Live data from Hacker News

Leaking YouTube creators' private videos

javoriuski.com

211–220 of 436 posts

Re: Leaking YouTube creators' private videos

#211
post #149

Earlier quoted context omitted.

[flagged]

> This is a prime example of why programmers are not seriously considered engineers. The problem isn't the programmers ffs. In your industry, if your superior orders you (or creates the incentive) to hide bad stuff under the rug, you have the ability to push back, at least to some degree. Programmers? We don't have that. Maybe the few of us who actually work on security critical stuff, but some generic AI BS? No chan…

I'm working on automotive safety-critical security-critical stuff. There is structure and bureaucracy around this stuff.

For example, a project gets a safety managers assigned who has to sign off the release. Project management is explicitly not superior to this safety manager. In most cases these safety managers are just there review stuff according to some process guidelines. If there is pressure (project is late, etc), there are more senior safety managers to call in and they will usually make more nuanced safety arguments (in this specific case, violate this guideline, but at least do X as mitigation).

In the end there is bureaucracy. Things need to be signed and archived for potential law suits. Not having archived things will be even worse in the law suits.

The upside: As a programmer, you don't need to argue that you need some time for unit testing.

The downside: 100% test coverage is mandatory and it really gets enforced.

Re: Leaking YouTube creators' private videos

#212
post #147

Earlier quoted context omitted.

If you allowlist javascript then yes your annoyance is tangential, and no it is not interesting for us to read you complain about. Hence why the HN guideline (that was quoted above) exists. (I also allowlist javascript. Regardless of your philosophical standpoint, many websites do break. If you don’t want “smacks me in the face multiple times a day” then stop allowlisting javascript.)

Comments whinging about this are not any more interesting to read either, even if they do not break discussion guidelines themselves. Use the flag button. This is what it's for.

Interesting choice of word; I wasn’t whinging, just trying to explain to the other commenter something useful. Flagging gives zero detail or nuance. Which presumably is why you replied instead of flagging my comment ;)

Re: Leaking YouTube creators' private videos

#213

Earlier quoted context omitted.

I feel like it would be cheaper to pay a few bounties you dont really agree with than to risk a bad rep with security researchers.il Its still a relatively small community. Besides, if you don't pay the competition will, and ther use cases for your vulns are unlikely to be good for your business.

Google? And bad rep? Surely you jest

I'm not and don't call me Shirley.

Re: Leaking YouTube creators' private videos

#214
post #149

I recently left Google having worked on a number of projects with various YouTube teams. I think I can explain why it's being handled this way by YouTube. This is a fairly nuanced/involved issue, so the task of classifying the bug likely made it's way to one of the engineers responsible for the implementation of this feature. That engineer has already launched this project, and filed it away under their GRAD (perform…

[flagged]

How is this remotely related? This is not a safety issue.

Re: Leaking YouTube creators' private videos

#215

The problem is bigger than just something that one engineer can fix, it's a genuine flaw in the training of Gemini, so in order to fix this the model has to be retrained, and new parameters put in place to prevent this kind of thing from happening. The moment a large youtuber gets private content leaked and lands YT in hot water with potential legal liability, and they start talking about what happened, this bug will…

I'm a little confused why so many here are making it seem like this particular attack is completely unstoppable. Just don't include private videos in training or inference. My guess is that the agent that runs this viewer comment aggregation feature has the same context as the one that runs other AI studio things, but attack or not, this isn't functionally correct to begin with. This attack implies that if Samsung has a private video for a new rollable phone, they might see "Viewers are excited about Samsung Roll 1" from this. The viewer comment aggregation feature should have the same information as the viewers to form an accurate summary, and the AI studio suggestion agent should have private context.

Now, the bigger problem of being able to make a "[Important Notice from YouTube]" banner might be harder to solve, but they could at least remove links from the input and output.

Re: Leaking YouTube creators' private videos

#216
post #149

I recently left Google having worked on a number of projects with various YouTube teams. I think I can explain why it's being handled this way by YouTube. This is a fairly nuanced/involved issue, so the task of classifying the bug likely made it's way to one of the engineers responsible for the implementation of this feature. That engineer has already launched this project, and filed it away under their GRAD (perform…

[flagged]

> This is a prime example of why programmers are not seriously considered engineers.

I'm a programmer working in healthcare. If I ignore a safety issue anyone discovered, people die and we go to prison. Am I an engineer now?

Re: Leaking YouTube creators' private videos

#218
post #212

Earlier quoted context omitted.

Comments whinging about this are not any more interesting to read either, even if they do not break discussion guidelines themselves. Use the flag button. This is what it's for.

Interesting choice of word; I wasn’t whinging, just trying to explain to the other commenter something useful. Flagging gives zero detail or nuance. Which presumably is why you replied instead of flagging my comment ;)

No, that'd be because your comment, for better or for worse, does not break guidelines, and because I frequently make the mistake of replying when I should have flagged as well.

Regarding helpful explanations, I really don't think they'd be unaware that allowing JavaScript wholesale would cease their run-ins with JS-dependent things not working, or that they wouldn't know their configuration was uncommon (thus ~definitionally tangential, as it makes them a minority). They are asserting that despite that, it should not be considered tangential (and that they do not consider it to be), for the reasons they list off (i.e. that there's no functional reason the site/page should depend on JS). I agree with this in the sense that I do think the topic and issue matters, but I disagree in the sense that it is absolutely a sidetrack to the blogpost itself. The word "tangential" is pulling a double duty like so in-context I'd say, and I think this is what they're trying to gesture at too.

Recounting that they're willfully running into issues like this is not useful. They have to know, and so this flagrantly sidesteps their point instead of invalidating it. Their complaining is inherently and knowingly performative and principled, as they're essentially engaging in activism with it. Even you and I are participating in this theatre; using the site guidelines and features as vehicles to make certain comments disappear / prevent them from appearing outright, or hammering on about them for the love of the game, alignment and discourse quality nonwithstanding. Whether or not participating in this way is entirely intentional though, I'm sure depends.

And personally, while I understand why this rule was placed into the guidelines, I do disagree with it; I think technical issues are not any less valid to discuss than anything else, although they are meta-commentary. The rule is also de facto perma broken in my experience, exactly because nobody actually flags for it.

Re: Leaking YouTube creators' private videos

#219
post #149

I recently left Google having worked on a number of projects with various YouTube teams. I think I can explain why it's being handled this way by YouTube. This is a fairly nuanced/involved issue, so the task of classifying the bug likely made it's way to one of the engineers responsible for the implementation of this feature. That engineer has already launched this project, and filed it away under their GRAD (perform…

[flagged]

> because of a performance review my engineering licence would be revoked and I would be kicked out of the industry.

Does this happen because train companies just decided to care or because regulators got involved? I believe it was the later. Regulation is often derided here on HN but good regulation does improve things.

Re: Leaking YouTube creators' private videos

#220

Earlier quoted context omitted.

>my engineering licence would be revoked and I would be kicked out of the industry. This isn't because you're a "real" engineer, it's because of regulation and industry licensing around specific engineering disciplines that didn't exist until the start of the 20th century. Railroad engineers in the 1800's didn't have the same set of regulations to follow, or the same liability for mistakes. Software engineering could…

I think the general hacker culture of most programmers prevents this. There's an undercurrent of anti-establishment, anti-authority, anti-management, etc... To think that the industry might choose to self enforce a license system seems very unlikely.

I've come to dislike hacker culture. Worst part is that when the hackers succeed with their objectives and take over systems; they become the authority coordinating others and they are often 10x worse than the authorities who came before them. They just focus on extracting money for themselves, pulling up the ladder behind them and building moats instead. There's nothing anti-establishment about it at the end of the day, they just join the establishment and make it much more oppressive for the next generation.
Post reply on HN