Live data from Hacker News

Leaking the email of any YouTube user for $10k

brutecat.com

371–380 of 487 posts

Re: Leaking the email of any YouTube user for $10k

#371
post #6

This is a puny payout IMO. If they poked around a bit more they may have found a better GAIA->Email vulnerability or perhaps could just use the one they found. A database of emails for every major youtube channel would be worth an awful lot.

I once reported a way to see anyone's gift registry shipping address on Amazon.com and they paid me $0 because they don't have a bug bounty. (But they did fix it.)

Re: Leaking the email of any YouTube user for $10k

#372

> That params is nothing more than just base64 encoded protobuf, which is a common encoding format used throughout Google. Pour one out for the google dev in charge of b64 encoding their fancy binary message format so it can be jammed inside a JSON blob. If you want a vision of the future, imagine a boot with "worse is better" imprinted on the sole stomping on an engineer's face, forever.

It's everywhere and it's the worst. I sometimes ponder whether or not the volume of protobuf bytes represented as b64 encoded protobuf in JSON exceeds that of actual protobuf bytes sent over the wires of the internet, and then I pour one out for myself.

Re: Leaking the email of any YouTube user for $10k

#374
post #335

Earlier quoted context omitted.

I'm not a SWE anymore and haven't been one for a long time. I think it's in everyone's interest for bug bounties to be higher than harmful markets for the same bug, and a decent fraction of the harms they prevent. That's what is going to result in the economically efficient amount of bug hunting. And it's going to result in a safer world with less cybercrime.

No, it's not. CNE is shockingly effective, both for organized crime and for the international IC. The productivity wins are so great there is enormous space for the market prices of tradable vulnerabilities to increase; maybe even multiple orders of magnitude. We're not going to disrupt that process with bug bounties. I really think people just like to think about stories where someone like them finds a bug and gets…

> I really think people just like to think about stories where someone like them finds a bug and gets a lottery jackpot as a result. I like that story too! It's fun.

Increasing bounties by a small factor will be enough to reduce things on the grey market and to increase the ROI of people choosing to do freelance security research. The time between payoffs is enough that no one is going to get rich from $150k bounties.

Don't forget the extrinsic benefits: easier to brag about bounties on your resume than selling things into the grey market.

> Smart companies running bug bounties --- Google is probably the smartest --- are using them like engineering tools; both to direct attention on specific parts of their codebase, and, just as importantly, as an internal tool to prioritize work.

These "smart" companies should consider just how cheap even higher bounties are to prevent massive downsides. Of course, an underlying problem is how well these companies have insulated themselves from the consequences of writing and not fixing vulnerable software. A sane liability (and insurance) regime would go a long way towards aligning incentives properly.

Re: Leaking the email of any YouTube user for $10k

#375
post #367
post #332

Earlier quoted context omitted.

Most people have an intuitive sense to ask themselves questions like "If I do this, will someone be harmed, who, how much harm, what kind of harm, etc.", that factors into moral decisions. Almost everyone, even people without a moral sense, have a self-preservation sense- "How likely is it that I will get caught? If I get caught, will I get punished? How bad will the punishment be?" and these factor into a personal r…

> Most people have an intuitive sense to ask themselves questions like "If I do this, will someone be harmed How much time do you spend asking yourself whether your paycheck is coming from a source that causes harm? Or whether the code you have written will be used directly or indirectly to cause harm? Pretty much everyone in tech is responsible for great harm by this logic.

That's definitely a factor at least some people consider when choosing their job.

> Pretty much everyone in tech is responsible for great harm by this logic.

We're also responsible for great good. The question which is greater is tricky, case-by-case and subjective.

Re: Leaking the email of any YouTube user for $10k

#376

I found this title confusing. For those who didn't make it toward the end of the article: the leaked emails didn't cost them anything (except their time and ingenuity), and they received 10k as the bug bounty.

Me too.

I thought it meant they were offering this as a service for $10k.

Re: Leaking the email of any YouTube user for $10k

#377
post #315

What can one do with a Gaia ID? I don't think the article went into the impact of having it.

Use it on the block user api and get an email address from what I understood.

But what else could definitely or potentially be done? It is an interesting question.

Re: Leaking the email of any YouTube user for $10k

#378
post #138

Earlier quoted context omitted.

Please read my posts more carefully. Virtually every response is non-responsive to what I wrote: I wrote: "unless you're dumb enough to ask questions about whom your selling to and have active knowledge you're assisting someone in breaking some law, selling to the black market is perfectly legal" You wrote: "If you sell information about a vulnerability to someone that you know specifically is going to use it to brea…

Someone gives you two kilos of cocaine, doesn’t tell you what’s in the box and tells you not to open it while you transport it across the border and when you get your the other side someone will pay you $20000. You get caught by the DEA. Do you think it’s a valid defense “I didn’t ask what was in the box”? Say the drug dealer you delivered it to got caught and then told authorities you delivered it to them, do you th…

Is that the right analogy? This sounds more like a free speech and free speech exceptions type of issue.

(Commenters keep moving the goalposts making for a complex thread where each node in the tree litigates a very different hypothetical situation. Ah HN!)

Similar to publishing say... the Anarchists Cookbook.

Re: Leaking the email of any YouTube user for $10k

#379
post #73

Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…

If you think Google had underpaid for this, imagine how much they got to underpay for this:

https://www.theverge.com/2016/1/29/10868404/google-reveals-h...

That guy is ridiculous! Could have made $50 million or more probably, if he had used a different registrar than Google itself.

He mentioned that Microsoft also let their domain lapse and that one was actually going to the open market... and what's more, they didn't even care when he contacted them! Oof:

https://www.theregister.com/2003/11/06/microsoft_forgets_to_...

Here are a few other doozies:

Apple forgot to renew their certificate for the entire Mac App Store, and didn't care much:

2014: https://www.macrumors.com/2014/05/25/apple-software-update-i...

if that wasn't bad enough... they did it again in 2015:

https://osxdaily.com/2015/11/12/fix-app-is-damaged-cant-be-o...

and almost in 2016:

https://apple.stackexchange.com/a/227787/75628

Post reply on HN