Live data from Hacker News

The newest Instagram “exploit” is the goofiest I've seen

0xsid.com

391–400 of 528 posts

Re: The newest Instagram “exploit” is the goofiest I've seen

#392
post #9

Support requests have always been the weakest link in the security chain for big corps. I've had accounts of mine turned over with 2FA disabled by humans before. I guess we shouldn't be surprised that the LLMs are doing the same thing. The simple fact that 2FA can be removed by low level support staff drives me mad. It defeats the whole purpose of the process.

[dead]

Re: The newest Instagram “exploit” is the goofiest I've seen

#393
post #358

Earlier quoted context omitted.

Malware on your phone can reroute your calls to the attacker. So you think you're calling the official number at the correct institution, but you're actually talking to the attacker.

What kind of malware are we talking about here? On a non-rooted phone?

It was in the news a few times in my country. Not sure about the exact technical details, but it might have been a malicious Android app that advertises itself as an improvement over the stock Phone app, encouraging users to set it as the default dialer. You don't need root for that.

Re: The newest Instagram “exploit” is the goofiest I've seen

#395

Earlier quoted context omitted.

You mean admin or Administrator ? Horrific, people should be jailed for cyberattacks when they carelessly just give out this word. The experiences I meant were mostly - password reset requests (admittedly, we had a protocol even then to strictly require a "physical signature", normally meaning Fax or internal snail mail) - medical protocols: don't wanna go into too much detail here, but: 1) Windows requires a lot of…

I support radiologies...I have seen things, patients wouldn't believe. MRI in helium off the shoulder of the CS student. I watched DICOMs corrupt in the dark near the PACS gateway. All those moments will be lost in time...like unsaved reports in rain. Time to reboot

We seem to work in very similar fields. I tend to work on the back-end line. To put it lightly: it is all a big shitshow. Vendor lock-in, non-standard communication, network admins who have no idea what they are doing, radiology imaging clinics with no IT staff at all (even on-call external people) or places that had their network set up 15 years ago by a guy who is now long dead or otherwise MIA. And then, inevitably, you have to guide the innocent girl sitting at the front desk to somewhere in the local backrooms just to reset a server remotely.

Re: The newest Instagram “exploit” is the goofiest I've seen

#397
This is a somewhat unpopular opinion but I find it depressing that this is what the so-called elite FAANG engineers are able to come up with.

Or maybe even more sad, this is what a FAANG product manager is able to pass through layers of "are you mad"

Re: The newest Instagram “exploit” is the goofiest I've seen

#398

Who looked at password resets and went “yeah, let the chatbot handle that one”

I kinda laughed at the “but it checks your general location to decide if you’re super legit” safety gate.

It had real, slap some duct tape on it and say, “Yeah that should hold” energy.

Re: The newest Instagram “exploit” is the goofiest I've seen

#399
post #373

Earlier quoted context omitted.

This is actually what microsoft does for microsoft accounts If you recover a microsoft account / submit a ticket to recover it and provide correct information, the active email gets an email letting them know about the request You can deny it, or if you ignore it for 30 days the request goes through Seems to be the best system IMO

Someone has been trying to hack into my MSFT account for years. I constantly get the notifications. I can not see where they are trying from (unlike some other services that give you info about failed login attempts) nor add more security measures. I worry one day I will accidentally hit "Approve" or they will guess the 6 digit code they have tried thousands of times. The fun part is that you can't disable OneDrive.…

The correct thing to do in this scenario is to create a new random login alias on your Microsoft account, make it the primary login alias, and disable login for the all other e-mails tied to the account.
Post reply on HN