Live data from Hacker News

Leaking the email of any YouTube user for $10k

brutecat.com

271–280 of 487 posts

Re: Leaking the email of any YouTube user for $10k

#271

Earlier quoted context omitted.

This will enable you to get the private e-mail of the google account that owns the channel, which is not necessarily the same one a channel may give away publicly. So for some channels that provided no contact information, you now can acquire an email address, and for everyone else you may now get an additional one. It also enables you to link multiple channels back to the same person. Every bit of information you ca…

I think we can imagine reasons why this would be valuable. It's a vuln. That's worth know about and fixing. I'm not sure that there are terribly many black market opportunities for "every bit of information" such that this should be a six figure payout or whatever.

Sure, but here's some examples that may be worth a lot of money to the right person, or can just cause a lot of harm:

- Regime critics with a channel on YT.

- Vulnerable individuals and others trying to keep their identity a secret. Putting yourself on YT means putting yourself in front of every deranged individual out there.

- Trump quite famously runs some of his own social media accounts personally, for better or for worse. And even where he doesn't, he probably retains ultimate control - in the case of YT it might be his personal google account that created the channel. He's probably not the only high value target to do so.

Also if you happen to be in any date leak, being able to figure out your private e-mail address gives attackers another place to check whether you re-used a password.

Re: Leaking the email of any YouTube user for $10k

#272
post #162
post #142

Earlier quoted context omitted.

> Day-Month-Year is the standard everywhere in the world apart from the US Nope, the standards are day.month.year, year-month-day, or month/day/year. The problem happens when the delimiter doesn't match the ordering.

Using / as the delimiter with day/month/year is also very common. Here in Brazil, dd/mm/yyyy (or sometimes dd/mm/yy, which used to be more common before year 2000) is the standard.

And then problems happen!

Re: Leaking the email of any YouTube user for $10k

#273
post #241

Earlier quoted context omitted.

Selling a bug is not a crime. > Bounty programs are very much not trying to compete with crime. Nor did my post posit this. Bounty programs should pay a substantial fraction of the downside saved by eliminating the bug, because A) this gives an appropriate incentive for effort and motivate the economically correct amount of outside research, and B) this will feel fair and make people more likely to do what you consid…

How do you propose to calculate "the downside saved by eliminating the bug" - ideally in general, but I'd be curious to see if you could do it even for the specific bug discussed in this article.

Organizations price future, nebulous things all the time.

Imagine a possible downside or two, imagine a probable risk, multiply, discount.

Re: Leaking the email of any YouTube user for $10k

#274
post #241

Earlier quoted context omitted.

Selling a bug is not a crime. > Bounty programs are very much not trying to compete with crime. Nor did my post posit this. Bounty programs should pay a substantial fraction of the downside saved by eliminating the bug, because A) this gives an appropriate incentive for effort and motivate the economically correct amount of outside research, and B) this will feel fair and make people more likely to do what you consid…

Should this be true only for vulns, or all bugs? If I as a third party find a bug that is causing Google to undercharge on ads by a fraction, should Google be obligated to pay me a mountain of cash? Is there any evidence that OP feels that this payout was unfair?

> If I as a third party find a bug that is causing Google to undercharge on ads by a fraction, should Google be obligated to pay me a mountain of cash?

No, but Google should understand that if they give a token payment, people will be less likely to help in future situations like this. And might be inclined to just instead tell ad buyers about the loophole quietly.

Re: Leaking the email of any YouTube user for $10k

#275

Earlier quoted context omitted.

To me its sounds better and more correct to say: February 12th, 2025 Rather than: 12 February 2025 And is easier to say than: The 12th of February 2025 So it's always been natural to write the numeric form the same way, but I am American. I can appreciate day first being easier to sort by machines and having an agreed upon international standard.

Just like the 4th of July, that most American of days

"The 4th of July" is more formal sounding, so it makes sense for the holiday, but many just say "July 4th" more informally when referring to the holiday.

Again grammatically is easier and shorter to say month day vs the day of month.

Re: Leaking the email of any YouTube user for $10k

#276
post #171

Earlier quoted context omitted.

>Massive email databases are extremely cheap, often free There are different qualities of email databases. "Known real email by Youtube account holders" would be a high value database. Definitely not free. This type of vulnerability is extremely valuable for private investigators, too. "Who uploaded this video which my client is extremely interested in?"

>This type of vulnerability is extremely valuable for private investigators, too. "Who uploaded this video which my client is extremely interested in?" Would exploiting this vulnerability violate the Computer Fraud and Abuse Act? If so, would a private investigator really want to do that?

The CFAA is so broad that it's really for the prosecutor to decide you're evil hacker and go after you, even if you didn't do anything bad. Like use view source in a web browser. A PI works around legally grey things anyway, what's the CFAA on top of that?

https://www.stltoday.com/news/local/government-politics/pars...

Re: Leaking the email of any YouTube user for $10k

#277

Earlier quoted context omitted.

I think we can imagine reasons why this would be valuable. It's a vuln. That's worth know about and fixing. I'm not sure that there are terribly many black market opportunities for "every bit of information" such that this should be a six figure payout or whatever.

Sure, but here's some examples that may be worth a lot of money to the right person, or can just cause a lot of harm: - Regime critics with a channel on YT. - Vulnerable individuals and others trying to keep their identity a secret. Putting yourself on YT means putting yourself in front of every deranged individual out there. - Trump quite famously runs some of his own social media accounts personally, for better or…

This is the “heist vs exploit sale” dichotomy that tptacek mentions.

For any vuln you can make up a hypothetical one off usage. But to find the right buyer for that is effectively building a team ala The Great Muppet Caper.

Re: Leaking the email of any YouTube user for $10k

#278

Earlier quoted context omitted.

Alarms is unreliable for the basic functionality of waking you up. Photos redesign makes it really hard to use. Siri works half of the times, maybe even less than that. Books lacks of basic functionalities such as downloading and keeping books on device.

How are alarms unreliable? Photos redesign maybe something you don’t like, but you can hardly call it half baked. All of the functionality is there and there’s a new consistency in how it works that wasn’t there previously. Books automatically downloads to device. There isn’t a way to read a book without it local.

> How are alarms unreliable?

A simple google search will answer this question

https://www.theverge.com/2025/1/9/24340238/apple-iphone-alar...

Even an hn search is fine, if you do not trust the Verge (notice these are comments from the last 3 months so not an old issue):

https://news.ycombinator.com/item?id=42705217 https://news.ycombinator.com/item?id=41887505 https://news.ycombinator.com/item?id=41962418

> Books automatically downloads to device. There isn’t a way to read a book without it local.

Have you used Books extensively or just skimmed it? There's no way to keep books on device, make another Google search if you do not believe me.

> Photos redesign maybe something you don’t like, but you can hardly call it half baked.

Perfect, then keep Photos and kill only alarms, books and Siri.

Re: Leaking the email of any YouTube user for $10k

#279
post #113
post #77

Earlier quoted context omitted.

Does that black-hat vendor already exist? Do they already sell the service of taking $25 to unmask Google users? What calculation does that vendor do about how many customers they'll get before Google notices? Does the exploit developer get a 50% cut? The black-hat vendor is taking all the risk; seems unlikely. Arranging this whole thing is work; finding the "black hat vendor" is work; not getting caught in the proce…

> not getting caught in the process is work Caught for what? If someone sells information about a vulnerability, what law are they breaking? In most jurisdictions, unless you're dumb enough to ask questions about whom your selling to and have active knowledge you're assisting someone in breaking some law, selling to the black market is perfectly legal, at least so long as you pay your taxes. If you're doing grey mark…

The parent is replying to something different (a $25 a pop dox service), just FYI.
Post reply on HN