|
|
|
|
|
by RJIb8RBYxzAMX9u
1191 days ago
|
|
There are a few possibilities I could think of: - LastPass breach related. - Classic phishing / session hijacking: apparently Google doesn't _always_ re-prompt for password when you change password / security device, if you have a valid session cookie. - Poor opsec from Linus (and by association probably also the rest of their upper management team). Luke, Linus's business partner, was recently "promoted" to CTO and has been working on their many know infra / security deficiencies. Alas, he's a bit too late it seems... |
|
However, for all we know there's a 0day in some part of the YouTube system. Maybe some (sponsored) device got hooked up to the internal network and laid dormant for a while.
I think one of the staff logged into the primary YouTube account got phished but there are so many ways this could've happened. Luckily for them, their channel is large enough that I think they'll make a full recovery once they've found out how this could have happened.