Live data from Hacker News

Leaking the email of any YouTube user for $10k

brutecat.com

301–310 of 487 posts

Re: Leaking the email of any YouTube user for $10k

#301
post #285

Earlier quoted context omitted.

Yes, but: 1. It can still take a while before Google finds out 2. You can log every mapping you got in the meanwhile, then keep selling the ones you already have Edit: although probably most of your business will be over when word gets out that your data isn’t exactly legal (which your clients have understood from the start, of course; they could just plead ignorance)

People keep talking about this as if there's a 0% chance of being caught if you do this?. So let's suppose that you did set up the service like this. Can you even make 10 K? What are your odds of getting caught? How much do you value not being in prison and/or having to hire a lawyer to get you out of there? I'd take the 10k every time.

I’d take the 10k, too, but I think it’s possible to pull this off without getting caught.

It’s a lot more work, of course, but you can scrape some top youtubers first as it seems relatively easy. If you can pull this off you can then try and figure out how to legitimize your offering – I won’t go into details here, for obvious reasons, but now that you have something valuable on your hands it makes sense to spend some time/money on selling that.

Re: Leaking the email of any YouTube user for $10k

#302
post #296

I see a lot of noise made about responsible disclosure, its drivers, and its rewards. What I don't see is talk about how this is one more datapoint against centralized permanent identities. Every time I see a service purporting that it works best only with a single link to your Real Identity™, I'm reminded that the vendors only abstractly care about actually protecting the user, and then only sometimes. Imagine being…

> Every time I see a service purporting that it works best only with a single link to your Real Identity™, I'm reminded that the vendors only abstractly care about actually protecting the user, and then only sometimes.

I abstractly agree with you. There is a level of obscurity and disposability that should be tolerated in these accounts. They’re just a row in a database somewhere anyways.

That said, many people transact with these businesses with real human money. For example, YouTube premium subscribers or content creators. From a practical perspective, that requires IRL identifiers to be stored somewhere with that otherwise disposable account. And due to fraud risks and other realities of banking, that requires giving these businesses actual identities and addresses which they store too.

While I don’t give random apps and websites my human-identifying information, anyone I do business with necessarily knows the real me, which is a theoretical point of data leaking.

Re: Leaking the email of any YouTube user for $10k

#303
post #223
post #190

Earlier quoted context omitted.

> because $10,000 feels extraordinarily high for a server-side web bug. Am I misunderstanding the bug? In my reading, this bug translates to "a list of the top 1,000 Youtube accounts' email addresses (or as many as you can get until Google detects it and shuts it down)." Why isn't that conceivably worth more than $10,000?

I think a simple way to think of it is: how much would an adversarial nation state buy this exploit for? I just don't think Russia would be willing to pay $100,000 to get Mr. Beast's email address, even if that sounds tempting to you.

Sure, they'd probably be more interested in political dissidents.

Re: Leaking the email of any YouTube user for $10k

#304
post #73

Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…

I'd also add that the legality of law enforcement exploiting a server-side bug is much more of a gray area (or actually illegal), whereas there is a standard process for law enforcement or the intelligence community to get a court order that enables them to exploit devices that belong to a specific target (phone, laptop, etc).

There's also the thing where like, as you go from iOS Safari to Windows Chrome to Acrobat Reader or whatever, grey market prices plummet. The top-dollar targets all have multilayered runtime protections and whole teams that do nothing but security refactoring. No serverside software is hardened that way (excepting the Linux kernel, maybe, but Linux kernel bugs are a standard component of clientside exploit chains). You could infer a pretty low price.

I will say: at Matasano, we were once asked by an established security company that turned out to be a broker to find PHPBB vulnerabilities.

Re: Leaking the email of any YouTube user for $10k

#305

Earlier quoted context omitted.

They could spin these products off into separate companies and cut the integration with the rest of the Google ecosystem.

Where is the profit for the individual product? There are a lot of services at every BigTech company that would not make sense as an individual product. But they make the overall ecosystem better or make money only because they are a part of the larger company. That’s part of the stupidity of the DOJ trying to force Google to sell Chrome. Who would want it? And how would they profit from it?

> That’s part of the stupidity of the DOJ trying to force Google to sell Chrome. Who would want it? And how would they profit from it?

All valid questions, but it might be that splitting the tool used to bludgeon everyone around is still worth it, even if pace of development slows down considerably.

Re: Leaking the email of any YouTube user for $10k

#306

Earlier quoted context omitted.

What are you talking about? I’ve got the books app open now, I can see all of my downloaded books. In fact there’s a whole section in the library for my downloaded books! Go to library > collections > downloaded. I can see books I purchased and other PDFs that I uploaded. I do agree on the Photos redesign. I feel like I constantly get stuck on certain pages.

> What are you talking about? Your tone is aggressive and uncalled for. In fact, the fact that you have never found a very common bug says a lot about your inattention to detail. There's no "keep forever on device" button, which to me seems like a basic functionality. If the app decides to delete them, it will. https://old.reddit.com/r/ios/comments/1b04rzy/apple_what_wer... https://news.ycombinator.com/item?id=237365…

Oh okay, but that’s not what you said? You implied that no books could be downloaded at all which is just not true.

iCloud offload is a pretty common feature on Apple devices and one that I find pretty handy. I understand why it doesn’t work for others though.

You can turn off iCloud sync in general for the device.

Re: Leaking the email of any YouTube user for $10k

#307

Earlier quoted context omitted.

Internally, it would be a b64 protobuf in a protobuf field. The json part is an automatic conversion.

Why would it be b64 encoded? There's nothing that prevents you from putting an encoded protobuf into a protobuf as `bytes` type. `bytes nestedMessage = 42;` Only delimited message formats like JSON or XML need to encapsulate messages before nesting.

Because it is in a Json? Internally it probably is protobuf with bytes.

But the external API is Json and so it needs to be converted at some point.

https://stackoverflow.com/questions/49358526/protobuf-messag...

Re: Leaking the email of any YouTube user for $10k

#308
post #110
post #59

Earlier quoted context omitted.

It's an extraordinarily high sum for this kind of finding. Bounties are generally not a referendum on how clever the underlying work is. A full-chain iOS bug is worth hundreds of thousands of dollars because Apple competes with the grey market for it (and even then, it's an apples-oranges comparison and Apple pays substantially less than the rest of the market for structural reasons). Nobody competes for this bug; no…

My commentary was precisely about the state-of-the-practice. That $10k is "an extraordinarily high sum for" what was likely weeks of work on this bug, and probably months of work poking in other places, reflects the very, very low focus on security industry-wide. This is why we need significant civil -- or possibly occasionally criminal -- liability. Civil if it's simple negligence, and criminal if it's gross neglige…

> If Google were to pay me $200 if it leaked my data, that would: Be worth much less than my privacy

I think you need to do a lot to justify a non-zero value for this, frankly.

How is your “privacy” worth $200? What data is valuable and what data isn’t? Under what context?

If your privacy is worth $200 per leak (by some definition of leak), you surely take steps to anonymize your data already and wouldn’t use a service like Google (or name your untrustworthy party).

I’m not saying leaks are good but trying to price it in seems fraught.

Post reply on HN