Live data from Hacker News

The newest Instagram “exploit” is the goofiest I've seen

0xsid.com

141–150 of 528 posts

Re: The newest Instagram “exploit” is the goofiest I've seen

#141
post #43
post #21

It's insane the AI has been provided the tooling to send emails to arbitrary addresses like that. Like, getting it to send a 2FA code at a user's request is one thing. But it should only be able to "hit a button" to send a 2FA email to the address attached to the account, all run with hand-written code. It shouldn't have access to the 2FA code itself, or the message subject, or body, or the recipient address, etc. Wh…

This exploit has essentially nothing to do with AI and everything to do with a terribly designed account recovery flow. This exact same flow could have been (and may have been; I don’t know how much the chatbot here actually does) statically coded.

I agree with your point, mostly.

Until I remember seeing someone saying "MCP is dead, we just give agents command line access now". Then I start to think that looking at this in the context of ai is helpful.

Re: The newest Instagram “exploit” is the goofiest I've seen

#142

I get that account recovery for sites with hundreds of millions of users is a huge burden they're struggling to manage but I'm shocked they didn't restrict such loose verification to the >90% of lower value accounts that aren't worth stealing and keep the stricter verif on high-value accounts. The next obvious thing would be to let accounts the algorithm judges to be low-value still opt-in to strict verif. The vast m…

That solution is like putting glitter on poop.

The entire process is bad, doing the measures you described would have helped, but it's still negligent to allow AI to do password resets to arbitrary emails without auth, even if the account is of low value.

Re: The newest Instagram “exploit” is the goofiest I've seen

#144
post #76

Earlier quoted context omitted.

My impression is that AI didn't replace static code in this place; it replaced a person, who (hopefully) would have been suspicious about sending an account recovery code for e.g. "obamawhitehouse" to e.g. "bscurtu.alfamm.ro@gmail.com"

You're giving a lot of credit to the human alternative, especially considering that the attacker only needs to find one lazy human.

Come on, this attack vector would have been flagged by at least one person and you won’t then have multiple accounts hacked because of it. AI reacts fairly predictably to a single attack vector and don’t learn unless it gets flagged and then taught.

Re: The newest Instagram “exploit” is the goofiest I've seen

#147
post #9

Support requests have always been the weakest link in the security chain for big corps. I've had accounts of mine turned over with 2FA disabled by humans before. I guess we shouldn't be surprised that the LLMs are doing the same thing. The simple fact that 2FA can be removed by low level support staff drives me mad. It defeats the whole purpose of the process.

The fact that if your account has had the SAME EMAIL AND NUMBER FOR 14 YEARS OR MORE and support still thinks you got hacked is more embarrassing to me.

Re: The newest Instagram “exploit” is the goofiest I've seen

#148
post #9

Support requests have always been the weakest link in the security chain for big corps. I've had accounts of mine turned over with 2FA disabled by humans before. I guess we shouldn't be surprised that the LLMs are doing the same thing. The simple fact that 2FA can be removed by low level support staff drives me mad. It defeats the whole purpose of the process.

Yeah. I spent years working partly for the account abuse team at Google and that is why I always shake my head (silently, because the HN groupthink disagrees) at the endless parade of stories on this site about people who lost access to their accounts and can't contact support. Under no circumstances do you want any possibility that front-line support can hand your account over to anyone.

The lack of account support is a safety feature, not a flaw. If your accounts are valuable to you, act like an adult and write down the recovery codes on paper.

Re: The newest Instagram “exploit” is the goofiest I've seen

#150
What's funny about this to me is that I tried to sign up for insta once and could never get past their automated ID check that would fire after signup despite using a real ID. (So never did sign up. I suspect maybe they just really don't want you using web on mobile devices but ymmv.)
Post reply on HN