Live data from Hacker News

The newest Instagram “exploit” is the goofiest I've seen

0xsid.com

111–120 of 528 posts

Re: The newest Instagram “exploit” is the goofiest I've seen

#111
post #91

Earlier quoted context omitted.

This is not true. Well, it kinda is, but nobody will be stupid enough to hand-code an account recovery where you get to type any email address. The reason it worked there is that the designers of the system didn't anticipate that the AI will agree to accept any email (maybe they even put guardrails against it in the system prompt, we don't know). It's more like social engineering than bad-security-code, except that l…

Maybe? I don’t know what logic was actually in the LLM vs it just using a bad tool. Unless I missed it, the article had no actual context on that either. This looks like a terrible design rather than an AI problem to me, though.

What would need to happen for it to be considered an AI problem to you?

Re: The newest Instagram “exploit” is the goofiest I've seen

#112
post #36

Earlier quoted context omitted.

This is not wrong but what’s really missing is cost: Meta did this so they can avoid paying people to do it. Lots of companies follow that decay spiral: your bank could shut phishers down cold by requiring wire transfers to be authorized in person but they don’t want to pay staff or risk you being upset by a transaction taking an extra hour so they don’t. Imagine an alternate universe where big tech companies worked…

for a while facebook had the ability to recover your account by having them ask several of your friends if the recovery was legitimate but it was turned off. my guess is that not enough people added trusted contacts to bother running it. https://www.theverge.com/2013/5/2/4292744/facebook-trusted-c...

I actually quite like this solution. Beats asking users to add a "recovery selfie" (something Meta actually does now) - I'd rather choose 3 of my friends and have them approve some notification in-app. Seems like better UX and preserves privacy a slight bit more, but we all know Meta's not in the privacy business.

Re: The newest Instagram “exploit” is the goofiest I've seen

#115
post #90

> All the Telegram groups have quieted down as Meta seems to have patched it already, but it appears this particular method was active for weeks, if not months. Is that for real? I find it hard to believe that an exploit THIS simple and easy to abuse managed to stay live for weeks or months.

I'm inclined to believe it. As someone who studies this side of the Internet quite often and has seen equally trivial exploits stay active for weeks or months without being patched, I have no trouble believing this claim. I'm sure there are messages in Telegram channels from weeks or months ago that corroborate this.

Re: The newest Instagram “exploit” is the goofiest I've seen

#118

Does this explain the numerous password reset messages I’ve received over the past year?

Those are just bots sending reset attempts to obtain your email or phone hint. I receive hundreds per year. All you need to send a password reset link is the account's username, which is, of course, publicly accessible.

Re: The newest Instagram “exploit” is the goofiest I've seen

#119

How is this "embarrassing" instead of subject to legal liability? We really need similar rules to other engineering disciplines. If your building falls with people inside, you killed them.

Nobody dies if instagram collapses. Might even cause more people to live.

Don't underestimate a motivated stalker or abuser.

Re: The newest Instagram “exploit” is the goofiest I've seen

#120
post #43

Earlier quoted context omitted.

This exploit has essentially nothing to do with AI and everything to do with a terribly designed account recovery flow. This exact same flow could have been (and may have been; I don’t know how much the chatbot here actually does) statically coded.

This is not true. Well, it kinda is, but nobody will be stupid enough to hand-code an account recovery where you get to type any email address. The reason it worked there is that the designers of the system didn't anticipate that the AI will agree to accept any email (maybe they even put guardrails against it in the system prompt, we don't know). It's more like social engineering than bad-security-code, except that l…

[deleted]
Post reply on HN