Live data from Hacker News

Leaking the email of any YouTube user for $10k

brutecat.com

401–410 of 487 posts

Re: Leaking the email of any YouTube user for $10k

#401
post #284

Earlier quoted context omitted.

Prominent youtuber doxxed and killed; terrible press extended for an extended period by litigation. 1 in 5000 but very high cost. Large scale data leak and need for data leak disclosure. 1 in 3, moderate cost. Bug report saving engineering time by giving clear report of issue instead of having to dig through telemetry and figure out misuse and then identify what is going on, extents of past damage, etc. 3 in 4.

You think that being able to get someone's email address (most likely a business email but let's pretend it's a personal email) has a 1 in 5,000 chance of being turned into enough personal information to track down AND that someone would use it to kill someone? Millions of usernames and emails are leaked every month; if this was the case you'd be seeing these murders in the news every week.

> Millions of usernames and emails are leaked every month; if this was the case you'd be seeing these murders in the news every week.

Yes, because all possible scenarios kill the same fraction of people-- whether we're talking about getting a dump of a million email addresses or giving some nutjob a chance to unmask people he doesn't like online.

Re: Leaking the email of any YouTube user for $10k

#402

Earlier quoted context omitted.

> Every time I see a service purporting that it works best only with a single link to your Real Identity™, I'm reminded that the vendors only abstractly care about actually protecting the user, and then only sometimes. I abstractly agree with you. There is a level of obscurity and disposability that should be tolerated in these accounts. They’re just a row in a database somewhere anyways. That said, many people trans…

This is a fixable problem if we can get congress to roll back the insane KYC laws.

It's also fixable in ways that don't require rolling back KYC laws.

Re: Leaking the email of any YouTube user for $10k

#403

I found this title confusing. For those who didn't make it toward the end of the article: the leaked emails didn't cost them anything (except their time and ingenuity), and they received 10k as the bug bounty.

From the D/M/Y date format at the end of the article, they may not be native English speakers (at least they aren’t American).

Re: Leaking the email of any YouTube user for $10k

#404

> Here's a POC of the exploit in action: This video has been removed for violating YouTube's Terms of Service That's hilarious.

Weird that it shows that to me at first as well, but now when I opened the article again, the video seems to be available? Not sure if it was restored just now.

Re: Leaking the email of any YouTube user for $10k

#405
post #340

I found this title confusing. For those who didn't make it toward the end of the article: the leaked emails didn't cost them anything (except their time and ingenuity), and they received 10k as the bug bounty.

I thought they meant providing the services to leak the email of any user for $10K, perhaps per user. :)

I thought they meant it cost $10K of compute time to brute force some process that would reveal one email address.

Re: Leaking the email of any YouTube user for $10k

#406
post #296

I see a lot of noise made about responsible disclosure, its drivers, and its rewards. What I don't see is talk about how this is one more datapoint against centralized permanent identities. Every time I see a service purporting that it works best only with a single link to your Real Identity™, I'm reminded that the vendors only abstractly care about actually protecting the user, and then only sometimes. Imagine being…

They don't care because there's no legal consequence for them.

Try and leak some medical data as a medical services provider. You will get your ass handed to you.

Re: Leaking the email of any YouTube user for $10k

#407

Earlier quoted context omitted.

The reputation angle shouldn't be dismissed: Google paying so little for this bug is the whole reason this article stays on the top page and gets so much discussion. I don't know how much it should be worth, but at least there's a PR effect and it's also a message towards the dev community. I see it the same way ridiculously low penalty for massive data breaches taught us how much privacy is actually valued.

If Google doesn't have the best reputation of any large tech company for security, it's in the top 3. This is not the nightmare scenario for Google that people think it is. It's a large payout for this bug class, so, if anything, what we're doing here is advertising for them.

I'm in all agreement (genuinely thankful for the context you brought on the difference in market values for this category of bugs), which is also part of why it's sobering privacy bugs have such a low valuation and this is set as a high payout.

For security researchers it's apparently obvious, but from the outside it's another nail in the coffin of how we want to think about user data (especially creators, many being at the front line of abuse already). As you point out Google here is only the messenger, but we'll still remember the face that delivered the bitter pill for better and worse.

Re: Leaking the email of any YouTube user for $10k

#408
post #403

I found this title confusing. For those who didn't make it toward the end of the article: the leaked emails didn't cost them anything (except their time and ingenuity), and they received 10k as the bug bounty.

From the D/M/Y date format at the end of the article, they may not be native English speakers (at least they aren’t American).

England is just one example of a country of native English speakers who use dd/mm/yyyy.

Re: Leaking the email of any YouTube user for $10k

#409
post #403

I found this title confusing. For those who didn't make it toward the end of the article: the leaked emails didn't cost them anything (except their time and ingenuity), and they received 10k as the bug bounty.

From the D/M/Y date format at the end of the article, they may not be native English speakers (at least they aren’t American).

The USofA is the bizarre exception here:

  The United States has a rather unique way of writing the date that is imitated in very few other countries (although Canada and Belize do also use the form). In America, the date is formally written in month/day/year form.
They don't use metric, still use First Past the Post voting, elect a mini monarch with effectively unchecked powers, ... it's an odd place.

Re: Leaking the email of any YouTube user for $10k

#410
post #403

Earlier quoted context omitted.

From the D/M/Y date format at the end of the article, they may not be native English speakers (at least they aren’t American).

England is just one example of a country of native English speakers who use dd/mm/yyyy.

yyyy-mm-dd is the iso standard, w/ the benefits of logical consistency (larger to smaller units left to right) and -- best of all -- sortability.
Post reply on HN