Live data from Hacker News

Leaking the email of any YouTube user for $10k

brutecat.com

341–350 of 487 posts

Re: Leaking the email of any YouTube user for $10k

#341
post #337

Earlier quoted context omitted.

Except it's not "legitimate cash" and that's the point. * Are you talking to someone legitimately interested in purchasing and paying you, or is this a sting? * If you're meeting up with someone in person, what is the risk that the person will bring payment or try to attack you? * If you're meeting with someone in person, how do you use $20k in cash without attracting suspicion? How much time will that take? * If it'…

It's not a crime to sell a bug. You can sell something like this to Crowdfense and receive money wired from the company (or cryptocurrency if you prefer anonymity).

It is not intrinsically a crime to sell a bug, but if you sell a bug and it can be demonstrated you reasonably knew the buyer was going to use it to commit a crime, you will end up with accessory liability to that crime. Selling vulnerabilities is not risk-free.

This is another reason why the distinction between well-worn markets (like Chrome RCEs) and ad-hoc markets is so important; there's a huge amount of plausible deniability built into the existing markets. Most sellers aren't selling to the ultimate users of the vulnerabilities, but to brokers. There aren't brokers for these Youtube vulnerabilities.

Re: Leaking the email of any YouTube user for $10k

#342
post #148
post #73

Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…

> Threat actors buy vulnerabilities that fit into existing business processes Isn't there a market for this? For example, "Reveal who is behind this account that's criticizing our sketchy company/government, so we can neutralize them". I'll also argue there's separate incentives, than the market value to threat actors... Although a violent stalker of an online personality might not be a lucrative market for a zero-da…

The only real market (that I can see) are shady data aggregators. Governments just file subpoenas, and abusive megacorps can file lawsuits (all the anti-SLAPP statues in the world can't prevent your Google account from being unmasked and having to pay for a lawyer). There is a limited market in the form of internet addicts who want to harass people for kicks (since finding an email gives them another route to do that with), but it's a small one. These people also tend to be entitled pricks, so they're not a very good customer base to have.

Re: Leaking the email of any YouTube user for $10k

#343
post #334

Earlier quoted context omitted.

https://www.youtube.com/watch?v=Y0pdQU87dc8

I think your comment energy is more https://youtu.be/Pzpx9f5ByyA?t=110

A friend generated a tag cloud from all my comments here like 10 years ago and it was just the word "No" like a supermassive black hole ringed by dozens of tiny little words I was saying "no" about.

Re: Leaking the email of any YouTube user for $10k

#344

He could have made WAY more money not disclosing this and that should scare any Google employee reading this

Curious if anyone knows, what legality of using a technique like this? I assume illegal, even though it's just making publicly available API calls?

Re: Leaking the email of any YouTube user for $10k

#345
post #334

Earlier quoted context omitted.

I think your comment energy is more https://youtu.be/Pzpx9f5ByyA?t=110

A friend generated a tag cloud from all my comments here like 10 years ago and it was just the word "No" like a supermassive black hole ringed by dozens of tiny little words I was saying "no" about.

That's a great example of "doing it wrong makes it better", in this case not filtering stop words.

Re: Leaking the email of any YouTube user for $10k

#346

I found this title confusing. For those who didn't make it toward the end of the article: the leaked emails didn't cost them anything (except their time and ingenuity), and they received 10k as the bug bounty.

Yeah, I thought it was going to be about compute cost for brute forcing some hash or something

Re: Leaking the email of any YouTube user for $10k

#347
post #337

Earlier quoted context omitted.

It's not a crime to sell a bug. You can sell something like this to Crowdfense and receive money wired from the company (or cryptocurrency if you prefer anonymity).

It is not intrinsically a crime to sell a bug, but if you sell a bug and it can be demonstrated you reasonably knew the buyer was going to use it to commit a crime, you will end up with accessory liability to that crime. Selling vulnerabilities is not risk-free. This is another reason why the distinction between well-worn markets (like Chrome RCEs) and ad-hoc markets is so important; there's a huge amount of plausibl…

There's not a standard price in a list, but you can absolutely sell a platform exploit to a broker.

Re: Leaking the email of any YouTube user for $10k

#348
post #73

Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…

The discoverer had these choices: - monetize the bug themselves; i.e. set up a site where you can submit a YouTube user id, pay some fee using your credit card and get an e-mail address. - report that they have the ability to convert any YouTube id to an e-mail, with proof: then negotiate over compensation for the disclosure of the details - just report the problem and be happy with whatever they get. Ten grand doesn…

Do any companies pay bounties for path #2? My understanding is that it's forbidden by most bounty programs since it could be seen as a form of extortion.

For #1, as tptacek says, it would be trivially easy for Google to shut a service like that down as soon as it was created, and prosecute the people running the service under the CFAA. Also, the amount of demand for that kind of data is pretty small given the number of email address databases already available online through legal means (e.g. Zoominfo, RocketReach, etc). It's a path filled with a lot of risk and not a ton of reward.

Re: Leaking the email of any YouTube user for $10k

#349
post #44

I haven't gotten access to my YouTube channel since it migrated to Google account. If anyone can set me in contact with anyone who can help recover my account, it will be rewarded with karma for life

Haha a human at google. Good luck. My maps review are almost always blocked because reasons for years, Im still trying to reach a human there.

Same here, I tried to fix the navigation by re-creating this bit of road multiple times but it's always rejected without a reason given. https://maps.app.goo.gl/YkjqBZSRPrjFLvsi8

Re: Leaking the email of any YouTube user for $10k

#350
post #332
post #298

Earlier quoted context omitted.

I wonder what your definition of crime is. Legally, in most places of the world it isn't. Morality differs among people too. Profiting off a trillion dollar company will not cross the line for a lot of people.

Most people have an intuitive sense to ask themselves questions like "If I do this, will someone be harmed, who, how much harm, what kind of harm, etc.", that factors into moral decisions. Almost everyone, even people without a moral sense, have a self-preservation sense- "How likely is it that I will get caught? If I get caught, will I get punished? How bad will the punishment be?" and these factor into a personal r…

...has even resulted in death

I wish developers (and their companies, tooling, industry, etc.) creating such flaws in the first place would treat the craft with a higher degree of diligence. It bothers me that someone didn't maintain the segregation between display name / global identifier (in YouTube frontend*) or global identifier / email address (in the older product), or was in a position to maintain the code without understanding the importance of that intended barrier.

If users knew what a mess most software these days looks like under the hood (especially with regard to privacy) I think they'd be a lot less comfortable using it. I'm encouraged by some of the efforts that are making an impact (e.g. advances in memory safety).

(*Seems like it wouldn't have been as big a deal if the architecture at Google relied more heavily on product-encapsulated account identifiers instead of global ones)

Post reply on HN