Hacker News new | ask | show | jobs
by tyrust 24 days ago
Why doesn't the article contain proof of either attack in action?

I would be surprised if the second attack worked after what must be at least a couple layers of markdown/html conversion and spam filtering.

disclaimer: work at Google, but far removed from YouTube

1 comments

The attack requires a third party to unknowingly click on the engineered URL that leak private video title. Not sure if it counts as a POC if you can only use your own channel to prove it works.

But still, it would require a user interaction to click on the link to leak data - and google should acknowledge it as an issue, because an attacker should never be able to generate a link they control in a trusted/secure environment.

I understand the purported vulnerability. What I am saying is that I would be surprised if the URL were rendered, let alone made it to the victim.
I ended up making it render automatically, but they didn't really seem to care.
Wow, that's pretty wild. Updating your post with pictures would be cool.