Skip to content

Comment on How I could delete any video on YouTubeparent

Comments

Why so little? Its a pretty damn critical bug especially if it were use judiciously -- it might be really hard to detect. For a company with billions it seems like they should have better incentivized this. I'd imagine China would have paid a lot more for this bug, or one of the upcoming presidential campaigns, for example.

Yes, this bug is worth more than $5k. To be honest I expected $15k - $20k :) I wanted to write a kind of "complain" to Google, but first I reread a Google Vulnerability Reward Program Rules and understood that Google could not pay me more. Take a look at the table here: http://www.google.com/about/appsecurity/reward-program/index..., YouTube is a "Normal Google application", this bug is in "Logic flaw bugs leaking or bypassing significant security controls" category. So that's mean that Google rewarded me a maximum reward - $5,000 :)

Facebook has not got a boundary for maximum reward, so they can pay as much as they want…

I'm also interested in knowing how one can really put a price on a bug, and user dsacco seems credible enough to answer that. For example, Facebook's bounty program paid $12,500[1] for the bug that could delete any photo album. This bug seems like it could have a much worse effect since some videos are a source of income for their owner.

[1] http://www.theverge.com/2015/2/12/8026159/facebook-photo-alb...

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.