Live data from Hacker News

Leaking the email of any YouTube user for $10k

brutecat.com

321–330 of 487 posts

Re: Leaking the email of any YouTube user for $10k

#321
post #134
post #73

Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…

I don't remember if I've ever thanked you for the dose or reality you bring to these discussions, but if not - thank you! Before I started reading your comments on bug bounty payouts I'd probably have made the typical thoughtless (in my case) remark that the bounties are tiny, without actually thinking through the realistic dollar value of bugs found. Not to mention not really thinking through how obviously stupid it…

https://www.youtube.com/watch?v=Y0pdQU87dc8

Re: Leaking the email of any YouTube user for $10k

#322

Earlier quoted context omitted.

> That’s part of the stupidity of the DOJ trying to force Google to sell Chrome. Who would want it? And how would they profit from it? All valid questions, but it might be that splitting the tool used to bludgeon everyone around is still worth it, even if pace of development slows down considerably.

There will be no development. Who is going to spend money to develop it and why would they? Microsoft even decided it wasn’t worth it to develop their own engine. Unless you are using Chromebooks, every desktop user who uses Chrome made an affirmative choice to download it.

> There will be no development.

My point is that maybe it is okay? Runaway churn is at least partially responsible for current situation, where most companies simply unable to compete.

Re: Leaking the email of any YouTube user for $10k

#323

Earlier quoted context omitted.

> What are you talking about? Your tone is aggressive and uncalled for. In fact, the fact that you have never found a very common bug says a lot about your inattention to detail. There's no "keep forever on device" button, which to me seems like a basic functionality. If the app decides to delete them, it will. https://old.reddit.com/r/ios/comments/1b04rzy/apple_what_wer... https://news.ycombinator.com/item?id=237365…

Oh okay, but that’s not what you said? You implied that no books could be downloaded at all which is just not true. iCloud offload is a pretty common feature on Apple devices and one that I find pretty handy. I understand why it doesn’t work for others though. You can turn off iCloud sync in general for the device.

I don't think I have implied that. I have said that there's no functionality to download and keep files on device, which is true, because you cannot trust the device will not delete your files without your permission (or even without warning you first). But I'm not a native speaker so I could have been misunderstood.

Re: Leaking the email of any YouTube user for $10k

#324
post #73

Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…

[deleted]

Re: Leaking the email of any YouTube user for $10k

#325
post #285

Earlier quoted context omitted.

Yes, but: 1. It can still take a while before Google finds out 2. You can log every mapping you got in the meanwhile, then keep selling the ones you already have Edit: although probably most of your business will be over when word gets out that your data isn’t exactly legal (which your clients have understood from the start, of course; they could just plead ignorance)

People keep talking about this as if there's a 0% chance of being caught if you do this?. So let's suppose that you did set up the service like this. Can you even make 10 K? What are your odds of getting caught? How much do you value not being in prison and/or having to hire a lawyer to get you out of there? I'd take the 10k every time.

You’re talking about this as if there aren’t other countries who actively infiltrate power infrastructure and for whom this is the most low risk mild attack (if you can call it that)

I’m not speaking theoretically, which I suspect most on this thread are.

Re: Leaking the email of any YouTube user for $10k

#326

> That params is nothing more than just base64 encoded protobuf, which is a common encoding format used throughout Google. Pour one out for the google dev in charge of b64 encoding their fancy binary message format so it can be jammed inside a JSON blob. If you want a vision of the future, imagine a boot with "worse is better" imprinted on the sole stomping on an engineer's face, forever.

JSON string of base64 encoded protocol buffer...you don't need to know what company did that to know what company did that.

Re: Leaking the email of any YouTube user for $10k

#327

Earlier quoted context omitted.

People don’t want to pay for things.

I want. And I do. Notable examples are Kagi.com and Raindrop.io. I've also been sponsoring a number of projects for a number of months, from journalism to social media startup. But I am getting more hesitant as often when I (and others) do it seems companies think they can increase their prices wildly or do other stuff. I have this exact feeling now with Logseq: I started paying for sync a while ago and it seems so d…

How many of those companies are profitable? How many do you think you will see a blog post about in a year or two - “Our Amazing Journey” where they won’t either go out of business or get acquired and their product gets shut down”?

From Kagi’s website

https://blog.kagi.com/status-update-first-three-months#:~:te...

We are currently serving around 2.1M queries a month, costing us around $26,250 USD/month.

Between Kagi and Orion, we are currently generating around $26,500 USD in monthly recurring revenue, which incidentally about exactly covers our current API and infrastructure costs.

That means that salaries and all other operating costs (order of magnitude of $100K USD/month) remain a challenge and are still paid out of the founders’ pocket (Kagi remains completely bootstrapped).

Re: Leaking the email of any YouTube user for $10k

#329

> That params is nothing more than just base64 encoded protobuf, which is a common encoding format used throughout Google. Pour one out for the google dev in charge of b64 encoding their fancy binary message format so it can be jammed inside a JSON blob. If you want a vision of the future, imagine a boot with "worse is better" imprinted on the sole stomping on an engineer's face, forever.

Internally, it would be a b64 protobuf in a protobuf field. The json part is an automatic conversion.

Huh?

Internally, it is (maybe) a binary field of a protobuf.

Then when translating to JSON, it was converted to a string via base64 encoding.

Re: Leaking the email of any YouTube user for $10k

#330
post #317
post #111

Earlier quoted context omitted.

For a person born and raised in metric system, MM/DD/YY is just as bonkers as if someone decided that MM:HH:SS makes sense.

Year month day makes sense. Month day year makes sense because that's how people talk: I'll be there February 5, etc. Month day year makes no sense because it's backwards, and no one talks that way. So why use that?

> Month day year makes sense because that's how people talk: I'll be there February 5, etc.

People also say "twelve past two" and yet you don't use 12:2:SS.

Post reply on HN