Live data from Hacker News

Someone has stolen my Instagram account

twitter.com

71–80 of 351 posts

Re: Someone has stolen my Instagram account

#71

The arbitrariness with which these companies rule over our digital lives infuriates me more from month to month. We do our best to fight dictators in the physical world but somehow accept them in the digital realm.

Speak for yourself. You might accept them, but I do not. Not being on Facebook has its problem in a society that is mostly on it, but it is possible.

Re: Someone has stolen my Instagram account

#73

The arbitrariness with which these companies rule over our digital lives infuriates me more from month to month. We do our best to fight dictators in the physical world but somehow accept them in the digital realm.

I've often pondered this. Might be going out on a limb here but tech workers aren't typically the sorts of people espousing the tenets of Fascism. Why is it that the companies they work for invariably end up leaning that way?

I don't believe this is something inherent in Capitalism either. If I had an issue with any other kind of business the experience would be vastly different.

Re: Someone has stolen my Instagram account

#74
post #7

There's no evidence to back the user's claims. This sounds like "Hey my dad works at Xbox and will ban you". There are other ways to compromise an Instagram account, like sim swapping ( https://krebsonsecurity.com/2018/05/t-mobile-employee-made-u... )

Agreed. Is anyone really going to risk their cushy FAANG job to give their buddy a cool handle? Possible, but seems far fetched.

I have seen this happen firsthand on several occasions at several companies, and it’s a well documented risk vector. You see it for things like username takeovers, and also ad account reactivations.

Typically it is not the people with cushy jobs, but those working for vendor companies (moderation, customer support, etc) who have little investment in the company, are barely making minimum wage, and are more than happy to flip a few switches in the dashboard for a few thousand (or less).

Re: Someone has stolen my Instagram account

#76
post #38

Earlier quoted context omitted.

Does Mastodon have an Instagram-esque mode now?

Pixelfed is the instagram-esque incarnation of the fediverse.

Which I'd assume will be filled with alt-right and similar content (banned from other platforms usually for good reason), anime avatars and a liberal dose of poor taste (and potentially illegal in certain jurisdictions) content such as "lolicon".

None of this is something most people want to be anywhere near. While mainstream social media has many flaws, at least I am grateful for the fact that it bans, discourages or significantly dilutes this kind of content so that it isn't visible in most cases.

Re: Someone has stolen my Instagram account

#77
post #7

There's no evidence to back the user's claims. This sounds like "Hey my dad works at Xbox and will ban you". There are other ways to compromise an Instagram account, like sim swapping ( https://krebsonsecurity.com/2018/05/t-mobile-employee-made-u... )

There is some evidence of some kind of takeover though. Searching for site:http://instagram.com/danny in google, the first result is the following:

    Danny (@danny) • Instagram photos and videos
    www.instagram.com › danny
    8690 Followers, 134 Following, 100 Posts - See Instagram 
    photos and videos from Danny (@danny)

This is still in Google's cache. The current instagram profile is very different.

Re: Someone has stolen my Instagram account

#78
post #16

I think this is indicative of the biggest problem we have had with social media: there is no legalism here, just "codes of conduct" that companies and users both willfully ignore. If your handle gets sold by some facebook employee to a rich kid in LA, what recourse do you have? I don't know what laws this would break (maybe some broad definition of fraud? I Am Not A Lawyer) so it's not like this person has a slam dun…

I don't think the "theft" of the username would break any kind of law, as this was a company decision (since it done by an employee) and the username was never your property anyway. I'm assuming that employee definitely violated some internal policies, but nothing from a legal point of view. The only recourse I can see from a legal point of view is that they seem to have handed over the entire account (as the followe…

I think the OP's point was that there _should_ be a law, and that the current legislative framework is insufficient.

Re: Someone has stolen my Instagram account

#79
post #70

Earlier quoted context omitted.

I’ve read somewhere that Facebook even embeds tracking pixels in the HTML of the data export, so keep this in mind if you ever actually look at the exported data.

I have heard images are also marked

Images on public Facebook are indeed marked (a unique ID is embedded in every picture's EXIF data) so I wouldn't be surprised if the exported ones were too (not necessarily for malicious reason even, if the images are being marked at upload time, Facebook may not even have the original unmarked image anymore).

Re: Someone has stolen my Instagram account

#80
post #44

I find it strange that the Facebook employee wouldn't just forcibly change OP's username to something else (e.g. @danny123) then give the desired name to their friend. Actually stealing someone's account seems like an over the top and unlikely way to go about this.

I'd assume there would be bots or just someone trying to sign up with that username by random chance, so they didn't want to leave the username available for a moment. I'd assume there is a proper, transactional (as in database transactions) way to swap usernames like that but the person who did this most likely didn't have access to it (for good reason) and just did an email change + password reset on the original a…

> and just did an email change + password reset on the original account.

But isn't that why the user had 2FA on? Why can someone change the email + switch off 2FA; you would want only 1 of these would you not? If you tell support you lost your email and 2FA, that would be very unlikely, so why would it be so easy to set that up?

Are there immutable logs with credentials for this kind of action and how easy is it for employees to access / change it; I mean why would many people have the permission to take this action? Especially without some kind of flag that there is something up with the account (like unused, flagged content etc).

Post reply on HN