Earlier quoted context omitted.
That's probably another reason why Google kills so many products that are successful, but not successful enough for Google's whole system to justify keeping them alive and secure.
Maybe Apple should do the same and kill their many half-baked software products.
Leaking the email of any YouTube user for $10k
191–200 of 487 posts
Re: Leaking the email of any YouTube user for $10k
#192Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…
In this case there were 4 billion email addresses on the line from being scraped, imagine if this was exploited and the data was leaked. The news would hit the headliners which would definitely be bad for Google's reputation and stock price.
However, the impact of the leak is not that high as it only consists of a channel email address mapping, and therefore I think 10k is a fair price
Re: Leaking the email of any YouTube user for $10k
#193Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…
> Threat actors buy vulnerabilities that fit into existing business processes Selling crazy stories to the media is as old as time. This vuln would give you a lookup table from email->YT SELECT * FROM table WHERE email LIKE “%.gov”
Come on.
Re: Leaking the email of any YouTube user for $10k
#194Earlier quoted context omitted.
Some malicious mail that grants remote access to the employees device? Its not that hard to understand.
Actually it is hard to understand because that employee's device isn't an attack vector.
Re: Leaking the email of any YouTube user for $10k
#195Am I very naive expecting the payout to be significantly higher?
To me, that payout felt quite high; it's bigger than the average monthly salary for a senior IT professional where I live. To put it another way, that bounty alone would be like being paid for several months of full-time employment.
Re: Leaking the email of any YouTube user for $10k
#196After reading the article top to bottom I still had to come to the comments to find out what the "for $10,000" was about. It's the payout for a bug bounty.
> Timeline
> 05/11/24 - Panel awards $3,133.
> 12/12/24 - Panel awards an additional $7,500.
Re: Leaking the email of any YouTube user for $10k
#197Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…
I hate how this HN thread is mostly about discussing the amount of bounty, but I'm afraid it's only natural. Most commenters here are working in the software industry and they want to normalize extremely high bounties. It's an extra income source for them. They want higher bug bounties much like they want SWEs to be a highly compensated profession. It's only natural for workers to demand higher pay for their own prof…
Re: Leaking the email of any YouTube user for $10k
#198Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…
How big of a threat is it/what impact will it have on business/reputation/etc.?
How likely is it to be exploited and how widely would it be considered useful to the market of threat actors?
Re: Leaking the email of any YouTube user for $10k
#199Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…
Most other fields of endeavor aren’t compensated based on the black market value of the thing that’s being produced. If we apply your analysis to other things, we’ll find that the upper bound price for a new car stereo or bike is ~ $100, and the price of any copyrighted good is bounded by the cost of transferring it over the network. I think it is more useful to divide the amount Google paid by the number of hours sp…
If security researchers want to have stable employment doing this sort of work, there's oodles of job applications they can send out.
Re: Leaking the email of any YouTube user for $10k
#200Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…
> because $10,000 feels extraordinarily high for a server-side web bug. Am I misunderstanding the bug? In my reading, this bug translates to "a list of the top 1,000 Youtube accounts' email addresses (or as many as you can get until Google detects it and shuts it down)." Why isn't that conceivably worth more than $10,000?
Our emails get leaked all the time in data breaches, sometimes alongside much more important information such as home addresses etc..
This was certainly a bad leak that could be used to further dox people by connecting the email to other leaked info or other sources, but from Google's perspective, all they did was leak the email.
It was a privacy breach for sure.
But further doxxing based on the email would be "not their problem" I suspect they would say.