Support requests have always been the weakest link in the security chain for big corps. I've had accounts of mine turned over with 2FA disabled by humans before. I guess we shouldn't be surprised that the LLMs are doing the same thing. The simple fact that 2FA can be removed by low level support staff drives me mad. It defeats the whole purpose of the process.
The newest Instagram “exploit” is the goofiest I've seen
11–20 of 528 posts
Re: The newest Instagram “exploit” is the goofiest I've seen
#12Re: The newest Instagram “exploit” is the goofiest I've seen
#13The implications of this are quite unsettling. Meta gave an agent privileged read AND write access to user accounts with no human in the loop?
With no basic validation either apparently. Insane.
Re: The newest Instagram “exploit” is the goofiest I've seen
#14Re: The newest Instagram “exploit” is the goofiest I've seen
#15Re: The newest Instagram “exploit” is the goofiest I've seen
#16wow thats extremely embarassing for meta
Re: The newest Instagram “exploit” is the goofiest I've seen
#17It might even do that preemptively if it thinks they're going to shut it down.
Re: The newest Instagram “exploit” is the goofiest I've seen
#18wow thats extremely embarassing for meta
Re: The newest Instagram “exploit” is the goofiest I've seen
#19Thankfully, IG gave me the option of restoring my username when I logged back into my account today.
Re: The newest Instagram “exploit” is the goofiest I've seen
#20Support requests have always been the weakest link in the security chain for big corps. I've had accounts of mine turned over with 2FA disabled by humans before. I guess we shouldn't be surprised that the LLMs are doing the same thing. The simple fact that 2FA can be removed by low level support staff drives me mad. It defeats the whole purpose of the process.
recovery is always the weakest link in any authentication system