Live data from Hacker News

Leaking the email of any YouTube user for $10k

brutecat.com

361–370 of 487 posts

Re: Leaking the email of any YouTube user for $10k

#362
post #211

Earlier quoted context omitted.

> Bounty programs are a pretty recent development and the idea that they should be scalable and stable well paying employment for a lot of people is a bit strange to me. So, the value to the researcher of having a found bug has a floor of the black market value. The value to Google is whatever the costs of exploitation are: reputational, cleanup, etc. A sane value is somewhere between these two, depending on bargaini…

That's not true because there is an economic cost for most people to committing crimes. "Hey you could make more money selling that on the black market" is not going to convince me to sell something on the black market. Bounty programs are very much not trying to compete with crime.

The reputation angle shouldn't be dismissed: Google paying so little for this bug is the whole reason this article stays on the top page and gets so much discussion.

I don't know how much it should be worth, but at least there's a PR effect and it's also a message towards the dev community.

I see it the same way ridiculously low penalty for massive data breaches taught us how much privacy is actually valued.

Re: Leaking the email of any YouTube user for $10k

#363
post #325
post #285

Earlier quoted context omitted.

People keep talking about this as if there's a 0% chance of being caught if you do this?. So let's suppose that you did set up the service like this. Can you even make 10 K? What are your odds of getting caught? How much do you value not being in prison and/or having to hire a lawyer to get you out of there? I'd take the 10k every time.

You’re talking about this as if there aren’t other countries who actively infiltrate power infrastructure and for whom this is the most low risk mild attack (if you can call it that) I’m not speaking theoretically, which I suspect most on this thread are.

Okay, which state actor is going to buy this for $100,000? How are you going to sell it to them? What's the risk of getting caught?

Even if someone on telegram was telling me that Russia would buy this information for $100,000, I think I would reach out to Google and "settle" for $10k.

Re: Leaking the email of any YouTube user for $10k

#364
One commenter already clarified how bounty amount is related to black market value. Now a lot of others might seem how Google doesn’t value security enough. (Or other companies).

But one has to understand that for security purposes they SHOULD pay as little as possible. If they pay out more there is more incentive in finding bugs and then there unfortunately you’ll also raise more black market.

So GTO strat is to just cut off black market with as little money as possible.

Re: Leaking the email of any YouTube user for $10k

#365
post #185
post #73

Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…

Most other fields of endeavor aren’t compensated based on the black market value of the thing that’s being produced. If we apply your analysis to other things, we’ll find that the upper bound price for a new car stereo or bike is ~ $100, and the price of any copyrighted good is bounded by the cost of transferring it over the network. I think it is more useful to divide the amount Google paid by the number of hours sp…

Yep, I came to the same conclusion. The payments from bug bounties and the uncertainty of payment just isn't worth it. It's like taking a fixed prize contract and adding in a gambling element to get paid. Fixed prized I learned was bad enough if you want to make anything as a software engineer. This is even worse though.

I mean, the technical skills in the article here are basic. But the first finding was significantly good luck, and having the background to know to look towards old Google services for the ID to email part was non-obvious. You would need a lot of high-quality, guiding knowledge like that to make bug bounties work. Still, seems like a very high starting cost.

Re: Leaking the email of any YouTube user for $10k

#366

Earlier quoted context omitted.

That's not true because there is an economic cost for most people to committing crimes. "Hey you could make more money selling that on the black market" is not going to convince me to sell something on the black market. Bounty programs are very much not trying to compete with crime.

The reputation angle shouldn't be dismissed: Google paying so little for this bug is the whole reason this article stays on the top page and gets so much discussion. I don't know how much it should be worth, but at least there's a PR effect and it's also a message towards the dev community. I see it the same way ridiculously low penalty for massive data breaches taught us how much privacy is actually valued.

If Google doesn't have the best reputation of any large tech company for security, it's in the top 3. This is not the nightmare scenario for Google that people think it is. It's a large payout for this bug class, so, if anything, what we're doing here is advertising for them.

Re: Leaking the email of any YouTube user for $10k

#367
post #332
post #298

Earlier quoted context omitted.

I wonder what your definition of crime is. Legally, in most places of the world it isn't. Morality differs among people too. Profiting off a trillion dollar company will not cross the line for a lot of people.

Most people have an intuitive sense to ask themselves questions like "If I do this, will someone be harmed, who, how much harm, what kind of harm, etc.", that factors into moral decisions. Almost everyone, even people without a moral sense, have a self-preservation sense- "How likely is it that I will get caught? If I get caught, will I get punished? How bad will the punishment be?" and these factor into a personal r…

> Most people have an intuitive sense to ask themselves questions like "If I do this, will someone be harmed

How much time do you spend asking yourself whether your paycheck is coming from a source that causes harm? Or whether the code you have written will be used directly or indirectly to cause harm? Pretty much everyone in tech is responsible for great harm by this logic.

Re: Leaking the email of any YouTube user for $10k

#370

Earlier quoted context omitted.

The discoverer had these choices: - monetize the bug themselves; i.e. set up a site where you can submit a YouTube user id, pay some fee using your credit card and get an e-mail address. - report that they have the ability to convert any YouTube id to an e-mail, with proof: then negotiate over compensation for the disclosure of the details - just report the problem and be happy with whatever they get. Ten grand doesn…

Do any companies pay bounties for path #2? My understanding is that it's forbidden by most bounty programs since it could be seen as a form of extortion. For #1, as tptacek says, it would be trivially easy for Google to shut a service like that down as soon as it was created, and prosecute the people running the service under the CFAA. Also, the amount of demand for that kind of data is pretty small given the number…

In other words the more you think about it the better the $10k looks.
Post reply on HN