> The first proper zero auth password reset I've seen in production. LinkedIn had one back in the day, before you got paid for discovering it I guess, never got a decent reply from them, but they eventually solved it. It went like this: they assumed that if you could read mail sent to some address, that address was yours and could be added to your account. So if I send you a LinkedIn invite to an email address, and y…
> someone invited a whole mailing list IIRC, LinkedIn would email everyone in your "address book" (or anything else it could find) back in the day.
The newest Instagram “exploit” is the goofiest I've seen
411–420 of 528 posts
Re: The newest Instagram “exploit” is the goofiest I've seen
#412Earlier quoted context omitted.
A flow can either fail safe or fail secure. Fail secure: if you lose your email, your account is forever locked. Fail safe: if you lose your email, your account is not forever locked. But, someone else might be able to get your account by pretending you lost your email. There are no other choices. When the electronic door controller loses power, either the door stays locked, or the door stays unlocked. In case of a f…
There are no other online choices. If my Bank login goes totally Kaput, though, I can take my ID down to the Branch to get it sorted. Same with my telecom provider. I try to only depend on services which have this property. I don't succeed.
Re: The newest Instagram “exploit” is the goofiest I've seen
#413Earlier quoted context omitted.
There are no other online choices. If my Bank login goes totally Kaput, though, I can take my ID down to the Branch to get it sorted. Same with my telecom provider. I try to only depend on services which have this property. I don't succeed.
Sounds great until you have an aging parent with a problem who can't get there. Get a power of attorney you say.. great but they won't accept unless parent comes to the branch. This comes back to haunt you in the future.
Re: The newest Instagram “exploit” is the goofiest I've seen
#414Support requests have always been the weakest link in the security chain for big corps. I've had accounts of mine turned over with 2FA disabled by humans before. I guess we shouldn't be surprised that the LLMs are doing the same thing. The simple fact that 2FA can be removed by low level support staff drives me mad. It defeats the whole purpose of the process.
Additionally, they fail to recover said account when it's taken over. My father's FaceBook account was hacked (likely through phishing) and it was impossible to contact anyone to get it back. The scum who stole his account also uploaded illegal context, so the account, along with ~10 years of personal memories, was deleted without any recourse. It was impossible to talk to a real human being at Meta. Nothing but an i…
Re: The newest Instagram “exploit” is the goofiest I've seen
#415Earlier quoted context omitted.
Someone being able to take over your account, read your DMs, and impersonate you is pretty serious. Should be treated as a data breach with serious penalties.
Sure, but it's not life-critical, lives don't depend on it. Other engineering disciplines have different rules, because for example a bridge or building with a fault might cause the loss of life of hunderds of people.
Re: The newest Instagram “exploit” is the goofiest I've seen
#416Earlier quoted context omitted.
This is actually what microsoft does for microsoft accounts If you recover a microsoft account / submit a ticket to recover it and provide correct information, the active email gets an email letting them know about the request You can deny it, or if you ignore it for 30 days the request goes through Seems to be the best system IMO
Someone has been trying to hack into my MSFT account for years. I constantly get the notifications. I can not see where they are trying from (unlike some other services that give you info about failed login attempts) nor add more security measures. I worry one day I will accidentally hit "Approve" or they will guess the 6 digit code they have tried thousands of times. The fun part is that you can't disable OneDrive.…
I would recommend you look at some other guides before you do this but the gist is My Account > Your Account > Manage Account Information. Then you can add a new email that you do not share as your primary login email, and disable login from the email you use to send emails.
Re: The newest Instagram “exploit” is the goofiest I've seen
#417Re: The newest Instagram “exploit” is the goofiest I've seen
#418Support requests have always been the weakest link in the security chain for big corps. I've had accounts of mine turned over with 2FA disabled by humans before. I guess we shouldn't be surprised that the LLMs are doing the same thing. The simple fact that 2FA can be removed by low level support staff drives me mad. It defeats the whole purpose of the process.
A flow can either fail safe or fail secure. Fail secure: if you lose your email, your account is forever locked. Fail safe: if you lose your email, your account is not forever locked. But, someone else might be able to get your account by pretending you lost your email. There are no other choices. When the electronic door controller loses power, either the door stays locked, or the door stays unlocked. In case of a f…
Re: The newest Instagram “exploit” is the goofiest I've seen
#419Re: The newest Instagram “exploit” is the goofiest I've seen
#420Earlier quoted context omitted.
I kinda laughed at the “but it checks your general location to decide if you’re super legit” safety gate. It had real, slap some duct tape on it and say, “Yeah that should hold” energy.
And honestly? That's brave.