Live data from Hacker News

Leaking the email of any YouTube user for $10k

brutecat.com

241–250 of 487 posts

Re: Leaking the email of any YouTube user for $10k

#241
post #211

Earlier quoted context omitted.

> Bounty programs are a pretty recent development and the idea that they should be scalable and stable well paying employment for a lot of people is a bit strange to me. So, the value to the researcher of having a found bug has a floor of the black market value. The value to Google is whatever the costs of exploitation are: reputational, cleanup, etc. A sane value is somewhere between these two, depending on bargaini…

That's not true because there is an economic cost for most people to committing crimes. "Hey you could make more money selling that on the black market" is not going to convince me to sell something on the black market. Bounty programs are very much not trying to compete with crime.

Selling a bug is not a crime.

> Bounty programs are very much not trying to compete with crime.

Nor did my post posit this.

Bounty programs should pay a substantial fraction of the downside saved by eliminating the bug, because A) this gives an appropriate incentive for effort and motivate the economically correct amount of outside research, and B) this will feel fair and make people more likely to do what you consider the right thing, which is less likely if people feel mistreated.

Re: Leaking the email of any YouTube user for $10k

#242

Earlier quoted context omitted.

And then what? Exploits need to plug into a business plan. Like any business plan there has to be somewhere that money gets extracted and that money needs to be more than the exploit cost & infrastructure costs & a risk premium. If you can’t trivially say how the exploit explicitly gets turned into cash you probably are on the wrong track. Doubly so if it’s not a known standard and commoditized way that’s happened be…

There is often phishing campaigns targeting larger channels on YT, trying to trick someone with access to it into opening malicious e-mail attachments, with the end-goal of taking over the channel. Usually the attackers then put a livestream on it and push some crypto scam. It must make enough money, given that it keeps happening. Most recent example I've seen: https://www.youtube.com/watch?v=EnVxWK6DfMQ

So then why do they need additional information about emails? They clearly already can email these youtubers.

Re: Leaking the email of any YouTube user for $10k

#243
post #190

Earlier quoted context omitted.

> because $10,000 feels extraordinarily high for a server-side web bug. Am I misunderstanding the bug? In my reading, this bug translates to "a list of the top 1,000 Youtube accounts' email addresses (or as many as you can get until Google detects it and shuts it down)." Why isn't that conceivably worth more than $10,000?

Oh darn, my youtube email was leaked... It certainly stinks that mybusinessname@gmail.com is now known to the world... There's certainly bad things that CAN be done to a number of people with information when it's a personal email address that's used for numerous purposes... but the 3 people I talked to about having youtube (or any streaming) accounts all have mentioned it as being a separate account. So the only thr…

Increasing the ease of phishing the top 1000 YouTube accounts seems like a pretty serious threat to me.

Re: Leaking the email of any YouTube user for $10k

#244

Earlier quoted context omitted.

Which ones? In my experience, a lot of Apples products have incredible longevity. Notes, Calendar, Pages all just get better and better.

Alarms, Photos, Siri, Books..

How are any of these half baked? (Aside from obvious Siri deficiencies)

Re: Leaking the email of any YouTube user for $10k

#245
post #185
post #73

Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…

Most other fields of endeavor aren’t compensated based on the black market value of the thing that’s being produced. If we apply your analysis to other things, we’ll find that the upper bound price for a new car stereo or bike is ~ $100, and the price of any copyrighted good is bounded by the cost of transferring it over the network. I think it is more useful to divide the amount Google paid by the number of hours sp…

> Most other fields of endeavor aren’t compensated based on the black market value of the thing that’s being produced.

> If we apply your analysis to other things

This analysis doesn't work for a few reasons:

* For physical goods, used items always fetch a lower price than new items due to unrelated effects. And if we're only looking at the used price, we do find that the black market price is just about equal to the used item's value minus the risk associated with dealing with stolen goods (unless the buyer is unaware of the theft, in which case the black market value is the same as the used value).

* For both physical and digital goods, there are millions of potential customers for whom breaking the law isn't an option, creating a large market for the legal good that can serve to counter the effect of the black market price. This isn't true of exploits, where the legal market is tiny relative to the black market. We should expect to see the legal market prices track the black market prices more closely when the legal market is basically "the company who built the service and maybe a few other agencies".

Re: Leaking the email of any YouTube user for $10k

#246
post #219
post #206

Earlier quoted context omitted.

> Why isn't that conceivably worth more than $10,000? If it exposed passwords as well then that would be worth a lot more, but a list of email addresses is not the most valuable of things on its own.

Potentially deanonymizing pseudonymous Youtube accounts sounds pretty bad by itself.

I can see that being worth a lot to a nation state

Re: Leaking the email of any YouTube user for $10k

#247
post #240

Earlier quoted context omitted.

And? So what. You can spam them? Come on.

You don’t think there are folks with content they’d very much not like to be directly associated with them? Comments, videos, likes, etc

And so what's going to happen? Are there blackmailing rings that are in active need of ways of tying youtube comments to work accounts that are paying out the nose?

Re: Leaking the email of any YouTube user for $10k

#248
post #221

Earlier quoted context omitted.

Why isn't that conceivably worth more than $10,000? As explained by the parent comment, because there isn't a market for it. It's a novelty. Who are you going to sell that exploit to? At this time, nobody. Since Google doesn't have to compete against others for the bug, it pays low.

To clarify, I'm not suggesting selling the exploit. I'm suggesting selling MrBeast, PewDiePie, Blackpink, Sony Music, etc.'s Youtube email addresses. To phishing rings. Those may be non-public email addresses (admin/billing emails), so the phishing potential is higher than emailing prteam@mrbeast.com (or whatever).

I`ll suggest you want the bottom 1000 as they are most likely to fall for a scam.

Re: Leaking the email of any YouTube user for $10k

#249
Everyone on HN has this addiction to “vulnerability” like it’s some grand thing and then concocts complicated “it could be worth millions; you then use it to find out their Swiss bank account number; and they watch the money go down as you drain it!”

It feels like most software sites are now populated by people who think software is like in the movies.

Re: Leaking the email of any YouTube user for $10k

#250
post #240

Earlier quoted context omitted.

And? So what. You can spam them? Come on.

You don’t think there are folks with content they’d very much not like to be directly associated with them? Comments, videos, likes, etc

There's no existing black market of criminals extorting politicians and celebrities over Youtube comments (also how you go from an email address to an identity is itself iffy).

You are imagining a potential market, the exploits are priced against markets that are real and pay out today. Security researchers aren't traveling salesmen going around to every shady character on the internet and pitching them on the potential of a new criminal enterprise.

Post reply on HN