news.volyx.in

Leaking the email of any YouTube user for $10k (brutecat.com)

1624 points by brutecat · 538 days ago · 466 comments on HN

Article summary

A security researcher discovered a vulnerability in Google's services that allowed them to leak the email address of any YouTube user for $10,000. The vulnerability was found in the YouTube and Pixel Recorder services, and it involved exploiting a flaw in the way Google handles user blocking and sharing of recordings. The researcher reported the issue to Google and received a total bounty of $10,633. The vulnerability has since been fixed.

Main themes

  • Google security vulnerability
  • YouTube and Pixel Recorder exploit
  • Bug bounty and reward
  • Security research and disclosure
  • Google product deprecation

What commenters say

  • The payout for the bug bounty was surprisingly high, considering the complexity of the attack chain required to exploit the vulnerability.
  • The deprecation of old Google products, such as Google Reader, can have a significant impact on users and the broader web ecosystem.
  • Some people believe that the killing of Google Reader marked a turning point in the shift from the open web to closed social media platforms.
  • Others argue that the loss of Google Reader was not a significant blow to the blogging ecosystem, and that alternative RSS readers have filled the gap.
  • The complexity and security of a system are inversely correlated, with more complex systems being more vulnerable to security breaches.
  • Security is ultimately an illusion, and even with significant investment in security measures, a single mistake can lead to a breach.
  • The use of old and forgotten products can be a fertile ground for security researchers to discover new vulnerabilities.