Live data from Hacker News

Leaking the email of any YouTube user for $10k

brutecat.com

391–400 of 487 posts

Re: Leaking the email of any YouTube user for $10k

#391
post #332
post #298

Earlier quoted context omitted.

I wonder what your definition of crime is. Legally, in most places of the world it isn't. Morality differs among people too. Profiting off a trillion dollar company will not cross the line for a lot of people.

Most people have an intuitive sense to ask themselves questions like "If I do this, will someone be harmed, who, how much harm, what kind of harm, etc.", that factors into moral decisions. Almost everyone, even people without a moral sense, have a self-preservation sense- "How likely is it that I will get caught? If I get caught, will I get punished? How bad will the punishment be?" and these factor into a personal r…

It‘s a grey zone.

If Mr GRU asks, I probably say say no.

If the CIA, Mossad or BND asks, maybe I say yes? It’s not clear for a person with a better moral compass than mine.

Re: Leaking the email of any YouTube user for $10k

#392

Earlier quoted context omitted.

How many of those companies are profitable? How many do you think you will see a blog post about in a year or two - “Our Amazing Journey” where they won’t either go out of business or get acquired and their product gets shut down”? From Kagi’s website https://blog.kagi.com/status-update-first-three-months#:~:te... We are currently serving around 2.1M queries a month, costing us around $26,250 USD/month. Between Kagi…

Wrong blog post, try this one ;) https://blog.kagi.com/what-is-next-for-kagi

So what do you know about kagi’s profitability :).

I’m honestly glad to hear that. Until I heard your interview with Gruber, I thought Kagi was the same company that use to provide a payment platform for Mac indie developers.

It’s always good to see a bootstrapped company become successful without enshittification. I put you up there with BackBlaze.

I see you have investors now (not saying that is a negative). Are the laws still the same about having to be a “qualified investor”? Can anyone invest - asking out of curiosity.

Re: Leaking the email of any YouTube user for $10k

#393
post #190
post #73

Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations: * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneou…

> because $10,000 feels extraordinarily high for a server-side web bug. Am I misunderstanding the bug? In my reading, this bug translates to "a list of the top 1,000 Youtube accounts' email addresses (or as many as you can get until Google detects it and shuts it down)." Why isn't that conceivably worth more than $10,000?

The majority of the top 1000 YouTube accounts will actually have an email address publicly available, as they are a business and they want people to be able to reach out to them for sponsorships or brand collaborations.

For example, MrBeast has this in the video description:

> For any questions or inquiries regarding this video, please reach out to chucky@mrbeastbusiness.com

The vulnerability here is that you can find the exact email address tied to their YouTube account, which you can't really do anything with if they have strong passwords and use 2FA.

Re: Leaking the email of any YouTube user for $10k

#394
post #315

Earlier quoted context omitted.

Use it on the block user api and get an email address from what I understood.

But what else could definitely or potentially be done? It is an interesting question.

I think it's mainly a way to discover who's behind a youtube comment or video. Getting their email address often leaks information about them

Re: Leaking the email of any YouTube user for $10k

#395
From the article...

  15/09/24 - Report sent to vendor
  ...
  29/01/25 - Vendor requests extension for disclosure to 12/02/2025
  09/02/25 - Confirm to vendor that both parts of the exploit have been fixed (T+147 days since disclosure)
  12/02/25 - Report disclosed
So that is 136 days not fixed(?) and Google asks for extension. Then 147 days to fix and 150 days to public disclosure.

Compare this to Google Project Zero which gives other companies the following time to fix before disclosure...

>"This bug is subject to a 90 day disclosure deadline. If a fix for this issue is made available to users before the end of the 90-day deadline, this bug report will become public 30 days after the fix was made available. Otherwise, this bug report will become public at the deadline."

>If the patch is expected to arrive within 14 days of the deadline expiring, then Project Zero may offer an extension...Note however, that the 14-day grace period overlaps with the 30-day patch uptake window, such that any vulnerability fixed within the grace period will still be publicly disclosed on day 120 at the latest (30 days after the original 90-day deadline).

>If we don't think a fix will be ready within 14 days, then we will use the original 90-day deadline as the time of disclosure. That means we grant a 14-day grace extension only when there's a commitment by the developer to ship a fix within the 14-day grace period.

https://googleprojectzero.blogspot.com/p/vulnerability-discl...

Re: Leaking the email of any YouTube user for $10k

#398
post #296

I see a lot of noise made about responsible disclosure, its drivers, and its rewards. What I don't see is talk about how this is one more datapoint against centralized permanent identities. Every time I see a service purporting that it works best only with a single link to your Real Identity™, I'm reminded that the vendors only abstractly care about actually protecting the user, and then only sometimes. Imagine being…

> Every time I see a service purporting that it works best only with a single link to your Real Identity™, I'm reminded that the vendors only abstractly care about actually protecting the user, and then only sometimes. I abstractly agree with you. There is a level of obscurity and disposability that should be tolerated in these accounts. They’re just a row in a database somewhere anyways. That said, many people trans…

This is a fixable problem if we can get congress to roll back the insane KYC laws.

Re: Leaking the email of any YouTube user for $10k

#399
post #335

Earlier quoted context omitted.

I'm not a SWE anymore and haven't been one for a long time. I think it's in everyone's interest for bug bounties to be higher than harmful markets for the same bug, and a decent fraction of the harms they prevent. That's what is going to result in the economically efficient amount of bug hunting. And it's going to result in a safer world with less cybercrime.

No, it's not. CNE is shockingly effective, both for organized crime and for the international IC. The productivity wins are so great there is enormous space for the market prices of tradable vulnerabilities to increase; maybe even multiple orders of magnitude. We're not going to disrupt that process with bug bounties. I really think people just like to think about stories where someone like them finds a bug and gets…

> I really think people just like to think about stories where someone like them finds a bug and gets a lottery jackpot as a result. I like that story too! It's fun.

P.S. a lot of time your writing comes off as having a smug tone that rubs me the wrong way.

Actually, I already won a small lottery jackpot doing security stuff. Then a large one doing security stuff. Then a small one again doing other stuff. I could have retired a couple of decades ago, but now I'm a schoolteacher for the funsies. My days of scrunching over IDA Pro for pennies are over: I've got no personal direct interest in whether research gets paid more or less.

I just think that bug bounties are a good thing, but by being underfunded and with uneven quality of administration a lot of the potential benefit is left on the table.

Re: Leaking the email of any YouTube user for $10k

#400

I found this title confusing. For those who didn't make it toward the end of the article: the leaked emails didn't cost them anything (except their time and ingenuity), and they received 10k as the bug bounty.

Could be a clickbait sort of title.
Post reply on HN