this post was submitted on 12 Feb 2025
351 points (97.8% liked)

Technology

69041 readers
3898 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
top 22 comments
sorted by: hot top controversial new old
[–] givesomefucks@lemmy.world 151 points 2 months ago (2 children)

To clarify this is about someone identifying a vulnerability and getting $10k from Google for it

[–] mrnarwall@lemmy.world 20 points 2 months ago (1 children)

I was just thinking "maybe I can just give them my email..." but of course it isn't that simple

[–] AdamEatsAss@lemmy.world 10 points 2 months ago (1 children)

I'd pay $10,000 for your email.

[–] NoForwardslashS@sopuli.xyz 8 points 2 months ago (1 children)

$10,000 and my ass eaten? Sold.

[–] AdamEatsAss@lemmy.world 6 points 2 months ago (1 children)

Prepare for a lot of furry porn on you inbox.

[–] Akasazh@feddit.nl 9 points 2 months ago (1 children)
[–] SkaveRat@discuss.tchncs.de 1 points 2 months ago

Prepare for a lot of furry scat porn in your inbox.

[–] JoYo@lemmy.ml 7 points 2 months ago (1 children)

that's the real maricle here, an actual payout of a bounty.

[–] Ledivin@lemmy.world 4 points 2 months ago

...huh? Bug bounty payouts are not even remotely rare in either the industry as a whole or Google specifically.

[–] qaz@lemmy.world 28 points 2 months ago (1 children)

Here's a POC of the exploit in action:

This video has been removed for violating the YouTube TOS

[–] pHr34kY@lemmy.world 13 points 2 months ago (1 children)

Sharing a video about a Google security vulnerability on Google's own platform. What would you expect?

[–] qaz@lemmy.world 11 points 2 months ago

They did disclose it to Google before, and got a bounty but it seems the moderators from YouTube didn't get the memo

[–] flames5123@lemmy.world 27 points 2 months ago (1 children)

When FFXIV implemented better blocking tools this past summer, there was an option when blocking a single character to block the entire service account. This would be fine, but the implementation they went with is client side, and when you select that option, you get the service account ID. Which means that if you’re blocked by someone, you can’t made an alt character to stalk/harass them. But with third party tools, we can see this account ID. The stalker could just use a new account and find the person’s account ID that they were harassing and find any alt character they have in the game. They’re changing this soon as a third party tool popped up and is now able to do this, full source code leaked so there’s no shutting it down until the game devs change how it’s done.

This sounds super similar, but the implementation that you had to do for google is crazy.

[–] redeven@lemmy.world 4 points 2 months ago (1 children)

Saying full source code leaked is a little wrong.

Plugin was always open source, and all plugins for that framework are required to be open source by the framework's licensing.

Doesn't change the fact that once one person did it, the code was available for anyone, though, you're right.

[–] flames5123@lemmy.world 1 points 2 months ago

Ah yea. Idk why I said leaked since it was published that way. Nice call out!

[–] tja@sh.itjust.works 20 points 2 months ago

So.. Google Mail will not show me emails if their title is 2.5 million letters long? Pathetic

[–] funkajunk@lemm.ee 20 points 2 months ago
[–] Dil@is.hardlywork.ing 14 points 2 months ago* (last edited 2 months ago) (2 children)

This and some browsing of the public Facebook account will get you into most people's accounts with minimal effort, social engineering is wild and made me lose interest in being a hacker growing up because it was too easy and made me uncomfortable. (I wanted to be mr robot so bad, I was delusional lol)

[–] Maiq@lemy.lol 11 points 2 months ago* (last edited 2 months ago)

Remember back in the day when you could get apple users emails through a simple number incrimination in i believe the app store website?

The documentary The Hacker Wars highlighted the issue and if i remember weev went to jail for it. I probably need to rewatch it again.

Also if people are interested in that kind of documentary The Internet's Own Boy is a heartbreakingly excellent story of what the US put Arron Schwartz through.

[–] Dil@is.hardlywork.ing 2 points 2 months ago

(This was when facebook contacts would/could get added to yahoo contacts or whatever? IDK I had 100s of emails in there)

[–] troed@fedia.io 14 points 2 months ago

Nice exploit chain!

[–] afk_strats@lemmy.world 9 points 2 months ago

It took them 147 days to fix this?!?