Live data from Hacker News

Leaking the email of any YouTube user for $10k

brutecat.com

291–300 of 487 posts

Re: Leaking the email of any YouTube user for $10k

#291

Earlier quoted context omitted.

Alarms is unreliable for the basic functionality of waking you up. Photos redesign makes it really hard to use. Siri works half of the times, maybe even less than that. Books lacks of basic functionalities such as downloading and keeping books on device.

What are you talking about? I’ve got the books app open now, I can see all of my downloaded books. In fact there’s a whole section in the library for my downloaded books! Go to library > collections > downloaded. I can see books I purchased and other PDFs that I uploaded. I do agree on the Photos redesign. I feel like I constantly get stuck on certain pages.

> What are you talking about?

Your tone is aggressive and uncalled for. In fact, the fact that you have never found a very common bug says a lot about your inattention to detail.

There's no "keep forever on device" button, which to me seems like a basic functionality. If the app decides to delete them, it will.

https://old.reddit.com/r/ios/comments/1b04rzy/apple_what_wer...

https://news.ycombinator.com/item?id=23736536

https://apple.stackexchange.com/questions/344271/books-autom...

Re: Leaking the email of any YouTube user for $10k

#292
post #185
post #73

Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…

Most other fields of endeavor aren’t compensated based on the black market value of the thing that’s being produced. If we apply your analysis to other things, we’ll find that the upper bound price for a new car stereo or bike is ~ $100, and the price of any copyrighted good is bounded by the cost of transferring it over the network. I think it is more useful to divide the amount Google paid by the number of hours sp…

I think the right comparison to make here is art. The compensation floor is zero, and, in fact, that's what most vuln research pays.

Re: Leaking the email of any YouTube user for $10k

#293

Earlier quoted context omitted.

It is a factor though. Most people will commit non-violent crime for a big enough pay off. Especially one where the individuals effected are hard to identify. If my bug bounty is $10,000 and I can sell it for $20,000 then most people will take the legitimate cash. If it's $10,000 and some black market trader will pay $10,000,000 (obviously exaggerating) then there's a whole mess of people are going to take the ten mi…

Except it's not "legitimate cash" and that's the point. * Are you talking to someone legitimately interested in purchasing and paying you, or is this a sting? * If you're meeting up with someone in person, what is the risk that the person will bring payment or try to attack you? * If you're meeting with someone in person, how do you use $20k in cash without attracting suspicion? How much time will that take? * If it'…

The "legitimate cash" option is the bug bounty without the risk. I think you are saying the same thing.

Re: Leaking the email of any YouTube user for $10k

#294
post #185
post #73

Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…

Most other fields of endeavor aren’t compensated based on the black market value of the thing that’s being produced. If we apply your analysis to other things, we’ll find that the upper bound price for a new car stereo or bike is ~ $100, and the price of any copyrighted good is bounded by the cost of transferring it over the network. I think it is more useful to divide the amount Google paid by the number of hours sp…

>Most other fields of endeavor aren’t compensated based on the black market value of the thing that’s being produced.

What you’re saying can be seen as tautological. The reason a gray/black market exists is precisely because the field is undercompensating (aka in disequilibrium)

Re: Leaking the email of any YouTube user for $10k

#295
post #73

Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…

There is kind of a market for server side vulnerabilities but I'm not sure if you would call it grey. I suspect ZDI will purchase commodity server side vulnerabilities ( https://www.zerodayinitiative.com/ ). So stuff like apache, nginx, and maybe opensource webapps that have a narrower usage.

ZDI claims they'll pay for bugs in serverside software, which is a different meaning of the term "serverside" than I'm using (admittedly, that definition is more precise). An nginx bug has a half-life once discovered. A Youtube bug does not.

I'm a little skeptical of published prices for serverside software, though. Do you know anyone who specializes in selling those bugs? I don't.

Re: Leaking the email of any YouTube user for $10k

#296
I see a lot of noise made about responsible disclosure, its drivers, and its rewards. What I don't see is talk about how this is one more datapoint against centralized permanent identities.

Every time I see a service purporting that it works best only with a single link to your Real Identity™, I'm reminded that the vendors only abstractly care about actually protecting the user, and then only sometimes.

Imagine being able get immediately three or four steps closer to doxing anyone interacting on YouTube. That's the actual impact of this bug IMO. It's good that this was fixed, but I don't think this class of bug goes away anytime soon. What do we need to do to get vendors and big companies to realize that this sort of design is landmines waiting to happen?

Re: Leaking the email of any YouTube user for $10k

#297
post #188

Earlier quoted context omitted.

You are imagining a market that doesn’t exist. First there are only very few gobs/companies that are sketchy enough to do this - and for those a huge number of non-anonymous people exist with huge reach that are very critical for years. If such a market would exist they would assassinate all those first - you don’t need the email if you have the face, voice, and name - since that is not happening they just don’t care…

There’s 100% an active market for this, and I think tptacek is simply wrong on this point (the others are valid) The likes of Cambridge Analytica didn’t go away, they exist and absolutely go hunting for data like this. The ability to map between different identifiers and pieces of content on the internet is central to so many things - why do you think adtech tries to join so many datapoints? Let alone things like inf…

I think you've missed my point. I know data brokers exist. Does there exist today a data broker that functions in whole or in significant part buy acquiring vulnerabilities and exploiting them to collect data? He's a more concise way to frame my argument: if you're imagining yourself to be the first person to sell a particular kind of vulnerability to, then your customer is imaginary.

Re: Leaking the email of any YouTube user for $10k

#298
post #211

Earlier quoted context omitted.

> Bounty programs are a pretty recent development and the idea that they should be scalable and stable well paying employment for a lot of people is a bit strange to me. So, the value to the researcher of having a found bug has a floor of the black market value. The value to Google is whatever the costs of exploitation are: reputational, cleanup, etc. A sane value is somewhere between these two, depending on bargaini…

That's not true because there is an economic cost for most people to committing crimes. "Hey you could make more money selling that on the black market" is not going to convince me to sell something on the black market. Bounty programs are very much not trying to compete with crime.

I wonder what your definition of crime is.

Legally, in most places of the world it isn't.

Morality differs among people too. Profiting off a trillion dollar company will not cross the line for a lot of people.

Re: Leaking the email of any YouTube user for $10k

#299

Earlier quoted context omitted.

Oh darn, my youtube email was leaked... It certainly stinks that mybusinessname@gmail.com is now known to the world... There's certainly bad things that CAN be done to a number of people with information when it's a personal email address that's used for numerous purposes... but the 3 people I talked to about having youtube (or any streaming) accounts all have mentioned it as being a separate account. So the only thr…

Increasing the ease of phishing the top 1000 YouTube accounts seems like a pretty serious threat to me.

But as I tried to highlight, the more valuable the YouTube account, the more likely they actually have an account manager at Google. Additionally, they probably have staff, and it's not actually the "star" that you would be emailing... Once you gain access to their YouTube account, what could you actually do to harm them? Upload a video that encourages somebody to go to a website and do a thing? It would probably get reported fairly quickly.. and it probably wouldn't look like a normal video for that channel, so it might stand out... It's just a very weird attack vector that is more easily achieved without spending lots of money to unmask email addresses. The fake Elon Musk profiles/accounts pushing watches or telling people to buy crypto are infinitely cheaper and probably more effective.. you could just make an account that pretends to be the person you're trying to scam and make comments on their videos
Post reply on HN