Live data from Hacker News

Leaking YouTube creators' private videos

javoriuski.com

391–400 of 436 posts

Re: Leaking YouTube creators' private videos

#391
post #166

Earlier quoted context omitted.

Youtube should consider their engineers responsible for the software they write. Big companies these days are just bureaucracy tricks and politics. There's a small handful of real talent, but they're quickly moving to new startups. Also, I'm Canadian as well, and almost everyone calls themselves "software engineer" these days. You just can't say P.eng. in your title. You could be forced to remove it from linkedin/etc…

Your latter point is legally incorrect. The protected term in Canada is “engineer”. If someone calls themselves an engineer without a P.Eng, that’s an offence.

Thank you for the education. What is the consequence of an offence?

Re: Leaking YouTube creators' private videos

#392
post #249

I don't understand, how does this leak a private video title¹ when you need to post a comment on the video you want to leak? Aren't you on the video page at that point? And the creator needs to click the link inside of a comment section or summary thereof. I disagree with Google saying that phishing vectors are irrelevant for security (it's basically the top vector and Google knows that), but it's hard to disagree wi…

The scenario described in the OP does not involve commenting on a private video. It involves commenting on any public video, then the uploader clicks on a suggested prompt in YouTube Studio which supposedly processes the comment and creates a URL with the title of a different video.

Okay yeah that was my best guess also, thanks for confirming. I don't know the modern yt back-end well enough to understand how it would mix these things up but it indeed can't work otherwise

Re: Leaking YouTube creators' private videos

#393
post #378
post #368

Earlier quoted context omitted.

> That's why trains work and that's why trains work but you have to pay a higher price to use it, while youtube is shitty, and breaks often, but it's free to use. It is about the trade offs - not the trade offs that someone talks about passively, but actual action based trade offs; ala voting with their feet.

You pay either just with money (Youtube premium) or by watching ads...

NYC subway has tons of ads and is constantly have problems, this thread comparison is horrible.

Re: Leaking YouTube creators' private videos

#394
post #181
post #71

Earlier quoted context omitted.

The described attack sounds like it's expecting the human to forget about having just clicked a UI element asking for a comment summary, and responding to a comment summary that tries to sound like an "important message from YouTube" as if it were actually such. It doesn't seem to involve the LLM actually having any agency to, for example, send an email to the creator. Mitigations would include ensuring it doesn't ha…

Its not hard to imagine this is a serious risk in some cases. For example: A youtuber essentially working as a journalist made a big story recently about some illegal actions of a lying and litigious company (Bricks and Minifigs story). The youtuber has a 3rd video ready for when his gag order drops, if that were to be released early he could find himself in jail.

Related to the bricks and minifigs story checkout the coffeezilla episode on it

Re: Leaking YouTube creators' private videos

#395
post #388
post #324

Earlier quoted context omitted.

> We're still figuring all this out. The defining feature of engineering as a profession isn't how much we collectively know about it, it's the attitude we bring into day-to-day practice. Take something like the Sony BMG rootkit scandal[0]. Anybody with an ounce of sense and even basic technical programming knowledge could tell the sort of security issues that that piece of software could lead to. Shipping that thing…

On the one hand, the developers who were ultimately tasked directly with building Horizon were completely unqualified to write an accounting system, and lacked even basic knowledge about accounting in general, including fundamental misunderstandings about the very nature of double-entry and ledger-based accounting. From what I can remember from released correspondence, for example, Horizon had fundamental design mist…

Funny you used the word "developer", and I used the word "engineer", because that distinction is critical. A brick layer is not a civil engineer, and is not signing off on a construction project. Likewise, the developers banging out tickets don't have to be software engineers who sign off on a software project.

In the Horizon case, I'm thinking of people like Gareth Jenkins. He was the guy who designed the system, and also one of the expert witnesses you mentioned. He's the one who should be held to the standards I'm talking about.

Re: Leaking YouTube creators' private videos

#396

Earlier quoted context omitted.

Your latter point is legally incorrect. The protected term in Canada is “engineer”. If someone calls themselves an engineer without a P.Eng, that’s an offence.

Thank you for the education. What is the consequence of an offence?

at least in Ontario, fines, starting at $ 25,000.

Re: Leaking YouTube creators' private videos

#397

Earlier quoted context omitted.

That's why trains work, but Google's shitty YouTube often does not: Terrible, terrible video player, tons of crap on the page, broken buffering all the time, huge memory and CPU hog, need to log in to even watch a video if using a VPN, insane key bindings that are switched around depending on full screen mode or not, stupid and manipulative ads that only the uninformed or simple minded can tolerate, and the list goes…

I find YouTube player better than any other online player

I find even standard HTML5 player better than YouTube's player. So many issues with YouTube's player. Sometimes not even the play button works properly.

Re: Leaking YouTube creators' private videos

#398
post #324

Earlier quoted context omitted.

> We're still figuring all this out. The defining feature of engineering as a profession isn't how much we collectively know about it, it's the attitude we bring into day-to-day practice. Take something like the Sony BMG rootkit scandal[0]. Anybody with an ounce of sense and even basic technical programming knowledge could tell the sort of security issues that that piece of software could lead to. Shipping that thing…

That would put full blame on the tech staff and let the C-suite get away. The success of a software product is measured by sales and user base, so the more successful their sales and marketing are, the higher the damages will be for the tech staff. I am of the opinion that companies and their management should be personally liable for damages caused by bad software, not their employees. They created the structure, hi…

I would argue the outcome of setting up a perverse incentive structure and failing to hire QA is pretty damn predictable, so that's entirely consistent with what I said :)

On a more serious note, I'm not saying "just make programmers liable for the code they write", and leave it at that. I'm saying that, when you sell a piece of software, someone needs to sign-off on that software being fit for purpose. It's that someone who's ultimately liable. Absent some explicit firebreak, that sign-off implicitly happens with the CTO or CEO.

Re: Leaking YouTube creators' private videos

#399
post #370
post #167

Why doesn't the article contain proof of either attack in action? I would be surprised if the second attack worked after what must be at least a couple layers of markdown/html conversion and spam filtering. disclaimer: work at Google, but far removed from YouTube

The attack requires a third party to unknowingly click on the engineered URL that leak private video title. Not sure if it counts as a POC if you can only use your own channel to prove it works. But still, it would require a user interaction to click on the link to leak data - and google should acknowledge it as an issue, because an attacker should never be able to generate a link they control in a trusted/secure env…

I understand the purported vulnerability. What I am saying is that I would be surprised if the URL were rendered, let alone made it to the victim.

Re: Leaking YouTube creators' private videos

#400
post #368

Earlier quoted context omitted.

> That's why trains work and that's why trains work but you have to pay a higher price to use it, while youtube is shitty, and breaks often, but it's free to use. It is about the trade offs - not the trade offs that someone talks about passively, but actual action based trade offs; ala voting with their feet.

> but it’s free to use This is false. Nothing is free. We watch ads. We are tracked like animals. That time, attention and loss of privacy *is* payment. For this, it’s reasonable to expect a service that aspires to rise above shit-show.

Is free software free?
Post reply on HN