Live data from Hacker News

Leaking the email of any YouTube user for $10k

brutecat.com

231–240 of 487 posts

Re: Leaking the email of any YouTube user for $10k

#231

Earlier quoted context omitted.

Twitch has found some not-amazing niches to bulk up its revenue. A service needs to be profitable to work, and I don't think anyone wanted to pay for RSS. Or not enough.

Somewhat true back then, but I think now there are more people who would pay for it, and they could capitalize a lot on integrating LLMs into RSS apps.

By comparison, Twitch's yearly revenue is consistently over $100m[0] from subscriptions and other in-app payments (e.g. taking a cut for buying their internal currency).

[0] https://www.statista.com/statistics/517907/twitch-app-revenu...

Re: Leaking the email of any YouTube user for $10k

#232
post #190
post #73

Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…

> because $10,000 feels extraordinarily high for a server-side web bug. Am I misunderstanding the bug? In my reading, this bug translates to "a list of the top 1,000 Youtube accounts' email addresses (or as many as you can get until Google detects it and shuts it down)." Why isn't that conceivably worth more than $10,000?

Oh darn, my youtube email was leaked... It certainly stinks that mybusinessname@gmail.com is now known to the world...

There's certainly bad things that CAN be done to a number of people with information when it's a personal email address that's used for numerous purposes... but the 3 people I talked to about having youtube (or any streaming) accounts all have mentioned it as being a separate account.

So the only threat I can see in most cases is just better phishing attempts, which is not necessarily an easy money maker... Unless they can steal the entire account? It is impossible to get support from Google, so it's quite possible you could change the bank info and get a month or two of payments before someone gets in the loop to stop it... and realistically, the more money someone is making on YouTube, the less likely they have troubles contacting someone at Google by some side channel... and the less likely it's a personal email address that reaches the actual star of the channel.. so the more popular the person, the less valuable the email address

Re: Leaking the email of any YouTube user for $10k

#233
post #167

Earlier quoted context omitted.

Nobody does this. It would be an insane proposition. The vulnerability is going to die very shortly into your attempt to capitalize on it. Businesses have startup costs they have to pay off.

>Nobody does that. Sure: https://www.abc.net.au/news/2016-07-01/league-of-legends-que...

He reportedly made $32k and barely avoided jail time... which does not sound to me like the $10k payout is undervalued.

Re: Leaking the email of any YouTube user for $10k

#234

> That params is nothing more than just base64 encoded protobuf, which is a common encoding format used throughout Google. Pour one out for the google dev in charge of b64 encoding their fancy binary message format so it can be jammed inside a JSON blob. If you want a vision of the future, imagine a boot with "worse is better" imprinted on the sole stomping on an engineer's face, forever.

[deleted]

Re: Leaking the email of any YouTube user for $10k

#235
post #211

Earlier quoted context omitted.

Bug bounty programs are not the only (or even primary) way that security researchers get paid. Google pays employees salaries to find vulns. Bounty programs are a pretty recent development and the idea that they should be scalable and stable well paying employment for a lot of people is a bit strange to me. If security researchers want to have stable employment doing this sort of work, there's oodles of job applicati…

> Bounty programs are a pretty recent development and the idea that they should be scalable and stable well paying employment for a lot of people is a bit strange to me. So, the value to the researcher of having a found bug has a floor of the black market value. The value to Google is whatever the costs of exploitation are: reputational, cleanup, etc. A sane value is somewhere between these two, depending on bargaini…

That's not true because there is an economic cost for most people to committing crimes. "Hey you could make more money selling that on the black market" is not going to convince me to sell something on the black market.

Bounty programs are very much not trying to compete with crime.

Re: Leaking the email of any YouTube user for $10k

#236
post #185
post #73

Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…

Most other fields of endeavor aren’t compensated based on the black market value of the thing that’s being produced. If we apply your analysis to other things, we’ll find that the upper bound price for a new car stereo or bike is ~ $100, and the price of any copyrighted good is bounded by the cost of transferring it over the network. I think it is more useful to divide the amount Google paid by the number of hours sp…

Most other fields produce things that can be sold in the legal market - and so the value of those things can be determined by the market.

Re: Leaking the email of any YouTube user for $10k

#237
post #185
post #73

Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…

Most other fields of endeavor aren’t compensated based on the black market value of the thing that’s being produced. If we apply your analysis to other things, we’ll find that the upper bound price for a new car stereo or bike is ~ $100, and the price of any copyrighted good is bounded by the cost of transferring it over the network. I think it is more useful to divide the amount Google paid by the number of hours sp…

They mentioned the grey market a couple time, although some of their examples did seem like applications that would be more useful for the black market.

Anyway, I’m not 100% sure what they meant by grey market. It looks like they were talking about maybe selling to “agencies” which, I guess, could include state intelligence agencies. If that’s what they meant, it wouldn’t be that surprising to find that the black market and grey market prices influence each other, right?

I mean we could ask our intelligence agencies why they are shopping in the same markets as criminals but I guess they will say something like “it is important that we on the , which will allow us to better serve the and keep the safe.”

Re: Leaking the email of any YouTube user for $10k

#238

Earlier quoted context omitted.

You don‘t need to sell the vulnerability to them, or even tell them the vulnerability is there. Just set up an API and bill them by the query.

This ignores tptacek's points in the top-level post. > [...] a bug that Google can kill instantaneously, that has effectively no half-life once discovered, and whose exploitation will generate reliable telemetry from the target. You can't set up unmask-as-a-service because it's going to take you longer to get clients than it will take Google to shut down your exploit.

Yes, but:

1. It can still take a while before Google finds out

2. You can log every mapping you got in the meanwhile, then keep selling the ones you already have

Edit: although probably most of your business will be over when word gets out that your data isn’t exactly legal (which your clients have understood from the start, of course; they could just plead ignorance)

Re: Leaking the email of any YouTube user for $10k

#239
post #89

Earlier quoted context omitted.

I remember being upset about Google Reader for a few months after its death… before moving to one of its many, fuller-featured competitors and carrying on using RSS feeds exactly as before. What upsets me re RSS these days is how many people were apparently so reliant on one reader that they still publicly mourn every time it comes up, 12 years later. Who are these fair-weather feed followers who threw their hands in…

There still is no replacement for Google Reader. The difference is that there was a community around Reader’s social features. That only really works with wide adoption, and it’s a lot easier for people to adopt a Google product than a random company x one. Today, there are many replacements with the mechanical features of browsing & sync, but the community will never come back. The other problem was that Google kill…

> The difference is that there was a community around Reader’s social features.

Are social features the main selling point of RSS readers? I mean I just use mine to know when there's a new blog post/webcomic posted on a few sites I follow, without having to give my email or use another platform like social media to know about it. And I'd use the social features which are present on the blogs, under the control of the blog owner(s), if there's any. Or maybe my use case is not the most common one?

Though I agress about the signal Google sent by killing GR.

Re: Leaking the email of any YouTube user for $10k

#240
post #183

Earlier quoted context omitted.

> Threat actors buy vulnerabilities that fit into existing business processes Selling crazy stories to the media is as old as time. This vuln would give you a lookup table from email->YT SELECT * FROM table WHERE email LIKE “%.gov”

And? So what. You can spam them? Come on.

You don’t think there are folks with content they’d very much not like to be directly associated with them? Comments, videos, likes, etc
Post reply on HN