Live data from Hacker News

The newest Instagram “exploit” is the goofiest I've seen

0xsid.com

311–320 of 528 posts

Re: The newest Instagram “exploit” is the goofiest I've seen

#311
post #285

Earlier quoted context omitted.

There are no other online choices. If my Bank login goes totally Kaput, though, I can take my ID down to the Branch to get it sorted. Same with my telecom provider. I try to only depend on services which have this property. I don't succeed.

Sounds great until you have an aging parent with a problem who can't get there. Get a power of attorney you say.. great but they won't accept unless parent comes to the branch. This comes back to haunt you in the future.

That's a strange one. I had to use POA for my mother in law last summer and it was straight forward.

Re: The newest Instagram “exploit” is the goofiest I've seen

#312
post #19

This happened to my instagram yesterday night while I was asleep. I don't have a particularly high value username (it's probably worth somewhere in between $300-500), but still incredibly frustrating to deal with. True to the article, I had already enabled 2FA last night and it didn't matter. Thankfully, IG gave me the option of restoring my username when I logged back into my account today.

> Thankfully, IG gave me the option of restoring my username when I logged back into my account today. The hackers read all your formerly private messages, saw all your private photos, saw all the photos your friends wanted only their social circle to see. They could have social-engineered a thousand scamss. I'm glad it worked out for you. But honestly, your baseline is kind of off.

I don’t use this account as a personal account. It has 0 followers. It’s solely used for design inspiration.

Re: The newest Instagram “exploit” is the goofiest I've seen

#313

Does this explain the numerous password reset messages I’ve received over the past year?

Those are just bots sending reset attempts to obtain your email or phone hint. I receive hundreds per year. All you need to send a password reset link is the account's username, which is, of course, publicly accessible.

One of the things I like about Steam is that your email address, username, display name and id slug (/id/*) aren't required to be the same. All public identifiers should be changeable (regardless of whether or not making the change is a publicly available option).

Re: The newest Instagram “exploit” is the goofiest I've seen

#314

Earlier quoted context omitted.

Can you sue? I assume there is a financial motive with this crime.

Sue who? Meta? You "consented" in the Terms of Service to waive your right to a trial and only get forced arbitration by an arbitrator of Meta's choosing. Sue the anonymous person who stole your account and sold it to someone else, who is probably nowhere near your jurisdiction? Good luck.

You shouldn't be getting downvoted, you're right.

Re: The newest Instagram “exploit” is the goofiest I've seen

#315

Earlier quoted context omitted.

Meta has the capability to find out who authorized the change to this person's account. They log every change done in their administrator panel with a scary level of granularity, as far as I know, and they're able to take actions against employees who go behind Meta's back and take bribes (which, in joao's case, is what happened). This enforcement creates "waves" of account thefts described like so: Suppose Mallory f…

this needs to be done and spend $$$$ all for username change? META already knows these and does not act on it clearly?

Meta's aware and tries their best to act on it, but the real solution is simply not hiring outsourced support workers. It's really that simple. They have the money to hire people in-house for good wages, which would solve the root issue: the outsourced workers are desperate for money and gladly will take bribes.

Re: The newest Instagram “exploit” is the goofiest I've seen

#317

Earlier quoted context omitted.

> [login.gov] if its good enough for ~342M Americans I am very curious about the actual number of users of login.gov. I am a US citizen and my experience was … negative to the point of actively avoiding it.

> I am very curious about the actual number of users of login.gov. "Login.gov has surpassed 100 million registered user accounts. The platform facilitates over 300 million sign-ins annually and sees more than 10 million monthly active users, acting as a secure single sign-on solution across nearly 50 federal, state, and local agencies." https://www.login.gov/partners/faq/ (It is the primary identity provider for Soci…

I have multiple login.gov accounts. They don’t let you change your primary email, so if you’re using corporate account and switch jobs the normal thing is to create new accounts. I’m sure this is padding their numbers.

Re: The newest Instagram “exploit” is the goofiest I've seen

#318

Earlier quoted context omitted.

Sue who? Meta? You "consented" in the Terms of Service to waive your right to a trial and only get forced arbitration by an arbitrator of Meta's choosing. Sue the anonymous person who stole your account and sold it to someone else, who is probably nowhere near your jurisdiction? Good luck.

Clickwrap terms of service are worth the paper they're printed on. You may still be able to sue.

You are 100% able to sue, but, in the US, the result of that suit is 99.9% that you will be held to that arbitration clause anyways, with an arbitrator of Meta's choosing.

Arbitration clauses are very strong in the United States and have been getting stronger for years. Across both Democratic and Republican administrations, in state and federal courts, judges constantly reaffirm that these provisions are binding. Even literal shrinkwrap arbitration clauses on foods (Vital Proteins, Daily Harvest), etc. are upheld.

Exceptions are rare, such as unborn babies getting sick who never signed a clause such as with Daily Harvest, or when a case is public enough to draw backlash such as with the Disney+ trial arbitration clause being used to prevent a man whose wife died at a DisneyWorld restaurant from suing. Even parents suing on behalf of their pre-teenage children (e.g. against Snapchat in an Illinois court) find themselves blocked by arbitration.

There is no way merely having someones Instagram hacked and having "their username stolen" (not something possible, it's Meta's property) will make for such a rare scneario.

Per Instagram's ToS, if you sued instead of filing a Notice of Dispute (i.e. arbitration), you would be forfeiting the provision where Meta pays for your arbitration and other fees for claims less than $75,000. You would also be risking a decision from the arbitrator (AAA, who you should expect to be biased to favor Meta) that you would also need to pay Meta's legal fees.

If you try to sue, your lawyer will tell you all this.

Not expecting to win a dime from Meta, your lawyer would only represent you if you have pockets deep enough to fight a losing fight.

Re: The newest Instagram “exploit” is the goofiest I've seen

#320

Earlier quoted context omitted.

A flow can either fail safe or fail secure. Fail secure: if you lose your email, your account is forever locked. Fail safe: if you lose your email, your account is not forever locked. But, someone else might be able to get your account by pretending you lost your email. There are no other choices. When the electronic door controller loses power, either the door stays locked, or the door stays unlocked. In case of a f…

There are definitely more shades of grey. On my iPhone I can select a close contact to be able to overturn my protection but this contact needs to have security features turned on, too. So Apple staff cannot do it, only a non publicly known person that has 2FA and encryption themselves. Add time delays, notifications, identity checks and more to it and you can make this process reasonably secure while still ensuring…

[deleted]
Post reply on HN