Live data from Hacker News

Leaking the email of any YouTube user for $10k

brutecat.com

261–270 of 487 posts

Re: Leaking the email of any YouTube user for $10k

#261
post #73

Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…

What’s the value of the mailing list with every YouTube users email address ?

Re: Leaking the email of any YouTube user for $10k

#262

Earlier quoted context omitted.

So then why do they need additional information about emails? They clearly already can email these youtubers.

This will enable you to get the private e-mail of the google account that owns the channel, which is not necessarily the same one a channel may give away publicly. So for some channels that provided no contact information, you now can acquire an email address, and for everyone else you may now get an additional one. It also enables you to link multiple channels back to the same person. Every bit of information you ca…

I think we can imagine reasons why this would be valuable. It's a vuln. That's worth know about and fixing.

I'm not sure that there are terribly many black market opportunities for "every bit of information" such that this should be a six figure payout or whatever.

Re: Leaking the email of any YouTube user for $10k

#263

Earlier quoted context omitted.

That's not true because there is an economic cost for most people to committing crimes. "Hey you could make more money selling that on the black market" is not going to convince me to sell something on the black market. Bounty programs are very much not trying to compete with crime.

It is a factor though. Most people will commit non-violent crime for a big enough pay off. Especially one where the individuals effected are hard to identify. If my bug bounty is $10,000 and I can sell it for $20,000 then most people will take the legitimate cash. If it's $10,000 and some black market trader will pay $10,000,000 (obviously exaggerating) then there's a whole mess of people are going to take the ten mi…

Except it's not "legitimate cash" and that's the point.

* Are you talking to someone legitimately interested in purchasing and paying you, or is this a sting?

* If you're meeting up with someone in person, what is the risk that the person will bring payment or try to attack you?

* If you're meeting with someone in person, how do you use $20k in cash without attracting suspicion? How much time will that take?

* If it's digital, is the person paying you or are the funds being used to pay you clean or the subject of an active investigation? What records are there? If this person is busted soon will you be charged with a crime?

There are a lot of unknowns and a lot of risks, and most people would gladly take a clean $10k they can immediately put in the bank and spend anywhere over the hassle.

Re: Leaking the email of any YouTube user for $10k

#264

Earlier quoted context omitted.

Sure, but do adtech companies buy vulnerabilities in web services to advance their mission? Wouldn't that risk running foul of e.g. the Computer Fraud and Abuse Act?

You don‘t need to sell the vulnerability to them, or even tell them the vulnerability is there. Just set up an API and bill them by the query.

An API is too much work. Grab the addresses for the top 100,000 YouTubers and sell that csv on the dark web.

Re: Leaking the email of any YouTube user for $10k

#265
post #189
post #73

Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…

I hate how this HN thread is mostly about discussing the amount of bounty, but I'm afraid it's only natural. Most commenters here are working in the software industry and they want to normalize extremely high bounties. It's an extra income source for them. They want higher bug bounties much like they want SWEs to be a highly compensated profession. It's only natural for workers to demand higher pay for their own prof…

SWE comp is weird in that typically it is zero (see what's on Github!) often it us middle class and sometimes it is small scale CEO (as in the actual job not a founder) level.

I guess bounties fit into the framework somewhere between the Github and middle class engineer.

I think it comes down to supply and demand. It also shows you what Google would pay employees if things were in their favour. On unrelated news, a tech billionaire is almost defacto VP of the US.

Re: Leaking the email of any YouTube user for $10k

#266
post #241

Earlier quoted context omitted.

That's not true because there is an economic cost for most people to committing crimes. "Hey you could make more money selling that on the black market" is not going to convince me to sell something on the black market. Bounty programs are very much not trying to compete with crime.

Selling a bug is not a crime. > Bounty programs are very much not trying to compete with crime. Nor did my post posit this. Bounty programs should pay a substantial fraction of the downside saved by eliminating the bug, because A) this gives an appropriate incentive for effort and motivate the economically correct amount of outside research, and B) this will feel fair and make people more likely to do what you consid…

Should this be true only for vulns, or all bugs? If I as a third party find a bug that is causing Google to undercharge on ads by a fraction, should Google be obligated to pay me a mountain of cash?

Is there any evidence that OP feels that this payout was unfair?

Re: Leaking the email of any YouTube user for $10k

#267
post #241

Earlier quoted context omitted.

That's not true because there is an economic cost for most people to committing crimes. "Hey you could make more money selling that on the black market" is not going to convince me to sell something on the black market. Bounty programs are very much not trying to compete with crime.

Selling a bug is not a crime. > Bounty programs are very much not trying to compete with crime. Nor did my post posit this. Bounty programs should pay a substantial fraction of the downside saved by eliminating the bug, because A) this gives an appropriate incentive for effort and motivate the economically correct amount of outside research, and B) this will feel fair and make people more likely to do what you consid…

How do you propose to calculate "the downside saved by eliminating the bug" - ideally in general, but I'd be curious to see if you could do it even for the specific bug discussed in this article.

Re: Leaking the email of any YouTube user for $10k

#268
post #211

Earlier quoted context omitted.

Bug bounty programs are not the only (or even primary) way that security researchers get paid. Google pays employees salaries to find vulns. Bounty programs are a pretty recent development and the idea that they should be scalable and stable well paying employment for a lot of people is a bit strange to me. If security researchers want to have stable employment doing this sort of work, there's oodles of job applicati…

> Bounty programs are a pretty recent development and the idea that they should be scalable and stable well paying employment for a lot of people is a bit strange to me. So, the value to the researcher of having a found bug has a floor of the black market value. The value to Google is whatever the costs of exploitation are: reputational, cleanup, etc. A sane value is somewhere between these two, depending on bargaini…

As mentioned by thread starter, you can also sell to some national security agency. That way, you're doing your patriotic duty and making a buck. So Google has an incentive to at least beat those offerings.

Re: Leaking the email of any YouTube user for $10k

#269

Earlier quoted context omitted.

Probably way too much effort. The apps aren't built for generic infra, but rather Google's internal weirdware. It wouldn't be possible to run it anywhere else without a rewrite.

I agree, and I like this term "internal weirdware". Real question: Why don't we see more start-ups try to clone old terminated Google services with a freemium model?

There probably are. The real question is why are they not successful. Maybe they need to solve distribution. I use Google Calendar tasks for todos because it is there, handy, for example.

As sister comments have said there is no money in it. They are stickiness plays or just bets for Google.

Re: Leaking the email of any YouTube user for $10k

#270

Earlier quoted context omitted.

Alarms is unreliable for the basic functionality of waking you up. Photos redesign makes it really hard to use. Siri works half of the times, maybe even less than that. Books lacks of basic functionalities such as downloading and keeping books on device.

How are alarms unreliable? Photos redesign maybe something you don’t like, but you can hardly call it half baked. All of the functionality is there and there’s a new consistency in how it works that wasn’t there previously. Books automatically downloads to device. There isn’t a way to read a book without it local.

They are not. I haven't seen an unreliable alarm since the digital age. 1980s LED alarm clocks were reliable.
Post reply on HN