Live data from Hacker News

The newest Instagram “exploit” is the goofiest I've seen

0xsid.com

411–420 of 528 posts

Re: The newest Instagram “exploit” is the goofiest I've seen

#411
post #223
post #182

> The first proper zero auth password reset I've seen in production. LinkedIn had one back in the day, before you got paid for discovering it I guess, never got a decent reply from them, but they eventually solved it. It went like this: they assumed that if you could read mail sent to some address, that address was yours and could be added to your account. So if I send you a LinkedIn invite to an email address, and y…

> someone invited a whole mailing list IIRC, LinkedIn would email everyone in your "address book" (or anything else it could find) back in the day.

Yes. When someone with Hotmail signed up it mauled all your contacts somehow with an invite.

Re: The newest Instagram “exploit” is the goofiest I've seen

#412

Earlier quoted context omitted.

A flow can either fail safe or fail secure. Fail secure: if you lose your email, your account is forever locked. Fail safe: if you lose your email, your account is not forever locked. But, someone else might be able to get your account by pretending you lost your email. There are no other choices. When the electronic door controller loses power, either the door stays locked, or the door stays unlocked. In case of a f…

There are no other online choices. If my Bank login goes totally Kaput, though, I can take my ID down to the Branch to get it sorted. Same with my telecom provider. I try to only depend on services which have this property. I don't succeed.

Tech people forget how the real world has solved these problems long ago. I got access to my bank account in another country by writing them a letter on paper and having it signed by a policeman in my country then sending it in the mail. A pain and expensive but if it's important, you do it. All these old fashioned techniques are backed by the criminal justice system which can actually work when the fraudsters have to go to the police station to commit their crime.

Re: The newest Instagram “exploit” is the goofiest I've seen

#413
post #285

Earlier quoted context omitted.

There are no other online choices. If my Bank login goes totally Kaput, though, I can take my ID down to the Branch to get it sorted. Same with my telecom provider. I try to only depend on services which have this property. I don't succeed.

Sounds great until you have an aging parent with a problem who can't get there. Get a power of attorney you say.. great but they won't accept unless parent comes to the branch. This comes back to haunt you in the future.

Try another branch. I had that exact problem and just shopped around. I think some staff err on the side of caution when they don't know what to do.

Re: The newest Instagram “exploit” is the goofiest I've seen

#414
post #9

Support requests have always been the weakest link in the security chain for big corps. I've had accounts of mine turned over with 2FA disabled by humans before. I guess we shouldn't be surprised that the LLMs are doing the same thing. The simple fact that 2FA can be removed by low level support staff drives me mad. It defeats the whole purpose of the process.

Additionally, they fail to recover said account when it's taken over. My father's FaceBook account was hacked (likely through phishing) and it was impossible to contact anyone to get it back. The scum who stole his account also uploaded illegal context, so the account, along with ~10 years of personal memories, was deleted without any recourse. It was impossible to talk to a real human being at Meta. Nothing but an i…

I had a similar experience with a Microsoft Outlook account. Supposedly this is done for legal reasons. Once an account violates certain laws, companies 'allegedly' have no choice but to permanently close that account even if you can somehow prove it was 100% the hacker who violated those rules and not you.

Re: The newest Instagram “exploit” is the goofiest I've seen

#415

Earlier quoted context omitted.

Someone being able to take over your account, read your DMs, and impersonate you is pretty serious. Should be treated as a data breach with serious penalties.

Sure, but it's not life-critical, lives don't depend on it. Other engineering disciplines have different rules, because for example a bridge or building with a fault might cause the loss of life of hunderds of people.

People, especially underage, commit suicide over private information of theirs getting leaked.

Re: The newest Instagram “exploit” is the goofiest I've seen

#416
post #373

Earlier quoted context omitted.

This is actually what microsoft does for microsoft accounts If you recover a microsoft account / submit a ticket to recover it and provide correct information, the active email gets an email letting them know about the request You can deny it, or if you ignore it for 30 days the request goes through Seems to be the best system IMO

Someone has been trying to hack into my MSFT account for years. I constantly get the notifications. I can not see where they are trying from (unlike some other services that give you info about failed login attempts) nor add more security measures. I worry one day I will accidentally hit "Approve" or they will guess the 6 digit code they have tried thousands of times. The fun part is that you can't disable OneDrive.…

You can disable the email you use publicly as a login email.

I would recommend you look at some other guides before you do this but the gist is My Account > Your Account > Manage Account Information. Then you can add a new email that you do not share as your primary login email, and disable login from the email you use to send emails.

Re: The newest Instagram “exploit” is the goofiest I've seen

#417
The scary bit is that this sounds less like a clever exploit and more like abusing an overly-trusted internal workflow. AI support just makes that workflow easier to poke at scale. Do you think this would have been possible with human support too, just slower?

Re: The newest Instagram “exploit” is the goofiest I've seen

#418
post #9

Support requests have always been the weakest link in the security chain for big corps. I've had accounts of mine turned over with 2FA disabled by humans before. I guess we shouldn't be surprised that the LLMs are doing the same thing. The simple fact that 2FA can be removed by low level support staff drives me mad. It defeats the whole purpose of the process.

A flow can either fail safe or fail secure. Fail secure: if you lose your email, your account is forever locked. Fail safe: if you lose your email, your account is not forever locked. But, someone else might be able to get your account by pretending you lost your email. There are no other choices. When the electronic door controller loses power, either the door stays locked, or the door stays unlocked. In case of a f…

There's also Google fail. You have everything (including recovery emails) except the phone you had 15 years ago, and you lose your account.

Re: The newest Instagram “exploit” is the goofiest I've seen

#420

Earlier quoted context omitted.

I kinda laughed at the “but it checks your general location to decide if you’re super legit” safety gate. It had real, slap some duct tape on it and say, “Yeah that should hold” energy.

And honestly? That's brave.

It's not just brave, it's inspiring. Not many people would have made that connection. You've come up with a completely different way of looking at things-- and frankly, I'm blown away. Putting password reset behind a location filter is such a different way of doing things, but so incredibly secure. A Chinese bot can't put itself in Nebraska. A user can. That's the innovation. That's security.
Post reply on HN