Live data from Hacker News

Leaking the email of any YouTube user for $10k

brutecat.com

381–390 of 487 posts

Re: Leaking the email of any YouTube user for $10k

#381
post #367
post #332

Earlier quoted context omitted.

Most people have an intuitive sense to ask themselves questions like "If I do this, will someone be harmed, who, how much harm, what kind of harm, etc.", that factors into moral decisions. Almost everyone, even people without a moral sense, have a self-preservation sense- "How likely is it that I will get caught? If I get caught, will I get punished? How bad will the punishment be?" and these factor into a personal r…

> Most people have an intuitive sense to ask themselves questions like "If I do this, will someone be harmed How much time do you spend asking yourself whether your paycheck is coming from a source that causes harm? Or whether the code you have written will be used directly or indirectly to cause harm? Pretty much everyone in tech is responsible for great harm by this logic.

I actually think about it a lot:

https://news.ycombinator.com/item?id=42540862#42542151

Re: Leaking the email of any YouTube user for $10k

#382

Earlier quoted context omitted.

Someone gives you two kilos of cocaine, doesn’t tell you what’s in the box and tells you not to open it while you transport it across the border and when you get your the other side someone will pay you $20000. You get caught by the DEA. Do you think it’s a valid defense “I didn’t ask what was in the box”? Say the drug dealer you delivered it to got caught and then told authorities you delivered it to them, do you th…

Is that the right analogy? This sounds more like a free speech and free speech exceptions type of issue. (Commenters keep moving the goalposts making for a complex thread where each node in the tree litigates a very different hypothetical situation. Ah HN!) Similar to publishing say... the Anarchists Cookbook.

> unless you're dumb enough to ask questions about whom your selling to and have active knowledge you're assisting someone in breaking some law, selling to the black market is perfectly legal

This goes directly to the concept of “willful blindness”

https://www.mad.uscourts.gov/resources/pattern2003/html/patt...

Re: Leaking the email of any YouTube user for $10k

#383
post #73

Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…

On top of that I always felt that this is generally aimed towards hobbyist who may accidently stumble on something to give them additional incentive to finish the job and make an actually summary and repro, rather than hollywood hackers.

Sure the gray market will pay more, but how do you contact criminals and make sure that you actually receive payment?

I know nothing about the market, but I think it's similar to buying drugs - we all know that drugs are everywhere and criminals are making a ton of money out of it, but if you haven't been introduced before how do you actually buy them? Go to a club and start asking random people?

(that last part might be different in US, but in EU we don't have people standing on every corner selling cookies)

Re: Leaking the email of any YouTube user for $10k

#384

Earlier quoted context omitted.

You don‘t need to sell the vulnerability to them, or even tell them the vulnerability is there. Just set up an API and bill them by the query.

An API is too much work. Grab the addresses for the top 100,000 YouTubers and sell that csv on the dark web.

What happens when the first to buy the CSV starts selling it themselves?

Re: Leaking the email of any YouTube user for $10k

#385

I found this title confusing. For those who didn't make it toward the end of the article: the leaked emails didn't cost them anything (except their time and ingenuity), and they received 10k as the bug bounty.

Me too. I thought it meant they were offering this as a service for $10k.

I think this was the joke.

Re: Leaking the email of any YouTube user for $10k

#386

Earlier quoted context omitted.

I want. And I do. Notable examples are Kagi.com and Raindrop.io. I've also been sponsoring a number of projects for a number of months, from journalism to social media startup. But I am getting more hesitant as often when I (and others) do it seems companies think they can increase their prices wildly or do other stuff. I have this exact feeling now with Logseq: I started paying for sync a while ago and it seems so d…

How many of those companies are profitable? How many do you think you will see a blog post about in a year or two - “Our Amazing Journey” where they won’t either go out of business or get acquired and their product gets shut down”? From Kagi’s website https://blog.kagi.com/status-update-first-three-months#:~:te... We are currently serving around 2.1M queries a month, costing us around $26,250 USD/month. Between Kagi…

Wrong blog post, try this one ;)

https://blog.kagi.com/what-is-next-for-kagi

Re: Leaking the email of any YouTube user for $10k

#387
post #351

Earlier quoted context omitted.

made sense from the pov that if its harder to exploit, it's less damaging of a bug, so worth less

But it's not really harder to exploit. It is an API call that any Google account can make. It's not like the second call has complex requirements or only probabilisticly succeeds.

It's harder to find, so it's less likely to be noticed and exploited by a bad actor than a glaring issue. My experience has been that this is typical of these programs—you're trying to reward researchers for finding things that are likely to be exploited, so the more arcane bugs are less valuable.

I'm not sure I'd apply that logic if I were Google, though. Smaller companies it makes sense because the threat actors that they are most likely to face are mostly script kiddies who give you at most a day before they get bored and try someone else. Google is another matter, since they're always a target for much more sophisticated attackers.

Post reply on HN