Live data from Hacker News

The newest Instagram “exploit” is the goofiest I've seen

0xsid.com

201–210 of 528 posts

Re: The newest Instagram “exploit” is the goofiest I've seen

#201
post #21

It's insane the AI has been provided the tooling to send emails to arbitrary addresses like that. Like, getting it to send a 2FA code at a user's request is one thing. But it should only be able to "hit a button" to send a 2FA email to the address attached to the account, all run with hand-written code. It shouldn't have access to the 2FA code itself, or the message subject, or body, or the recipient address, etc. Wh…

It's stuff like this that honestly makes it very hard for me to take anyone working at Meta seriously. How much communication had to happen to enable this feature? It really casts doubt across the organization at multiple levels, don't tell me a single engineer caused this.

Re: The newest Instagram “exploit” is the goofiest I've seen

#202
post #43
post #21

It's insane the AI has been provided the tooling to send emails to arbitrary addresses like that. Like, getting it to send a 2FA code at a user's request is one thing. But it should only be able to "hit a button" to send a 2FA email to the address attached to the account, all run with hand-written code. It shouldn't have access to the 2FA code itself, or the message subject, or body, or the recipient address, etc. Wh…

This exploit has essentially nothing to do with AI and everything to do with a terribly designed account recovery flow. This exact same flow could have been (and may have been; I don’t know how much the chatbot here actually does) statically coded.

Vibe coded?

Re: The newest Instagram “exploit” is the goofiest I've seen

#203
post #78

Earlier quoted context omitted.

I love those admin passwords which a tech will give you at some point because he doesn't want to do the work himself. If they even have passwords... Unfortunately Siemens woke up.

You mean admin or Administrator ? Horrific, people should be jailed for cyberattacks when they carelessly just give out this word. The experiences I meant were mostly - password reset requests (admittedly, we had a protocol even then to strictly require a "physical signature", normally meaning Fax or internal snail mail) - medical protocols: don't wanna go into too much detail here, but: 1) Windows requires a lot of…

I support radiologies...I have seen things, patients wouldn't believe. MRI in helium off the shoulder of the CS student. I watched DICOMs corrupt in the dark near the PACS gateway. All those moments will be lost in time...like unsaved reports in rain. Time to reboot

Re: The newest Instagram “exploit” is the goofiest I've seen

#204
post #43
post #21

It's insane the AI has been provided the tooling to send emails to arbitrary addresses like that. Like, getting it to send a 2FA code at a user's request is one thing. But it should only be able to "hit a button" to send a 2FA email to the address attached to the account, all run with hand-written code. It shouldn't have access to the 2FA code itself, or the message subject, or body, or the recipient address, etc. Wh…

This exploit has essentially nothing to do with AI and everything to do with a terribly designed account recovery flow. This exact same flow could have been (and may have been; I don’t know how much the chatbot here actually does) statically coded.

Nobody would handcraft a password reset flow that ignores the users' email and 2fa settings lol

Also I've used Meta's old password recovery system. It's not possible to do this in that version. The chatbot is what makes this possible.

Re: The newest Instagram “exploit” is the goofiest I've seen

#205
post #9

Support requests have always been the weakest link in the security chain for big corps. I've had accounts of mine turned over with 2FA disabled by humans before. I guess we shouldn't be surprised that the LLMs are doing the same thing. The simple fact that 2FA can be removed by low level support staff drives me mad. It defeats the whole purpose of the process.

A flow can either fail safe or fail secure.

Fail secure: if you lose your email, your account is forever locked.

Fail safe: if you lose your email, your account is not forever locked. But, someone else might be able to get your account by pretending you lost your email.

There are no other choices.

When the electronic door controller loses power, either the door stays locked, or the door stays unlocked. In case of a fire you want it unlocked so people can get out. But then a burglar can cut the power to get in. Doors that stay permanently locked in a power outage are only permitted in extreme cases where security is of the utmost importance. Obviously Instagram accounts aren't as important as doors in a fire.

Re: The newest Instagram “exploit” is the goofiest I've seen

#206

Earlier quoted context omitted.

I always thought the entire concept of even password resets was absurd. Email is a huge SPOF for basically everyone. If you lose your password or 2FA, you should lose your account, too bad so sad.

Completely unrealistic. Stuff happens. Email accounts get closed for no reason. People lose their phones, or have them stolen. Lots of reasons why someone might need an exceptional account recovery process. Not saying it should be easy or routine, it should not be. But it must be possible.

That's what recovery codes are for. Unfortunately it seems a lot of 2FA is now implemented without recovery codes.

Re: The newest Instagram “exploit” is the goofiest I've seen

#207
post #9

Support requests have always been the weakest link in the security chain for big corps. I've had accounts of mine turned over with 2FA disabled by humans before. I guess we shouldn't be surprised that the LLMs are doing the same thing. The simple fact that 2FA can be removed by low level support staff drives me mad. It defeats the whole purpose of the process.

>> The simple fact that 2FA can be removed by low level support staff drives me mad. It defeats the whole purpose of the process. The fact it can be removed by anyone is the problem. If you lose access to your 2FA (and recovery codes) then you should lose access to your account. Having it removable by anyone (other than a logged in account holder) defeats the entire point.

What if I don't want to lose my account if I lose my 2FA? Then I don't enable 2FA, presumably. But some security guy at your company is forcing me to enable 2FA or you'll just lock my account until I do.

Re: The newest Instagram “exploit” is the goofiest I've seen

#209

Earlier quoted context omitted.

Can you sue? I assume there is a financial motive with this crime.

Sue who? Meta? You "consented" in the Terms of Service to waive your right to a trial and only get forced arbitration by an arbitrator of Meta's choosing. Sue the anonymous person who stole your account and sold it to someone else, who is probably nowhere near your jurisdiction? Good luck.

Clickwrap terms of service are worth the paper they're printed on. You may still be able to sue.

Re: The newest Instagram “exploit” is the goofiest I've seen

#210
post #21

It's insane the AI has been provided the tooling to send emails to arbitrary addresses like that. Like, getting it to send a 2FA code at a user's request is one thing. But it should only be able to "hit a button" to send a 2FA email to the address attached to the account, all run with hand-written code. It shouldn't have access to the 2FA code itself, or the message subject, or body, or the recipient address, etc. Wh…

This reeks of vibe coding. "Make it so the AI agent can help with password resets" and then zero human vetting of the change.

And zero accountability too. No one will be found and detected.
Post reply on HN