Live data from Hacker News

Leaking the email of any YouTube user for $10k

brutecat.com

251–260 of 487 posts

Re: Leaking the email of any YouTube user for $10k

#251
post #73

Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…

I'd also add that the legality of law enforcement exploiting a server-side bug is much more of a gray area (or actually illegal), whereas there is a standard process for law enforcement or the intelligence community to get a court order that enables them to exploit devices that belong to a specific target (phone, laptop, etc).

Re: Leaking the email of any YouTube user for $10k

#253

Earlier quoted context omitted.

Alarms, Photos, Siri, Books..

How are any of these half baked? (Aside from obvious Siri deficiencies)

Alarms is unreliable for the basic functionality of waking you up.

Photos redesign makes it really hard to use.

Siri works half of the times, maybe even less than that.

Books lacks of basic functionalities such as downloading and keeping books on device.

Re: Leaking the email of any YouTube user for $10k

#255

Earlier quoted context omitted.

There is often phishing campaigns targeting larger channels on YT, trying to trick someone with access to it into opening malicious e-mail attachments, with the end-goal of taking over the channel. Usually the attackers then put a livestream on it and push some crypto scam. It must make enough money, given that it keeps happening. Most recent example I've seen: https://www.youtube.com/watch?v=EnVxWK6DfMQ

So then why do they need additional information about emails? They clearly already can email these youtubers.

This will enable you to get the private e-mail of the google account that owns the channel, which is not necessarily the same one a channel may give away publicly.

So for some channels that provided no contact information, you now can acquire an email address, and for everyone else you may now get an additional one.

It also enables you to link multiple channels back to the same person.

Every bit of information you can get your hands on counts for social engineering attacks.

For very famous individuals this may also open them up to harassment. You can't find Elon Musk's private telephone number on the Tesla homepage for good reason. For that class of people, any time that sort of information leaks, they need to get a new private phone number/e-mail address.

Re: Leaking the email of any YouTube user for $10k

#256
post #220

Earlier quoted context omitted.

> The dollar value of a responsible report going up means more responsibility overall and less problem leaks, exploits, etc. Does it? I just had a bug bounty program denied for budget approval at my work because of the cost of the bounties and the sufficiency of our existing security program. On the margins, it's not clear to me that the dollar value of a report going up is incentivizing better reports vs pricing sma…

This is a great point and I did not really think of this in the above statement. It may work kind of how employment works, where Google can afford to pay more than a company that cannot afford a 10k bounty. Google paying a 10k bounty is the equivalent of the bottom 10% of earners in the US paying a 6th(napkin math) of a soon to be discontinued penny. Regardless, you are correct that the calculation is not obvious, un…

> I expect a smaller company to have an easier time here as well, lessening the financial burden.

Why would you expect that? In a smaller company the ratio of developers to HTTP endpoints tends to be substantially lower (fewer devs per feature) than in a large company, so I'd expect the opposite.

Re: Leaking the email of any YouTube user for $10k

#257
post #211

Earlier quoted context omitted.

> Bounty programs are a pretty recent development and the idea that they should be scalable and stable well paying employment for a lot of people is a bit strange to me. So, the value to the researcher of having a found bug has a floor of the black market value. The value to Google is whatever the costs of exploitation are: reputational, cleanup, etc. A sane value is somewhere between these two, depending on bargaini…

That's not true because there is an economic cost for most people to committing crimes. "Hey you could make more money selling that on the black market" is not going to convince me to sell something on the black market. Bounty programs are very much not trying to compete with crime.

It is a factor though. Most people will commit non-violent crime for a big enough pay off. Especially one where the individuals effected are hard to identify.

If my bug bounty is $10,000 and I can sell it for $20,000 then most people will take the legitimate cash. If it's $10,000 and some black market trader will pay $10,000,000 (obviously exaggerating) then there's a whole mess of people are going to take the ten million.

Re: Leaking the email of any YouTube user for $10k

#258
post #73

Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…

The fact that the amounts in apple's bounty program can range from 5k-500k for a single category tells me that the answer is it depends.

It's most likely not just a comparison to black market prices or how many lines of code it'd take to patch.

https://security.apple.com/bounty/categories/

Re: Leaking the email of any YouTube user for $10k

#259

Earlier quoted context omitted.

[flagged]

You say greed but I would wager that most people in the thread are not financially independent. If someone can't retire from needing money in perpetuity, is it really greed to want to move that needle from "no" closer to "yes"?

Or even just the next meal. We don't know their situation, and I've heard quite a few stories of the tech-adept being on the streets or behind bars. Some amount of greed is normal. It's when goes way beyond that, into averice that it's a problem.

Re: Leaking the email of any YouTube user for $10k

#260

Earlier quoted context omitted.

How are any of these half baked? (Aside from obvious Siri deficiencies)

Alarms is unreliable for the basic functionality of waking you up. Photos redesign makes it really hard to use. Siri works half of the times, maybe even less than that. Books lacks of basic functionalities such as downloading and keeping books on device.

How are alarms unreliable?

Photos redesign maybe something you don’t like, but you can hardly call it half baked. All of the functionality is there and there’s a new consistency in how it works that wasn’t there previously.

Books automatically downloads to device. There isn’t a way to read a book without it local.

Post reply on HN