Earlier quoted context omitted.
This is not true. Well, it kinda is, but nobody will be stupid enough to hand-code an account recovery where you get to type any email address. The reason it worked there is that the designers of the system didn't anticipate that the AI will agree to accept any email (maybe they even put guardrails against it in the system prompt, we don't know). It's more like social engineering than bad-security-code, except that l…
Maybe? I don’t know what logic was actually in the LLM vs it just using a bad tool. Unless I missed it, the article had no actual context on that either. This looks like a terrible design rather than an AI problem to me, though.
The newest Instagram “exploit” is the goofiest I've seen
111–120 of 528 posts
Re: The newest Instagram “exploit” is the goofiest I've seen
#112Earlier quoted context omitted.
This is not wrong but what’s really missing is cost: Meta did this so they can avoid paying people to do it. Lots of companies follow that decay spiral: your bank could shut phishers down cold by requiring wire transfers to be authorized in person but they don’t want to pay staff or risk you being upset by a transaction taking an extra hour so they don’t. Imagine an alternate universe where big tech companies worked…
for a while facebook had the ability to recover your account by having them ask several of your friends if the recovery was legitimate but it was turned off. my guess is that not enough people added trusted contacts to bother running it. https://www.theverge.com/2013/5/2/4292744/facebook-trusted-c...
Re: The newest Instagram “exploit” is the goofiest I've seen
#113wow thats extremely embarassing for meta
Re: The newest Instagram “exploit” is the goofiest I've seen
#114Re: The newest Instagram “exploit” is the goofiest I've seen
#115> All the Telegram groups have quieted down as Meta seems to have patched it already, but it appears this particular method was active for weeks, if not months. Is that for real? I find it hard to believe that an exploit THIS simple and easy to abuse managed to stay live for weeks or months.
Re: The newest Instagram “exploit” is the goofiest I've seen
#116Re: The newest Instagram “exploit” is the goofiest I've seen
#117META should pay a 20B fine for this one.
Re: The newest Instagram “exploit” is the goofiest I've seen
#118Does this explain the numerous password reset messages I’ve received over the past year?
Re: The newest Instagram “exploit” is the goofiest I've seen
#119How is this "embarrassing" instead of subject to legal liability? We really need similar rules to other engineering disciplines. If your building falls with people inside, you killed them.
Nobody dies if instagram collapses. Might even cause more people to live.
Re: The newest Instagram “exploit” is the goofiest I've seen
#120Earlier quoted context omitted.
This exploit has essentially nothing to do with AI and everything to do with a terribly designed account recovery flow. This exact same flow could have been (and may have been; I don’t know how much the chatbot here actually does) statically coded.
This is not true. Well, it kinda is, but nobody will be stupid enough to hand-code an account recovery where you get to type any email address. The reason it worked there is that the designers of the system didn't anticipate that the AI will agree to accept any email (maybe they even put guardrails against it in the system prompt, we don't know). It's more like social engineering than bad-security-code, except that l…