> Exploit a Protobuf Flaw to Easily Remove All Ads by Changing One Byte
He's intentionally corrupting the tag on one field of the protobuf. The "flaw" is apparently that Protobuf ignores tag numbers it doesn't recognize. But that's not a flaw, it's a core design feature of Protobuf, designed to allow extensibility.
> Notice how the Protobuf response payload is 1.87 MiB? As I said, Google makes it computationally expensive to decode, alter, and re-encode without the C++ source proto files, but a quick linear scan takes no effort at all.
1.87MB is not that big, and presumably these messages only come through occasionally, not in a constant stream, so I'm a bit perplexed about the purported performance barrier here.
The text seems to be claiming that Protobuf encoding is designed to be expensive to decode, but it's actually the opposite, Protobuf is intended to be efficient to decode.
He says you need the source proto (schema) files to make it efficient, but this isn't really true, you can decode directly into UnknownFieldSet easily enough.
Or better, he could have written his own fake .proto schema that covers just the one field he is aiming to remove. This would have been much less error-prone than the string-scanning approach which could accidentally match other data where the same byte sequence happened to appear by coincidence.
> While computationally expensive, decoding, editing, and re-encoding without the original schema leads to a modified encoding. This is likely because we cannot detect if ZigZag encoding is being used, or if a number is an int32, int64, sint32/64, varint, etc., plus the order of object fields is normally non-deterministic. Here is some Protobuf trivia on the matter:
I think he's misunderstanding here. The point is that the Protobuf encoder is allowed to encode fields in any order, hence decoding and immediately re-encoding a message can lead to different bytes. But, the receiver is supposed to treat the message the same regardless. It's unlikely that the YouTube app is going to notice if the field order changes.
(I used to work on Protobufs, a long time ago.)