Wow, if I needed any more proof Google is a ghost ship then this is it. The $5K bounty is an insult, and the fact that they low-balled it in the first place makes them look like absolute clowns. Good on you for calling out how little of a shit Google gives about actually protecting user data.
Nobody is forced to participate in a bug bounty. If you don't like the rewards, don't do it. There's a limit to the financial viability of these programs.
Bruteforcing the phone number of any Google user
101–110 of 204 posts
Re: Bruteforcing the phone number of any Google user
#102This article highlights something interesting... it is quite common to get at least one /64 IPv6 block from a hosting provider or ISP. Yet most of the rate-limiting and IP blocking is done for a single IP. Sounds like when dealing with IPv6, an entire block of /64 should be rate-limited or blocked.
Re: Bruteforcing the phone number of any Google user
#103Earlier quoted context omitted.
How does a new hire know "what it is supposed to be"?
The information is transferred through a method called "communication" by another human.
Re: Bruteforcing the phone number of any Google user
#104Earlier quoted context omitted.
> It must be a daunting chore to maintain all the legacy pages. Clearly $350 billion revenue in 2024 is not enough...
Something that can be hard to appreciate if you haven't managed this sort of project is that it can be surprisingly hard to throw money at the problem. If you try to hire at your regular "bar" for skill for boring work like this - people will often quit. This is one of the reasons many company's integrations are lacking despite it being a strategic interest - integration work is miserable and doesn't help your career…
can you elaborate on this?
Re: Bruteforcing the phone number of any Google user
#105This article highlights something interesting... it is quite common to get at least one /64 IPv6 block from a hosting provider or ISP. Yet most of the rate-limiting and IP blocking is done for a single IP. Sounds like when dealing with IPv6, an entire block of /64 should be rate-limited or blocked.
I'd be rather surprised if IPv6 hasn't done some damage to the idea of IP blocking on the whole. It's possible, even as a residential Internet user, to request a /56 or /48 automatically with DHCPv6 Prefix Delegation. I have a /56 with Comcast. That's potentially up to 65536 /64 blocks, just from a residential user, so if you're going to attempt IP filtering for IPv6, it's got to be a lot smarter than swapping out yo…
Assuming a /64 as a starting point is an easy win and bumping it up with repeat offenders seems pretty easy in the grand scheme of things.
Re: Bruteforcing the phone number of any Google user
#106Earlier quoted context omitted.
In addition to having the money, Google also needs the incentive to spend that money on such projects. If the perceived return on capital is low (or negative!), the incentive is simply not there.
In addition to having the money, Google also needs the incentive to spend that money on such projects. If the perceived return on capital is low (or negative!), the incentive is simply not there. Perhaps Google should Google the concepts of "customer service," "standing behind your product," and "brand reputation."
They're probably satisfied with their reputation with their customers, who are advertisers. The corporate IT folks who buy their G Suite products are also their customers, but overall the majority of the users of Google's software are not their customers, and Google cares about them the same way I care about how the gasoline in my car feels.
Re: Bruteforcing the phone number of any Google user
#107Earlier quoted context omitted.
> It must be a daunting chore to maintain all the legacy pages. Clearly $350 billion revenue in 2024 is not enough...
Google's main search page is the slowest page & UI I have found on the internet today (not accounting for bandwidth limits). Even on modern devices it lags at text entry and even rearranges characters in the text box so you have to wait 10+ seconds for it to finish loading or it will go haywire. The shopping and other pages are actually worse. So it appears you're right, $350B isn't enough money to maintain a web pag…
Re: Bruteforcing the phone number of any Google user
#108Earlier quoted context omitted.
How does a new hire know "what it is supposed to be"?
The information is transferred through a method called "communication" by another human.
If something is obvious, sure, but how is the new intern even going to know when to ask?
Re: Bruteforcing the phone number of any Google user
#109Earlier quoted context omitted.
The information is transferred through a method called "communication" by another human.
What is the point of assigning something to a new hire, if they can't do it without another person watching the whole thing over their shoulder AND they are unlikely to benefit from this knowledge in the future (since it's a legacy page that is supposed to be deleted)?
How are we seriously this obtuse? Is it deliberate?
Re: Bruteforcing the phone number of any Google user
#110I did something similar way back when I was trying to find the phone number for a person, using Facebook. When recovering a password Facebook would give you most of the digits of the phone number, so I wrote them down in a vcard file and imported it on my phone to just look at the pictures. It worked surprisingly good.
This is why I don't use a real phone number with any of these services. They don't need my phone number to operate either.