YouTube video has its own URL in it
youtube.com
youtube.com
It's just a fun video of me messing around with Windows 8.1 I made a while back, trying out different "apps" and stuff. I thought it'd be a fun easter egg to download the video itself when I was trying out that strange YouTube MP3 downloader app :D
I didn't do it with the API (even though I tried to at first), just the normal youtube.com/upload site. I used Fiddler (Burpsuite alternative) to achieve this
I am not the first person to do this however, Insane Doll Gallery has made a video demonstrating this [youtu.be/ufq2Eb78kSU] (apparently used the API) and the channel NightFalls Studios has also used this trick in their My Little Pony comic animations [youtu.be/FDLvR9xrCag and youtu.be/7oXsOmqs6R4]
[1]: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Re...
http://www.alaricstephen.com/main-featured/2017/7/3/the-clin...
I'm going to try to solve it both ways. :)
I imagine that website is doing something that I wouldn't approve of.
1. create a resumable session (here we specify video length in bytes)
2. YouTube returns a session URI which contains the upload ID
3. create a video with the upload ID baked in (edit video to match length from step 1)
4. upload video to the session URI
https://developers.google.com/youtube/v3/guides/using_resuma...
The video sequence editor in Blender is awesome for arranging tracks, audio, transitions, overlays, text, etc. And with ffmpeg you can move it to any format you need. To clean up audio I use Audacity.
I have a project file I use as a template with the top right panel set as Video Sequence Editor "Image Preview", the top left for Graph Editor (for transitions curves and stuff), the bottom half of the screen for the Video Sequence Editor for moving around the tracks. Then I just use Add -> Movie/Sound/Image/Effect for all of the actual editing.
When I'm done I switch one of the panels to Properties where I have the render settings configured to use ffmpeg for MP4 output and hit Animate.
I've just pulled down a 2.80 release candidate with the UI overhaul to see if it's any better. It's actually pretty nice. I just selected the video editor option in the startup screen, and things sort of worked like I expect in a NLE.
Good to put some VFX.
Also available for GNU/Linux: https://www.blackmagicdesign.com/products/davinciresolve/
(And as we all know Twitter has no edit button, no post-upload shenanigans are possible here, just some clever guessing and reverse-engineering Twitter's ID generation algorithm)
As you said, it largely relies on reverse engineering and bruteforcing Twitter's ID generation.
Screenshot: https://i.imgur.com/3oTXTDK.png
To: Pi
Subject: Project Time Machine - Test #3
It sounds like someone's trying to create some fun meta-fiction - it looks like a letter from the creator's future self to his past-self, describing future-self's experience going through some iteration of the time-loop ("Don't talk about fate. You did it once and it was cringy.")
The document is covering the sign at the start of the video, so the uploader could have uploaded that section (without any text on the sign in-game), then "resumed" the upload with a different video that contains the URL on the sign and starts after he switches to the Minecraft window.
---
It's actually a bit of a long story, but it's kind of an interesting part of reddit's history. Some of my details are probably off, but this is how I understand it.
A long, long time ago, reddit only supported submitting links. Link submissions were pretty much exactly the same as they still are now, including having a comments page that you could go to with an address like the page we're currently on: http://www.reddit.com/r/help/comments/2bmy3l/what_does_the_s...
If you look at that address, one thing to notice is that it includes the submission's ID in base-36, which for this post is "2bmy3l". If you go to http://www.reddit.com/r/all/new and look at the links to the comments pages of the newest posts, you'll notice that their IDs are increasing. For example, at the time I'm writing this, the newest IDs are 2bo3uw, 2bo3ux, 2bo3uy.
Since the IDs are increasing, you can predict which ones are coming up. You know that the next ID after those ones should be 2bo3uz. So some person decided it would be funny if they pre-constructed a link like this: http://www.reddit.com/r/reddit.com/comments/<id>/this_post_w... and then checked which IDs were coming up, filled in the "<id>" spot with one that should be used soon, and submitted it.
If they got their timing right, they'd end up with a link post that actually went nowhere. Clicking it would just take you to its own comments page, since they had managed to predict the url that the comments page would have. This was a "self post", a post that linked to itself.
So this was a pretty neat trick, and when it was successfully pulled off for the first time, it got a whole bunch of attention. Unfortunately, reddit's never been very good at just seeing some new popular thing as a novelty and moving on. No, of course pretty much everybody wanted to get their own "self post". The majority of the new submissions to the site were suddenly just people trying to make a self post, completely drowning out all the real submissions.
It was causing a gigantic mess, so one of the admins at the time decided to get people to stop by taking all the fun out of the game. They made it so that you could just choose to make a self post. You didn't have to guess the ID or anything, you just selected that you wanted to make a self post and automatically got one. It didn't have the option to add additional text or anything yet (that came later), it was just a title that linked to its own comments page.
So that's how self posts came about, and where the name originated. A quick solution to a mess being made by users that eventually turned into one of the most important pieces of reddit.
https://www.reddit.com/r/finance/comments/3ancv0/selffinance...
I later became "more" famous for inadvertently DDoSing reddit, and forgot all about it until someone replied to one of my comments saying "aren't you the asshole who brought down reddit as an April fool's joke?". "Huh? No! Oh, wait".
It had millions of subscribers. They all kept refreshing.
So very reddit.
Do you know what year that was?
1) Make an educated guess about what the URL will be and put it in the video.
2) Upload.
3) If you were wrong, delete it and go to 1).
I'm half joking, but that's basically what they did for a git utility that would let you edit histories so that messages could refer (by partial hash) to later commits. I forget the name, though, and couldn't find it on a quick search.
You seem to be calculating some combinatorial explosion, where there probably is none
38 frames * 8 (or however many possible characters there are.
It's 62^11 * 0.016 (seconds). 11 because 11-character-long id; 62 because 62 possible characters in each location (26 lowercase, 26 uppercase, 10 numerals); 16ms in each frame of a 60fps video.
for idIndex in 0..<11 {
for character in setOfPossible {
draw(character)
frame += 1
}
}YouTube uses base64 for the URLs, which makes 64 different characters
I divided it by 60 frames, 60 seconds, 60 minutes, 24 hours and 365 days
This wouldn't violate the write-once model since the submission wouldn't be completed, it'd just defer finalizing and publishing it for a little.
Any one has a guess how this was done? If they use a one way hash over metadata and content if video does this not mean that someone has figured out their secret key.
Also you could pad the file with some extra data, but that feels like cheating.
It's a PDF, a ZIP, and an HTML page:
If you drop it on itself in a browser,
it can give you a PDF viewer, a video
and a PNG explaining the whole file structure.
All these files have the same MD5.
https://twitter.com/angealbertini/status/1111329484647616513The explanation for how the MD5 trick is achieved is in the PDF, starting on page 21.
Edit: whoops, probably more relevant is this earlier issue, which has the MD5 printed on the cover. https://github.com/angea/pocorgtfo/blob/master/contents/issu... The relevant article in that issue starts on page 46.
edit: Yes, sorry for the crappy source though -> https://www.reviewjournal.com/insidetech/youtube-lets-some-u...
edit: after looking at the other guy mentioning the time machine reference, my theory would be that he just spammed this API until he got a plausible URL and only then recorded and uploaded the video, probably would take a while but not forever considering how loose the URL actually is to delorean
Edit: I don't know the answer but I assume from all the APIs I worked with in the past, but if you get the URL before the upload is completed then yeah it's pretty easy to "fake".
My guess is that you can start an upload, get the ID, and then stream unimportant and non-comitall video headers and chunks (e.g. subtitle tracks or other metadata) slowly enough to keep the server from closing the connection on you. Then you can just record your video and start uploading actual video chunks once ready.
Or maybe YouTube doesn't have a huge timeout for starting your upload, so you don't even have to do all of that.
So it seems you can get the URL immediately... maybe then stop the upload mess with the video and then resume the upload... but I assume the resume feature takes a hash or something to make sure it's the same file..
I tried it with a named pipe ("mknod /tmp/foo.mp4 p") and it gave me an error, but before the error, the web page blocked during upload, but it showed me the URL that will be used (before I gave it a single byte of data).
Edit: Oh, I didn't even see the time travel reference in the ID. Maybe the ID is generated from metadata, and there's some endpoint where he was able to throw random metadata at it in an automated process until it came out looking somewhat like "delorean". Or he was able to get ahold of the algorithm locally for a quicker version of that process. In any case, I doubt he backwards-engineered anything.
tip: if you see something magic it's usually just dilligence in disguise. (like the Prestige)
- post first half
- fumble around trying to find the link
- get despearate because my comment only shows an /edit link
- find another link from someone else, paste that in
- change the /item?id=<n> to the id of my /edit?id=<n> comment
- save the change
- follow the link
- follow the link a few more times
- relax.