Live data from Hacker News

Leaking the email of any YouTube user for $10k

brutecat.com

441–450 of 487 posts

Re: Leaking the email of any YouTube user for $10k

#441
post #440

It's quite clever how the email notification was disabled (setting the email subject length to 2.5million characters, so the email delivery itself would fail).

Right? You’d think at Google’s scale they’d sanitize every single user inputs, like truncate the string and suffix it with “…” instead of the mail delivery throwing an exception.

Re: Leaking the email of any YouTube user for $10k

#442

I found this title confusing. For those who didn't make it toward the end of the article: the leaked emails didn't cost them anything (except their time and ingenuity), and they received 10k as the bug bounty.

The title should have been something like, "Revealing the email address"...

Re: Leaking the email of any YouTube user for $10k

#443

Earlier quoted context omitted.

> Most other fields of endeavor aren’t compensated based on the black market value of the thing that’s being produced. > If we apply your analysis to other things This analysis doesn't work for a few reasons: * For physical goods, used items always fetch a lower price than new items due to unrelated effects. And if we're only looking at the used price, we do find that the black market price is just about equal to the…

> For physical goods, used items always fetch a lower price than new items This is only true under certain circumstances. If there are supply chain issues, used prices can go up and over the list price. The most extreme (and obvious) example I've seen is home gym equipment during the Covid lockdowns, particularly for stuff like rowing machines. The other potentially less obvious example is seen in countries that don'…

> If there are supply chain issues, used prices can go up and over the list price.

The comment you're replying to isn't referring to list price, they're referring to the price of a new item.

Supply chain issues, as we saw during COVID, affect the cost of new items by making them effectively infinite: if there are only 100 new rowing machines available and 1000 people want them, then for 900 people, the list price of a new rowing machine is irrelevant because they can't actually buy it at that price.

Re: Leaking the email of any YouTube user for $10k

#444

Earlier quoted context omitted.

But then what? Given the number of accounts Google has, odds are that nearly every alphanumeric combo less than 8 or 10 characters plus “@gmail.com” is a google account. This vulnerability gets you other domains, but still not seeing it. Massive databases of email addresses are a dime a dozen. The only angle I can imagine is phishing for high profile creators, and at most this is a “makes it easier” and not a “create…

The back of an envelope can get you making silly claims quickly (ex. 26 ^ 8 is 208 billion)

Not seeing the problem. Are you assuming that somehow there is at most one Gmail account per person on earth?

I have… I’m not sure. Ten maybe? And those are actual conveniences for different purposes. I’m sure plenty of people have hundreds, if not thousands. So what?

Re: Leaking the email of any YouTube user for $10k

#445
post #155

Earlier quoted context omitted.

And then what? Exploits need to plug into a business plan. Like any business plan there has to be somewhere that money gets extracted and that money needs to be more than the exploit cost & infrastructure costs & a risk premium. If you can’t trivially say how the exploit explicitly gets turned into cash you probably are on the wrong track. Doubly so if it’s not a known standard and commoditized way that’s happened be…

Say you’re a blackhat OSINTer trying to steal crypto. You have a first initial and a last name for a target (“J. Smith”) - plus you know this person is on github and discord. You take out your handy email list and run a regex to find candidate accounts that match “J Smith”. You pipe matches into a recon script to check if github and discord accounts exist for each email. Suddenly, you’ve got a small pool of matches.…

Surely the key part of this is "this person's email address and password has been published online together" rather than "I can identify this person's email address."

Re: Leaking the email of any YouTube user for $10k

#446
post #188

Earlier quoted context omitted.

There’s 100% an active market for this, and I think tptacek is simply wrong on this point (the others are valid) The likes of Cambridge Analytica didn’t go away, they exist and absolutely go hunting for data like this. The ability to map between different identifiers and pieces of content on the internet is central to so many things - why do you think adtech tries to join so many datapoints? Let alone things like inf…

I think you've missed my point. I know data brokers exist. Does there exist today a data broker that functions in whole or in significant part buy acquiring vulnerabilities and exploiting them to collect data? He's a more concise way to frame my argument: if you're imagining yourself to be the first person to sell a particular kind of vulnerability to, then your customer is imaginary.

Yeah, I think this is valid. “I’m confident I can find someone who will buy this” vs “I’ll message grugq”, roughly?

Re: Leaking the email of any YouTube user for $10k

#447

Earlier quoted context omitted.

> How are alarms unreliable? A simple google search will answer this question https://www.theverge.com/2025/1/9/24340238/apple-iphone-alar... Even an hn search is fine, if you do not trust the Verge (notice these are comments from the last 3 months so not an old issue): https://news.ycombinator.com/item?id=42705217 https://news.ycombinator.com/item?id=41887505 https://news.ycombinator.com/item?id=41962418 > Books aut…

> Have you used Books extensively or just skimmed it? There's no way to keep books on device, make another Google search if you do not believe me. Once you download a book to a device, it stays downloaded. There is a setting to automatically remove downloads once you're finished with the book, but that defaults to off (and I didn't even realize it was there until I went looking just now).

>Once you download a book to a device, it stays downloaded.

This is objectively false. I suggest you do a simple google search or read my other comment.

Re: Leaking the email of any YouTube user for $10k

#448

From the article... 15/09/24 - Report sent to vendor ... 29/01/25 - Vendor requests extension for disclosure to 12/02/2025 09/02/25 - Confirm to vendor that both parts of the exploit have been fixed (T+147 days since disclosure) 12/02/25 - Report disclosed So that is 136 days not fixed(?) and Google asks for extension. Then 147 days to fix and 150 days to public disclosure. Compare this to Google Project Zero which g…

I don't think this is a useful comparison. This is Google's bug with Google's software vs. Project Zero's discoveries are (as I understand them) typically in software used by multiple people and thus there's a higher urgency to fix them.

Re: Leaking the email of any YouTube user for $10k

#449
post #240

Earlier quoted context omitted.

You don’t think there are folks with content they’d very much not like to be directly associated with them? Comments, videos, likes, etc

And so what's going to happen? Are there blackmailing rings that are in active need of ways of tying youtube comments to work accounts that are paying out the nose?

You don’t think the daily mail would buy a story about how firstname.lastname@nypd.ny.gov posted a comment in support of the KKK?

Re: Leaking the email of any YouTube user for $10k

#450
post #355
post #188

Earlier quoted context omitted.

There’s 100% an active market for this, and I think tptacek is simply wrong on this point (the others are valid) The likes of Cambridge Analytica didn’t go away, they exist and absolutely go hunting for data like this. The ability to map between different identifiers and pieces of content on the internet is central to so many things - why do you think adtech tries to join so many datapoints? Let alone things like inf…

There's an easy way to put your money where your mouth is here. Just offer $11k for this or similar vulnerabilities out of your own pocket, and then resell them. If there really is a large and active market for this at higher dollar values, you'll make a killing! Sure is funny there's nobody doing that despite so many people being so dead certain there's an active market.

If I did, would you know?

And if I did, it wouldn’t stop people from doing co-ordinated disclosure either, would it? Same with high end exploits - some folks do co-ord disclosure because it feels good and is great for your CV; others sell gray market and we generally have no idea what’s being traded.

(With the exception of say, zerodium or 0xcharlie’s various talks)

Post reply on HN