Given that this bug could compromise part of the foundation of YouTube (deleting videos, messing up ad revenue), this should be worth a lot more than just $5k. A quick script running on several servers could take down a large part of youtube in a matter of minutes. Imagine if he went over through all the maker studios channels like pewdiepie and deleted stuff. All those view counts AND trust would be gone.
This bug honestly deserved a year's salary. But that's just my opinion I guess.
In other thoughts, I really need to try my hand at this stuff :)
This is a very persistent meme that is ultimately incorrect. You can't judge the value of a vulnerability by how large its host company is, or even by its severity.
In the security industry we use the term "vulnerability half-life" for this purpose. Basically, a bug in Google will be discovered between a day and a week after it is first exploited instead of reported. If you try to commercialize it, it will quickly be discovered because the top tech companies have the best incident response teams in the world.
Once the flaw is patched once in Google, it's effectively patched. Game over for the attacker. Compare this to a vulnerability like Heartbleed that is actually worth money - critical flaw that can compromise over a third of all the servers on the entire internet. If that vulnerability is patched anywhere, it's not patched everywhere, unlike a single web application instance in Google.
The greater the half life, the greater the value of the vulnerability. A vulnerability in Java is worth money because it will still exist in the wild for years, providing consistent income and ROI for a purchased exploit.
A vulnerability in Facebook is worth money to Facebook for brand integrity, but it isn't worth much to blackhat groups. You could theoretically commercialize it, but not quickly enough or in a meaningfully consistent or lucrative enough way to really make it worth the hassle.
While I agree that this was worth more than 5k, I'd like to think the delete functionality is only setting a flag and not physically removing all traces of the video, if that's the case then it'll be trivial to undo the damage.
Undo damage might be easy from a technical point of view, but PR damage is not. If Google paid much more at Pwn2Own, so why not more for this critical bug?
Why so little? Its a pretty damn critical bug especially if it were use judiciously -- it might be really hard to detect. For a company with billions it seems like they should have better incentivized this. I'd imagine China would have paid a lot more for this bug, or one of the upcoming presidential campaigns, for example.
Yes, this bug is worth more than $5k. To be honest I expected $15k - $20k :) I wanted to write a kind of "complain" to Google, but first I reread a Google Vulnerability Reward Program Rules and understood that Google could not pay me more. Take a look at the table here: http://www.google.com/about/appsecurity/reward-program/index..., YouTube is a "Normal Google application", this bug is in "Logic flaw bugs leaking or bypassing significant security controls" category. So that's mean that Google rewarded me a maximum reward - $5,000 :)
Facebook has not got a boundary for maximum reward, so they can pay as much as they want…
I'm also interested in knowing how one can really put a price on a bug, and user dsacco seems credible enough to answer that. For example, Facebook's bounty program paid $12,500[1] for the bug that could delete any photo album. This bug seems like it could have a much worse effect since some videos are a source of income for their owner.
Do not be silly. Turning a bug like this into a commercial venture? How do you find customers fast enough before a patch? 6337$ for a days work is very reasonable, while selling a bug like this makes you not worthy of a quarter.
Comments
Now that's a critical bug.
Absolutely critical. And he got $5k? Glad his ethics are sound.
This bug is probably worth about that much. It was a good find, however.
Given that this bug could compromise part of the foundation of YouTube (deleting videos, messing up ad revenue), this should be worth a lot more than just $5k. A quick script running on several servers could take down a large part of youtube in a matter of minutes. Imagine if he went over through all the maker studios channels like pewdiepie and deleted stuff. All those view counts AND trust would be gone.
This bug honestly deserved a year's salary. But that's just my opinion I guess.
In other thoughts, I really need to try my hand at this stuff :)
This is a very persistent meme that is ultimately incorrect. You can't judge the value of a vulnerability by how large its host company is, or even by its severity.
In the security industry we use the term "vulnerability half-life" for this purpose. Basically, a bug in Google will be discovered between a day and a week after it is first exploited instead of reported. If you try to commercialize it, it will quickly be discovered because the top tech companies have the best incident response teams in the world.
Once the flaw is patched once in Google, it's effectively patched. Game over for the attacker. Compare this to a vulnerability like Heartbleed that is actually worth money - critical flaw that can compromise over a third of all the servers on the entire internet. If that vulnerability is patched anywhere, it's not patched everywhere, unlike a single web application instance in Google.
The greater the half life, the greater the value of the vulnerability. A vulnerability in Java is worth money because it will still exist in the wild for years, providing consistent income and ROI for a purchased exploit.
A vulnerability in Facebook is worth money to Facebook for brand integrity, but it isn't worth much to blackhat groups. You could theoretically commercialize it, but not quickly enough or in a meaningfully consistent or lucrative enough way to really make it worth the hassle.
While I agree that this was worth more than 5k, I'd like to think the delete functionality is only setting a flag and not physically removing all traces of the video, if that's the case then it'll be trivial to undo the damage.
Undo damage might be easy from a technical point of view, but PR damage is not. If Google paid much more at Pwn2Own, so why not more for this critical bug?
Why so little? Its a pretty damn critical bug especially if it were use judiciously -- it might be really hard to detect. For a company with billions it seems like they should have better incentivized this. I'd imagine China would have paid a lot more for this bug, or one of the upcoming presidential campaigns, for example.
Yes, this bug is worth more than $5k. To be honest I expected $15k - $20k :) I wanted to write a kind of "complain" to Google, but first I reread a Google Vulnerability Reward Program Rules and understood that Google could not pay me more. Take a look at the table here: http://www.google.com/about/appsecurity/reward-program/index..., YouTube is a "Normal Google application", this bug is in "Logic flaw bugs leaking or bypassing significant security controls" category. So that's mean that Google rewarded me a maximum reward - $5,000 :)
Facebook has not got a boundary for maximum reward, so they can pay as much as they want…
I'm also interested in knowing how one can really put a price on a bug, and user dsacco seems credible enough to answer that. For example, Facebook's bounty program paid $12,500[1] for the bug that could delete any photo album. This bug seems like it could have a much worse effect since some videos are a source of income for their owner.
[1] http://www.theverge.com/2015/2/12/8026159/facebook-photo-alb...
Are you kidding? You could make more than 5K in an hour of "YT cleaning service, $100 per video"
Do not be silly. Turning a bug like this into a commercial venture? How do you find customers fast enough before a patch? 6337$ for a days work is very reasonable, while selling a bug like this makes you not worthy of a quarter.
Or 1$/100k existing views/video, because the gangnam style video is a higher profile clip than my garage built rock band clip