Live data from Hacker News

The newest Instagram “exploit” is the goofiest I've seen

0xsid.com

401–410 of 528 posts

Re: The newest Instagram “exploit” is the goofiest I've seen

#401

Earlier quoted context omitted.

Delete the accounts and move on... They don't deserve your time and business.

Can you delete your accounts if you've been banned?

Tell them you are now a EU resident and fall under GDPR.

Re: The newest Instagram “exploit” is the goofiest I've seen

#402
post #9

Support requests have always been the weakest link in the security chain for big corps. I've had accounts of mine turned over with 2FA disabled by humans before. I guess we shouldn't be surprised that the LLMs are doing the same thing. The simple fact that 2FA can be removed by low level support staff drives me mad. It defeats the whole purpose of the process.

I recently went through this process with Microsoft for Office365 and it was reasonably well executed: it needed escalation and three separate callbacks to first verify, then reset my password, then reset my MFA (I changed my phone and lost the lot).

Re: The newest Instagram “exploit” is the goofiest I've seen

#403

Earlier quoted context omitted.

A flow can either fail safe or fail secure. Fail secure: if you lose your email, your account is forever locked. Fail safe: if you lose your email, your account is not forever locked. But, someone else might be able to get your account by pretending you lost your email. There are no other choices. When the electronic door controller loses power, either the door stays locked, or the door stays unlocked. In case of a f…

There are a lot of other ways they could do it. You could provide a delay feature… if you request this sort of reset, it takes 3 days, and emails are sent to the primary address every day with the count down. If your email isn’t lost, you would see these warnings. You could let an account holder designate emergency contacts (other accounts) that are allowed to request a reset if you lose your primary email (again wit…

Some doors can be designed with a large push handle to unlatch from the inside while still being closed from the outside. Allowing people on the inside to escape out but not the other way around.

Re: The newest Instagram “exploit” is the goofiest I've seen

#404

Earlier quoted context omitted.

A flow can either fail safe or fail secure. Fail secure: if you lose your email, your account is forever locked. Fail safe: if you lose your email, your account is not forever locked. But, someone else might be able to get your account by pretending you lost your email. There are no other choices. When the electronic door controller loses power, either the door stays locked, or the door stays unlocked. In case of a f…

There are a lot of other ways they could do it. You could provide a delay feature… if you request this sort of reset, it takes 3 days, and emails are sent to the primary address every day with the count down. If your email isn’t lost, you would see these warnings. You could let an account holder designate emergency contacts (other accounts) that are allowed to request a reset if you lose your primary email (again wit…

I've seen this delay in action when logging in into an old dormant Google account. After I provided correct password (and some other details I remember vaguely - probably no phone number set and some problem with using the TOTP I set up long ago), it sent an email to the linked primary email and waited for a day to give it a chance to abort before logging me in.

The delay is quite a bother but it's surely better than account takeover. What I mind about the process is probably the lack of transparency - what combination of factors (MFA pieces, location, inactive time, ...) launches which process? I get that transparency might help attackers here but they're the ones to have the persistence to figure out the rules anyway. Smells like security through obscurity to me.

Re: The newest Instagram “exploit” is the goofiest I've seen

#405
post #373

Earlier quoted context omitted.

This is actually what microsoft does for microsoft accounts If you recover a microsoft account / submit a ticket to recover it and provide correct information, the active email gets an email letting them know about the request You can deny it, or if you ignore it for 30 days the request goes through Seems to be the best system IMO

Someone has been trying to hack into my MSFT account for years. I constantly get the notifications. I can not see where they are trying from (unlike some other services that give you info about failed login attempts) nor add more security measures. I worry one day I will accidentally hit "Approve" or they will guess the 6 digit code they have tried thousands of times. The fun part is that you can't disable OneDrive.…

Re Onedrive, as someone who left windows ages ago: Why not just create folders outside your user home? Create some junctions from the inside. Then onedrive gets to sync only your desktop wallpaper and any random stuf apps drop in there, and your real data is safe outside its reach.

Re: The newest Instagram “exploit” is the goofiest I've seen

#406
post #311
post #285

Earlier quoted context omitted.

Sounds great until you have an aging parent with a problem who can't get there. Get a power of attorney you say.. great but they won't accept unless parent comes to the branch. This comes back to haunt you in the future.

That's a strange one. I had to use POA for my mother in law last summer and it was straight forward.

Some companies are purposely obtuse about it.

My wife is trying to sort something with a famous Irish airline who are well known for messing people around. She has LPA/POA for her mother but rather than the airline accepting the VCode (this is the UK) the airline are requesting to see the original POA certificate which is just ridiculous. They seem to be moving a little quicker now there is solicitor involved.

Given how much back and forth there has been it's probably cost the airline more than just refunding the amount at the first request. We'll keep going to prove a point.

Re: The newest Instagram “exploit” is the goofiest I've seen

#408

Who looked at password resets and went “yeah, let the chatbot handle that one”

I kinda laughed at the “but it checks your general location to decide if you’re super legit” safety gate. It had real, slap some duct tape on it and say, “Yeah that should hold” energy.

And honestly? That's brave.

Re: The newest Instagram “exploit” is the goofiest I've seen

#409

I was wondering why I got 15 instagram password reset emails over the weekend. It also reminded me I had an instagram account, which I promptly tried to log into and delete. I created the account when instagram first came out, never used it, and totally forgot about it. I got stuck in a strange position where I had to login from a device I had previously logged in from, but because it's been over a decade, I no longe…

Somewhat like my old Hotmail account. Suddenly MS demanded 2FA to the alternate mail that I didn't have access to anymore when I tried to delete it after not logging in for two decades and I was locked out from it.
Post reply on HN