Leaking the email of any YouTube user for $10k
361–370 of 487 posts
Re: Leaking the email of any YouTube user for $10k
#362Earlier quoted context omitted.
> Bounty programs are a pretty recent development and the idea that they should be scalable and stable well paying employment for a lot of people is a bit strange to me. So, the value to the researcher of having a found bug has a floor of the black market value. The value to Google is whatever the costs of exploitation are: reputational, cleanup, etc. A sane value is somewhere between these two, depending on bargaini…
That's not true because there is an economic cost for most people to committing crimes. "Hey you could make more money selling that on the black market" is not going to convince me to sell something on the black market. Bounty programs are very much not trying to compete with crime.
I don't know how much it should be worth, but at least there's a PR effect and it's also a message towards the dev community.
I see it the same way ridiculously low penalty for massive data breaches taught us how much privacy is actually valued.
Re: Leaking the email of any YouTube user for $10k
#363Earlier quoted context omitted.
People keep talking about this as if there's a 0% chance of being caught if you do this?. So let's suppose that you did set up the service like this. Can you even make 10 K? What are your odds of getting caught? How much do you value not being in prison and/or having to hire a lawyer to get you out of there? I'd take the 10k every time.
You’re talking about this as if there aren’t other countries who actively infiltrate power infrastructure and for whom this is the most low risk mild attack (if you can call it that) I’m not speaking theoretically, which I suspect most on this thread are.
Even if someone on telegram was telling me that Russia would buy this information for $100,000, I think I would reach out to Google and "settle" for $10k.
Re: Leaking the email of any YouTube user for $10k
#364But one has to understand that for security purposes they SHOULD pay as little as possible. If they pay out more there is more incentive in finding bugs and then there unfortunately you’ll also raise more black market.
So GTO strat is to just cut off black market with as little money as possible.
Re: Leaking the email of any YouTube user for $10k
#365Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…
Most other fields of endeavor aren’t compensated based on the black market value of the thing that’s being produced. If we apply your analysis to other things, we’ll find that the upper bound price for a new car stereo or bike is ~ $100, and the price of any copyrighted good is bounded by the cost of transferring it over the network. I think it is more useful to divide the amount Google paid by the number of hours sp…
I mean, the technical skills in the article here are basic. But the first finding was significantly good luck, and having the background to know to look towards old Google services for the ID to email part was non-obvious. You would need a lot of high-quality, guiding knowledge like that to make bug bounties work. Still, seems like a very high starting cost.
Re: Leaking the email of any YouTube user for $10k
#366Earlier quoted context omitted.
That's not true because there is an economic cost for most people to committing crimes. "Hey you could make more money selling that on the black market" is not going to convince me to sell something on the black market. Bounty programs are very much not trying to compete with crime.
The reputation angle shouldn't be dismissed: Google paying so little for this bug is the whole reason this article stays on the top page and gets so much discussion. I don't know how much it should be worth, but at least there's a PR effect and it's also a message towards the dev community. I see it the same way ridiculously low penalty for massive data breaches taught us how much privacy is actually valued.
Re: Leaking the email of any YouTube user for $10k
#367Earlier quoted context omitted.
I wonder what your definition of crime is. Legally, in most places of the world it isn't. Morality differs among people too. Profiting off a trillion dollar company will not cross the line for a lot of people.
Most people have an intuitive sense to ask themselves questions like "If I do this, will someone be harmed, who, how much harm, what kind of harm, etc.", that factors into moral decisions. Almost everyone, even people without a moral sense, have a self-preservation sense- "How likely is it that I will get caught? If I get caught, will I get punished? How bad will the punishment be?" and these factor into a personal r…
How much time do you spend asking yourself whether your paycheck is coming from a source that causes harm? Or whether the code you have written will be used directly or indirectly to cause harm? Pretty much everyone in tech is responsible for great harm by this logic.
Re: Leaking the email of any YouTube user for $10k
#368Re: Leaking the email of any YouTube user for $10k
#369I found this title confusing. For those who didn't make it toward the end of the article: the leaked emails didn't cost them anything (except their time and ingenuity), and they received 10k as the bug bounty.
Re: Leaking the email of any YouTube user for $10k
#370Earlier quoted context omitted.
The discoverer had these choices: - monetize the bug themselves; i.e. set up a site where you can submit a YouTube user id, pay some fee using your credit card and get an e-mail address. - report that they have the ability to convert any YouTube id to an e-mail, with proof: then negotiate over compensation for the disclosure of the details - just report the problem and be happy with whatever they get. Ten grand doesn…
Do any companies pay bounties for path #2? My understanding is that it's forbidden by most bounty programs since it could be seen as a form of extortion. For #1, as tptacek says, it would be trivially easy for Google to shut a service like that down as soon as it was created, and prosecute the people running the service under the CFAA. Also, the amount of demand for that kind of data is pretty small given the number…