

Re: Leaking the email of any YouTube user for $10k

#212
post #205
post #189

Earlier quoted context omitted.

I hate how this HN thread is mostly about discussing the amount of bounty, but I'm afraid it's only natural. Most commenters here are working in the software industry and they want to normalize extremely high bounties. It's an extra income source for them. They want higher bug bounties much like they want SWEs to be a highly compensated profession. It's only natural for workers to demand higher pay for their own prof…

It isn't always about money, even when that is the stated problem. The dollar value of a responsible report going up means more responsibility overall and less problem leaks, exploits, etc. I would be equally happy to see any solution where the end result is increased security and privacy for everyone, even at zero bounty. The problem being overlooked is that the actual cost of these exploits and bugs is paid by the…

> The dollar value of a responsible report going up means more responsibility overall and less problem leaks, exploits, etc.

Does it? I just had a bug bounty program denied for budget approval at my work because of the cost of the bounties and the sufficiency of our existing security program. On the margins, it's not clear to me that the dollar value of a report going up is incentivizing better reports vs pricing smaller companies out of the market.

Re: Leaking the email of any YouTube user for $10k

#213
post #78

Breaking the email system so that it's not sent is the cherry on top. With companies as big as Google who have developed so many products, "security" feels fake. If every line of code is a possible vulnerability, with millions it's just inevitable. It feels like the only way is to keep things simple (e.g., deprecate the recorder site), but even then.

That's probably another reason why Google kills so many products that are successful, but not successful enough for Google's whole system to justify keeping them alive and secure.

There's a lot of truth to that. Older projects often get bogged down by new security & compliance horizontals, to the point where maintenance is just no longer worth it.

Re: Leaking the email of any YouTube user for $10k

#214
post #73

Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…

If the value of the bug payout is equal to the grey market payout, why would I ever sell it to Google? I could sell it on the grey market and not pay taxes on the sale, or worry about cumbersome reporting requirements. Google plays a dangerous game with this logic.

Re: Leaking the email of any YouTube user for $10k

#215
post #148
post #73

Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…

> Threat actors buy vulnerabilities that fit into existing business processes Isn't there a market for this? For example, "Reveal who is behind this account that's criticizing our sketchy company/government, so we can neutralize them". I'll also argue there's separate incentives, than the market value to threat actors... Although a violent stalker of an online personality might not be a lucrative market for a zero-da…

i think what's being conflated here is that there are reasonably buyers for this kind of vulnerability but there's no market in the truest sense. I think a correctly connected individual could well sell this vuln to a state actor or a contractor to one; but the ecosystem of bug sales to these parties has no aggregate appetite for them, thus, there is nothing driving the price up. People in the market for cyberweapons want point and shoot vulns that have broad usage beyond a specific server for a specific company or parts for them, and ones that will last beyond a single corporation patching something. They are willing to pay such big $$$ for this that the whole market is optimized for it. The power players here would much rather buy a gun and shoot the lock off a door than a specialised set of picks that work for that lock in that building.

Re: Leaking the email of any YouTube user for $10k

#216
post #90

Earlier quoted context omitted.

I realized I was reading too many websites and decided to switch to RSS, only to find out that Google had killed Reader a month earlier. Years later, I came across Artifact, created by the founders of Instagram, and thought it was an interesting idea. The problem was I was reading its shutdown announcement. Sometimes I think products are killed way too early. Look at twitch, it boomed after years of stagnation.

Twitch has found some not-amazing niches to bulk up its revenue. A service needs to be profitable to work, and I don't think anyone wanted to pay for RSS. Or not enough.

Somewhat true back then, but I think now there are more people who would pay for it, and they could capitalize a lot on integrating LLMs into RSS apps.

Re: Leaking the email of any YouTube user for $10k

#217
post #29

Earlier quoted context omitted.

MM/DD/YY is an exclusively American standard https://en.wikipedia.org/wiki/List_of_date_formats_by_countr... I have no idea why America settled on MM/DD/YY, which seems like absolutely the least intuitive permutation of D, M, and Y. Except perhaps MYD.

To me its sounds better and more correct to say: February 12th, 2025 Rather than: 12 February 2025 And is easier to say than: The 12th of February 2025 So it's always been natural to write the numeric form the same way, but I am American. I can appreciate day first being easier to sort by machines and having an agreed upon international standard.

Just like the 4th of July, that most American of days

Re: Leaking the email of any YouTube user for $10k

#218
post #189

Earlier quoted context omitted.

I hate how this HN thread is mostly about discussing the amount of bounty, but I'm afraid it's only natural. Most commenters here are working in the software industry and they want to normalize extremely high bounties. It's an extra income source for them. They want higher bug bounties much like they want SWEs to be a highly compensated profession. It's only natural for workers to demand higher pay for their own prof…

[flagged]

You say greed but I would wager that most people in the thread are not financially independent. If someone can't retire from needing money in perpetuity, is it really greed to want to move that needle from "no" closer to "yes"?

Re: Leaking the email of any YouTube user for $10k

#219
post #206
post #190

Earlier quoted context omitted.

> because $10,000 feels extraordinarily high for a server-side web bug. Am I misunderstanding the bug? In my reading, this bug translates to "a list of the top 1,000 Youtube accounts' email addresses (or as many as you can get until Google detects it and shuts it down)." Why isn't that conceivably worth more than $10,000?

> Why isn't that conceivably worth more than $10,000? If it exposed passwords as well then that would be worth a lot more, but a list of email addresses is not the most valuable of things on its own.

Potentially deanonymizing pseudonymous Youtube accounts sounds pretty bad by itself.

Re: Leaking the email of any YouTube user for $10k

#220
post #205

Earlier quoted context omitted.

It isn't always about money, even when that is the stated problem. The dollar value of a responsible report going up means more responsibility overall and less problem leaks, exploits, etc. I would be equally happy to see any solution where the end result is increased security and privacy for everyone, even at zero bounty. The problem being overlooked is that the actual cost of these exploits and bugs is paid by the…

> The dollar value of a responsible report going up means more responsibility overall and less problem leaks, exploits, etc. Does it? I just had a bug bounty program denied for budget approval at my work because of the cost of the bounties and the sufficiency of our existing security program. On the margins, it's not clear to me that the dollar value of a report going up is incentivizing better reports vs pricing sma…

This is a great point and I did not really think of this in the above statement.

It may work kind of how employment works, where Google can afford to pay more than a company that cannot afford a 10k bounty.

Google paying a 10k bounty is the equivalent of the bottom 10% of earners in the US paying a 6th(napkin math) of a soon to be discontinued penny.

Regardless, you are correct that the calculation is not obvious, unlike how I presented it. Preferably, things like multiple million character titles are handled correctly and no bounty is paid at all. I expect a smaller company to have an easier time here as well, lessening the financial burden.

Post reply on HN