Live data from Hacker News

Leaking the email of any YouTube user for $10k

brutecat.com

331–340 of 487 posts

Re: Leaking the email of any YouTube user for $10k

#331

Earlier quoted context omitted.

There will be no development. Who is going to spend money to develop it and why would they? Microsoft even decided it wasn’t worth it to develop their own engine. Unless you are using Chromebooks, every desktop user who uses Chrome made an affirmative choice to download it.

> There will be no development. My point is that maybe it is okay? Runaway churn is at least partially responsible for current situation, where most companies simply unable to compete.

What companies are trying to “compete” in the browser space?

Apple has no reason to compete, it can just make more and more functionality for native apps as can Google if it doesn’t have to worry about Chrome anymore.

Microsoft doesn’t care about the browser anymore and just uses Chromium. Firefox’s revenue comes completely from Google. If Google doesn’t have to prop up Firefox for antitrust reasons anymore, why would they?

Re: Leaking the email of any YouTube user for $10k

#332
post #298

Earlier quoted context omitted.

That's not true because there is an economic cost for most people to committing crimes. "Hey you could make more money selling that on the black market" is not going to convince me to sell something on the black market. Bounty programs are very much not trying to compete with crime.

I wonder what your definition of crime is. Legally, in most places of the world it isn't. Morality differs among people too. Profiting off a trillion dollar company will not cross the line for a lot of people.

Most people have an intuitive sense to ask themselves questions like "If I do this, will someone be harmed, who, how much harm, what kind of harm, etc.", that factors into moral decisions.

Almost everyone, even people without a moral sense, have a self-preservation sense- "How likely is it that I will get caught? If I get caught, will I get punished? How bad will the punishment be?" and these factor into a personal risk decision. Laws, among having other purposes, are a convenient way to inform people ahead of time of the risks, in hopes of deterring undesirable behavior.

But most people aren't sociopaths and while they might make fuzzy moral decisions about low-harm low-risk activities, they will shy away from high-harm or high-risk activities, either out of moral sense or self preservation sense or both.

"Stealing from rich companies" is a just a cope. In the case of an exploit against a large company, real innocent people can be harmed, even severely. Exposing whistleblowers or dissidents has even resulted in death.

Re: Leaking the email of any YouTube user for $10k

#334
post #134

Earlier quoted context omitted.

I don't remember if I've ever thanked you for the dose or reality you bring to these discussions, but if not - thank you! Before I started reading your comments on bug bounty payouts I'd probably have made the typical thoughtless (in my case) remark that the bounties are tiny, without actually thinking through the realistic dollar value of bugs found. Not to mention not really thinking through how obviously stupid it…

https://www.youtube.com/watch?v=Y0pdQU87dc8

I think your comment energy is more https://youtu.be/Pzpx9f5ByyA?t=110

Re: Leaking the email of any YouTube user for $10k

#335
post #189
post #73

Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…

I hate how this HN thread is mostly about discussing the amount of bounty, but I'm afraid it's only natural. Most commenters here are working in the software industry and they want to normalize extremely high bounties. It's an extra income source for them. They want higher bug bounties much like they want SWEs to be a highly compensated profession. It's only natural for workers to demand higher pay for their own prof…

I'm not a SWE anymore and haven't been one for a long time.

I think it's in everyone's interest for bug bounties to be higher than harmful markets for the same bug, and a decent fraction of the harms they prevent. That's what is going to result in the economically efficient amount of bug hunting. And it's going to result in a safer world with less cybercrime.

Re: Leaking the email of any YouTube user for $10k

#336

Earlier quoted context omitted.

It is a factor though. Most people will commit non-violent crime for a big enough pay off. Especially one where the individuals effected are hard to identify. If my bug bounty is $10,000 and I can sell it for $20,000 then most people will take the legitimate cash. If it's $10,000 and some black market trader will pay $10,000,000 (obviously exaggerating) then there's a whole mess of people are going to take the ten mi…

Except it's not "legitimate cash" and that's the point. * Are you talking to someone legitimately interested in purchasing and paying you, or is this a sting? * If you're meeting up with someone in person, what is the risk that the person will bring payment or try to attack you? * If you're meeting with someone in person, how do you use $20k in cash without attracting suspicion? How much time will that take? * If it'…

You have discovered the one real practical application of crypto.

Re: Leaking the email of any YouTube user for $10k

#337

Earlier quoted context omitted.

It is a factor though. Most people will commit non-violent crime for a big enough pay off. Especially one where the individuals effected are hard to identify. If my bug bounty is $10,000 and I can sell it for $20,000 then most people will take the legitimate cash. If it's $10,000 and some black market trader will pay $10,000,000 (obviously exaggerating) then there's a whole mess of people are going to take the ten mi…

Except it's not "legitimate cash" and that's the point. * Are you talking to someone legitimately interested in purchasing and paying you, or is this a sting? * If you're meeting up with someone in person, what is the risk that the person will bring payment or try to attack you? * If you're meeting with someone in person, how do you use $20k in cash without attracting suspicion? How much time will that take? * If it'…

It's not a crime to sell a bug. You can sell something like this to Crowdfense and receive money wired from the company (or cryptocurrency if you prefer anonymity).

Re: Leaking the email of any YouTube user for $10k

#338
post #330
post #317

Earlier quoted context omitted.

Year month day makes sense. Month day year makes sense because that's how people talk: I'll be there February 5, etc. Month day year makes no sense because it's backwards, and no one talks that way. So why use that?

> Month day year makes sense because that's how people talk: I'll be there February 5, etc. People also say "twelve past two" and yet you don't use 12:2:SS.

People only say "twelve past two" when they want to be formal and awkward.

Re: Leaking the email of any YouTube user for $10k

#340

I found this title confusing. For those who didn't make it toward the end of the article: the leaked emails didn't cost them anything (except their time and ingenuity), and they received 10k as the bug bounty.

I thought they meant providing the services to leak the email of any user for $10K, perhaps per user. :)
Post reply on HN