I would've expected at least a job offer or public praise for his offers. No wonders bug hunting is not attracting enough people.
Out of interest, how do you think you'd go about monetising this bug?
I agree that the information leakage is definitely bad, but exploiting that to turn it in to cold hard cash seems tricky at best imo. I presume this factors in to Google's payout calculations.
And no, how much it could be monetized certainly shouldn't factor into lowering the bounty. Maybe when raising it, since you need to be competing with the black market, but an exploit should be valued only on how much damage it could cause, and getting people disappeared for watching anti-government videos sounds like pretty big damage.
I think this part is probably pretty hard and is certainly risky.
We almost always talk about how pitiful the rewards are, every time someone discloses a pitiful reward. Your post is doing exactly that.
We need to disabuse corporations of the idea that they deserve responsible disclosure when they pay paltry sums for serious bugs.
YouTube embeds are such universal things on the web, I doubt anyone would even think twice about security concerns coming from seeing that on a third-party site.
Because it's Google, right? /s