2024-09-15

Leaking the email of any YouTube user for $10,000

A security researcher discovered a method to leak any YouTube user's email address by exploiting a chain of vulnerabilities in YouTube's blocking system and Google's Pixel Recorder app, earning a $10,000 bug bounty. The exploit involved obtaining a user's Gaia ID through YouTube's API and converting it to an email address via Pixel Recorder's sharing functionality, while bypassing notification systems using an oversized recording title.

Original archive.is archive.ph web.archive.org

Log in to get one-click access to archived versions of this article.

read comments on news aggregators:

Related articles

POLL: Trust in Firefox and Mozilla is Gone - Let's Talk Alternatives

Mozilla's recent source code changes removing the 'we don't sell your data' promise have severely damaged user trust, with a survey showing 90% of Firefox users either distrusting or doubting the organization. Multiple privacy-focused browser alternatives exist, including Librewolf, Waterfox, and emerging projects like Ladybird, offering users various options for secure browsing.

What, if anything, should I do about using Mozilla's Firefox

A reflection on the continued use of Firefox browser amid Mozilla's recent controversial decisions, exploring alternatives like LibreWolf, Debian repos version, and standalone applications. The analysis weighs various options while considering privacy, security, and functionality needs, ultimately leaning towards maintaining Firefox usage while monitoring Mozilla's direction.

I’m done with coding

A former Microsoft engineer shares their journey from networking enthusiast to software developer, ultimately leaving their role at Viva Insights due to ethical concerns about surveillance. The narrative explores the conflict between high-paying tech jobs and personal values, leading to a decision to pursue entrepreneurship through an IT startup called Fourplex.

Xcode constantly phones home

An investigation reveals how Xcode's unnecessary connections to Apple's servers can significantly slow down build times, particularly during the 'Gather provisioning inputs' phase. The post details how blocking specific connections through Little Snitch can improve build performance and reduce unwanted analytics collection by Xcode.

Fast and Private Web Browser

Waterfox is a privacy-focused web browser offering built-in tracking protection, container tabs, and private browsing features by default. The browser prioritizes user privacy by not collecting telemetry data while providing easy migration from other browsers and maintaining high performance standards.

nRootTag - Tracking You from a Thousand Miles Away!

Find My offline finding enables AirTags to be located through a network of Apple devices when separated from their paired device. The system uses public/private key encryption for secure location reporting, with nearby Apple devices acting as anonymous finders to relay encrypted location data through Apple Cloud.

Some TXT about, and A PTR to, new DNS insights on Cloudflare Radar

Cloudflare's 1.1.1.1 DNS resolver processes 1.9 trillion queries daily across 250 locations worldwide, with new analytics features launched on Cloudflare Radar's DNS page. The service provides insights into DNS traffic patterns, protocol usage, and security metrics while maintaining user privacy through anonymized query logs.

Teslas Monitor Everything—Including You | WIRED

Modern Tesla vehicles are equipped with extensive surveillance capabilities, including multiple cameras and sensors that collect significant amounts of data about the car's surroundings and occupants. While Tesla claims to protect user privacy through data anonymization and limited collection practices, investigations have revealed concerning privacy breaches and employee misuse of customer data. Privacy experts express skepticism about Tesla's data protection measures and policy transparency.

Xcode constantly phones home

The article discusses performance issues with Xcode builds caused by unnecessary connections to Apple's servers during the 'Gather provisioning inputs' phase. The author discovers that blocking certain Apple domains through Little Snitch significantly improves build times while exploring Xcode's seemingly unnecessary tracking and analytics connections.

How to Change Your Meta Settings

A comprehensive guide details step-by-step instructions for enhancing privacy settings on Meta platforms, specifically targeting ad preferences and data collection. The guide walks users through disabling targeted advertising, preventing cross-platform data sharing, and unlinking third-party data collection on Facebook and Instagram accounts. Additional privacy recommendations include using Firefox browser and Privacy Badger extension.