Earlier quoted context omitted.
Most people have an intuitive sense to ask themselves questions like "If I do this, will someone be harmed, who, how much harm, what kind of harm, etc.", that factors into moral decisions. Almost everyone, even people without a moral sense, have a self-preservation sense- "How likely is it that I will get caught? If I get caught, will I get punished? How bad will the punishment be?" and these factor into a personal r…
> Most people have an intuitive sense to ask themselves questions like "If I do this, will someone be harmed How much time do you spend asking yourself whether your paycheck is coming from a source that causes harm? Or whether the code you have written will be used directly or indirectly to cause harm? Pretty much everyone in tech is responsible for great harm by this logic.
Leaking the email of any YouTube user for $10k
381–390 of 487 posts
Re: Leaking the email of any YouTube user for $10k
#382Earlier quoted context omitted.
Someone gives you two kilos of cocaine, doesn’t tell you what’s in the box and tells you not to open it while you transport it across the border and when you get your the other side someone will pay you $20000. You get caught by the DEA. Do you think it’s a valid defense “I didn’t ask what was in the box”? Say the drug dealer you delivered it to got caught and then told authorities you delivered it to them, do you th…
Is that the right analogy? This sounds more like a free speech and free speech exceptions type of issue. (Commenters keep moving the goalposts making for a complex thread where each node in the tree litigates a very different hypothetical situation. Ah HN!) Similar to publishing say... the Anarchists Cookbook.
This goes directly to the concept of “willful blindness”
https://www.mad.uscourts.gov/resources/pattern2003/html/patt...
Re: Leaking the email of any YouTube user for $10k
#383Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…
Sure the gray market will pay more, but how do you contact criminals and make sure that you actually receive payment?
I know nothing about the market, but I think it's similar to buying drugs - we all know that drugs are everywhere and criminals are making a ton of money out of it, but if you haven't been introduced before how do you actually buy them? Go to a club and start asking random people?
(that last part might be different in US, but in EU we don't have people standing on every corner selling cookies)
Re: Leaking the email of any YouTube user for $10k
#384Earlier quoted context omitted.
You don‘t need to sell the vulnerability to them, or even tell them the vulnerability is there. Just set up an API and bill them by the query.
An API is too much work. Grab the addresses for the top 100,000 YouTubers and sell that csv on the dark web.
Re: Leaking the email of any YouTube user for $10k
#385I found this title confusing. For those who didn't make it toward the end of the article: the leaked emails didn't cost them anything (except their time and ingenuity), and they received 10k as the bug bounty.
Me too. I thought it meant they were offering this as a service for $10k.
Re: Leaking the email of any YouTube user for $10k
#386Earlier quoted context omitted.
I want. And I do. Notable examples are Kagi.com and Raindrop.io. I've also been sponsoring a number of projects for a number of months, from journalism to social media startup. But I am getting more hesitant as often when I (and others) do it seems companies think they can increase their prices wildly or do other stuff. I have this exact feeling now with Logseq: I started paying for sync a while ago and it seems so d…
How many of those companies are profitable? How many do you think you will see a blog post about in a year or two - “Our Amazing Journey” where they won’t either go out of business or get acquired and their product gets shut down”? From Kagi’s website https://blog.kagi.com/status-update-first-three-months#:~:te... We are currently serving around 2.1M queries a month, costing us around $26,250 USD/month. Between Kagi…
Re: Leaking the email of any YouTube user for $10k
#387Earlier quoted context omitted.
made sense from the pov that if its harder to exploit, it's less damaging of a bug, so worth less
But it's not really harder to exploit. It is an API call that any Google account can make. It's not like the second call has complex requirements or only probabilisticly succeeds.
I'm not sure I'd apply that logic if I were Google, though. Smaller companies it makes sense because the threat actors that they are most likely to face are mostly script kiddies who give you at most a day before they get bored and try someone else. Google is another matter, since they're always a target for much more sophisticated attackers.
Re: Leaking the email of any YouTube user for $10k
#388Re: Leaking the email of any YouTube user for $10k
#389What can one do with a Gaia ID? I don't think the article went into the impact of having it.
Re: Leaking the email of any YouTube user for $10k
#390A little Update on the video, seems to be disabled by YouTube ToS
https://web.archive.org/web/0id_/http://wayback-fakeurl.arch...