Earlier quoted context omitted.
How do you propose to calculate "the downside saved by eliminating the bug" - ideally in general, but I'd be curious to see if you could do it even for the specific bug discussed in this article.
Organizations price future, nebulous things all the time. Imagine a possible downside or two, imagine a probable risk, multiply, discount.
Leaking the email of any YouTube user for $10k
281–290 of 487 posts
Re: Leaking the email of any YouTube user for $10k
#282Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…
- monetize the bug themselves; i.e. set up a site where you can submit a YouTube user id, pay some fee using your credit card and get an e-mail address.
- report that they have the ability to convert any YouTube id to an e-mail, with proof: then negotiate over compensation for the disclosure of the details
- just report the problem and be happy with whatever they get.
Ten grand doesn't look too bad for the most timid choice.
Re: Leaking the email of any YouTube user for $10k
#283Earlier quoted context omitted.
I think a simple way to think of it is: how much would an adversarial nation state buy this exploit for? I just don't think Russia would be willing to pay $100,000 to get Mr. Beast's email address, even if that sounds tempting to you.
Why a nation state? My hypothetical is a phishing ring that sends an official-looking phishing email to 1000 non-public email accounts that typically only get emails from Youtube. The exploit can be valued at: number of emails * probability that you'll phish them into letting you in * value of posting a "Free Robux" scam on a channel with 100M subscribers.
I feel like you are just taking into account the theoretical max value of a bad actor having these accounts, not the cost/risk of using this knowledge.
I could have the master key of a bank safe with 100MM worth of gold in the basement, but it's value is going to be nowhere near that, even to bad actors.
Re: Leaking the email of any YouTube user for $10k
#284Earlier quoted context omitted.
Organizations price future, nebulous things all the time. Imagine a possible downside or two, imagine a probable risk, multiply, discount.
Sure, but give some specific values. What potential damages and potential risk multiply to more than $10k?
Large scale data leak and need for data leak disclosure. 1 in 3, moderate cost.
Bug report saving engineering time by giving clear report of issue instead of having to dig through telemetry and figure out misuse and then identify what is going on, extents of past damage, etc. 3 in 4.
Re: Leaking the email of any YouTube user for $10k
#285Earlier quoted context omitted.
This ignores tptacek's points in the top-level post. > [...] a bug that Google can kill instantaneously, that has effectively no half-life once discovered, and whose exploitation will generate reliable telemetry from the target. You can't set up unmask-as-a-service because it's going to take you longer to get clients than it will take Google to shut down your exploit.
Yes, but: 1. It can still take a while before Google finds out 2. You can log every mapping you got in the meanwhile, then keep selling the ones you already have Edit: although probably most of your business will be over when word gets out that your data isn’t exactly legal (which your clients have understood from the start, of course; they could just plead ignorance)
So let's suppose that you did set up the service like this. Can you even make 10 K? What are your odds of getting caught? How much do you value not being in prison and/or having to hire a lawyer to get you out of there?
I'd take the 10k every time.
Re: Leaking the email of any YouTube user for $10k
#286Earlier quoted context omitted.
How are any of these half baked? (Aside from obvious Siri deficiencies)
Alarms is unreliable for the basic functionality of waking you up. Photos redesign makes it really hard to use. Siri works half of the times, maybe even less than that. Books lacks of basic functionalities such as downloading and keeping books on device.
Go to library > collections > downloaded.
I can see books I purchased and other PDFs that I uploaded.
I do agree on the Photos redesign. I feel like I constantly get stuck on certain pages.
Re: Leaking the email of any YouTube user for $10k
#287Re: Leaking the email of any YouTube user for $10k
#288Earlier quoted context omitted.
How are alarms unreliable? Photos redesign maybe something you don’t like, but you can hardly call it half baked. All of the functionality is there and there’s a new consistency in how it works that wasn’t there previously. Books automatically downloads to device. There isn’t a way to read a book without it local.
> How are alarms unreliable? A simple google search will answer this question https://www.theverge.com/2025/1/9/24340238/apple-iphone-alar... Even an hn search is fine, if you do not trust the Verge (notice these are comments from the last 3 months so not an old issue): https://news.ycombinator.com/item?id=42705217 https://news.ycombinator.com/item?id=41887505 https://news.ycombinator.com/item?id=41962418 > Books aut…
I haven’t used Books extensively outside of audiobooks. So it sounds like there’s offloading of caching going on that’s iCloud wide; disabling iCloud sync would fix this. I can imagine that being frustrating if the book you want isn’t there when you’re on a flight (which should only happen if you haven’t recently accessed it). I agree there should be a way to prevent this. I wouldn’t call that half baked, but it’s a big enough problem I’d agree that’s not fully thought through (or more likely, they did think through it but came to a different conclusion).
Re: Leaking the email of any YouTube user for $10k
#289Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…
Most other fields of endeavor aren’t compensated based on the black market value of the thing that’s being produced. If we apply your analysis to other things, we’ll find that the upper bound price for a new car stereo or bike is ~ $100, and the price of any copyrighted good is bounded by the cost of transferring it over the network. I think it is more useful to divide the amount Google paid by the number of hours sp…
They're buying exclusive access to some information, which is a somewhat unusual thing to pay for.
News reporters do take spicy stories to tabloids, rather than the normal press, as the tabloids will pay more.
Re: Leaking the email of any YouTube user for $10k
#290Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…