I'm among the first 6000 users of Instagram and my first name username was stolen a few years ago. Support for verified accounts acknowledged the issue, but couldn't do anything about it. This turn was an AI exploit, in my case was an outsourcing support 'exploit', where someone paid for my username to be manually changed and given to another user. There will always be a way to get access to accounts if human account…
The newest Instagram “exploit” is the goofiest I've seen
151–160 of 528 posts
Re: The newest Instagram “exploit” is the goofiest I've seen
#152Security 101 when changing the email of an account for any reason: email the old account and let it know the change happened. The weird thing is I know the Instagram security team, and they are top notch. I have a feeling this was vibe coded by someone outside of security and security wasn't looped in.
Re: The newest Instagram “exploit” is the goofiest I've seen
#153Like - account is locked, you must use 2FA backup codes.
Else go to western union / 7-eleven / super-market, show ID proof, pay $10 for recovery service.
Wait 2 days (of someone not clicking on this-was-not-me)
If account is already hacked - pay $100 for expert support
Re: The newest Instagram “exploit” is the goofiest I've seen
#154Earlier quoted context omitted.
> But it should only be able to "hit a button" to send a 2FA email to the address attached to the account, all run with hand-written code. Genuine question...why would that need to be hand-written? It makes absolute sense as a general statement and is kinda crazy that this wasn't a built-in limitation, but I'm not quite sure why the code for that bit must be hand-written (provided the code functionally does what you…
I think he likely means "code that is hand-reviewed" and not directly controlled by the agent. He's probably meaning to differentiate it against the in-process agent writing the code. It doesn't matter too much if that fixed code was written by an LLM under guidance and review of the SWE, outside the agent.
Re: The newest Instagram “exploit” is the goofiest I've seen
#155Security 101 when changing the email of an account for any reason: email the old account and let it know the change happened. The weird thing is I know the Instagram security team, and they are top notch. I have a feeling this was vibe coded by someone outside of security and security wasn't looped in.
The fact that this can happen at all without the security team's knowledge is telling.
Re: The newest Instagram “exploit” is the goofiest I've seen
#156Earlier quoted context omitted.
This exploit has essentially nothing to do with AI and everything to do with a terribly designed account recovery flow. This exact same flow could have been (and may have been; I don’t know how much the chatbot here actually does) statically coded.
The AI part does seem relevant because it enabled incredibly low-effort “social” engineering. For what it’s worth I don’t think you can call this social engineering since there was no human on the other end, even though it appears similar. The question is, if there were actual human support agents, would they have built additional safeguards to prevent social engineering in this manner?
Re: The newest Instagram “exploit” is the goofiest I've seen
#157It's insane the AI has been provided the tooling to send emails to arbitrary addresses like that. Like, getting it to send a 2FA code at a user's request is one thing. But it should only be able to "hit a button" to send a 2FA email to the address attached to the account, all run with hand-written code. It shouldn't have access to the 2FA code itself, or the message subject, or body, or the recipient address, etc. Wh…
This exploit has essentially nothing to do with AI and everything to do with a terribly designed account recovery flow. This exact same flow could have been (and may have been; I don’t know how much the chatbot here actually does) statically coded.
Re: The newest Instagram “exploit” is the goofiest I've seen
#158Re: The newest Instagram “exploit” is the goofiest I've seen
#159Earlier quoted context omitted.
This exploit has essentially nothing to do with AI and everything to do with a terribly designed account recovery flow. This exact same flow could have been (and may have been; I don’t know how much the chatbot here actually does) statically coded.
The AI part does seem relevant because it enabled incredibly low-effort “social” engineering. For what it’s worth I don’t think you can call this social engineering since there was no human on the other end, even though it appears similar. The question is, if there were actual human support agents, would they have built additional safeguards to prevent social engineering in this manner?
Re: The newest Instagram “exploit” is the goofiest I've seen
#160This happened to my instagram yesterday night while I was asleep. I don't have a particularly high value username (it's probably worth somewhere in between $300-500), but still incredibly frustrating to deal with. True to the article, I had already enabled 2FA last night and it didn't matter. Thankfully, IG gave me the option of restoring my username when I logged back into my account today.
The hackers read all your formerly private messages, saw all your private photos, saw all the photos your friends wanted only their social circle to see. They could have social-engineered a thousand scamss.
I'm glad it worked out for you. But honestly, your baseline is kind of off.