Live data from Hacker News

Leaking YouTube creators' private videos

javoriuski.com

41–50 of 436 posts

Re: Leaking YouTube creators' private videos

#42

I recently left Google having worked on a number of projects with various YouTube teams. I think I can explain why it's being handled this way by YouTube. This is a fairly nuanced/involved issue, so the task of classifying the bug likely made it's way to one of the engineers responsible for the implementation of this feature. That engineer has already launched this project, and filed it away under their GRAD (perform…

Of all the fucked up things in this comment, giving a single Engineer lifetime responsibility for all bugs in code they wrote is probably the dumbest.

And it's slowly becoming the norm. The last place I worked at, a large and well known Tech company, didn't even roll with QA's. That just wasn't a role anywhere in the division. You are fully responsible for all the bugs in all the code you ever wrote

Cute at first. Unsustainable in the long term

Re: Leaking YouTube creators' private videos

#43
post #31

Earlier quoted context omitted.

You're in for a surprise then, because this article is clearly in an LLM style. That doesn't mean it's hallucinated, no, there is a real human behind, but the actual content that you enjoyed is LLM-written.

It's no secret LLM's can disseminate news in a superior fashion to 99% of human writers, when instructed properly

Confession:

I sometimes ask an LLM to explain something to a certain kind of audience. Usually I need to ask it to keep things briefer and which things to really focus on. I typically do 2-3 iterations and then manual editing to make it feel like 'me'. This would be for a 2-3 sentence kind of thing.

Not a native English speaker. I used to think I was pretty good, but I get way less misunderstood this way.

(I didn't use an LLM for this message.)

Re: Leaking YouTube creators' private videos

#45

Earlier quoted context omitted.

They care. They'll fix it. They just won't pay the bounty for this bug.

I feel like it would be cheaper to pay a few bounties you dont really agree with than to risk a bad rep with security researchers.il Its still a relatively small community. Besides, if you don't pay the competition will, and ther use cases for your vulns are unlikely to be good for your business.

Google? And bad rep? Surely you jest

Re: Leaking YouTube creators' private videos

#46

Earlier quoted context omitted.

Glad to hear this is a universal big tech experience. The promo process is entirely antithetical to shipping good products

What do you mean? Youtube is unquestionably one of the most successful projects ever launched? Seems like the process works astoundingly well.

Youtube survives on google's massive repertoire of products being vastly more profitable, not because it's the best of its kind.

Re: Leaking YouTube creators' private videos

#47
post #38

> Attacker leaves the comment on a creator's video. > Creator opens YouTube studio's comment tab. > Creator clicks a suggested AI prompt (Designed by YouTube) > Injection fires, attacker-controlled content appears in the response. It's insane that YouTube doesn't see prompt injection as a bug.

Yeah, if going to site and just clicking a link given to me by the site itself is getting socially engineered, then something is very wrong with that site.

Re: Leaking YouTube creators' private videos

#48

Earlier quoted context omitted.

Glad to hear this is a universal big tech experience. The promo process is entirely antithetical to shipping good products

What do you mean? Youtube is unquestionably one of the most successful projects ever launched? Seems like the process works astoundingly well.

And you honestly believe the main factor in YouTube success was the quality of the code?

That's a thought that doesn't even deserve further comment.

Re: Leaking YouTube creators' private videos

#49
post #33

Earlier quoted context omitted.

What do you mean? Youtube is unquestionably one of the most successful projects ever launched? Seems like the process works astoundingly well.

Good != Successful. I assume that's why they wrote good and not successful. It's an average software product with incredible scaling behind it and a lot of elbow grease to keep it chumming along, but it's not great software by the definition of "bugs actually get dealt with"

It's great software in the sense that it makes a shit ton of money though. In the end software that doesn't get used and doesn't make any money but has no bugs is not valuable either.

Not saying that this is the trade off you have to make but if you have a working mode in place that achieves usage and money somewhat consistently i can understand being hesitant about changing it to optimize for less bugs instead.

Re: Leaking YouTube creators' private videos

#50
post #38

> Attacker leaves the comment on a creator's video. > Creator opens YouTube studio's comment tab. > Creator clicks a suggested AI prompt (Designed by YouTube) > Injection fires, attacker-controlled content appears in the response. It's insane that YouTube doesn't see prompt injection as a bug.

Well prompt injection is pretty much unfixable. So if they actually saw this as a security vulnerability they would have to remove this feature.
Post reply on HN