PC Pro Magazine

Real world computing

“This attack highlights a significant problem with the way services such as YouTube are designed”

The recent attack on Linus Tech Tips shows that YouTube needs to update its security procedures. Plus, why the pub will always win over zero inbox

Another day, another YouTube channel hack. This time it was Linus Tech Tips, one of the more prolific YouTubers. Linus and team lost control of multiple channels that they run, and the miscreants decided to delist most of the huge library of videos stored there, and also to start posting videos of their own.

Fortunately, Linus and co took back control of the channels quite quickly; YouTube support was apparently a big help, but this should be no surprise for a channel that has 15.3 million subscribers and nearly 7 billion video views.

So, what went wrong? Surely they weren’t using passwords such as “password” or “12345678”? No, of course not. Instead, this attack highlights a significant and growing problem with the way in which services such as YouTube are designed and implemented.

There’s a long video on the channel explaining the attack, but the short version is this. Someone on the team downloaded what appeared to be a PDF file from an address that, at first glance, looked legitimate. Said person unpacked the file, and then tried to run the PDF file to see the contents. However, it didn’t render cleanly. That’s because it wasn’t a PDF file at all, but malware. Malware designed to steal the session token from a browser that was already logged in to and authenticated for YouTube.

Here’s how it works. When you log in, the browser session takes

You’re reading a preview, subscribe to read more.

More from PC Pro Magazine

PC Pro Magazine3 min read
Asus Vivobook Pro 15 OLED (2024)
PRICE £1,333 (£1,600 inc VAT) from uk.store.asus.com This year’s update to Asus’ Vivobook Pro 15 makes one thing obvious: the days when you had to pay over £2,000 for a powerful mobile workstation are gone. Packed inside this 1.8kg monster you’ll fin
PC Pro Magazine9 min read
Turn Your Dumb TV Into A Smart One With A Raspberry Pi
Old TVs are cheap to replace, even if you’re buying something larger or smarter. But disposing of a spare display is wasteful. It could be given a second life in a kitchen or bedroom – and, while you can’t make your old TV any bigger, you can make it
PC Pro Magazine9 min read
7 Habits of highly Effective IT Pros
Short-term thinking is the absolute enemy of effective working. I have lost count of the number of times I’ve completed a firewall audit, only to find an incoming route punched through the firewall because the CEO wanted to run some weird software fr

Related Books & Audiobooks