Skip to content

Comment on How I could delete any video on YouTubeparent

Comments

Given that this bug could compromise part of the foundation of YouTube (deleting videos, messing up ad revenue), this should be worth a lot more than just $5k. A quick script running on several servers could take down a large part of youtube in a matter of minutes. Imagine if he went over through all the maker studios channels like pewdiepie and deleted stuff. All those view counts AND trust would be gone.

This bug honestly deserved a year's salary. But that's just my opinion I guess.

In other thoughts, I really need to try my hand at this stuff :)

This is a very persistent meme that is ultimately incorrect. You can't judge the value of a vulnerability by how large its host company is, or even by its severity.

In the security industry we use the term "vulnerability half-life" for this purpose. Basically, a bug in Google will be discovered between a day and a week after it is first exploited instead of reported. If you try to commercialize it, it will quickly be discovered because the top tech companies have the best incident response teams in the world.

Once the flaw is patched once in Google, it's effectively patched. Game over for the attacker. Compare this to a vulnerability like Heartbleed that is actually worth money - critical flaw that can compromise over a third of all the servers on the entire internet. If that vulnerability is patched anywhere, it's not patched everywhere, unlike a single web application instance in Google.

The greater the half life, the greater the value of the vulnerability. A vulnerability in Java is worth money because it will still exist in the wild for years, providing consistent income and ROI for a purchased exploit.

A vulnerability in Facebook is worth money to Facebook for brand integrity, but it isn't worth much to blackhat groups. You could theoretically commercialize it, but not quickly enough or in a meaningfully consistent or lucrative enough way to really make it worth the hassle.

While I agree that this was worth more than 5k, I'd like to think the delete functionality is only setting a flag and not physically removing all traces of the video, if that's the case then it'll be trivial to undo the damage.

Undo damage might be easy from a technical point of view, but PR damage is not. If Google paid much more at Pwn2Own, so why not more for this critical bug?

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.