The stories of AI support fails are getting funnier and stupider.
The newest Instagram “exploit” is the goofiest I've seen
121–130 of 528 posts
Re: The newest Instagram “exploit” is the goofiest I've seen
#122The weird thing is I know the Instagram security team, and they are top notch. I have a feeling this was vibe coded by someone outside of security and security wasn't looped in.
Re: The newest Instagram “exploit” is the goofiest I've seen
#123It's insane the AI has been provided the tooling to send emails to arbitrary addresses like that. Like, getting it to send a 2FA code at a user's request is one thing. But it should only be able to "hit a button" to send a 2FA email to the address attached to the account, all run with hand-written code. It shouldn't have access to the 2FA code itself, or the message subject, or body, or the recipient address, etc. Wh…
I do a lot of bug bounty research on Meta and Instagram, and some of the bugs I find look extremely simple like this but have some slightly complicated reason for why they occur. Maybe not this one, but I do have a guess as to what might have actually happened. Based on what I've seen so far, Meta AI Support Assistant (they call it "MAISA") had tool calls that a) start an email verification to any specific email, pho…
Re: The newest Instagram “exploit” is the goofiest I've seen
#124Earlier quoted context omitted.
This is not wrong but what’s really missing is cost: Meta did this so they can avoid paying people to do it. Lots of companies follow that decay spiral: your bank could shut phishers down cold by requiring wire transfers to be authorized in person but they don’t want to pay staff or risk you being upset by a transaction taking an extra hour so they don’t. Imagine an alternate universe where big tech companies worked…
> your bank could shut phishers down cold by requiring wire transfers to be authorized in person but they don’t want to pay staff or risk you being upset by a transaction taking an extra hour so they don’t. Isn't this essentially what just recently happened to the Pope? Then there were people here doing the rest of your comment for him saying how egregious it was for them to ask for an in person authorization. It sou…
Re: The newest Instagram “exploit” is the goofiest I've seen
#125Support requests have always been the weakest link in the security chain for big corps. I've had accounts of mine turned over with 2FA disabled by humans before. I guess we shouldn't be surprised that the LLMs are doing the same thing. The simple fact that 2FA can be removed by low level support staff drives me mad. It defeats the whole purpose of the process.
>> The simple fact that 2FA can be removed by low level support staff drives me mad. It defeats the whole purpose of the process. The fact it can be removed by anyone is the problem. If you lose access to your 2FA (and recovery codes) then you should lose access to your account. Having it removable by anyone (other than a logged in account holder) defeats the entire point.
If you lose your password or 2FA, you should lose your account, too bad so sad.
Re: The newest Instagram “exploit” is the goofiest I've seen
#126Earlier quoted context omitted.
recovery is always the weakest link in any authentication system
It's a hard problem. How do you prove you own an account if you lost all proof of ownership? Especially so if an account was never tied to your real name, in which case you could at least rely on government ids.
Re: The newest Instagram “exploit” is the goofiest I've seen
#127Security 101 when changing the email of an account for any reason: email the old account and let it know the change happened. The weird thing is I know the Instagram security team, and they are top notch. I have a feeling this was vibe coded by someone outside of security and security wasn't looped in.
Re: The newest Instagram “exploit” is the goofiest I've seen
#128I'm sitting here wondering why the Chief Master Sergeant of the U.S. Space Force has an Instagram account to begin with. I understand it's the office itself, but still don't see the reason to expand the attack surface of government offices. X makes sense, Instagram, I'm not so sure as much
I see no difference between X and Instagram in this regard whatsoever. Think NASA, for example; it's also a government agency, and they are doing great job posting photos in Instagram, do you think anything is wrong with it?
Something to think about when we consider what is "normal" today. Not much really is normal. We've been beaten to think it is.
Re: The newest Instagram “exploit” is the goofiest I've seen
#129I'm among the first 6000 users of Instagram and my first name username was stolen a few years ago. Support for verified accounts acknowledged the issue, but couldn't do anything about it. This turn was an AI exploit, in my case was an outsourcing support 'exploit', where someone paid for my username to be manually changed and given to another user. There will always be a way to get access to accounts if human account…
> with criminal consequences for employees that violate it lol, no. The day someone is criminally charged with "stealing" a username is the day that humanity has lost
While it isn't directly "stealing", the government has brought charges against people in the past for username-related crimes. There are several similar cases, but this is the first one that came to mind.
Re: The newest Instagram “exploit” is the goofiest I've seen
#130I created the account when instagram first came out, never used it, and totally forgot about it. I got stuck in a strange position where I had to login from a device I had previously logged in from, but because it's been over a decade, I no longer have any of the devices I might have used to create/access the account.
I still have access to both the email and phone number used for the account, but that was not good enough.
How hilariously incompetent. I filed a CCPA complaint.