Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…
Leaking the email of any YouTube user for $10k
251–260 of 487 posts
Re: Leaking the email of any YouTube user for $10k
#252Re: Leaking the email of any YouTube user for $10k
#253Earlier quoted context omitted.
Alarms, Photos, Siri, Books..
How are any of these half baked? (Aside from obvious Siri deficiencies)
Photos redesign makes it really hard to use.
Siri works half of the times, maybe even less than that.
Books lacks of basic functionalities such as downloading and keeping books on device.
Re: Leaking the email of any YouTube user for $10k
#254Re: Leaking the email of any YouTube user for $10k
#255Earlier quoted context omitted.
There is often phishing campaigns targeting larger channels on YT, trying to trick someone with access to it into opening malicious e-mail attachments, with the end-goal of taking over the channel. Usually the attackers then put a livestream on it and push some crypto scam. It must make enough money, given that it keeps happening. Most recent example I've seen: https://www.youtube.com/watch?v=EnVxWK6DfMQ
So then why do they need additional information about emails? They clearly already can email these youtubers.
So for some channels that provided no contact information, you now can acquire an email address, and for everyone else you may now get an additional one.
It also enables you to link multiple channels back to the same person.
Every bit of information you can get your hands on counts for social engineering attacks.
For very famous individuals this may also open them up to harassment. You can't find Elon Musk's private telephone number on the Tesla homepage for good reason. For that class of people, any time that sort of information leaks, they need to get a new private phone number/e-mail address.
Re: Leaking the email of any YouTube user for $10k
#256Earlier quoted context omitted.
> The dollar value of a responsible report going up means more responsibility overall and less problem leaks, exploits, etc. Does it? I just had a bug bounty program denied for budget approval at my work because of the cost of the bounties and the sufficiency of our existing security program. On the margins, it's not clear to me that the dollar value of a report going up is incentivizing better reports vs pricing sma…
This is a great point and I did not really think of this in the above statement. It may work kind of how employment works, where Google can afford to pay more than a company that cannot afford a 10k bounty. Google paying a 10k bounty is the equivalent of the bottom 10% of earners in the US paying a 6th(napkin math) of a soon to be discontinued penny. Regardless, you are correct that the calculation is not obvious, un…
Why would you expect that? In a smaller company the ratio of developers to HTTP endpoints tends to be substantially lower (fewer devs per feature) than in a large company, so I'd expect the opposite.
Re: Leaking the email of any YouTube user for $10k
#257Earlier quoted context omitted.
> Bounty programs are a pretty recent development and the idea that they should be scalable and stable well paying employment for a lot of people is a bit strange to me. So, the value to the researcher of having a found bug has a floor of the black market value. The value to Google is whatever the costs of exploitation are: reputational, cleanup, etc. A sane value is somewhere between these two, depending on bargaini…
That's not true because there is an economic cost for most people to committing crimes. "Hey you could make more money selling that on the black market" is not going to convince me to sell something on the black market. Bounty programs are very much not trying to compete with crime.
If my bug bounty is $10,000 and I can sell it for $20,000 then most people will take the legitimate cash. If it's $10,000 and some black market trader will pay $10,000,000 (obviously exaggerating) then there's a whole mess of people are going to take the ten million.
Re: Leaking the email of any YouTube user for $10k
#258Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…
It's most likely not just a comparison to black market prices or how many lines of code it'd take to patch.
Re: Leaking the email of any YouTube user for $10k
#259Earlier quoted context omitted.
[flagged]
You say greed but I would wager that most people in the thread are not financially independent. If someone can't retire from needing money in perpetuity, is it really greed to want to move that needle from "no" closer to "yes"?
Re: Leaking the email of any YouTube user for $10k
#260Earlier quoted context omitted.
How are any of these half baked? (Aside from obvious Siri deficiencies)
Alarms is unreliable for the basic functionality of waking you up. Photos redesign makes it really hard to use. Siri works half of the times, maybe even less than that. Books lacks of basic functionalities such as downloading and keeping books on device.
Photos redesign maybe something you don’t like, but you can hardly call it half baked. All of the functionality is there and there’s a new consistency in how it works that wasn’t there previously.
Books automatically downloads to device. There isn’t a way to read a book without it local.