Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…
Leaking the email of any YouTube user for $10k
261–270 of 487 posts
Re: Leaking the email of any YouTube user for $10k
#262Earlier quoted context omitted.
So then why do they need additional information about emails? They clearly already can email these youtubers.
This will enable you to get the private e-mail of the google account that owns the channel, which is not necessarily the same one a channel may give away publicly. So for some channels that provided no contact information, you now can acquire an email address, and for everyone else you may now get an additional one. It also enables you to link multiple channels back to the same person. Every bit of information you ca…
I'm not sure that there are terribly many black market opportunities for "every bit of information" such that this should be a six figure payout or whatever.
Re: Leaking the email of any YouTube user for $10k
#263Earlier quoted context omitted.
That's not true because there is an economic cost for most people to committing crimes. "Hey you could make more money selling that on the black market" is not going to convince me to sell something on the black market. Bounty programs are very much not trying to compete with crime.
It is a factor though. Most people will commit non-violent crime for a big enough pay off. Especially one where the individuals effected are hard to identify. If my bug bounty is $10,000 and I can sell it for $20,000 then most people will take the legitimate cash. If it's $10,000 and some black market trader will pay $10,000,000 (obviously exaggerating) then there's a whole mess of people are going to take the ten mi…
* Are you talking to someone legitimately interested in purchasing and paying you, or is this a sting?
* If you're meeting up with someone in person, what is the risk that the person will bring payment or try to attack you?
* If you're meeting with someone in person, how do you use $20k in cash without attracting suspicion? How much time will that take?
* If it's digital, is the person paying you or are the funds being used to pay you clean or the subject of an active investigation? What records are there? If this person is busted soon will you be charged with a crime?
There are a lot of unknowns and a lot of risks, and most people would gladly take a clean $10k they can immediately put in the bank and spend anywhere over the hassle.
Re: Leaking the email of any YouTube user for $10k
#264Earlier quoted context omitted.
Sure, but do adtech companies buy vulnerabilities in web services to advance their mission? Wouldn't that risk running foul of e.g. the Computer Fraud and Abuse Act?
You don‘t need to sell the vulnerability to them, or even tell them the vulnerability is there. Just set up an API and bill them by the query.
Re: Leaking the email of any YouTube user for $10k
#265Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…
I hate how this HN thread is mostly about discussing the amount of bounty, but I'm afraid it's only natural. Most commenters here are working in the software industry and they want to normalize extremely high bounties. It's an extra income source for them. They want higher bug bounties much like they want SWEs to be a highly compensated profession. It's only natural for workers to demand higher pay for their own prof…
I guess bounties fit into the framework somewhere between the Github and middle class engineer.
I think it comes down to supply and demand. It also shows you what Google would pay employees if things were in their favour. On unrelated news, a tech billionaire is almost defacto VP of the US.
Re: Leaking the email of any YouTube user for $10k
#266Earlier quoted context omitted.
That's not true because there is an economic cost for most people to committing crimes. "Hey you could make more money selling that on the black market" is not going to convince me to sell something on the black market. Bounty programs are very much not trying to compete with crime.
Selling a bug is not a crime. > Bounty programs are very much not trying to compete with crime. Nor did my post posit this. Bounty programs should pay a substantial fraction of the downside saved by eliminating the bug, because A) this gives an appropriate incentive for effort and motivate the economically correct amount of outside research, and B) this will feel fair and make people more likely to do what you consid…
Is there any evidence that OP feels that this payout was unfair?
Re: Leaking the email of any YouTube user for $10k
#267Earlier quoted context omitted.
That's not true because there is an economic cost for most people to committing crimes. "Hey you could make more money selling that on the black market" is not going to convince me to sell something on the black market. Bounty programs are very much not trying to compete with crime.
Selling a bug is not a crime. > Bounty programs are very much not trying to compete with crime. Nor did my post posit this. Bounty programs should pay a substantial fraction of the downside saved by eliminating the bug, because A) this gives an appropriate incentive for effort and motivate the economically correct amount of outside research, and B) this will feel fair and make people more likely to do what you consid…
Re: Leaking the email of any YouTube user for $10k
#268Earlier quoted context omitted.
Bug bounty programs are not the only (or even primary) way that security researchers get paid. Google pays employees salaries to find vulns. Bounty programs are a pretty recent development and the idea that they should be scalable and stable well paying employment for a lot of people is a bit strange to me. If security researchers want to have stable employment doing this sort of work, there's oodles of job applicati…
> Bounty programs are a pretty recent development and the idea that they should be scalable and stable well paying employment for a lot of people is a bit strange to me. So, the value to the researcher of having a found bug has a floor of the black market value. The value to Google is whatever the costs of exploitation are: reputational, cleanup, etc. A sane value is somewhere between these two, depending on bargaini…
Re: Leaking the email of any YouTube user for $10k
#269Earlier quoted context omitted.
Probably way too much effort. The apps aren't built for generic infra, but rather Google's internal weirdware. It wouldn't be possible to run it anywhere else without a rewrite.
I agree, and I like this term "internal weirdware". Real question: Why don't we see more start-ups try to clone old terminated Google services with a freemium model?
As sister comments have said there is no money in it. They are stickiness plays or just bets for Google.
Re: Leaking the email of any YouTube user for $10k
#270Earlier quoted context omitted.
Alarms is unreliable for the basic functionality of waking you up. Photos redesign makes it really hard to use. Siri works half of the times, maybe even less than that. Books lacks of basic functionalities such as downloading and keeping books on device.
How are alarms unreliable? Photos redesign maybe something you don’t like, but you can hardly call it half baked. All of the functionality is there and there’s a new consistency in how it works that wasn’t there previously. Books automatically downloads to device. There isn’t a way to read a book without it local.