Live data from Hacker News

Leaking the email of any YouTube user for $10k

brutecat.com

221–230 of 487 posts

Re: Leaking the email of any YouTube user for $10k

#221
post #190

Earlier quoted context omitted.

> because $10,000 feels extraordinarily high for a server-side web bug. Am I misunderstanding the bug? In my reading, this bug translates to "a list of the top 1,000 Youtube accounts' email addresses (or as many as you can get until Google detects it and shuts it down)." Why isn't that conceivably worth more than $10,000?

Why isn't that conceivably worth more than $10,000? As explained by the parent comment, because there isn't a market for it. It's a novelty. Who are you going to sell that exploit to? At this time, nobody. Since Google doesn't have to compete against others for the bug, it pays low.

To clarify, I'm not suggesting selling the exploit. I'm suggesting selling MrBeast, PewDiePie, Blackpink, Sony Music, etc.'s Youtube email addresses. To phishing rings.

Those may be non-public email addresses (admin/billing emails), so the phishing potential is higher than emailing prteam@mrbeast.com (or whatever).

Re: Leaking the email of any YouTube user for $10k

#222
post #185
post #73

Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…

Most other fields of endeavor aren’t compensated based on the black market value of the thing that’s being produced. If we apply your analysis to other things, we’ll find that the upper bound price for a new car stereo or bike is ~ $100, and the price of any copyrighted good is bounded by the cost of transferring it over the network. I think it is more useful to divide the amount Google paid by the number of hours sp…

> and the price of any copyrighted good is bounded by the cost of transferring it over the network

It sure has worked out pretty much like this for music. The cost is not exactly zero, but pretty close to that.

Re: Leaking the email of any YouTube user for $10k

#223
post #190
post #73

Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…

> because $10,000 feels extraordinarily high for a server-side web bug. Am I misunderstanding the bug? In my reading, this bug translates to "a list of the top 1,000 Youtube accounts' email addresses (or as many as you can get until Google detects it and shuts it down)." Why isn't that conceivably worth more than $10,000?

I think a simple way to think of it is: how much would an adversarial nation state buy this exploit for?

I just don't think Russia would be willing to pay $100,000 to get Mr. Beast's email address, even if that sounds tempting to you.

Re: Leaking the email of any YouTube user for $10k

#224
post #188

Earlier quoted context omitted.

There’s 100% an active market for this, and I think tptacek is simply wrong on this point (the others are valid) The likes of Cambridge Analytica didn’t go away, they exist and absolutely go hunting for data like this. The ability to map between different identifiers and pieces of content on the internet is central to so many things - why do you think adtech tries to join so many datapoints? Let alone things like inf…

Sure, but do adtech companies buy vulnerabilities in web services to advance their mission? Wouldn't that risk running foul of e.g. the Computer Fraud and Abuse Act?

You don‘t need to sell the vulnerability to them, or even tell them the vulnerability is there. Just set up an API and bill them by the query.

Re: Leaking the email of any YouTube user for $10k

#225

Earlier quoted context omitted.

Maybe Apple should do the same and kill their many half-baked software products.

Which ones? In my experience, a lot of Apples products have incredible longevity. Notes, Calendar, Pages all just get better and better.

Alarms, Photos, Siri, Books..

Re: Leaking the email of any YouTube user for $10k

#226
post #223
post #190

Earlier quoted context omitted.

> because $10,000 feels extraordinarily high for a server-side web bug. Am I misunderstanding the bug? In my reading, this bug translates to "a list of the top 1,000 Youtube accounts' email addresses (or as many as you can get until Google detects it and shuts it down)." Why isn't that conceivably worth more than $10,000?

I think a simple way to think of it is: how much would an adversarial nation state buy this exploit for? I just don't think Russia would be willing to pay $100,000 to get Mr. Beast's email address, even if that sounds tempting to you.

Why a nation state? My hypothetical is a phishing ring that sends an official-looking phishing email to 1000 non-public email accounts that typically only get emails from Youtube.

The exploit can be valued at: number of emails * probability that you'll phish them into letting you in * value of posting a "Free Robux" scam on a channel with 100M subscribers.

Re: Leaking the email of any YouTube user for $10k

#227

Earlier quoted context omitted.

Sure, but do adtech companies buy vulnerabilities in web services to advance their mission? Wouldn't that risk running foul of e.g. the Computer Fraud and Abuse Act?

You don‘t need to sell the vulnerability to them, or even tell them the vulnerability is there. Just set up an API and bill them by the query.

This ignores tptacek's points in the top-level post.

> [...] a bug that Google can kill instantaneously, that has effectively no half-life once discovered, and whose exploitation will generate reliable telemetry from the target.

You can't set up unmask-as-a-service because it's going to take you longer to get clients than it will take Google to shut down your exploit.

Re: Leaking the email of any YouTube user for $10k

#228
post #226
post #223

Earlier quoted context omitted.

I think a simple way to think of it is: how much would an adversarial nation state buy this exploit for? I just don't think Russia would be willing to pay $100,000 to get Mr. Beast's email address, even if that sounds tempting to you.

Why a nation state? My hypothetical is a phishing ring that sends an official-looking phishing email to 1000 non-public email accounts that typically only get emails from Youtube. The exploit can be valued at: number of emails * probability that you'll phish them into letting you in * value of posting a "Free Robux" scam on a channel with 100M subscribers.

Yea. Especially with AI, easy access to identities of email users makes it so much easier to scam on a massive scale.

Re: Leaking the email of any YouTube user for $10k

#229

Earlier quoted context omitted.

Sure, but do adtech companies buy vulnerabilities in web services to advance their mission? Wouldn't that risk running foul of e.g. the Computer Fraud and Abuse Act?

You don‘t need to sell the vulnerability to them, or even tell them the vulnerability is there. Just set up an API and bill them by the query.

I’ve seen a light version of this, where a “marketing data” company was scraping baby shower gift registry pages and selling the data to an infant formula company in the US.

The scraping was def in violation of the EULAs. Product data is one thing, but I believe this group was combining it with other sources and selling the identities and context as a bundle.

Re: Leaking the email of any YouTube user for $10k

#230
post #185
post #73

Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…

Most other fields of endeavor aren’t compensated based on the black market value of the thing that’s being produced. If we apply your analysis to other things, we’ll find that the upper bound price for a new car stereo or bike is ~ $100, and the price of any copyrighted good is bounded by the cost of transferring it over the network. I think it is more useful to divide the amount Google paid by the number of hours sp…

[deleted]
Post reply on HN