Leaking the email of any YouTube user for $10k
brutecat.com
brutecat.com
I thought it meant they were offering this as a service for $10k.
I thought it meant they were offering this as a service for $10k.
However, with ISO you're likely referring to RFC3339. The full ISO8601 standard allows insane date representations you're not going to see anywhere but the documentation that explains them.
The United States has a rather unique way of writing the date that is imitated in very few other countries (although Canada and Belize do also use the form). In America, the date is formally written in month/day/year form.
They don't use metric, still use First Past the Post voting, elect a mini monarch with effectively unchecked powers, ... it's an odd place.But seriously, America is awesome for rich people if you don't mind living in a poor, third-world country that still believes it's a first-world, exceptional country.
The standard was for written and radio communication to be unambiguous.
If you're writing software, believe me you want a format like 13FEB2025 over anything except maybe unix timestamp in UTC.
02/13/2025. I personally use ISO dates because i like getting sorting for free.
Every time I see a service purporting that it works best only with a single link to your Real Identity™, I'm reminded that the vendors only abstractly care about actually protecting the user, and then only sometimes.
Imagine being able get immediately three or four steps closer to doxing anyone interacting on YouTube. That's the actual impact of this bug IMO. It's good that this was fixed, but I don't think this class of bug goes away anytime soon. What do we need to do to get vendors and big companies to realize that this sort of design is landmines waiting to happen?
I abstractly agree with you. There is a level of obscurity and disposability that should be tolerated in these accounts. They’re just a row in a database somewhere anyways.
That said, many people transact with these businesses with real human money. For example, YouTube premium subscribers or content creators. From a practical perspective, that requires IRL identifiers to be stored somewhere with that otherwise disposable account. And due to fraud risks and other realities of banking, that requires giving these businesses actual identities and addresses which they store too.
While I don’t give random apps and websites my human-identifying information, anyone I do business with necessarily knows the real me, which is a theoretical point of data leaking.
Certainly not theoretical. You can be certain that nearly every company who knows your identity has leaked/sold it to others in one fashion or another.
Try and leak some medical data as a medical services provider. You will get your ass handed to you.
That's hilarious.
* Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneously, that has effectively no half-life once discovered, and whose exploitation will generate reliable telemetry from the target.
* Similarly, bugs like full-chain Android/Chrome go for hundreds of thousands of dollars because Google competes with a well-established grey market; a firm can take that bug and sell it to potentially 6 different agencies at a single European country.
* Even then, bounty vs. grey market is an apples-oranges comparison. Google will pay substantially less than the grey market, because Google doesn't need a reliable exploit (just proof that one can be written) and doesn't need to pay maintenance. The rest of the market will pay a total amount that is heavily tranched and subject to risk; Google can offer a lump-sum payment which is attractive even if discounted.
* Threat actors buy vulnerabilities that fit into existing business processes. They do not, as a general rule, speculate on all the cool things they might do with some new kind of vulnerability and all the ways they might make money with it. Collecting payment information? Racking up thousands of machines for a botnet? Existing business processes. Unmasking Google accounts? Could there be a business there? Sure, maybe. Is there one already? Presumably no.
A bounty payout is not generally a referendum on how clever or exciting a bug is. Here, it kind of is, though, because $10,000 feels extraordinarily high for a server-side web bug.
For people who make their nut finding these kinds of bugs, the business strategy is to get good at finding lots of them. It's not like iOS exploit development, where you might sink months into a single reliable exploit.
This is closer to the kind of vulnerability research I've done recently in my career than a lot of other vuln work, so I'm reasonably confident. But there are people on HN who actually full-time do this kind of bounty work, and I'd be thrilled to be corrected by any of them.
Do you really want to know what the FSB plans to do with your exploit?
For any other kind of vulnerability, you're not so much "selling a product" as you are "helping plan a heist".
Absolutely, yes. Spam and targeted phishing attacks are in high demand.
My understanding is that it is possible to retrieve every public youtube channel ID, if not also Google Maps/Play reviewers, quite easily. This exploit could have been used to create a massive near-complete database of every Google account has automatically had a Youtube account created.
The only angle I can imagine is phishing for high profile creators, and at most this is a “makes it easier” and not a “creates the problem” bug.
I have… I’m not sure. Ten maybe? And those are actual conveniences for different purposes. I’m sure plenty of people have hundreds, if not thousands. So what?
- I charitably went with 208 billion, 25 for every single individual on this planet.
- As the other replies note, I chose a misleading number that is off by an order of magnitude at even the most charitable reading
- You can't see the problem
I don't think it's fair to you to assume you can't see it, maybe you were in an old tab that had my reply but none of the descendants.
Exploits need to plug into a business plan. Like any business plan there has to be somewhere that money gets extracted and that money needs to be more than the exploit cost & infrastructure costs & a risk premium.
If you can’t trivially say how the exploit explicitly gets turned into cash you probably are on the wrong track. Doubly so if it’s not a known standard and commoditized way that’s happened before.
Most recent example I've seen: https://www.youtube.com/watch?v=EnVxWK6DfMQ
So for some channels that provided no contact information, you now can acquire an email address, and for everyone else you may now get an additional one.
It also enables you to link multiple channels back to the same person.
Every bit of information you can get your hands on counts for social engineering attacks.
For very famous individuals this may also open them up to harassment. You can't find Elon Musk's private telephone number on the Tesla homepage for good reason. For that class of people, any time that sort of information leaks, they need to get a new private phone number/e-mail address.
I'm not sure that there are terribly many black market opportunities for "every bit of information" such that this should be a six figure payout or whatever.
- Regime critics with a channel on YT.
- Vulnerable individuals and others trying to keep their identity a secret. Putting yourself on YT means putting yourself in front of every deranged individual out there.
- Trump quite famously runs some of his own social media accounts personally, for better or for worse. And even where he doesn't, he probably retains ultimate control - in the case of YT it might be his personal google account that created the channel. He's probably not the only high value target to do so.
Also if you happen to be in any date leak, being able to figure out your private e-mail address gives attackers another place to check whether you re-used a password.
For any vuln you can make up a hypothetical one off usage. But to find the right buyer for that is effectively building a team ala The Great Muppet Caper.
Or, you know, develop a new "business plan" around an exploit.
Sure: https://www.abc.net.au/news/2016-07-01/league-of-legends-que...
You could sell it non-exclusively to every data broker
You take out your handy email list and run a regex to find candidate accounts that match “J Smith”. You pipe matches into a recon script to check if github and discord accounts exist for each email. Suddenly, you’ve got a small pool of matches. You try more account-existence recon to find all the sites they’re signed up on. You look up all breached creds tied to the target emails, then run cred stuffing against any sensitive services they’ve signed up for.
Boom, you’ve gone from first initial + last name to compromising an account in thirty minutes.
Motivation in the abstract is not enough to counter GP's point—they have to have enough motivation that it's worth more than $10,000 to them and also have more than $10,000 to spend and also have the connections necessary to get in touch with someone who's able to sell a vulnerability like this and also be able to exploit it in a timely manner or at least think they can.
Massive email databases are extremely cheap, often free. For this vulnerability to be worth more than $10k there would have to be something about it being a near-complete library of Google accounts (rather than just another massive mailing list).
And that's assuming the prospective buyer believed that they could exploit this vulnerability in full before discovery. If I'm reading this exploit right, each email recovered requires two requests, one of which needs to make one of the fields 2.5 million characters long in order to error out the notification email sent to the victim. Presumably that email sending error would show up in a log somewhere, so the prospective attacker would have to send billions of requests fast enough that Google can't block them as suspicious or patch the vulnerability, all the while knowing full well that they're filling up an error log somewhere and leaving an extremely suspicious pattern of megabyte-sized request bodies on a route that normally doesn't even reach kilobytes.
I'm honestly not seeing how you could make an email list out of this that is anywhere near complete, and even if you could I'm not sure where the value to it would be.
There are different qualities of email databases. "Known real email by Youtube account holders" would be a high value database. Definitely not free.
This type of vulnerability is extremely valuable for private investigators, too. "Who uploaded this video which my client is extremely interested in?"
That database only exists in theory, based on extrapolation of this vulnerability to billions of individual exploits, and I think we can all agree that Google would detect this activity and shut it down.
Hence, that database might fetch a decent price if it existed, but it doesn't.
Would exploiting this vulnerability violate the Computer Fraud and Abuse Act? If so, would a private investigator really want to do that?
https://www.stltoday.com/news/local/government-politics/pars...
Not to mention not really thinking through how obviously stupid it is to immediately compare a legal activity to a highly illegal one, as if they're real alternatives for most people.
Isn't there a market for this? For example, "Reveal who is behind this account that's criticizing our sketchy company/government, so we can neutralize them".
I'll also argue there's separate incentives, than the market value to threat actors... Although a violent stalker of an online personality might not be a lucrative market for a zero-day exploit for this "threat actor" market, the vulnerability is still a liability (and ethical) risk for the company that could negligently disclose the identity of target to violent stalker.
IMHO, if you're paying well a gazillion Leetcode performance artists, to churn out massive amounts of code with imperfect attention to security, then you should also pay well the people who help you catch and fix their gazillion mistakes, before bad things happens.
You missed their point about the business model of the security researchers here: their business model is finding a large number of small value vulnerabilities. Those who are good at this are very very good at this.
My company has a bug bounty program and some of the researchers participating in it make double or more my salary off of our program, but we never pay out more than this for a single report. And it's not like we're particularly vulnerable, we just get a steady stream of very small issues and we pay accordingly.
Their last paragraph shows that they didn't understand your paragraph here:
> For people who make their nut finding these kinds of bugs, the business strategy is to get good at finding lots of them. It's not like iOS exploit development, where you might sink months into a single reliable exploit.
I think I understood. The last paragraph of mine that you cite was speaking of the creator of the bugs, not the discoverer.
The liable party should be investing reasonably towards non-negligence. (Especially in the context of spending billions of dollars each year on oft-misaligned headcount that's creating many of these liabilities.)
I'm not talking about the company optimizing for the minimal amount they think they can get away with paying to try to cover their butt. Nor am I talking about how white/gray-hat researchers adapt viable small businesses to that reality.
First there are only very few gobs/companies that are sketchy enough to do this - and for those a huge number of non-anonymous people exist with huge reach that are very critical for years. If such a market would exist they would assassinate all those first - you don’t need the email if you have the face, voice, and name - since that is not happening they just don’t care that much about it.
The likes of Cambridge Analytica didn’t go away, they exist and absolutely go hunting for data like this.
The ability to map between different identifiers and pieces of content on the internet is central to so many things - why do you think adtech tries to join so many datapoints? Let alone things like influence campaigns for political purposes.
I’m not talking about assasination plots, but more mundane data mining. This is why so much effort in the EU has gone into preventing companies from joining data sources across products - that’s embedded in DMA
> [...] a bug that Google can kill instantaneously, that has effectively no half-life once discovered, and whose exploitation will generate reliable telemetry from the target.
You can't set up unmask-as-a-service because it's going to take you longer to get clients than it will take Google to shut down your exploit.
1. It can still take a while before Google finds out
2. You can log every mapping you got in the meanwhile, then keep selling the ones you already have
Edit: although probably most of your business will be over when word gets out that your data isn’t exactly legal (which your clients have understood from the start, of course; they could just plead ignorance)
So let's suppose that you did set up the service like this. Can you even make 10 K? What are your odds of getting caught? How much do you value not being in prison and/or having to hire a lawyer to get you out of there?
I'd take the 10k every time.
It’s a lot more work, of course, but you can scrape some top youtubers first as it seems relatively easy. If you can pull this off you can then try and figure out how to legitimize your offering – I won’t go into details here, for obvious reasons, but now that you have something valuable on your hands it makes sense to spend some time/money on selling that.
I’m not speaking theoretically, which I suspect most on this thread are.
Even if someone on telegram was telling me that Russia would buy this information for $100,000, I think I would reach out to Google and "settle" for $10k.
The scraping was def in violation of the EULAs. Product data is one thing, but I believe this group was combining it with other sources and selling the identities and context as a bundle.
"The Dark Net” – Jamie Bartlett “We Are Anonymous” – Parmy Olson “Future Crimes” – Marc Goodman “Kingpin” – Kevin Poulsen
Sure is funny there's nobody doing that despite so many people being so dead certain there's an active market.
And if I did, it wouldn’t stop people from doing co-ordinated disclosure either, would it? Same with high end exploits - some folks do co-ord disclosure because it feels good and is great for your CV; others sell gray market and we generally have no idea what’s being traded.
(With the exception of say, zerodium or 0xcharlie’s various talks)
Probably the risk of going to jail outweighs the extra $5k, but if a company is serious about the bug bounty program, they would offer a reward that's competitive with what you could extract from the black market, and I don't think that's hard to do.
Selling crazy stories to the media is as old as time.
This vuln would give you a lookup table from email->YT
SELECT * FROM table WHERE email LIKE “%.gov”
Come on.
You are imagining a potential market, the exploits are priced against markets that are real and pay out today. Security researchers aren't traveling salesmen going around to every shady character on the internet and pitching them on the potential of a new criminal enterprise.
If we apply your analysis to other things, we’ll find that the upper bound price for a new car stereo or bike is ~ $100, and the price of any copyrighted good is bounded by the cost of transferring it over the network.
I think it is more useful to divide the amount Google paid by the number of hours spent on this and any unsuccessful exploit attempts since the last bounty was paid.
I’d guess that the vast majority of people in this space are making less than US minimum wage for their efforts, with a six figure per year opportunity cost.
That tells you exactly how much Google values the security and preserving the privacy of its end users. The number is significantly lower than what they pay other engineers orders of magnitude more to steal personal information from the same group of people.
If security researchers want to have stable employment doing this sort of work, there's oodles of job applications they can send out.
So, the value to the researcher of having a found bug has a floor of the black market value.
The value to Google is whatever the costs of exploitation are: reputational, cleanup, etc.
A sane value is somewhere between these two, depending on bargaining power, of course. Now, Google has all the bargaining power. On the other hand, at some point there's the point where you feel like you're being cheated and you'd rather just deal with the bad guys instead.
Bounty programs are very much not trying to compete with crime.
> Bounty programs are very much not trying to compete with crime.
Nor did my post posit this.
Bounty programs should pay a substantial fraction of the downside saved by eliminating the bug, because A) this gives an appropriate incentive for effort and motivate the economically correct amount of outside research, and B) this will feel fair and make people more likely to do what you consider the right thing, which is less likely if people feel mistreated.
Is there any evidence that OP feels that this payout was unfair?
No, but Google should understand that if they give a token payment, people will be less likely to help in future situations like this. And might be inclined to just instead tell ad buyers about the loophole quietly.
Imagine a possible downside or two, imagine a probable risk, multiply, discount.
Large scale data leak and need for data leak disclosure. 1 in 3, moderate cost.
Bug report saving engineering time by giving clear report of issue instead of having to dig through telemetry and figure out misuse and then identify what is going on, extents of past damage, etc. 3 in 4.
Millions of usernames and emails are leaked every month; if this was the case you'd be seeing these murders in the news every week.
Yes, because all possible scenarios kill the same fraction of people-- whether we're talking about getting a dump of a million email addresses or giving some nutjob a chance to unmask people he doesn't like online.
If my bug bounty is $10,000 and I can sell it for $20,000 then most people will take the legitimate cash. If it's $10,000 and some black market trader will pay $10,000,000 (obviously exaggerating) then there's a whole mess of people are going to take the ten million.
* Are you talking to someone legitimately interested in purchasing and paying you, or is this a sting?
* If you're meeting up with someone in person, what is the risk that the person will bring payment or try to attack you?
* If you're meeting with someone in person, how do you use $20k in cash without attracting suspicion? How much time will that take?
* If it's digital, is the person paying you or are the funds being used to pay you clean or the subject of an active investigation? What records are there? If this person is busted soon will you be charged with a crime?
There are a lot of unknowns and a lot of risks, and most people would gladly take a clean $10k they can immediately put in the bank and spend anywhere over the hassle.
This is another reason why the distinction between well-worn markets (like Chrome RCEs) and ad-hoc markets is so important; there's a huge amount of plausible deniability built into the existing markets. Most sellers aren't selling to the ultimate users of the vulnerabilities, but to brokers. There aren't brokers for these Youtube vulnerabilities.
Legally, in most places of the world it isn't.
Morality differs among people too. Profiting off a trillion dollar company will not cross the line for a lot of people.
Almost everyone, even people without a moral sense, have a self-preservation sense- "How likely is it that I will get caught? If I get caught, will I get punished? How bad will the punishment be?" and these factor into a personal risk decision. Laws, among having other purposes, are a convenient way to inform people ahead of time of the risks, in hopes of deterring undesirable behavior.
But most people aren't sociopaths and while they might make fuzzy moral decisions about low-harm low-risk activities, they will shy away from high-harm or high-risk activities, either out of moral sense or self preservation sense or both.
"Stealing from rich companies" is a just a cope. In the case of an exploit against a large company, real innocent people can be harmed, even severely. Exposing whistleblowers or dissidents has even resulted in death.
I wish developers (and their companies, tooling, industry, etc.) creating such flaws in the first place would treat the craft with a higher degree of diligence. It bothers me that someone didn't maintain the segregation between display name / global identifier (in YouTube frontend*) or global identifier / email address (in the older product), or was in a position to maintain the code without understanding the importance of that intended barrier.
If users knew what a mess most software these days looks like under the hood (especially with regard to privacy) I think they'd be a lot less comfortable using it. I'm encouraged by some of the efforts that are making an impact (e.g. advances in memory safety).
(*Seems like it wouldn't have been as big a deal if the architecture at Google relied more heavily on product-encapsulated account identifiers instead of global ones)
How much time do you spend asking yourself whether your paycheck is coming from a source that causes harm? Or whether the code you have written will be used directly or indirectly to cause harm? Pretty much everyone in tech is responsible for great harm by this logic.
> Pretty much everyone in tech is responsible for great harm by this logic.
We're also responsible for great good. The question which is greater is tricky, case-by-case and subjective.
Most will just take the 500k paycheck and work at whatever the next big tech thing is.
There's some chance that thing is autonomous drones or something like that...
If Mr GRU asks, I probably say say no.
If the CIA, Mossad or BND asks, maybe I say yes? It’s not clear for a person with a better moral compass than mine.
I don't know how much it should be worth, but at least there's a PR effect and it's also a message towards the dev community.
I see it the same way ridiculously low penalty for massive data breaches taught us how much privacy is actually valued.
For security researchers it's apparently obvious, but from the outside it's another nail in the coffin of how we want to think about user data (especially creators, many being at the front line of abuse already). As you point out Google here is only the messenger, but we'll still remember the face that delivered the bitter pill for better and worse.
How many young computer enthusiasts / aspiring security researchers are motivated to learn more because they see, what to them are, massive payouts.
You or I might not get out of bed for the hourly rate that translates to, fine by me - I have a job that pays the figure I negotiated.
Bug bounty programs pay the market clearing rate, always. One bug, two market participants, one price.
It sure has worked out pretty much like this for music. The cost is not exactly zero, but pretty close to that.
Anyway, I’m not 100% sure what they meant by grey market. It looks like they were talking about maybe selling to “agencies” which, I guess, could include state intelligence agencies. If that’s what they meant, it wouldn’t be that surprising to find that the black market and grey market prices influence each other, right?
I mean we could ask our intelligence agencies why they are shopping in the same markets as criminals but I guess they will say something like “it is important that we <redacted> on the <redacted>, which will allow us to better serve the <redacted> and keep the <redacted> safe.”
> If we apply your analysis to other things
This analysis doesn't work for a few reasons:
* For physical goods, used items always fetch a lower price than new items due to unrelated effects. And if we're only looking at the used price, we do find that the black market price is just about equal to the used item's value minus the risk associated with dealing with stolen goods (unless the buyer is unaware of the theft, in which case the black market value is the same as the used value).
* For both physical and digital goods, there are millions of potential customers for whom breaking the law isn't an option, creating a large market for the legal good that can serve to counter the effect of the black market price. This isn't true of exploits, where the legal market is tiny relative to the black market. We should expect to see the legal market prices track the black market prices more closely when the legal market is basically "the company who built the service and maybe a few other agencies".
This is only true under certain circumstances. If there are supply chain issues, used prices can go up and over the list price. The most extreme (and obvious) example I've seen is home gym equipment during the Covid lockdowns, particularly for stuff like rowing machines.
The other potentially less obvious example is seen in countries that don't have a local presence or distributor for a given item, and the pain and slowness of importing leads to local used prices being above list price.
One other potentially interesting semi-related point: prices for used items can sometimes increase in unexpected ways (excluding obvious stuff like collectables, art, antiques etc). In the UK, the used price for a Nissan Leaf EV started increasing with age after the market realised that fears about their battery failing ~5 years into ownership were unfounded urban myths, and repriced accordingly.
The comment you're replying to isn't referring to list price, they're referring to the price of a new item.
Supply chain issues, as we saw during COVID, affect the cost of new items by making them effectively infinite: if there are only 100 new rowing machines available and 1000 people want them, then for 900 people, the list price of a new rowing machine is irrelevant because they can't actually buy it at that price.
They're buying exclusive access to some information, which is a somewhat unusual thing to pay for.
News reporters do take spicy stories to tabloids, rather than the normal press, as the tabloids will pay more.
What you’re saying can be seen as tautological. The reason a gray/black market exists is precisely because the field is undercompensating (aka in disequilibrium)
I mean, the technical skills in the article here are basic. But the first finding was significantly good luck, and having the background to know to look towards old Google services for the ID to email part was non-obvious. You would need a lot of high-quality, guiding knowledge like that to make bug bounties work. Still, seems like a very high starting cost.
The dollar value of a responsible report going up means more responsibility overall and less problem leaks, exploits, etc.
I would be equally happy to see any solution where the end result is increased security and privacy for everyone, even at zero bounty.
The problem being overlooked is that the actual cost of these exploits and bugs is paid by the people who had no say whatsoever in any matter regarding the issue. Any time a company is being "cheap" at the expense of regular people is a bad time, from my perspective.
Google has the power to limit the exposure of the people who use there products (and this isn't always voluntary exposure mind you) and is choosing to profit a teeny tiny bit more instead. At no immediately obvious cost to them, why not?
Does it? I just had a bug bounty program denied for budget approval at my work because of the cost of the bounties and the sufficiency of our existing security program. On the margins, it's not clear to me that the dollar value of a report going up is incentivizing better reports vs pricing smaller companies out of the market.
It may work kind of how employment works, where Google can afford to pay more than a company that cannot afford a 10k bounty.
Google paying a 10k bounty is the equivalent of the bottom 10% of earners in the US paying a 6th(napkin math) of a soon to be discontinued penny.
Regardless, you are correct that the calculation is not obvious, unlike how I presented it. Preferably, things like multiple million character titles are handled correctly and no bounty is paid at all. I expect a smaller company to have an easier time here as well, lessening the financial burden.
Why would you expect that? In a smaller company the ratio of developers to HTTP endpoints tends to be substantially lower (fewer devs per feature) than in a large company, so I'd expect the opposite.
I guess bounties fit into the framework somewhere between the Github and middle class engineer.
I think it comes down to supply and demand. It also shows you what Google would pay employees if things were in their favour. On unrelated news, a tech billionaire is almost defacto VP of the US.
I think it's in everyone's interest for bug bounties to be higher than harmful markets for the same bug, and a decent fraction of the harms they prevent. That's what is going to result in the economically efficient amount of bug hunting. And it's going to result in a safer world with less cybercrime.
I really think people just like to think about stories where someone like them finds a bug and gets a lottery jackpot as a result. I like that story too! It's fun.
Smart companies running bug bounties --- Google is probably the smartest --- are using them like engineering tools; both to direct attention on specific parts of their codebase, and, just as importantly, as an internal tool to prioritize work. This is part of why we keep having stories where we're shocked about people finding oddball security- and security-adjacent bugs that get zero payouts.
Increasing bounties by a small factor will be enough to reduce things on the grey market and to increase the ROI of people choosing to do freelance security research. The time between payoffs is enough that no one is going to get rich from $150k bounties.
Don't forget the extrinsic benefits: easier to brag about bounties on your resume than selling things into the grey market.
> Smart companies running bug bounties --- Google is probably the smartest --- are using them like engineering tools; both to direct attention on specific parts of their codebase, and, just as importantly, as an internal tool to prioritize work.
These "smart" companies should consider just how cheap even higher bounties are to prevent massive downsides. Of course, an underlying problem is how well these companies have insulated themselves from the consequences of writing and not fixing vulnerable software. A sane liability (and insurance) regime would go a long way towards aligning incentives properly.
Where we differ is the long-term impact of those increasing costs. I don't think market competition is going to meaningfully improve security. Things like swapping out components for memory-safe replacements, hardening runtimes, and deprecating ancient protocols and formats have, though, and will continue to pay off. So I'm optimistic, just for a different reason than you are.
I think the things you describe all have long-term wins but may worsen the short-term picture. Sure, using better tools is good, but younger code is riskier for its own reasons.
Bounties are a great short to intermediate strategy. There's code that's used today, and this is the way to get some near-term outside effort towards making it better (and these sentinel events can provide guidance on where to spend inside effort as you say).
And, of course, if software engineering growing up means we actually get fewer bugs, bounties become even more worthwhile: any issues found will remove a bigger proportion of total vulnerability.
I see bounties as an engineering tool more than anything else. For the reason I provided upthread, I don't think it's likely that they're going to alter market dynamics. I don't have a really strong basis to claim this; it's just a conclusion I'm drawing from the incentives at play. I think the most important thing bounties do is mobilize people who would never work with a grey-market broker to do good vuln research work, I think the sums we're transacting in today are clearly enough to accomplish that, and regardless of whether you agree there, we both agree that those sums are set to increase.
I'm reminded of when we really systematically started treating temporary names correctly and thought security was going to be so much better.
I think there's no shortage of bugs and exploitation scenarios. We'll eliminate the easiest to exploit and most common mistakes, but there will be yet more.
> I think the most important thing bounties do is mobilize people who would never work with a grey-market broker to do good vuln research work
I think it makes it easier for those who work with grey market brokers to "go legit", too. Even if bounties can't win on price, this doesn't mean they can't win people over.
Of course, the fact that they can't win on price is a market oddity. Exploitation causes net economic harm; it's a negative-sum proposition. The only reason why software vendors can't outbid the criminals is because the software vendors don't pay the actual losses. I'm hoping this changes some over time.
> we both agree that those sums are set to increase.
I don't/didn't know that's true, but that's welcome news if true.
More like mid-80's with effects dragging on to mid-90's.
There was never a market back then at all. ;) The point is, many confidently announced that all the easy to exploit stuff in Unix was being fixed and soon security was going to be less of a problem.
> but we've been in what seems like a stable state for over a decade on which of those vulnerabilities are actually tradable.
Yes, but that doesn't stay the same if the low hanging fruit dries up as you posit. The level of sophistication of both exploit writers and exploit consumers will have to climb, but we're nowhere near the ceiling of the skills and effort that crime and intelligence can pay for.
P.S. a lot of time your writing comes off as having a smug tone that rubs me the wrong way.
Actually, I already won a small lottery jackpot doing security stuff. Then a large one doing security stuff. Then a small one again doing other stuff. I could have retired a couple of decades ago, but now I'm a schoolteacher for the funsies. My days of scrunching over IDA Pro for pennies are over: I've got no personal direct interest in whether research gets paid more or less.
I just think that bug bounties are a good thing, but by being underfunded and with uneven quality of administration a lot of the potential benefit is left on the table.
You're right that I've not been involved in the grey market for awhile. And when I did, I was on the "advising sophisticated buyers" side of it, rather than trying to sell things.
I don't think you're getting a ton of money for them.
But, it's my understanding that there are state actors who want to unmask people who are saying things they consider not-nice on social platforms and who have made it known that they will pay for things like this.
Am I misunderstanding the bug? In my reading, this bug translates to "a list of the top 1,000 Youtube accounts' email addresses (or as many as you can get until Google detects it and shuts it down)." Why isn't that conceivably worth more than $10,000?
Our emails get leaked all the time in data breaches, sometimes alongside much more important information such as home addresses etc..
This was certainly a bad leak that could be used to further dox people by connecting the email to other leaked info or other sources, but from Google's perspective, all they did was leak the email.
It was a privacy breach for sure.
But further doxxing based on the email would be "not their problem" I suspect they would say.
As explained by the parent comment, because there isn't a market for it. It's a novelty. Who are you going to sell that exploit to? At this time, nobody. Since Google doesn't have to compete against others for the bug, it pays low.
Those may be non-public email addresses (admin/billing emails), so the phishing potential is higher than emailing prteam@mrbeast.com (or whatever).
If it exposed passwords as well then that would be worth a lot more, but a list of email addresses is not the most valuable of things on its own.
But its not, its giving their gmail address which is mostlikely something like mrbeast01@gmail.com
I just don't think Russia would be willing to pay $100,000 to get Mr. Beast's email address, even if that sounds tempting to you.
The exploit can be valued at: number of emails * probability that you'll phish them into letting you in * value of posting a "Free Robux" scam on a channel with 100M subscribers.
I feel like you are just taking into account the theoretical max value of a bad actor having these accounts, not the cost/risk of using this knowledge.
I could have the master key of a bank safe with 100MM worth of gold in the basement, but it's value is going to be nowhere near that, even to bad actors.
There's certainly bad things that CAN be done to a number of people with information when it's a personal email address that's used for numerous purposes... but the 3 people I talked to about having youtube (or any streaming) accounts all have mentioned it as being a separate account.
So the only threat I can see in most cases is just better phishing attempts, which is not necessarily an easy money maker... Unless they can steal the entire account? It is impossible to get support from Google, so it's quite possible you could change the bank info and get a month or two of payments before someone gets in the loop to stop it... and realistically, the more money someone is making on YouTube, the less likely they have troubles contacting someone at Google by some side channel... and the less likely it's a personal email address that reaches the actual star of the channel.. so the more popular the person, the less valuable the email address
For example, MrBeast has this in the video description:
> For any questions or inquiries regarding this video, please reach out to chucky@mrbeastbusiness.com
The vulnerability here is that you can find the exact email address tied to their YouTube account, which you can't really do anything with if they have strong passwords and use 2FA.
In this case there were 4 billion email addresses on the line from being scraped, imagine if this was exploited and the data was leaked. The news would hit the headliners which would definitely be bad for Google's reputation and stock price.
However, the impact of the leak is not that high as it only consists of a channel <> email address mapping, and therefore I think 10k is a fair price
How big of a threat is it/what impact will it have on business/reputation/etc.?
How likely is it to be exploited and how widely would it be considered useful to the market of threat actors?
I will say: at Matasano, we were once asked by an established security company that turned out to be a broker to find PHPBB vulnerabilities.
It's most likely not just a comparison to black market prices or how many lines of code it'd take to patch.
- monetize the bug themselves; i.e. set up a site where you can submit a YouTube user id, pay some fee using your credit card and get an e-mail address.
- report that they have the ability to convert any YouTube id to an e-mail, with proof: then negotiate over compensation for the disclosure of the details
- just report the problem and be happy with whatever they get.
Ten grand doesn't look too bad for the most timid choice.
For #1, as tptacek says, it would be trivially easy for Google to shut a service like that down as soon as it was created, and prosecute the people running the service under the CFAA. Also, the amount of demand for that kind of data is pretty small given the number of email address databases already available online through legal means (e.g. Zoominfo, RocketReach, etc). It's a path filled with a lot of risk and not a ton of reward.
I'm a little skeptical of published prices for serverside software, though. Do you know anyone who specializes in selling those bugs? I don't.
Google knew about this already, and hadn't done anything to fix it...and when it was reported, they didn't fully understand it and were dismissive, until the author came back at them again.
> Unmasking Google accounts? Could there be a business there? Sure, maybe
I'm pretty sure there are a _lot_ of youtube channels that private and public entities would love to uncover the identity of, and I would say that it's very unlikely these guys were the first to piece all this together.
The main takeaway for me is how incompetent Googlers seem to be, both in the basic "web application 101" mistakes made (not properly validating/restricting fields) and the clearly rushed evaluation of the security report. Such a report should trigger some folks going "oh, that's not good. I wonder what else is broken about this." Not "meh, not significant, quick patch, fixed."
Nobody at Google wants to work on stuff that isn't going to get them up a rung on the ladder.
https://www.theverge.com/2016/1/29/10868404/google-reveals-h...
That guy is ridiculous! Could have made $50 million or more probably, if he had used a different registrar than Google itself.
He mentioned that Microsoft also let their domain lapse and that one was actually going to the open market... and what's more, they didn't even care when he contacted them! Oof:
https://www.theregister.com/2003/11/06/microsoft_forgets_to_...
Here are a few other doozies:
Apple forgot to renew their certificate for the entire Mac App Store, and didn't care much:
2014: https://www.macrumors.com/2014/05/25/apple-software-update-i...
if that wasn't bad enough... they did it again in 2015:
https://osxdaily.com/2015/11/12/fix-app-is-damaged-cant-be-o...
and almost in 2016:
Sure the gray market will pay more, but how do you contact criminals and make sure that you actually receive payment?
I know nothing about the market, but I think it's similar to buying drugs - we all know that drugs are everywhere and criminals are making a ton of money out of it, but if you haven't been introduced before how do you actually buy them? Go to a club and start asking random people?
(that last part might be different in US, but in EU we don't have people standing on every corner selling cookies)
I also wouldn't call it just a server-side web bug, it's more like data exfiltration. TFA author could have sold it for more money to some gray market dudes if he were willing to accept bitcoin.
I’ve only participated in a few vulnerability programs, and most of them reward less if the security flaw is stupidly simple (but serious) such as revealing user emails in the page source.
I'm not sure I'd apply that logic if I were Google, though. Smaller companies it makes sense because the threat actors that they are most likely to face are mostly script kiddies who give you at most a day before they get bored and try someone else. Google is another matter, since they're always a target for much more sophisticated attackers.
Should... should this just be public: https://staging-people-pa.sandbox.googleapis.com/$discovery/...
Furthermore the discovery endpoint is publicly documented[0] and specifically meant for external users. Nobody internal would read the discovery endpoint: they would just pull up the .proto file through code search.
Another observation: from my experience at Google it took multiple weeks of effort fighting against the bureaucracy to be able to expose an API to the public. It's not like an AWS S3 bucket that could just be accidentally public. The team knew this is public and had fought the bureaucracy to make it public.
[0]: https://developers.google.com/discovery/v1/getting_started
15/09/24 - Report sent to vendor
...
29/01/25 - Vendor requests extension for disclosure to 12/02/2025
09/02/25 - Confirm to vendor that both parts of the exploit have been fixed (T+147 days since disclosure)
12/02/25 - Report disclosed
So that is 136 days not fixed(?) and Google asks for extension.
Then 147 days to fix and 150 days to public disclosure.Compare this to Google Project Zero which gives other companies the following time to fix before disclosure...
>"This bug is subject to a 90 day disclosure deadline. If a fix for this issue is made available to users before the end of the 90-day deadline, this bug report will become public 30 days after the fix was made available. Otherwise, this bug report will become public at the deadline."
>If the patch is expected to arrive within 14 days of the deadline expiring, then Project Zero may offer an extension...Note however, that the 14-day grace period overlaps with the 30-day patch uptake window, such that any vulnerability fixed within the grace period will still be publicly disclosed on day 120 at the latest (30 days after the original 90-day deadline).
>If we don't think a fix will be ready within 14 days, then we will use the original 90-day deadline as the time of disclosure. That means we grant a 14-day grace extension only when there's a commitment by the developer to ship a fix within the 14-day grace period.
https://googleprojectzero.blogspot.com/p/vulnerability-discl...
Pour one out for the google dev in charge of b64 encoding their fancy binary message format so it can be jammed inside a JSON blob. If you want a vision of the future, imagine a boot with "worse is better" imprinted on the sole stomping on an engineer's face, forever.
The json part is an automatic conversion.
But the external API is Json and so it needs to be converted at some point.
https://stackoverflow.com/questions/49358526/protobuf-messag...
Internally, it is (maybe) a binary field of a protobuf.
Then when translating to JSON, it was converted to a string via base64 encoding.
If only there were some way to easily send this binary gzip data to this API that accepts JSON...
I'm still upset about Google Reader.
I'd be so glad now to give up on Google and all its enshittified shit. I could give up things that are still super useful and I get value from every day: YouTube, Gmail, Play Services, Drive, Maps. But I don't think I could give them all up at once. I've been trying to migrate to Proton and OpenStreetMap and some kind of real Linux phone etc, I don't even mind if I have to fiddle around before everything works. The trouble is that the claws are in, but they're not in me.
Remember when Google proudly didn't advertise themselves? They got to critical mass through word of mouth, from having a compellingly better product. Now what they have is network effects and locking. They used to appeal to developers and techies because and that ended up making the services better for everyone. Now like all the other tech giants they have PHB's optimizing for the next millisecond of attention and Microdollar of ad revenue from a lowest-common-denominator victim.
Google is so big that it's a significant part of life for a significant proportion of the world. When Google is shit it moves the needle on net human suffering. I think the UN should be focussing on prevent war and trying to salvage our environment, but if they aren't going to do that then it might be rational to just form a worldwide consumer group to take on megacorps.
What upsets me re RSS these days is how many people were apparently so reliant on one reader that they still publicly mourn every time it comes up, 12 years later. Who are these fair-weather feed followers who threw their hands in the air with the loss of exactly one product?
All so they could clear the way for Google Plus. And look how that turned out.
So yeah, watershed moment, the point where the scales fell from my eyes, still justifiably pissed, fool me twice, etc etc etc
(Still using RSS daily, though I lapsed for a while).
The other problem was that Google killing Reader was a signal to the broader web to move away from RSS. RSS has kind of limped along since then.
Are social features the main selling point of RSS readers? I mean I just use mine to know when there's a new blog post/webcomic posted on a few sites I follow, without having to give my email or use another platform like social media to know about it. And I'd use the social features which are present on the blogs, under the control of the blog owner(s), if there's any. Or maybe my use case is not the most common one?
Though I agress about the signal Google sent by killing GR.
That marks my coming of age on the enshittified web. The killing of Google Reader was a watershed moment. It marks the moment in time when the tide turned from the open Web to closed social media gardens.
Years later, I came across Artifact, created by the founders of Instagram, and thought it was an interesting idea. The problem was I was reading its shutdown announcement.
Sometimes I think products are killed way too early. Look at twitch, it boomed after years of stagnation.
[0] https://www.statista.com/statistics/517907/twitch-app-revenu...
There's definitely some measure of complexity. I still like simple cyclomatic but I know there are better ones out there that try to capture the cognitive load of understanding the code.
The attack surface of the system is definitely important. The more ways that more people have to interface with the code, the more likely it is that there will be a mistake.
Security practices need to be captured in some way (maybe a factor that gets applied). If you have vulnerability scanning enabled that's going to catch some percentage of bugs. So will static analysis, code reviews, etc.
It's not a black and white of "an app is truly secure" or "an app is truly insecure", but rather a continuum from "secure enough in practice for this threat model and purpose" to "an insecure mess".
Like, plenty of websites and apps have launched, existed for years, and then shutdown without a single security incident. In those cases, surely the app was secure, right? At least secure enough? Signal so far has been "secure enough in practice" for most people, while iMessage has in practice been "secure enough if you're a normal person, but with serious security issues for anyone who might be subject to serious targeted attacks"
Say more about what you mean by "no app is truly secure"? Especially in the context of signal?
> Im just saying that all it takes is one employee to click onto the wrong URL to breach your apps security
Pretend I'm a signal employee. What link can I click that breaches the app's security?
They don't store unencrypted data, pushing source code changes requires review, releases are signed and a single employee can't compromise the release process, so I'm missing how one employee being compromised could lead to the signal app breaching signal's security.
Also, in practice, how often are apps compromised from a phishing attack? I don't even really see news reports on that, so I'm curious if you're operating off like a specific case or something.
The part that sucks for consumers is that they often kill things that people like. I wish they had a better way of doing this.
Bravo to brutecat for this excellent discovery, productionization, and writeup.
But I am getting more hesitant as often when I (and others) do it seems companies think they can increase their prices wildly or do other stuff.
I have this exact feeling now with Logseq: I started paying for sync a while ago and it seems so did others and now they are rewriting the whole thing from plain text[1] to some kind of database based storage :-/
[1]: which could be synced over git, transferred effortlessly into another application and was one of the reasons I went with Logseq
From Kagi’s website
https://blog.kagi.com/status-update-first-three-months#:~:te...
We are currently serving around 2.1M queries a month, costing us around $26,250 USD/month.
Between Kagi and Orion, we are currently generating around $26,500 USD in monthly recurring revenue, which incidentally about exactly covers our current API and infrastructure costs.
That means that salaries and all other operating costs (order of magnitude of $100K USD/month) remain a challenge and are still paid out of the founders’ pocket (Kagi remains completely bootstrapped).
I’m honestly glad to hear that. Until I heard your interview with Gruber, I thought Kagi was the same company that use to provide a payment platform for Mac indie developers.
It’s always good to see a bootstrapped company become successful without enshittification. I put you up there with BackBlaze.
I see you have investors now (not saying that is a negative). Are the laws still the same about having to be a “qualified investor”? Can anyone invest - asking out of curiosity.
As sister comments have said there is no money in it. They are stickiness plays or just bets for Google.
That’s part of the stupidity of the DOJ trying to force Google to sell Chrome. Who would want it? And how would they profit from it?
All valid questions, but it might be that splitting the tool used to bludgeon everyone around is still worth it, even if pace of development slows down considerably.
Unless you are using Chromebooks, every desktop user who uses Chrome made an affirmative choice to download it.
My point is that maybe it is okay? Runaway churn is at least partially responsible for current situation, where most companies simply unable to compete.
Apple has no reason to compete, it can just make more and more functionality for native apps as can Google if it doesn’t have to worry about Chrome anymore.
Microsoft doesn’t care about the browser anymore and just uses Chromium. Firefox’s revenue comes completely from Google. If Google doesn’t have to prop up Firefox for antitrust reasons anymore, why would they?
Photos redesign makes it really hard to use.
Siri works half of the times, maybe even less than that.
Books lacks of basic functionalities such as downloading and keeping books on device.
Photos redesign maybe something you don’t like, but you can hardly call it half baked. All of the functionality is there and there’s a new consistency in how it works that wasn’t there previously.
Books automatically downloads to device. There isn’t a way to read a book without it local.
A simple google search will answer this question
https://www.theverge.com/2025/1/9/24340238/apple-iphone-alar...
Even an hn search is fine, if you do not trust the Verge (notice these are comments from the last 3 months so not an old issue):
https://news.ycombinator.com/item?id=42705217 https://news.ycombinator.com/item?id=41887505 https://news.ycombinator.com/item?id=41962418
> Books automatically downloads to device. There isn’t a way to read a book without it local.
Have you used Books extensively or just skimmed it? There's no way to keep books on device, make another Google search if you do not believe me.
> Photos redesign maybe something you don’t like, but you can hardly call it half baked.
Perfect, then keep Photos and kill only alarms, books and Siri.
I haven’t used Books extensively outside of audiobooks. So it sounds like there’s offloading of caching going on that’s iCloud wide; disabling iCloud sync would fix this. I can imagine that being frustrating if the book you want isn’t there when you’re on a flight (which should only happen if you haven’t recently accessed it). I agree there should be a way to prevent this. I wouldn’t call that half baked, but it’s a big enough problem I’d agree that’s not fully thought through (or more likely, they did think through it but came to a different conclusion).
Once you download a book to a device, it stays downloaded. There is a setting to automatically remove downloads once you're finished with the book, but that defaults to off (and I didn't even realize it was there until I went looking just now).
This is objectively false. I suggest you do a simple google search or read my other comment.
I just checked my phone, I have 169 books downloaded. This includes many books I haven't looked at for years and years. This includes many books that I bought 3, 4, 5 iPhones ago and are still present, copied from device to device, because Books does not remove store downloads unless asked to.
It's happened for years: it was pretty bad about 5/6 years ago, but Apple claimed they fixed it, but it's still happening a bit.
In fact, when I really need to wake up at a particular time (say for a flight), I set two alarms 1 minutes apart.
Go to library > collections > downloaded.
I can see books I purchased and other PDFs that I uploaded.
I do agree on the Photos redesign. I feel like I constantly get stuck on certain pages.
Your tone is aggressive and uncalled for. In fact, the fact that you have never found a very common bug says a lot about your inattention to detail.
There's no "keep forever on device" button, which to me seems like a basic functionality. If the app decides to delete them, it will.
https://old.reddit.com/r/ios/comments/1b04rzy/apple_what_wer...
https://news.ycombinator.com/item?id=23736536
https://apple.stackexchange.com/questions/344271/books-autom...
iCloud offload is a pretty common feature on Apple devices and one that I find pretty handy. I understand why it doesn’t work for others though.
You can turn off iCloud sync in general for the device.
Most software products rely on very complex software stacks, and if you trust 100% all the libraries and the OS you use I would say it's a wrong mindset. There were bugs even in the processor (meltdown). Security is a continuous battle and you never know if you won, only (sometimes) if you loose.
When I breeze through your login process with the wrong credentials that's because your security was fake, if it was real that would break because it didn't know who I was, so if some bug lets me past login I don't somehow successfully log in as me, I'm logging in as nobody at all which is clearly nonsense.
This is "Make Invalid States Unrepresentable" at scale, and it's difficult to do, but not impossible.
This is just not how it works. Most likely author spent weeks or months digging into different products until he found something worthville.
Congrats!
YouTube used to have DMs so you could do this. I don't remember exactly when it was removed. Probably late aughts.
It feels like most software sites are now populated by people who think software is like in the movies.
Still, impressive writeup. Shows how chaining a few reverse engineered endpoints can generate created a significant exploit.
> Timeline
> 05/11/24 - Panel awards $3,133.
> 12/12/24 - Panel awards an additional $7,500.
But one has to understand that for security purposes they SHOULD pay as little as possible. If they pay out more there is more incentive in finding bugs and then there unfortunately you’ll also raise more black market.
So GTO strat is to just cut off black market with as little money as possible.
Industry-wide SWE compensation is somewhere in the $100k-$200k range. Typical Google SWE compensation is $350k. Top Google SWE salary is north of $1M. Increase by 60-100% for overhead, or somewhat more for consulting overhead.
The amount of work doing something like this is orders of magnitude more than the compensation:
1) Most security vulnerabilities investigated lead nowhere, were previously discovered, etc. That's lost time.
2) Working out something like this is much more than 0.25-3 weeks.
More critically, the black market value of most vulnerabilities is much more than Google pays out. A rational economic actor would sell something like this grey market or black market, rather than reporting.
The problem is none of the big companies take security seriously. The reason is that there are no economic damages to even serious data leaks, so what incentive is there for them to take data security seriously?
Many companies (including big ones like T-Mobile) have major security compromises every few months (and in the case of T-Mobile, have had so for decades) and simply don't care. I don't mean to pick on T-Mobile -- I like them as a company -- but they're pretty representative.
It requires some legwork but they could’ve seen somewhere in the ballpark of 6 figures over 1 year if the exploit wasn’t patched.
Oh, and if they had no ethics.
I think the reality though is just that there's literally no buyer for this.
You could sell the service yourself! I bet you could make a couple thousand bucks before you and your customers got indicted.
Caught for what? If someone sells information about a vulnerability, what law are they breaking? In most jurisdictions, unless you're dumb enough to ask questions about whom your selling to and have active knowledge you're assisting someone in breaking some law, selling to the black market is perfectly legal, at least so long as you pay your taxes.
If you're doing grey market, it's even more legal. If a dictatorship wants to unmask a critic for assassination, and one is selling this information to a government security agency, it's legal by definition.
I wrote: "unless you're dumb enough to ask questions about whom your selling to and have active knowledge you're assisting someone in breaking some law, selling to the black market is perfectly legal"
You wrote: "If you sell information about a vulnerability to someone that you know specifically is going to use it to break the law, you are an accessory to that lawbreaking"
That's the exact same thing.
You, likewise, didn't notice I was advocating for new statutes in a post above.
You get caught by the DEA. Do you think it’s a valid defense “I didn’t ask what was in the box”?
Say the drug dealer you delivered it to got caught and then told authorities you delivered it to them, do you think you would have a valid defense?
(Commenters keep moving the goalposts making for a complex thread where each node in the tree litigates a very different hypothetical situation. Ah HN!)
Similar to publishing say... the Anarchists Cookbook.
This goes directly to the concept of “willful blindness”
https://www.mad.uscourts.gov/resources/pattern2003/html/patt...
Calling 10k an "extraordinarily high sum" is accurate to some and inaccurate to others.
I would bet the groups would differ by perceived personal cost more than the opinion of Google, Apple, and the like. These groups would also probably show distinction where people have been victimized by "identity theft."
The opinions of those bearing the cost are more important here, in my opinion.
That $10k is "an extraordinarily high sum for" what was likely weeks of work on this bug, and probably months of work poking in other places, reflects the very, very low focus on security industry-wide. This is why we need significant civil -- or possibly occasionally criminal -- liability. Civil if it's simple negligence, and criminal if it's gross negligence leading to harm.
If Google were to pay me $200 if it leaked my data, that would:
- Be worth much less than my privacy
- Amount to damages of $400B worldwide if there were a compromise impacting all $2B users (although, realistically, damages would be lower in middle and low income countries)
This would represent a 20% fall in Google's market cap, which feels about right.
At that point, I expect the bug bounties would be set many orders of magnitude higher. Security bugs should be rare. They're common. This is a problem, and one created by our market incentive structures.
You are correct that Apple is an exception, and seems to mind security.
Google is not going to pay you $200 if they leak your email address.
Google pays as much attention to security as Apple does.
If you want a world in which these kinds of security bugs create multimillion-dollar liabilities, you can advocate for the new statutes that will create that world; just be aware that only companies like Google will be able to afford to operate in that world.
I disagree with the claim that "only companies like Google will be able to afford to operate in that world." That's not how markets work.
1) The impact would be that frameworks would develop with better security. This would result in a slowdown of software engineering. Perhaps it would start to look like any other engineering discipline, where things are analyzed for safety.
2) Every other industry shows that in situations like this, big players are disadvantaged.
The analysis here is pretty basic:
- If I'm running a small $10M startup making a little iPhone app for some obscure task, the risk of legal liability from this is among the smallest of my risks of going under, so I'm incentivized to ignore it. If I were faced with a $400B liability, I declare bankruptcy, so in effect, that's a $10M liability. The expected cost is 5% times 10M = $500k, so it makes sense to spend up to $500k to mitigate a 5% risk.
- If Google has a team working on that same app, and doesn't manage security properly, the $400B liability stays a $400B liability. There is no ROI analysis where it makes sense to build a little app which has a 5% chance of leaking data. Do it right, or don't do it at all. The expected cost to Google here is 5% times $400B = $20B.
This is why, in virtually every other industry, big players are (1) more trusted (2) more expensive, and phrases like "small, fly-by-night operation" exist (and make business sense to run).
Security is hard. Incredibly hard. Unlike most things in business which are positive-sum, security isn't - it's adversarial. If we make companies pay huge civil fines for things that are so hard to protect against, we're stifling a ton of innovation.
I usually analogize a large company to a bank. A bank is supposed to keep your money secure, and for sure you'd have a legitimate beef if a bank robber could waltz in and steal your money easily because it's not kept in a vault.
But what if it is kept in a vault? What if the bank isn't attacked by a random group of bank robbers, but rather by the armed forces of a hostile nation? We don't expect banks to protect against armies - that's what we have states for! They provide centralized protection against threats that are far too large for any individual entity to take on by themselves.
This is the same, albeit out of sight, situation with large companies. You can have thousands, tens of thousands of people around the world poking at everything your company does for years, looking for any vulnerability. No company can truly withstand that kind of scrutiny - and I don't think making civil penalties higher will change that. And on top of criminal or opportunistic actors, companies also have to be worried about state actors too.
The only way is for the state to take on an active role in security. I don't see any other way that gets real security for anyone.
I think you need to do a lot to justify a non-zero value for this, frankly.
How is your “privacy” worth $200? What data is valuable and what data isn’t? Under what context?
If your privacy is worth $200 per leak (by some definition of leak), you surely take steps to anonymize your data already and wouldn’t use a service like Google (or name your untrustworthy party).
I’m not saying leaks are good but trying to price it in seems fraught.
I used to get books dropped off at my door with the names, addresses, and phone numbers of thousands of people. The first two are often public record.
The other comment has already addressed the market value question.
This is what baffles me about Apple's bug bounty program.
> $1,000,000: Zero-click remote chain with full kernel execution and persistence, including kernel PAC bypass, on latest shipping hardware. As an example, you demonstrated a zero-click remote chain with full kernel execution and a PAC/PPL bypass with persistence on the latest iOS device.
This is easily worth significantly more. You don't even need to sell it to the black market, sell it to all the 3 letter agencies in the world.
For private corporations/closed code, it is a way to get a thousand engineers looking at their code and APIs and only pay a small amount to however is the first one to find something. Everybody else gets nothing even if they put a lot of time and effort.
Underpaid is an understatement.
Neither Google nor Etisalat have responded to request for comment at the time of writing.
The issue appears to be very similar to a problem which was reported by users of Kuwaiti ISP FASTtelco , who said that they were able to see other users Gmail accounts and other personal details, although this was later denied by the ISP'
On the other hand, a spearfishing campaign could be valuable. And launch a memecoin on some people’s account to make millions
(Of course, they can still apply more computational work and possibly identify you without you logging in.)
https://web.archive.org/web/0id_/http://wayback-fakeurl.arch...
Regarding the payout-- I'm curious if targeting (in the disclosure video) a CEO/C-Suite exec @ Google would have encouraged a higher amount from the panel.
That seems extremely long for an organisation as technically competent as google.
$100.00 is enough to cause most to blush.
The attack chain isn't that complex...
It's very lame to be stingy with a bug bounty program.
https://support.google.com/youtube/answer/7001996?hl=en-GB
edit: My hunch is that the channels the OP's attack was able to target are not actual channels but rather YouTube users (who have a "channel" because that's how YouTube represents users): so "YouTube User" is the correct description of this attack, which is distinct from what you're thinking of as a channel.
Talk about puny!
> If they poked around a bit more they may have found a better GAIA->Email vulnerability
They still can! Report more bugs, get more bounties. I don't see how this is related to how much they paid for this one.
> A database of emails for every major youtube channel would be worth an awful lot.
It's pretty clear from the article that you can't use this API to scrape at that kind of volume. This kind of thing was never in the offering. As the title says, you can leak "any" email, not "every" email.
Or just plain ole pwning them. Most users still tend to use the same password across different services, not use 2FA, and involved in at least 1 high profile leak (I know I’m in at least a dozen so far per haveibeenpwned).
Occasionally you get the victim that uses that same password for their e-mail service and that can allow you to bypass e-mail 2FA if enabled. Even better if the account is used for social SSO (ie, Google, Facebook, Twitter). Then you have access to a treasure trove of services; or just delete them for lulz
I'll take a cheque.
EDIT: oh I see .. DD/MM/YY is a new one to me
https://en.wikipedia.org/wiki/List_of_date_formats_by_countr...
https://en.wikipedia.org/wiki/List_of_date_formats_by_countr...
I have no idea why America settled on MM/DD/YY, which seems like absolutely the least intuitive permutation of D, M, and Y. Except perhaps MYD.
Yes, this effectively makes dates nearly impossible to decipher here.
Like US customary units, imported from the british, but the UK modernized its system, not the US.
February 12th, 2025
Rather than:
12 February 2025
And is easier to say than:
The 12th of February 2025
So it's always been natural to write the numeric form the same way, but I am American. I can appreciate day first being easier to sort by machines and having an agreed upon international standard.
Again grammatically is easier and shorter to say month day vs the day of month.
Month day year makes no sense because it's backwards, and no one talks that way. So why use that?
People also say "twelve past two" and yet you don't use 12:2:SS.
February Twelfth Two Thousand and Twenty Five
Feb 12 2025
02/12/2025
I know it's cool for Europeans ... and everyone else to hate on us for it but it does seem to make sense given the way we typically say the date.
Big and little endian dates are the only way that makes sense I think. Doing it the US way where day is inexplicably between year and month just feels corrupted to my mind.
IIRC, Japan uses Year-Month-Day, which is the other order which makes sense.
Nope, the standards are day.month.year, year-month-day, or month/day/year. The problem happens when the delimiter doesn't match the ordering.