Live data from Hacker News

Leaking the email of any YouTube user for $10k

brutecat.com

471–480 of 487 posts

Re: Leaking the email of any YouTube user for $10k

#471
post #466

Earlier quoted context omitted.

You're free to disagree, but you don't need to do it with the snarky variant "I like that story too! It's fun." that's so easily misread on the internet. You're right that I've not been involved in the grey market for awhile. And when I did, I was on the "advising sophisticated buyers" side of it, rather than trying to sell things.

I think our biggest point of disagreement is just on the notion that you can sell bugs like the one on this thread to brokers. I think we're directionally in similar places on Google and Apple. As I said: I know who you are; I'm not writing to you as if you're a rando who thinks logout CSRFs are worth big money.

> I think our biggest point of disagreement is just on the notion that you can sell bugs like the one on this thread to brokers.

I don't think you're getting a ton of money for them.

But, it's my understanding that there are state actors who want to unmask people who are saying things they consider not-nice on social platforms and who have made it known that they will pay for things like this.

Re: Leaking the email of any YouTube user for $10k

#472
post #471

Earlier quoted context omitted.

I think our biggest point of disagreement is just on the notion that you can sell bugs like the one on this thread to brokers. I think we're directionally in similar places on Google and Apple. As I said: I know who you are; I'm not writing to you as if you're a rando who thinks logout CSRFs are worth big money.

> I think our biggest point of disagreement is just on the notion that you can sell bugs like the one on this thread to brokers. I don't think you're getting a ton of money for them. But, it's my understanding that there are state actors who want to unmask people who are saying things they consider not-nice on social platforms and who have made it known that they will pay for things like this.

It's fine that we disagree. I don't think there's a real market for this. I think you can plan a heist with anybody, though, if that's a road you want to go down.

Re: Leaking the email of any YouTube user for $10k

#473
post #470

Earlier quoted context omitted.

I hear that concern a lot, about younger code, but I think that misapprehends the situation. New code will bring new bugs, but only specific kinds of bugs have real market value. I think we're on a trajectory towards those marketable bugs having something like a vintage. I see bounties as an engineering tool more than anything else. For the reason I provided upthread, I don't think it's likely that they're going to a…

> I think we're on a trajectory towards those marketable bugs having something like a vintage. I'm reminded of when we really systematically started treating temporary names correctly and thought security was going to be so much better. I think there's no shortage of bugs and exploitation scenarios. We'll eliminate the easiest to exploit and most common mistakes, but there will be yet more. > I think the most importa…

If we're talking about mid-90s race conditions there, with "temporary names", there was never a market for those vulnerabilities. There's a myriad of different vulnerabilities and new bug classes announced with fanfare every year at Black Hat and the Big Four conferences, but we've been in what seems like a stable state for over a decade on which of those vulnerabilities are actually tradable.

Re: Leaking the email of any YouTube user for $10k

#474
post #470

Earlier quoted context omitted.

> I think we're on a trajectory towards those marketable bugs having something like a vintage. I'm reminded of when we really systematically started treating temporary names correctly and thought security was going to be so much better. I think there's no shortage of bugs and exploitation scenarios. We'll eliminate the easiest to exploit and most common mistakes, but there will be yet more. > I think the most importa…

If we're talking about mid-90s race conditions there, with "temporary names", there was never a market for those vulnerabilities. There's a myriad of different vulnerabilities and new bug classes announced with fanfare every year at Black Hat and the Big Four conferences, but we've been in what seems like a stable state for over a decade on which of those vulnerabilities are actually tradable.

> If we're talking about mid-90s race conditions there, with "temporary names", there was never a market for those vulnerabilities.

More like mid-80's with effects dragging on to mid-90's.

There was never a market back then at all. ;) The point is, many confidently announced that all the easy to exploit stuff in Unix was being fixed and soon security was going to be less of a problem.

> but we've been in what seems like a stable state for over a decade on which of those vulnerabilities are actually tradable.

Yes, but that doesn't stay the same if the low hanging fruit dries up as you posit. The level of sophistication of both exploit writers and exploit consumers will have to climb, but we're nowhere near the ceiling of the skills and effort that crime and intelligence can pay for.

Re: Leaking the email of any YouTube user for $10k

#475
post #474

Earlier quoted context omitted.

If we're talking about mid-90s race conditions there, with "temporary names", there was never a market for those vulnerabilities. There's a myriad of different vulnerabilities and new bug classes announced with fanfare every year at Black Hat and the Big Four conferences, but we've been in what seems like a stable state for over a decade on which of those vulnerabilities are actually tradable.

> If we're talking about mid-90s race conditions there, with "temporary names", there was never a market for those vulnerabilities. More like mid-80's with effects dragging on to mid-90's. There was never a market back then at all. ;) The point is, many confidently announced that all the easy to exploit stuff in Unix was being fixed and soon security was going to be less of a problem. > but we've been in what seems l…

Right, so I'm not confidently predicting the end of software security (I'm "optimistic" about its relevance, in the same way you're pessimistic about the long term security of software). But drive-by clientside exploits are a particular kind of software security problem, and that one, I do see the light at the end of the tunnel (and also a prolonged period of 7-8 figure exploit premiums).

Re: Leaking the email of any YouTube user for $10k

#476

From the article... 15/09/24 - Report sent to vendor ... 29/01/25 - Vendor requests extension for disclosure to 12/02/2025 09/02/25 - Confirm to vendor that both parts of the exploit have been fixed (T+147 days since disclosure) 12/02/25 - Report disclosed So that is 136 days not fixed(?) and Google asks for extension. Then 147 days to fix and 150 days to public disclosure. Compare this to Google Project Zero which g…

I don't think this is a useful comparison. This is Google's bug with Google's software vs. Project Zero's discoveries are (as I understand them) typically in software used by multiple people and thus there's a higher urgency to fix them.

Its not apples to apples but i think it shows Google's hypocrisy.

Re: Leaking the email of any YouTube user for $10k

#477

Earlier quoted context omitted.

> Have you used Books extensively or just skimmed it? There's no way to keep books on device, make another Google search if you do not believe me. Once you download a book to a device, it stays downloaded. There is a setting to automatically remove downloads once you're finished with the book, but that defaults to off (and I didn't even realize it was there until I went looking just now).

>Once you download a book to a device, it stays downloaded. This is objectively false. I suggest you do a simple google search or read my other comment.

I read your other comment. It looks like you're talking about iCloud Storage there. Books downloaded from the Apple Books Store do not go into iCloud Storage. Books you've uploaded are stored in iCloud.

I just checked my phone, I have 169 books downloaded. This includes many books I haven't looked at for years and years. This includes many books that I bought 3, 4, 5 iPhones ago and are still present, copied from device to device, because Books does not remove store downloads unless asked to.

Re: Leaking the email of any YouTube user for $10k

#478

Earlier quoted context omitted.

The back of an envelope can get you making silly claims quickly (ex. 26 ^ 8 is 208 billion)

Not seeing the problem. Are you assuming that somehow there is at most one Gmail account per person on earth? I have… I’m not sure. Ten maybe? And those are actual conveniences for different purposes. I’m sure plenty of people have hundreds, if not thousands. So what?

I'm a bit confused:

- I charitably went with 208 billion, 25 for every single individual on this planet.

- As the other replies note, I chose a misleading number that is off by an order of magnitude at even the most charitable reading

- You can't see the problem

I don't think it's fair to you to assume you can't see it, maybe you were in an old tab that had my reply but none of the descendants.

Re: Leaking the email of any YouTube user for $10k

#479

Earlier quoted context omitted.

In any case there are two sane ways to write dates, and the middle-endian format is not one of them.

The other is the US military one 14FEB2025,yes? That and ISO are all we need.

That military style uses little endian so it belongs in the sane formats category.

However, with ISO you're likely referring to RFC3339. The full ISO8601 standard allows insane date representations you're not going to see anywhere but the documentation that explains them.

Re: Leaking the email of any YouTube user for $10k

#480

Earlier quoted context omitted.

Wrong blog post, try this one ;) https://blog.kagi.com/what-is-next-for-kagi

So what do you know about kagi’s profitability :). I’m honestly glad to hear that. Until I heard your interview with Gruber, I thought Kagi was the same company that use to provide a payment platform for Mac indie developers. It’s always good to see a bootstrapped company become successful without enshittification. I put you up there with BackBlaze. I see you have investors now (not saying that is a negative). Are th…

For the particular type of investment we were doing (angel list roll up vehicle with basically our users) one needs to verify they are an accredited investor.
Post reply on HN