
Channel with 15MIL subs: DELETED
NBTV: Your Money, Your Data, Your Life
00:00
How YouTube and Google Stolen Session Tokens
Someone on Linus' team downloaded what appeared to be a sponsorship offer. What they'd actually downloaded was malware, and in the background it had accessed all user data from both of their installed browsers. This basically gave the hacker an exact copy of this person's browser which included all the session tokens to every account he was logged into. The hacker could now trick the website into letting them into Linus' account because they had the token that said, this person is verified and allowed access.
Transcript
Play full episode