6 ms·
>Unmasking Google accounts? Could there be a business there? Sure, maybe. Is there one already? Presumably no. Absolutely, yes. Spam and targeted phishing atta
by mmsc 2y ago
>Unmasking Google accounts? Could there be a business there? Sure, maybe. Is there one already? Presumably no.
Absolutely, yes. Spam and targeted phishing attacks are in high demand.
My understanding is that it is possible to retrieve every public youtube channel ID, if not also Google Maps/Play reviewers, quite easily. This exploit could have been used to create a massive near-complete database of every Google account has automatically had a Youtube account created.
- brookst 2y agoBut then what? Given the number of accounts Google has, odds are that nearly every alphanumeric combo less than 8 or 10 characters plus “@gmail.com” is a google account. This vulnerability gets you other domains, but still not seeing it. Massive databases of email addresses are a dime a dozen. The only angle I can imagine is phishing for high profile creators, and at most this is a “makes it easier” and not a “creates the problem” bug.
- refulgentis 2y agoThe back of an envelope can get you making silly claims quickly (ex. 26 ^ 8 is 208 billion)
- cirego 2y agoI think you might be off by a factor of 10. Alphanumeric would be at least 36 characters, which would imply 2.8 trillion combininations (36 ^ 8).
- refulgentis 2y agoyeah, I was doing the charitable as possible version
- brookst 2y agoNot seeing the problem. Are you assuming that somehow there is at most one Gmail account per person on earth? I have… I’m not sure. Ten maybe? And those are actual conveniences for different purposes. I’m sure plenty of people have hundreds, if not thousands. So what?
- refulgentis 2y agoI'm a bit confused: - I charitably went with 208 billion, 25 for every single individual on this planet. - As the other replies note, I chose a misleading number that is off by an order of magnitude at even the most charitable reading - You can't see the problem I don't think it's fair to you to assume you can't see it, maybe you were in an old tab that had my reply but none of the descendants.
- ineedasername 2y agoYou could target accounts of users likely to be younger & more susceptible to phishing for passwords-- kids subscribed to channels with younger content. Or other interest-based targeting. It's not quite spear phishing, but still more targeted.
- kasey_junk 2y agoAnd then what? Exploits need to plug into a business plan. Like any business plan there has to be somewhere that money gets extracted and that money needs to be more than the exploit cost & infrastructure costs & a risk premium. If you can’t trivially say how the exploit explicitly gets turned into cash you probably are on the wrong track. Doubly so if it’s not a known standard and commoditized way that’s happened before.
- chmod775 2y agoThere is often phishing campaigns targeting larger channels on YT, trying to trick someone with access to it into opening malicious e-mail attachments, with the end-goal of taking over the channel. Usually the attackers then put a livestream on it and push some crypto scam. It must make enough money, given that it keeps happening. Most recent example I've seen: https://www.youtube.com/watch?v=EnVxWK6DfMQ https://www.youtube.com/watch?v=EnVxWK6DfMQ
- UncleMeat 2y agoSo then why do they need additional information about emails? They clearly already can email these youtubers.
- chmod775 2y agoThis will enable you to get the private e-mail of the google account that owns the channel, which is not necessarily the same one a channel may give away publicly. So for some channels that provided no contact information, you now can acquire an email address, and for everyone else you may now get an additional one. It also enables you to link multiple channels back to the same person. Every bit of information you can get your hands on counts for social engineering attacks. For very famous individuals this may also open them up to harassment. You can't find Elon Musk's private telephone number on the Tesla homepage for good reason. For that class of people, any time that sort of information leaks, they need to get a new private phone number/e-mail address.
- 2y ago
- jeffwask 2y agoHonestly, that leaves straight up harassment of YouTubers by other YouTubers and fans off the table which by itself would motivate a few of them. Some of the same people who play in the black and grey hat worlds are the same people buying DDOS attacks and swatting streamers. They would have a party with their emails.
- tptacek 2y agoDraw up a straw-man business plan for this, with SWAG numbers.
- jeffwask 2y agoThe motivation isn't financial but the impact to some of Google's biggest earners would be significant. Never mind the PR when Mr Beast and SSSniperwolf's personal details leak online.
- tptacek 2y agoYou mean, "mrbeastcompanyofficial@gmail.com"?
- jeffwask 2y agohttps://www.wired.com/story/youtube-bitcoin-scam-account-hijacking-google-phishing/ https://www.wired.com/story/youtube-bitcoin-scam-account-hij...
- jsnell 2y agoMajor channels typically would be using a YouTube brand account, not a single normal Google account. (This is so that they can e.g. delegate parts of the channel management to multiple people without sharing a single login). The email address for a brand account is totally worthless.
- lolinder 2y ago> which by itself would motivate a few of them Motivation in the abstract is not enough to counter GP's point—they have to have enough motivation that it's worth more than $10,000 to them and also have more than $10,000 to spend and also have the connections necessary to get in touch with someone who's able to sell a vulnerability like this and also be able to exploit it in a timely manner or at least think they can.
- lolinder 2y ago> This exploit could have been used to create a massive near-complete database of every Google account has automatically had a Youtube account created. Massive email databases are extremely cheap, often free. For this vulnerability to be worth more than $10k there would have to be something about it being a near-complete library of Google accounts (rather than just another massive mailing list). And that's assuming the prospective buyer believed that they could exploit this vulnerability in full before discovery. If I'm reading this exploit right, each email recovered requires two requests, one of which needs to make one of the fields 2.5 million characters long in order to error out the notification email sent to the victim. Presumably that email sending error would show up in a log somewhere, so the prospective attacker would have to send billions of requests fast enough that Google can't block them as suspicious or patch the vulnerability, all the while knowing full well that they're filling up an error log somewhere and leaving an extremely suspicious pattern of megabyte-sized request bodies on a route that normally doesn't even reach kilobytes. I'm honestly not seeing how you could make an email list out of this that is anywhere near complete, and even if you could I'm not sure where the value to it would be.
- mmsc 2y ago>Massive email databases are extremely cheap, often free There are different qualities of email databases. "Known real email by Youtube account holders" would be a high value database. Definitely not free. This type of vulnerability is extremely valuable for private investigators, too. "Who uploaded this video which my client is extremely interested in?"
- sbarre 2y agoSure but did you read the rest of the post you're replying to? That database only exists in theory, based on extrapolation of this vulnerability to billions of individual exploits, and I think we can all agree that Google would detect this activity and shut it down. Hence, that database might fetch a decent price if it existed, but it doesn't.
- 0xDEAFBEAD 2y ago>This type of vulnerability is extremely valuable for private investigators, too. "Who uploaded this video which my client is extremely interested in?" Would exploiting this vulnerability violate the Computer Fraud and Abuse Act? If so, would a private investigator really want to do that?