Live data from Hacker News

Leaking the email of any YouTube user for $10k

brutecat.com

351–360 of 487 posts

Re: Leaking the email of any YouTube user for $10k

#351

“Applied 1 downgrade from the base amount due to complexity of attack chain required” I’ve only participated in a few vulnerability programs, and most of them reward less if the security flaw is stupidly simple (but serious) such as revealing user emails in the page source.

Yeah, this seems backwards. It should be upgraded from the base amount because they effectively found 2 bugs!

made sense from the pov that if its harder to exploit, it's less damaging of a bug, so worth less

Re: Leaking the email of any YouTube user for $10k

#353
post #351

Earlier quoted context omitted.

Yeah, this seems backwards. It should be upgraded from the base amount because they effectively found 2 bugs!

made sense from the pov that if its harder to exploit, it's less damaging of a bug, so worth less

But it's not really harder to exploit. It is an API call that any Google account can make. It's not like the second call has complex requirements or only probabilisticly succeeds.

Re: Leaking the email of any YouTube user for $10k

#354
post #284

Earlier quoted context omitted.

Sure, but give some specific values. What potential damages and potential risk multiply to more than $10k?

Prominent youtuber doxxed and killed; terrible press extended for an extended period by litigation. 1 in 5000 but very high cost. Large scale data leak and need for data leak disclosure. 1 in 3, moderate cost. Bug report saving engineering time by giving clear report of issue instead of having to dig through telemetry and figure out misuse and then identify what is going on, extents of past damage, etc. 3 in 4.

You think that being able to get someone's email address (most likely a business email but let's pretend it's a personal email) has a 1 in 5,000 chance of being turned into enough personal information to track down AND that someone would use it to kill someone?

Millions of usernames and emails are leaked every month; if this was the case you'd be seeing these murders in the news every week.

Re: Leaking the email of any YouTube user for $10k

#355
post #188

Earlier quoted context omitted.

You are imagining a market that doesn’t exist. First there are only very few gobs/companies that are sketchy enough to do this - and for those a huge number of non-anonymous people exist with huge reach that are very critical for years. If such a market would exist they would assassinate all those first - you don’t need the email if you have the face, voice, and name - since that is not happening they just don’t care…

There’s 100% an active market for this, and I think tptacek is simply wrong on this point (the others are valid) The likes of Cambridge Analytica didn’t go away, they exist and absolutely go hunting for data like this. The ability to map between different identifiers and pieces of content on the internet is central to so many things - why do you think adtech tries to join so many datapoints? Let alone things like inf…

There's an easy way to put your money where your mouth is here. Just offer $11k for this or similar vulnerabilities out of your own pocket, and then resell them. If there really is a large and active market for this at higher dollar values, you'll make a killing!

Sure is funny there's nobody doing that despite so many people being so dead certain there's an active market.

Re: Leaking the email of any YouTube user for $10k

#356
post #347

Earlier quoted context omitted.

It is not intrinsically a crime to sell a bug, but if you sell a bug and it can be demonstrated you reasonably knew the buyer was going to use it to commit a crime, you will end up with accessory liability to that crime. Selling vulnerabilities is not risk-free. This is another reason why the distinction between well-worn markets (like Chrome RCEs) and ad-hoc markets is so important; there's a huge amount of plausibl…

There's not a standard price in a list, but you can absolutely sell a platform exploit to a broker.

Say more. What do you mean by "platform exploit", and which brokers are you talking about? I am immediately skeptical, but it should be easy to knock me down on this.

Re: Leaking the email of any YouTube user for $10k

#357
post #335
post #189

Earlier quoted context omitted.

I hate how this HN thread is mostly about discussing the amount of bounty, but I'm afraid it's only natural. Most commenters here are working in the software industry and they want to normalize extremely high bounties. It's an extra income source for them. They want higher bug bounties much like they want SWEs to be a highly compensated profession. It's only natural for workers to demand higher pay for their own prof…

I'm not a SWE anymore and haven't been one for a long time. I think it's in everyone's interest for bug bounties to be higher than harmful markets for the same bug, and a decent fraction of the harms they prevent. That's what is going to result in the economically efficient amount of bug hunting. And it's going to result in a safer world with less cybercrime.

No, it's not. CNE is shockingly effective, both for organized crime and for the international IC. The productivity wins are so great there is enormous space for the market prices of tradable vulnerabilities to increase; maybe even multiple orders of magnitude. We're not going to disrupt that process with bug bounties.

I really think people just like to think about stories where someone like them finds a bug and gets a lottery jackpot as a result. I like that story too! It's fun.

Smart companies running bug bounties --- Google is probably the smartest --- are using them like engineering tools; both to direct attention on specific parts of their codebase, and, just as importantly, as an internal tool to prioritize work. This is part of why we keep having stories where we're shocked about people finding oddball security- and security-adjacent bugs that get zero payouts.

Re: Leaking the email of any YouTube user for $10k

#358
post #73

Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…

> that has effectively no half-life once discovered

Google knew about this already, and hadn't done anything to fix it...and when it was reported, they didn't fully understand it and were dismissive, until the author came back at them again.

> Unmasking Google accounts? Could there be a business there? Sure, maybe

I'm pretty sure there are a _lot_ of youtube channels that private and public entities would love to uncover the identity of, and I would say that it's very unlikely these guys were the first to piece all this together.

The main takeaway for me is how incompetent Googlers seem to be, both in the basic "web application 101" mistakes made (not properly validating/restricting fields) and the clearly rushed evaluation of the security report. Such a report should trigger some folks going "oh, that's not good. I wonder what else is broken about this." Not "meh, not significant, quick patch, fixed."

Nobody at Google wants to work on stuff that isn't going to get them up a rung on the ladder.

Re: Leaking the email of any YouTube user for $10k

#359

I found this title confusing. For those who didn't make it toward the end of the article: the leaked emails didn't cost them anything (except their time and ingenuity), and they received 10k as the bug bounty.

Yeah, I thought it was going to be about compute cost for brute forcing some hash or something

The domain name kind of suggests this interpretation, too.

Re: Leaking the email of any YouTube user for $10k

#360

Earlier quoted context omitted.

How are alarms unreliable? Photos redesign maybe something you don’t like, but you can hardly call it half baked. All of the functionality is there and there’s a new consistency in how it works that wasn’t there previously. Books automatically downloads to device. There isn’t a way to read a book without it local.

Probably a few times every quarter I have iOS alarms that didn't go off for some reason on my iPhone. It's happened for years: it was pretty bad about 5/6 years ago, but Apple claimed they fixed it, but it's still happening a bit. In fact, when I really need to wake up at a particular time (say for a flight), I set two alarms 1 minutes apart.

Seems like there is more to this. I have been using iPhones since they came out and can't think of a time my alarm never worked, and I use them multiple times a day.
Post reply on HN