10 ms·
The embedded YouTube player told me what you were watching
- djrogers 6y agoThis is a bad link, not sure how it got upvoted when following it fails (there’s a trailing . after the domain). That’s kinda fishy... Correct link should be https://bugs.xdavidhu.me/google/2021/01/18/the-embedded-youtube-player-told-me-what-you-were-watching-and-more/ https://bugs.xdavidhu.me/google/2021/01/18/the-embedded-yout...
- joshuaissac 6y agoIt works for me, and having a dot after the TLD is perfectly valid.[1] 1. Page 7 of RFC 1034 https://www.ietf.org/rfc/rfc1034.txt https://www.ietf.org/rfc/rfc1034.txt
- heinrich5991 6y agoInterestingly enough, I can follow it without any errors. Firefox 84.0 on Arch Linux.
- kahrl 6y agoWorking in Mozilla, Edge, Chrome 87....
- leothecool 6y agoThe trailing dot is fine. http://www.dns-sd.org/trailingdotsindomainnames.html http://www.dns-sd.org/trailingdotsindomainnames.html Though now I'm curious why it fails for you.
- noman-land 6y agoAdding the dot after the tld actually works on some sites to bypass paywalls.
- cuspycode 6y agoAnd in the old days people were accustomed to be able to resolve local hostnames, without having to supply any domain part. The "search" keyword in resolv.conf is a remnant of this. By adding a final dot, you ensured that the domain part you wrote referred to the global DNS root, not any local one. Unless of course someone had changed "ndots" which controls how many dots are needed to disable the search feature.
- taldo 6y ago$1,337 for watch history + liked videos + watch later disclosure? Requires user to visit a malicious site, yes, but still feels a bit skimpy.
- sbarre 6y ago> Requires user to visit a malicious site YouTube embeds are such universal things on the web, I doubt anyone would even think twice about security concerns coming from seeing that on a third-party site. Because it's Google, right? /s
- Nextgrid 6y agoDo you actually need to see it? The exploit should work fine even if the player is not visible.
- satya71 6y agoStrangely, I almost never allow YouTube embeds (or for that matter any embeds) using uMatrix. I click the pop out link that appears in its place.
- sthnblllII 6y agoNice. What amazes me is how most of big tech's efforts on web development have gone into making you 0.01% more likely to click on an ad, and almost none of has gone into cleaning up the privacy nightmare of 25 years of hacks with clean browser-based protocols.
- sbarre 6y agoThat's actually a really good idea, I should do that too.. Thanks!
- verganileonardo 6y agoProbably not even worth the time he invested in looking for the bug or writing the post. And is basically nothing compared to the value of "exploiting" this bug. I would've expected at least a job offer or public praise for his offers. No wonders bug hunting is not attracting enough people.
- layer8 6y agoEDIT: never mind Should probably be (2019), as the bug has been fixed since (as noted at the bottom of TFA).
- warp 6y agoAFAICS the article was first posted 18 January 2021, so (2019) would be incorrect.
- layer8 6y agoYou’re right of course, I had overlooked the header and misinterpreted the title to refer to the present rather than to the past.
- ehsankia 6y agoEvery bounty bug write up I've seen on HN was after it had been long fixed, so that should be a given when you see a write up like this.
- layer8 6y agoI misinterpreted the "2019, October 11, 00:16" to indicate when the following text was written.
- gverrilla 6y agodoesn't google employ the elite of world programming? how can such stuff even happen? honest question.
- Jaygles 6y agoProbably due to the scale they're operating at. Maybe there were parts of things that didn't have such a vulnerability alone but did when put together. Maybe there isn't a clear owner of the code so no one felt responsible to find and patch such a thing. Maybe the entire system is too complex for one or even a small team of developers to grok so things can easily slip through the cracks from time to time.
- bidirectional 6y agoNo, Google employs far too many developers for the median to be close to 'elite'. I'm sure there are elite teams at Google, but I very much doubt the average Googler is, and that's probably been the case for a decade at this point. The famous Rob Pike quote sums it up quite well: > The key point here is our programmers are Googlers, they’re not researchers. They’re typically, fairly young, fresh out of school, probably learned Java, maybe learned C or C++, probably learned Python. They’re not capable of understanding a brilliant language but we want to use them to build good software.
- xirbeosbwo1234 6y agoI think Rob Pike's commentary on Go is why I decided to go into research. Google hires kilotons of developers and pays them gigadollars every year, then makes them work in dumbed-down languages because they can't be trusted with power tools. How has our industry gone so far astray that we pay people hundreds of thousands of dollars a year when they can't even understand generics? In what universe does it make sense to design an entire new language rather than offering new hires two months of training? Why are we pretending programming is a skilled trade when the things people actually wind up doing are so easy they can be learned in three months at a boot camp? Rob Pike is a legend. He is the man who brought us Plan 9. How is this what he wound up working on?
- AbuAssar 6y agoThat’s why I don’t browse the web while logged in google/fb/twitter. As I keep them in separated firefox containers
- fredley 6y agoIt's not about you, it's about your parents and grandparents.
- banjomet 6y agoWhat do you mean by that?
- xphx 6y agoIt's an ageist way of saying that this exploit is less critical for people who take proactive counter-measures, and more affects less technically inclined or security-minded people.
- mosselman 6y agoAgeist how? Who says you have to be a certain age to be a parent or grandparent? Sounds very ageist to me. And that is an example of how political correctness is an arms race.
- grlass 6y agoYou misunderstand: it's ageist to suggest that parents and grandparents are by definition not likely to be technical enough to use mitigations like containers and such. Which it is.
- kuroguro 6y agoHaha, he's kind of right - there's two assumptions there. Saying grandparents are old and saying grandparents aren't technically inclined.
- kkotak 6y agoHe lost me at - Forgot to eat Pizza.
- grishka 6y agoYet another example of why the whole concept of third-party cookies does much more evil than good. Yet all major browsers keep them enabled by default.
- anonymousiam 6y agoI can see why Google might want to downplay this. Partner websites could obtain the history info directly from users and Google would not need to disclose the data sharing. I'm sure the watchlists/history would be valuable tools for profiling and advertising purposes.
- pcthrowaway 6y agoI honestly feel like Google's award in this case is pathetic. This is an exploit which would be worth 100s of thousands, if not millions to the wrong people.
- akanet 6y agoThere is no entity that would pay anywhere near that amount of money for this. This is useless to black hats, and of course no legitimate service could pay to exploit this flaw. The last remotely plausible actor is like, various espionage agencies but good luck with that one.
- pcthrowaway 6y agoI suspect the NSA would be able to keep much better tabs on people if they know exactly what they're watching on Youtube all the time, and $100,000 would be a pittance to them. I assume they already have access to this, but other espionage agencies may not.
- franga2000 6y agoChina.
- ChrisRR 6y agoIt's worth a lot more than $1337 though. That sort of money is so low that it may not even be worth the time to white hats
- gjs278 6y agothis exploit is worth basically nothing to anybody. they can just run google ads and google already does that targeting for them because they all know what the user is watching on youtube.
- neetodavid 6y agoIts too bad (in a way...) they couldn't get private video IDs to leak. It would have made an impressive combination with their bug posted earlier this month (Stealing Your Private Youtube Videos, One Frame at a Time https://news.ycombinator.com/item?id=25728175 https://news.ycombinator.com/item?id=25728175) Speaking of... do security researchers sometimes just sit on their discoveries in hopes that they will eventually lead to a bigger payout? I would be kicking myself if I had reported a bug for a relatively small reward that I could have leveraged in combination with another discovery
- buo 6y agoMy understanding is that the javascript in a web page executes in the client. How can the page owner obtain the video lists?
- ummonk 6y agoThis was an extremely serious privacy issue, and it's shocking that they'd only award $1,337 for a bug of this scope.
- intricatedetail 6y agoCompanies should stop exploiting developers. Instead of erecting another sky scraper they should start paying the fair share.