Single Point of Failure: The (Fictional) Day Google Forgot To Check Passwords

Поділитися
Вставка
  • Опубліковано 15 січ 2014
  • tomscott.com - @tomscott - I spin a (fictional) tale of the day that Google accidentally opened everything. Performed at GeekyConf, with thanks to Betsy Weber and Natalie Downe on camera.

КОМЕНТАРІ • 1,9 тис.

  • @ColeRees
    @ColeRees 5 років тому +11522

    “Facebook became the most trusted site” boy did that one age beautifully

    • @c3po_bby796
      @c3po_bby796 4 роки тому +74

      definitely

    • @theajayyy
      @theajayyy 4 роки тому +593

      They've never been seen as a trusted site. That's the joke

    • @vedvod
      @vedvod 4 роки тому +37

      I see your point, but that must have been partially untrue for people to be highly surprised by the leak

    • @theajayyy
      @theajayyy 4 роки тому +114

      @@vedvod have you seen Zuckerberg's quote about people being stupid giving him their personal data? Data leaks are the least of their problems.

    • @maruftim
      @maruftim 4 роки тому +6

      That's funniest joke I laughed at hahahah

  • @Ken.-
    @Ken.- 7 років тому +9417

    "Google's Trusted Five"
    Marvel is already buying the rights.

    • @YonatanAvhar
      @YonatanAvhar 5 років тому +116

      *Avengers theme intensifies*

    • @jamiee7367
      @jamiee7367 5 років тому +88

      *Kazoo Avengers theme intensifies*

    • @snoopyguy21
      @snoopyguy21 4 роки тому +29

      Too late. Disney already did and claimed copyright.

    • @lalalalexie
      @lalalalexie 4 роки тому +3

      Hey Ken M get back to us soon buddy

    • @ryan1696
      @ryan1696 4 роки тому +17

      @@snoopyguy21 Disney owns Marvel

  • @thestateofalaska
    @thestateofalaska 8 років тому +9696

    "Everyone has that one single point of failure"
    Like that semicolon on line 463

    • @dreadwing93
      @dreadwing93 8 років тому +430

      **shudders**

    • @hecko-yes
      @hecko-yes 8 років тому +35

      Can't remember.

    • @brucebaker810
      @brucebaker810 8 років тому +168

      +ToCzegoSzukasz But if the semi colon weren't there...you WOULD remember. Ooooooohh...scaaaaaary.

    • @ShiftyMcGoggles
      @ShiftyMcGoggles 8 років тому +103

      +ᕕ( ᐛ )ᕗ or the Greek question-mark on line 6.

    • @LoganDark4357
      @LoganDark4357 8 років тому +171

      +Coty0010 When you accidently tapped the Caps Lock key instead of A on line 2 and didn't notice it until you were done making that 53-line rewrite.

  • @Stratelier
    @Stratelier 4 роки тому +1028

    "Forgot" is such an innocent, optimistic term ... like saying you "forgot" to lock the door on your way out, when what you did was _remove the door from its hinges._

    • @frozenheartedgiant8330
      @frozenheartedgiant8330 2 роки тому +22

      Take my like good sir, you made me laugh

    • @thomasslone1964
      @thomasslone1964 9 місяців тому

      fancy guy _using italics on UA-cam_

    • @hibblebins
      @hibblebins 9 місяців тому +1

      @@frozenheartedgiant8330 XD u2

    • @dogemaaaaaan
      @dogemaaaaaan 9 місяців тому +1

      Nice

    • @0akshadow
      @0akshadow 7 місяців тому +1

      This feels like a line which could actually have been in the video

  • @Rycluse
    @Rycluse 3 роки тому +1560

    The mundanity of Tom's sci-fi is always what I find most gripping. Like with the Earworm story, people ultimately just want to get back to their lives.

    • @ChrisPoindexter98
      @ChrisPoindexter98 Рік тому +46

      It's incredible, how it's intense enough to warrant concern, yet generally turns out neutral or positive in its consequences and seems...just barely plausible. Granted, his "Ganymede 2030" talk and the "copyrighted memory/personality" conceptuals he did are a touch hard to set in stone or conceivably believe can happen, but they're not *that* implausible, and this one is strangely realistic.

  • @MegaChickenfish
    @MegaChickenfish 4 роки тому +3450

    Me: Well it's not like this fictional scenario has e-
    Tom Scott: *It already happened with Dropbox.*

    • @talongreenlee7704
      @talongreenlee7704 4 роки тому +66

      It’ll happen again if quantum computers ever happen

    • @Luk3Stein
      @Luk3Stein 4 роки тому +18

      @@talongreenlee7704 Elaborate?

    • @talongreenlee7704
      @talongreenlee7704 4 роки тому +194

      Shubham Pawar all computer security is based on how hard it is to guess really really big numbers and quantum computers are really really good at doing just that. A powerful enough quantum computer can break any encryption almost instantly.

    • @silience4095
      @silience4095 4 роки тому +135

      @@talongreenlee7704 Which is why quantum cryptography is being developed.

    • @talongreenlee7704
      @talongreenlee7704 4 роки тому +11

      Xelphonential how does that work?

  • @chessanator3692
    @chessanator3692 8 років тому +7114

    You missed the chance to name the three groups "Defenders, Detectives, Destroyers" for the alliteration.

    • @Crick1952
      @Crick1952 8 років тому +413

      Alliteration is always awesome

    • @joshuabrown2125
      @joshuabrown2125 8 років тому +92

      +Ryan Gilbert assonance is vowel sounds, alliteration consonants

    • @enoughofyourkoicarp
      @enoughofyourkoicarp 7 років тому +89

      Tripple Ds are just too big. ;)

    • @DlcEnergy
      @DlcEnergy 6 років тому +20

      :DDD
      :DDB *_double butted_*

    • @of3natlas507
      @of3natlas507 6 років тому +20

      Crick1952 Alliterations are always awesome

  • @mika2666
    @mika2666 8 років тому +4162

    *reads the video is fictional*
    *halfway through thinks its not*
    *flips shit inside his head*
    *thinks again*
    *realises that it's fictional*

    • @brucebaker810
      @brucebaker810 8 років тому +83

      +Mikat Tech at Google pushes his chair back. Goes to play foosball, having averted yet another Customer Realization Cascade.

    • @theowletblog
      @theowletblog 7 років тому +38

      Mikat same here. Got half way through and went to download a backup of my blog 😁

    • @adamschlinker972
      @adamschlinker972 5 років тому +3

      Yup. Hahah.

    • @Chris_Cross
      @Chris_Cross 5 років тому +1

      So it didn't actually happen?

    • @lucifer2b666
      @lucifer2b666 4 роки тому +2

      @@Chris_Cross Is this real or not?

  • @janiscena3126
    @janiscena3126 8 років тому +6564

    This must be made into a movie.

    • @prookarus
      @prookarus 7 років тому +87

      Totally!

    • @Calvinatorzcraft
      @Calvinatorzcraft 7 років тому +19

      Peteris Rudzitis the new episode of South Park kinda covered this

    • @EcasmbNoobje
      @EcasmbNoobje 7 років тому +295

      nah not really. it really really really fits a "black mirror" episode though.

    • @otocan
      @otocan 7 років тому +3

      Agreed

    • @TheKhopesh
      @TheKhopesh 7 років тому +2

      Which one?

  • @TristanBomber
    @TristanBomber 9 років тому +1161

    For fucks sake, can nobody see the (Fictional) in the title?

    • @TomScottGo
      @TomScottGo  9 років тому +250

      TristanBomb That's because I only added the (Fictional) a couple of weeks ago, after people didn't notice the (Fictional) in the description!

    • @TristanBomber
      @TristanBomber 9 років тому +34

      ***** Ah, that makes sense.

    • @mav6771
      @mav6771 9 років тому +7

      ***** I was wondering why I didn't remember this xD

    • @creeperslayer505
      @creeperslayer505 8 років тому +36

      +Tom Scott Change the title back so we can continue trolling people

    • @CoacoBudder
      @CoacoBudder 7 років тому +5

      +Tom Scott We must prepare 17 sacrifices a day to feed the holy Google.

  • @Z3Cubing
    @Z3Cubing 9 років тому +6325

    I love how he added (fictional) to the title. xD

    • @sagiksp4979
      @sagiksp4979 8 років тому +61

      +legoboyz3! Didn't expect to see you here

    • @TheSuperDerp
      @TheSuperDerp 6 років тому +59

      That's what they want you to think.

    • @oakentravis
      @oakentravis 6 років тому +12

      Didn't think you'd be here.

    • @Chris_Cross
      @Chris_Cross 5 років тому +11

      I don't get it. Why?

    • @jeim376
      @jeim376 5 років тому +3

      I mean, if aliens...

  • @larynxaustrene3073
    @larynxaustrene3073 8 років тому +4725

    She got caught at the airport, Her flight got delayed the airport ran google systems.
    Just the best ending ever!

  • @iambensummers
    @iambensummers 8 років тому +5733

    Obviously it's fictional because Kim Kardashian's tweet has proper grammar.

    • @3ktone685
      @3ktone685 7 років тому +97

      This is just waaaaaaayyyyyy to good....

    • @BRACEY12345
      @BRACEY12345 6 років тому +46

      *Yeah, you need some proper grammar lessons too.

    • @AlexanderKG
      @AlexanderKG 6 років тому +22

      BRACEY12345 Punctuation is what he needs, not grammar.

    • @AguaFluorida
      @AguaFluorida 6 років тому +20

      Uku Sibul - The asterisk (*) denotes the response was a correction to a preceding comment. Is capitalisation a grammar issue, or something else? And discerning between to/too is arguably an issue of both grammar and spelling.

    • @Aric-ls7bf
      @Aric-ls7bf 6 років тому +7

      Uku Sibul He never said it was a grammar mistake, he simply corrected the sentence.

  • @RealationGames
    @RealationGames 10 років тому +2219

    So detailed story that I actually thought this was true and wondered how could I have missed those news...

    • @davidpox
      @davidpox 10 років тому +131

      Yup! I thought it was real and I was like "Huh? did I sleep through that day or something?" but then I read the description :p

    • @hellterminator
      @hellterminator 10 років тому +49

      It took me a while to figure out, too. I mean I did once completely miss the hockey world championship (as in I had no idea whatsoever that it was happening until 2 days after it had ended) but IT news of this magnitude? I think I would have noticed.

    • @DanAtuch_Archives
      @DanAtuch_Archives 2 роки тому +6

      Me too

    • @mike70377
      @mike70377 Рік тому +5

      @@hellterminator didn't even know there was a world hockey championship. Used to play in school though, hated playing on the turf, scraping knees

    • @Imolos
      @Imolos Рік тому +2

      Same

  • @Chowder77654
    @Chowder77654 8 років тому +1856

    It's like the purge, only online.

  • @FireSiku
    @FireSiku 8 років тому +1108

    UA-cam recommended this video on April's Fools. Pretty convenient.

  • @tommysandal6930
    @tommysandal6930 9 років тому +2072

    THIS. Is a prime example of why you should always read descriptions before watching a video. LOL

    • @francobuzzetti9424
      @francobuzzetti9424 9 років тому +32

      10:20 mins on,, and i read the comments and the description , i was worried.. and surpriced..

    • @metafis2490
      @metafis2490 9 років тому +30

      Yes, although it is a bit of click bait to not say its fiction in the title.

    • @GhostInTheShell29
      @GhostInTheShell29 9 років тому +88

      The first time I watched this, I didn't realize it was fictional. I already told several people about this..
      Great.. now I gotta tell them it was fictional. Sounded so plausible.

    • @saeidz.a1280
      @saeidz.a1280 9 років тому +37

      And I was wondering why I've never heard of this.

    •  9 років тому +5

      GhostInTheShell29
      Me too, only after searching the web for corroboration and not finding anything except the text of this video I noticed that it was fictional.

  • @lemapp
    @lemapp 8 років тому +786

    Back in the early Internet days, I worked at a company doing a presentation to a group of future major companies. An engineer at a remote site, was told to wipe a machine. He executed the command that raced through all of its directories including linkages to main servers. The presentation began to disappear. Unfortunately this also affected the hundreds of sites we hosts around the world. This type of 'simple' failures happens more often than you realize. It's not always reported.

  • @weesalikesmilktea4829
    @weesalikesmilktea4829 5 років тому +2344

    "OH GOB I ACCIDENTALLY FILMED VERTICALLY"
    "Oh gob oh gob oh gob OKAY STAY CALM *WHAT DO WE DO"*
    "uh, uh, LETS PUT THE SLIDES NEXT TO IT "
    "phew, nice save"
    "thanks dude"

  • @mickeleh
    @mickeleh 10 років тому +708

    A marvelous comical geeky horror fiction with just enough points of specificity and verisimilitude to keep you awake at night.

    • @The7wc
      @The7wc 10 років тому +70

      "Geeky horror fiction" is the best phrase I can think of to describe it, mostly because of how shockingly feasible it is.

    • @Sumanitu
      @Sumanitu 4 роки тому +8

      5 year old comment I know, but thanks anyway for a new word of the day for me! Surprising too, considering the connotation of the word, that it isn't in the V for Vendetta monologue.

  • @riverw4721
    @riverw4721 7 років тому +192

    Tom, if you wrote a novel about this, I would buy it immediately. You had me thrilled for the entire fifteen minutes.

  • @gesit7120
    @gesit7120 3 роки тому +119

    The worst thing is, I remembered the talk a few months later after seeing it and didn't remember this was a fictional story. I told many people about this, like it really happened, well everyone was shocked but believed it.

  • @tomburris8380
    @tomburris8380 8 років тому +880

    At about 6 minutes in, I got convinced to change my password to a random hash. So I open a new tab, and click on my gmail, then click the 'account' button. After the loading wheel spun 30 times, I got an error: "502. That’s an error. The server encountered a temporary error and could not complete your request." And I got very afraid this video wasn't hypothetical.

    • @icedragon769
      @icedragon769 7 років тому +111

      1: changing your password doesn't help this attack scenario
      2: random passwords are bad passwords unless they are also long and have caps, numbers, and special characters, in which case they are not rememberable. If you want to be secure, you need a password manager.

    • @feisty-trog-12345
      @feisty-trog-12345 7 років тому +2

      May I ask what this vulnerability is?

    • @feisty-trog-12345
      @feisty-trog-12345 7 років тому +4

      *****
      That problem is pretty trivial actually. The application itself can only check for updates on its own, not download them, so the worst that could happen on that side would be that a user thinks he needs an update when he doesn't. The website also uses HTTP, which means that a MitM attack could send the user a malicious file, which can be checked against by looking at the certificate. I don't really think it's a security issue when you're just a bit careful.
      Sidenote: I just love how Softpedia makes it sound like KeePass could update itself or that KeeFarce can just unlock any file. Really great journalism.

    • @feisty-trog-12345
      @feisty-trog-12345 7 років тому

      The specific article is actually not relevant, a simple google search shows more than enough results (including the note on the official website).
      You're right, even though and especially since you use a password manager, you still have to be wary of malware. Just goes to show that you should always be careful with your passwords and the security of your PC.
      I'm quite curious how much actual spyware there is for client side password managers. You'd think that the cross section between the people who constantly get their PC infected and the users of password managers is rather small, but there might also be a false sense of security there which leads to more carefree behaviour.
      I do think that your file is more secure, as long as the editor you're using doesn't write unencrypted backups or something terrible like that. However I personally prefer my password manager, since it's better suited to handle large amounts of accounts as well as giving me the ability to more easily find weaknesses in my pseudonymity. The tradeoff between convenience and security is worth it to me.

    • @josgeerink9434
      @josgeerink9434 7 років тому

      +Politiekman ben je Nederlands?

  • @SillyTheWhen
    @SillyTheWhen Рік тому +27

    Why is the way Tom says “as their phones quietly erase themselves” so iconic

  • @hecko-yes
    @hecko-yes 7 років тому +1136

    Imagine the blame tech support all around the world would unfairly get.
    "HELLO MY GOOGLE ISN'T WORKING PLEASE FIX IT"
    "Sir, we can't do anything abo"
    "I DON'T CARE I'M LOSING 50000 DOLLARS AN HOUR I NEED THIS FIXED NOW"

    • @Spoonable
      @Spoonable 4 роки тому

      Sobsz hold on I recognise your username.

    • @AlicjaDee
      @AlicjaDee 4 роки тому +36

      I used to work in tech support for a while and that's actually what some people told me

    • @paulweaver5624
      @paulweaver5624 4 роки тому +19

      "Maybe you should have been paying me 50000 dollars an hour then"

    • @pandaqwanda
      @pandaqwanda 9 місяців тому +1

      do i know you

    • @hecko-yes
      @hecko-yes 9 місяців тому +1

      @@pandaqwanda sona a

  • @egot1stical
    @egot1stical 7 років тому +996

    One account. All of Google. ☺

    • @plumeater1
      @plumeater1 7 років тому +17

      Only if you know the username?

    • @1973Washu
      @1973Washu 7 років тому +27

      A screen name can differ significantly from a username and that is at least something.

    • @fdagpigj
      @fdagpigj 7 років тому +3

      but the part after /user/ in your yt channel's URL (if you have a pre-googleplus account) is sufficient for logging in, is it not?

    • @tiagodarkpeasant
      @tiagodarkpeasant 6 років тому +5

      or the email, so if you ever sent a email to me, i can login in your account, them go to your blizzard account , reset the password and erase all your characters, it is even easier to erase your yout tube account

    • @spencermitchell5951
      @spencermitchell5951 6 років тому +4

      All of Google. One account.

  • @Borjigin.
    @Borjigin. 9 років тому +170

    DEAR LORD. I WATCHED 13 MINUTES OF THIS WITHOUT KNOWING THAT IT WAS FICTIONAL. It's only good fortune that made me look at the description before telling someone / everyone, or Googling (funny enough) to try to figure out why the hell I hadn't heard about this.
    You really should have included something at the beginning of the video. Really. Extremely irresponsible.

    • @NathanTAK
      @NathanTAK 9 років тому +42

      Or in the title

    •  9 років тому +9

      Nathan T This.

    • @Fabelaz
      @Fabelaz 9 років тому +25

      Why? Watching all this not knowing that's fictional was quite amazing for me :D

    • @legendariersgaming
      @legendariersgaming 9 років тому +3

      Dmitry Dronov Why? Because I ended up telling people about it and now they all think that Google screwed up and all this crazy stuff happened and they didn't hear about it. Only AFTER that did I realize it was fictional.

    • @Fabelaz
      @Fabelaz 9 років тому +1

      ***** lol

  • @Pantsmode
    @Pantsmode 5 років тому +400

    Moral of the story: do not put "return: true;" on top of any code.

    • @codinghub3759
      @codinghub3759 4 роки тому +17

      What if, I want to make a boolean function. And it will have to take some time to code it. Visual Studio will keep saying it, and so I just add it.
      Though sometimes, I do forget to remove it, and wonder why the false statement isn't working.

    • @TheGodlikeBlock
      @TheGodlikeBlock 4 роки тому +23

      Coding Hub i always have "functions that would return a bool but i wanna write them later" always default to false ^^

    • @ghosty918
      @ghosty918 3 роки тому +5

      What you should do is set a "Dev_Variable1" as true and a "Dev_Variable2" as False. Whenever you want to do that boolean stuff you throw a reference to the Dev variables.
      Before you commit, delete the Dev Variables and see what throws errors.

    • @vojtechstrnad1
      @vojtechstrnad1 3 роки тому +4

      Your IDE/linter should warn you of the dead code, and you should have automated tests that would detect that your code isn't running correctly.

    • @Aera223
      @Aera223 3 роки тому +2

      What if the return: true; was for "If the user was logged OUT"?

  • @deathsheir2035
    @deathsheir2035 9 років тому +135

    you sir, are very good at telling stories. If it wasn't for me liking to read descriptions, to see what sources you used, I would have never known this was fictional. I also wouldn't have done much of anything even if this was true.

    • @natevonhartleben2737
      @natevonhartleben2737 9 років тому +1

      ***** idk, they were careless before, there was a program from google offering 5k for any bugs found in software, and there was a command left in the code from the early days of UA-cam, which would allow for the removal of any video, or all videos at once, and that was found not too long ago, by a guy who luckily was nice enough to reveal it to google rather than the rest of the world. That, my friend, is carelessness lol.

    • @natevonhartleben2737
      @natevonhartleben2737 9 років тому

      ***** What is the gain by killing people? Terrorists see it as a benefit because it scares people, if people see it as for the greater good, whatever their motive, they do it. You sir, seem to be a believer that 9/11 was an inside job, because you can't see past monetary motive. It was performed because they thought they were doing something for the greater good. No one benefited from it... why can't you understand that? I'm taking cs50 classes, so I'm still new to coding, but I have an understanding, and coding has very little to do with your argument, that they have a "database" which again, is entirely speculation on at which point did they obtain this backup. I understand your argument, it is just wrong lol, put simply.

    • @deathsheir2035
      @deathsheir2035 9 років тому +1

      Nate Von Hartleben 1. If UA-cam didn't have a backup database, then every video that is taken down (let's say copyright claim) would be incapable of being restored (copyright claim challenged and succeeded). Yet they are capable of restoring videos, therefore they have a backup database. You saying "that they have a "database" which again, is entirely speculation on at which point did they obtain this backup," is completely ignorant.
      2. I agree that coding and having a backup doesn't go hand-in-hand. You don't need a backup, but you would be stupid not to have one.
      3. I do agree that monetary value isn't the sole reason. That still doesn't excuse you jumping straight to 9/11. You simply needed to mention other motivations upon which people can act upon.
      ***** 4. Other motivations people can act upon:
      A. To cause panic
      B. Just to prove that they can (whether to self or to friends)
      C. Try and get people off the computers and into the real world (though that would require the shutting down of more than just a single website)
      D. Other (that isn't listed and I haven't thought of)
      E. All of the above rolled into a nice little package.
      I find this conversation interesting, because it went somewhere I didn't mean for it to go. But now it's getting tiresome. Can you please stop the discussion?

    • @natevonhartleben2737
      @natevonhartleben2737 9 років тому +1

      You could have the access to the videos removed rather than removing the videos altogether, nullifying the need for a backup. And i think my statement was misunderstood, I meant that we didn't know at which point a backup system would have been implemented, although it probably would've been implemented when the value of the company was seen as significant, meaning before that point, there was a point of significant value the company had, and also that line of code allowing for it's deletion also existed. To explain my jump to 9/11, it was a simple reference to make, easily the most recognizable act of terrorism in at least American history. With this comment I say my last piece, and will respectfully close my argument.

    • @patentlypaul1832
      @patentlypaul1832 7 років тому +1

      Death's Heir /)

  • @BobfromSydney
    @BobfromSydney 5 років тому +64

    Tom Scott just channelled Tom Clancy for 13 minutes.

  • @henmasman
    @henmasman 7 років тому +496

    THIS WOULD MAKE AN GREAT MOVIE

    • @sprytt
      @sprytt 7 років тому +92

      An great movie. An great move?! AN GREAT MOVIE?!?

    • @siquod
      @siquod 7 років тому +12

      Yes, if you write in all caps, the indefinite article is obviously always AN, otherwise it would sound stupid when read/screamed out. Don't tell me you didn't know this basic rule⸮

    • @verdatum
      @verdatum 6 років тому +16

      How the hell would you shoot it?? A bunch of people, staring at there phones, going "Oh no! Oh NO! OH NO!!" for two hours??
      Good novel, sure. But I can think of hundreds of ways this would make a horrible movie.

    • @noahjames9457
      @noahjames9457 6 років тому

      Henry Lange This would make an even better book.

    • @zhgt8853
      @zhgt8853 5 років тому

      Henry Lange welp they makin it into a movie m8

  • @ctyoung16
    @ctyoung16 9 років тому +185

    I didn't read the description and I totally had a War of the Worlds moment just now...

  • @antler4979
    @antler4979 8 років тому +173

    Single Point of Failure: The (Real) Day UA-camrs Forgot To Check Video Descriptions

    • @the.abhiram.r
      @the.abhiram.r 6 років тому

      Antler ourmine are back (read the description)

  • @ElectricPandemic
    @ElectricPandemic 10 років тому +35

    I had a horrific moment watching this of thinking "Why don't I remember this happening!? Surely this is something that would stick in my mind!" before I realised it was fiction. You had me scared there, Tom!

  • @PhazonSouffle
    @PhazonSouffle 9 років тому +82

    I for one can't wait for the Internet apocalypse.

    • @Woodside235
      @Woodside235 9 років тому +6

      PhazonSouffle See you down an Arizona bay.

    • @Nevir202
      @Nevir202 8 років тому

      +Woodside I'm already here, it's unusually cold right now for some reason.

  • @jaykay4137
    @jaykay4137 8 років тому +263

    This is why I use [undisclosed email service] instead of Google as my primary email service. Nobody uses [undisclosed email service], so nobody would bother attacking [undisclosed email service].

  • @SallyLePage
    @SallyLePage 10 років тому +559

    Really good video - very thought-provoking, and your storytelling is excellent. In fact, all your videos over the past year or so have been particularly good. I look forward to seeing more :)

    • @osdever
      @osdever 3 роки тому +10

      Why do you dress like him

    • @TemphinFD
      @TemphinFD 3 роки тому +1

      @@osdever LMAO

    • @almostcertainlynotapotato6528
      @almostcertainlynotapotato6528 2 роки тому

      @@osdever Sally, Tom, Jay Foreman and all these people belong to the same circles. (why do you think they dress like him though?)

  • @TheDavidLiou
    @TheDavidLiou 9 років тому +521

    Time to write a new novel dude :P

  • @realscapegoat592
    @realscapegoat592 9 років тому +384

    I would be a Self-Burner, I would destroy my own account so nobody stole my information

    • @kito4525
      @kito4525 6 років тому +36

      Backup and delete

    • @supercool1312
      @supercool1312 5 років тому +83

      realscapegoat so a defender

    • @Multibe150
      @Multibe150 5 років тому +22

      @@kito4525 Google has already done the backup for you (Both in this scenario and in real life), so this is the smartest plan in a situation like this.

    • @sirrivet9557
      @sirrivet9557 4 роки тому +5

      Ahaha my accounts have nothing on them but shitposts. And I have zero personal information

    • @Leekodot15
      @Leekodot15 3 роки тому +3

      @@sirrivet9557 ALL your accounts? Keyword: ALL. If you leave a single account with personal info, then you're toast.

  • @bahazbz
    @bahazbz 4 роки тому +19

    I literally just now realized Tom Scott wears the same red T-shirt in almost every appearance.

  • @vsolyomi
    @vsolyomi 3 роки тому +61

    "It takes more than a single point of failure to change the world..." I'd say exactly three - a bat, a civet and a human wanting an exotic snack

  • @ActuallyIsScorpion
    @ActuallyIsScorpion 9 років тому +197

    i absolutely thought it was real until i finished the video. tom scott you're brilliant.

  • @youtubecommenter-on9kd
    @youtubecommenter-on9kd 6 років тому +39

    I notice a significant lack of DOS impacts - there would be an essentially astronomical increase in traffic, when EVERYONE with an internet connection would be logging on to EVERYTHING - reading about the news or watching videos on it; determining which of their accounts was linked to gmail and which (thankfully) weren't; and trying to fill the defender, detective or burner roles you presented --- and that's not even including those intentionally increasing (manually or via scripts that may already be waiting to take advantage of something like this happened) the impact of their intentionally disruptive DDOS schemes.

    • @OnlyKaerius
      @OnlyKaerius 2 роки тому +6

      This is the only scenario in which DDOS is actually a defender mechanism.

    • @dzaima
      @dzaima 2 роки тому +1

      Well, by now there has been at least one major outage for both Google and Facebook, and neither had *too* much of an effect on other sites. Sure, the scenario in the video would be worse, but not too much worse I'd guess.

  • @juxtalightborne3253
    @juxtalightborne3253 8 років тому +95

    Dear hackers...
    I have a challenge for you...

    • @thewizard1152
      @thewizard1152 8 років тому +42

      it's been 2 months could you tell us already mate

    • @aceman0000099
      @aceman0000099 8 років тому

      hahahahahahahaha

    • @diamondengineering7507
      @diamondengineering7507 8 років тому

      Knock knock

    • @CanyonF
      @CanyonF 8 років тому +2

      Sure, they can totally just hack Google. That's defiantly doable

    • @CanyonF
      @CanyonF 7 років тому +1

      ***** Fair enough

  • @woodfur00
    @woodfur00 7 років тому +174

    Well damn. And I'd be the one person locked out of secure interaction because I didn't put my trust in Facebook.

    • @debesys6306
      @debesys6306 7 років тому +1

      Well, I have pretty much abandoned my gmail. I only use it for youtube comments. So uh, I probably wouldn't be effected too much; despite not using facebook. Ye...

    • @woodfur00
      @woodfur00 7 років тому +1

      Lilly S You know Google owns UA-cam, right?

    • @debesys6306
      @debesys6306 7 років тому +2

      woodfur00 Yes, but the worst anyone can do on my youtube is do hate comments or delete it.

    • @woodfur00
      @woodfur00 7 років тому

      Lilly S But would you have a secure way to communicate with people?

    • @debesys6306
      @debesys6306 7 років тому +4

      woodfur00 Text. Or Calling them. I don't really talk to people though unless I'm with them in person. Sometimes I don't even go on youtube, so I might not even notice xD

  • @joblessalex
    @joblessalex 7 років тому +144

    Everything this guy does is interesting.

  • @Ruminations09
    @Ruminations09 9 років тому +241

    I recognize that this story is false, but one thing I'm really curious about is the "Trusted Five" part of the story. I googled "Google's trusted 5" as well as "Maria Christensen" and nothing related other than this very video showed up, but having only 5, or at least some small-ish number of coders as the only ones allowed to touch the core code sounds very believable, so I'm curious about how true it is.

    • @JH1010IsAwesome
      @JH1010IsAwesome 8 років тому +58

      Unless someone goes crazy or devotes a ridiculous amount of their life to ruining your company, it's a pretty safe way to run things.

    • @ceruchi2084
      @ceruchi2084 5 років тому +144

      In my organization we have the O5 Council, but if you figure out any of their actual identities you get given amnesia meds and fed to a giant superintelligent crocodile.

    • @williamwhitehouse8741
      @williamwhitehouse8741 4 роки тому +29

      _scp 762 has escaped containment_

    • @prolapses
      @prolapses 3 роки тому +11

      @@williamwhitehouse8741 how can scp 762 escape containment? its just an inanimate coffin

    • @vojtechstrnad1
      @vojtechstrnad1 3 роки тому +40

      @@ceruchi2084 Why would they give the person amnesia meds if they're going to feed them to a crocodile anyway? Is it so that you can't tell the crocodile?

  • @NotNite
    @NotNite 8 років тому +465

    If this really happened:
    1. I would download ALL my files and try and secure my account from anything I couldn't protect.
    2. Go into everyone's account.

    • @brucebaker810
      @brucebaker810 8 років тому +30

      +NiteDasher So defense against the offensive...but then be offensive. Nice.
      Actually, not.

    • @mrWade101
      @mrWade101 8 років тому +3

      +Teddy Frozevelt I don't use Gmail ;)

    • @HarmonicVector
      @HarmonicVector 8 років тому

      Hahahaha.

    • @mrWade101
      @mrWade101 8 років тому

      ***** Idc about my youtube, and my google and I don't have a Gmail account, why would I?

    • @mrWade101
      @mrWade101 8 років тому

      ***** sooooo?

  • @Aniruddha_godbole
    @Aniruddha_godbole 2 роки тому +8

    Whatsapp, Facebook, Instagram are globally down due to unknown reason 4 oct 2021 evening GMT

  • @nekolalia3389
    @nekolalia3389 5 років тому +22

    This is a GeekyConf presentation about a future.
    Not *the* future; just *a* future.

  • @markes4465
    @markes4465 2 роки тому +7

    I find it amusing that UA-cam decided to recommend this video to me, a few days after I accidentally leaked my personal most secure password into a public repository to the main branch

  • @madmanmortonyt4890
    @madmanmortonyt4890 3 роки тому +12

    Tom Scott's alt history scenarios are always a treat

  • @DubsRoss
    @DubsRoss 8 років тому +47

    "The backup you haven't done in a while"
    Shit.... Now I have to find my external hard drive.

  • @Valery0p5
    @Valery0p5 2 роки тому +6

    When you suddenly wipe your BGP routing tables and deplatform yourself, all of your workers, technicians and engineers:
    Press F

  • @TheRealFlenuan
    @TheRealFlenuan 9 років тому +48

    It took me five minutes to realize this was fictional.

    • @ABaumstumpf
      @ABaumstumpf 9 років тому +31

      The Real Flenuan Yeah, when he said Facebook was used for trusted communication :D

    • @jothain
      @jothain 9 років тому +5

      The Real Flenuan I looked pretty much through whole thing wondering pretty much all the time "how the heck have I missed this thing?". Even tried to search for Christiansens current state until figured out that something is not quite right :)

    • @cameronwebster6866
      @cameronwebster6866 9 років тому +3

      The Real Flenuan it took me watching it for a second time to figure it out.

    • @TheRealFlenuan
      @TheRealFlenuan 9 років тому

      Cameron Webster Haha, damn…

  • @Thoressau
    @Thoressau 2 роки тому +59

    "Facebook became the most trusted site" that one is becoming like a fine wine

  • @imslackingrightnow9765
    @imslackingrightnow9765 7 років тому +27

    Jeez Tom, you're so good at making fake things seem real that you should work for The Onion!

    • @noizepusher7594
      @noizepusher7594 Рік тому

      I’d love it if he made nerdy onion stories, it would be great

  • @ThatBiohazardGuy
    @ThatBiohazardGuy 4 роки тому +20

    “Facebook became the most trusted site” that ages like fine milk.

  • @johannstark8040
    @johannstark8040 3 роки тому +3

    The anxiety this video gives me is telling me to throw my computer into a lake and go live in the woods forever

  • @xkcdstickfigure
    @xkcdstickfigure 5 років тому +26

    "Thank you very much, I've been Tom Scott, Enjoy the rest of the Show"
    Who you going to be next time?

  • @kadmii
    @kadmii 2 роки тому +6

    This seems strangely relevant now

  • @ughhhhhhhhhhhjhh
    @ughhhhhhhhhhhjhh 2 роки тому +4

    this aged like a fine wine

  • @Ahead144
    @Ahead144 10 років тому +59

    Actually thought this was real, until i read the description. But made me realise how much i have centered around one account. Thanks for opening my eyes

  • @noizepusher7594
    @noizepusher7594 Рік тому +3

    One underrated thing about this story is that the password glitch was intentional. Knowing Tom I would’ve thought that he would’ve made the source of the glitch a simple accident by a reckless executive but it is much more interesting that it was an intentional attack. This top CEO who was one of the “trusted five” who has access to Google’s code decides to let everything burn. Her manifesto is provocative and hopeful and perfect for the tone of the story.

  • @mangoscrub
    @mangoscrub 3 роки тому +18

    Watching this just after the Google crash of 2020 makes this frighteningly more realistic

    • @antg1597
      @antg1597 3 роки тому

      Same, friends are worrying if we should change our password immediately.

    • @floatingblaze8405
      @floatingblaze8405 3 роки тому +3

      The single point of failure is the same: The Login API. Just instead of a massive breach of privacy, we got the most impactful DoS against google's whole infrastructure.

    • @albertjackinson
      @albertjackinson 3 роки тому +1

      There was a crash? Why didn't I know?

    • @antg1597
      @antg1597 3 роки тому

      @@albertjackinson just a few hours of outage on Dec 14, 2020. It wouldn't cause a glitch on your experience if not online that time

    • @pianopianist5709
      @pianopianist5709 2 роки тому

      The time when Google and youtube were taken down for a few hours for updates? I'm actually surprised at how I don't know about it.

  • @ReyosBlackwood
    @ReyosBlackwood 2 роки тому +92

    The single point of failure wasn't passwords and it wasn't google. It was facebook running everything through facebook and accidentally deleting their DNS entries.

    • @thatonecookie242
      @thatonecookie242 Рік тому +4

      is this referring to a real event?

    • @NiklasVWWV
      @NiklasVWWV Рік тому

      Also wondering

    • @ABT554
      @ABT554 10 місяців тому

      Yes it is. There was a huge "outage" of all Facebook systems some time ago because there was a Problem with their DNS configuration. I remember it very fondly because I hate FB with all my heart and rejoice whenever something bad happens to them ^^@@thatonecookie242

  • @delfikpro7375
    @delfikpro7375 2 роки тому +2

    Time for a yearly rewatch!

  • @DonovanDMC
    @DonovanDMC 4 роки тому +6

    "This too, shall pass" is a quote I've been using for years, love it.

  • @d9zirable
    @d9zirable 3 роки тому +7

    This was a warning message.

  • @meribold
    @meribold 3 роки тому +40

    Who's here after the Google outage?

    • @vojtechstrnad1
      @vojtechstrnad1 3 роки тому +2

      Ah, so THAT'S why I just got this video in my recommended.

  • @puellanivis
    @puellanivis 9 років тому +235

    There are several reasons why this could never happen. (Disclosure: I was a Google SRE, most of this will be vague because it would otherwise contain some proprietary Google information.)
    0) Google SREs. An entire group of engineers whose values intrinsically value reliability, stability and dependability.
    1) Google doesn't run 24h oncalls for critical infrastructure. They run 12h oncalls between two sites at least 8 hours apart.
    2) Google has an in-company "open source" design where any engineer can access nearly any source code. So, someone, somewhere, could roll this back.
    3) Google corp uses two-factor authentication. No one could ever login far enough to remote wipe any coworker's phone. (Not that it matters, the oncall is awake anyways. cf. #1)
    4) all Google engineers have a laptop setup and ready to get onto the corp network and work on code-securely-from anywhere in the internet.
    5) Google has continuous tests running and, someone, somewhere, at Google is running a test against this. When it triggers, pager storm.
    The likelihood against this, even in the face of malicious intent, lasting for longer than 5 minutes is so many 9's that you might as well consider it 1.

    • @magnum3.14
      @magnum3.14 9 років тому +41

      puellanivis at least point 3 was mentioned in the story. The fictional code change also ruled out two-factor authentification and other checks

    • @puellanivis
      @puellanivis 9 років тому +56

      danielcw Different code, different owners. One person cannot unilaterally remove both the password and two-factor authentication without at least one other person approving the checkin... which in this scenario would require two people with malicious intent.
      ... also, it wouldn't make sense to make this change when everyone is in the office, so we're talking about a person who is already in London/Dublin, and thus wouldn't need to take a plane flight to Europe. Which also means the two actors with malicious intent would have had to orchestrate their on-calls shifts to overlap.
      Honestly, with the inhouse knowledge, the best time to get this commit through would be end-of-day Friday... when SREs pretty much universally are going to lynch you for doing any sort of checkin...
      I realize that the idea is to contrive an example to say "what if..." but these sorts of "what if"s are the exact thing that SREs are tasked with preventing.

    • @nowandaround312
      @nowandaround312 8 років тому +10

      +puellanivis Because if you THINK your security is infallible and you can't come up with a way it could fail, then it's impossible for it to fail in some novel way no one considered or realized was possible, right?

    • @puellanivis
      @puellanivis 8 років тому +40

      +Privacy Lover It's not that I think their security is infallible. It's that the particularly "novel" way that Tom describes is not actually novel and couldn't happen at Google.
      So, to be clear, this is not some "novel way no one considered or realized"... sure there could be a different way that this specific scenario (Google stops checking password validity) could happen, but nothing he actually described is possible.

    • @GeoNeilUK
      @GeoNeilUK 8 років тому +29

      +puellanivis But he did say it was fictional and does he even _have_ inside knowledge at Google?
      Furthermore, he just used Google as an example of a company that wouldn't sue him. He could have picked Microsoft (which would have been entertaining him describing all those Windows 8 and Windows 10 PCs going doolally because the user's main account is linked to a Microsoft online account) Apple, Facebook, any system.
      It's why I find it hilarious that all these commenters are specifically talking about Google.

  • @HenirHerrscher
    @HenirHerrscher 3 роки тому +27

    Single Point of Failure: The Day (14/12/2020) Google Actually Shut Down For 30 Minutes

    • @tux1468
      @tux1468 3 роки тому

      Good thing I slept through it.

    • @pianopianist5709
      @pianopianist5709 2 роки тому

      How come I don't know anything about it? Can you please explain what happened?

  • @richardtimmsdesign
    @richardtimmsdesign 7 років тому +11

    This needs to be a movie.

  • @NoriMori1992
    @NoriMori1992 8 років тому +5

    Wow. That sent chills up my spine. Fantastic work, Tom!

  • @ladymilliejean4166
    @ladymilliejean4166 7 років тому +19

    The Purge: Internet Edition

  • @mistaecco
    @mistaecco 7 років тому +4

    This is so fascinating, I've watched it dozens of times but still will a dozen more times I bet.

  • @evilparkin
    @evilparkin 10 років тому

    Excellent stuff. This is the Tom Scott I'm subscribed for - interesting hypotheticals followed through in vivid detail. Great work! :)

  • @v-vanilla5259
    @v-vanilla5259 3 роки тому +9

    “The trusted five”
    *Scp vibes intensify*

    • @wenlock8069
      @wenlock8069 3 роки тому

      The trusted 13 for the O-5 but yes

  • @durchschnittlich
    @durchschnittlich 8 років тому +17

    I forgot so many times that it's only fictional

  • @remorsefulidiot4326
    @remorsefulidiot4326 3 роки тому +6

    I remember when we had a data breach with an active attacker inside our network , everyone was freaking out and I literally went to the firewall and unplugged it from WAN

  • @nedgeake4081
    @nedgeake4081 2 роки тому +10

    Remarkably prescient, this. Not exactly what seems to have happened but still fun to watch as Facebook burns

  • @eppssilon
    @eppssilon 3 роки тому +4

    This sounds like a really good plot for anything: a game, a movie, a book, anything

  • @umnikos
    @umnikos 7 років тому +80

    9:45 Just now I realised this is all FICTIONAL...
    damn it seemed so real to me...

  • @Roto255
    @Roto255 10 років тому +2

    This is one of the most interesting speeches I've seen in a while... I stumbled on this video after a tweet by a Mojang member (ironic, because I used my gmail to register for twitter) and it freaked me out, in a good way. I would love to see more vids like these!

  • @PrakritiSinha
    @PrakritiSinha 10 років тому +2

    This just became my favorite video on UA-cam. I can't thank you enough.

  • @HouseBricksDoor187
    @HouseBricksDoor187 4 роки тому +4

    "4chan entered chat"
    "You have lost connection to the server"

  • @123456789robbie
    @123456789robbie 10 років тому +7

    Tom needs to write a book or something, this is genius

  • @luigigaminglp
    @luigigaminglp 5 років тому

    The video is 5 years old, and i already watched it at least time, yet here it is back in my youtube feed.
    And honestly, this video deserves this.

  • @watchletter
    @watchletter Рік тому +1

    I often come back to his because the quote "the world doesnt get changed through a single point of failure" just stuck with me

  • @clray123
    @clray123 4 роки тому +5

    The code-to-production release process works like that in small screwy shops (Dropbox apparently being one of them), but in case of modifying widely used software, and especially security critical pieces of it, and especially where lotsa money is involved, there is a formal code review / signoff process that requires multiple persons to become involved before anything goes "live".

  • @Hebdomad7
    @Hebdomad7 4 роки тому +4

    I'd love to see this as a movie.

    • @gingerlyshrimp8480
      @gingerlyshrimp8480 4 роки тому

      There is a yt premium skit of collage humor kind of like this

  • @raulgalets
    @raulgalets Рік тому +2

    Oh so this is what is happening now, innit? but instead of the no-password-bug, we just need to ask chat gpt how to steal a session token!

  • @B1gBoyPants
    @B1gBoyPants 3 роки тому +1

    I loved every moment of this. So glad UA-cam recommended it to me today- years later.

  • @KayleLang
    @KayleLang 9 років тому +9

    I was going "how the hell did I miss this story." I started googling and nothing but this video came up. Then I read the comments, which pointed me to the description. This is why I always check multiple sources and not immediately repost everything.

  • @herohamp2
    @herohamp2 8 років тому +3

    We need more of these I loved it!

  • @heatherosullivanlewis5791
    @heatherosullivanlewis5791 6 років тому

    I've watched this so many times already, and I don't think I'll ever get sick of it

  • @sullivan3503
    @sullivan3503 8 років тому +40

    This is why we need client-side encryption.

    • @StickPlaysBR
      @StickPlaysBR 8 років тому +12

      +Sullivan Muse nope. Terrible idea. Maybe dedicated server just for encryption, but client-side encryption would be so damn easy to bypass.

    • @sullivan3503
      @sullivan3503 8 років тому +1

      Why? What are you talking about?

    • @StickPlaysBR
      @StickPlaysBR 8 років тому +1

      your afirmative

    • @sullivan3503
      @sullivan3503 8 років тому +1

      Redder-ish kugelblitz Client-side encryption is already extremely powerful. You just have to have enough entropy. You are acting like client-side encryption is easy to bypass when it is not.

    • @StickPlaysBR
      @StickPlaysBR 8 років тому +1

      So, you is saying that entropy is information, or any other thing? Just to make it clear that me agree on that

  • @eldrago19
    @eldrago19 5 років тому +3

    "And logs out, which is ironic because logging out doesn't mean anything anymore" Tom Scott is wonderful.

  • @NamEhcatsoum
    @NamEhcatsoum 4 роки тому +5

    The way Tom says this sounds like he's describing a XK class end of the world scenario.

  • @vedantraghuwanshi555
    @vedantraghuwanshi555 3 роки тому +8

    Coming back here, to confirm UA-cam's up again after today's outage in Google :P