Live data from Hacker News

The newest Instagram “exploit” is the goofiest I've seen

0xsid.com

421–430 of 528 posts

Re: The newest Instagram “exploit” is the goofiest I've seen

#421
post #9

Support requests have always been the weakest link in the security chain for big corps. I've had accounts of mine turned over with 2FA disabled by humans before. I guess we shouldn't be surprised that the LLMs are doing the same thing. The simple fact that 2FA can be removed by low level support staff drives me mad. It defeats the whole purpose of the process.

A flow can either fail safe or fail secure. Fail secure: if you lose your email, your account is forever locked. Fail safe: if you lose your email, your account is not forever locked. But, someone else might be able to get your account by pretending you lost your email. There are no other choices. When the electronic door controller loses power, either the door stays locked, or the door stays unlocked. In case of a f…

There is a third option. Most banks here in Sweden solve this by forcing you to show up in person (with a ID card) if you loose your password.

I get that this also is technically a 2FA bypass but the cost is extreme and its really hard to impersonate someone in real life.

Re: The newest Instagram “exploit” is the goofiest I've seen

#422
post #421

Earlier quoted context omitted.

A flow can either fail safe or fail secure. Fail secure: if you lose your email, your account is forever locked. Fail safe: if you lose your email, your account is not forever locked. But, someone else might be able to get your account by pretending you lost your email. There are no other choices. When the electronic door controller loses power, either the door stays locked, or the door stays unlocked. In case of a f…

There is a third option. Most banks here in Sweden solve this by forcing you to show up in person (with a ID card) if you loose your password. I get that this also is technically a 2FA bypass but the cost is extreme and its really hard to impersonate someone in real life.

How would that even work for internet companies without physical stores? Go to Menlo Park, CA to recover your account?

Re: The newest Instagram “exploit” is the goofiest I've seen

#423

Earlier quoted context omitted.

And honestly? That's brave.

It's not just brave, it's inspiring. Not many people would have made that connection. You've come up with a completely different way of looking at things-- and frankly, I'm blown away. Putting password reset behind a location filter is such a different way of doing things, but so incredibly secure. A Chinese bot can't put itself in Nebraska. A user can. That's the innovation. That's security.

[dead]

Re: The newest Instagram “exploit” is the goofiest I've seen

#425

Earlier quoted context omitted.

And honestly? That's brave.

It's not just brave, it's inspiring. Not many people would have made that connection. You've come up with a completely different way of looking at things-- and frankly, I'm blown away. Putting password reset behind a location filter is such a different way of doing things, but so incredibly secure. A Chinese bot can't put itself in Nebraska. A user can. That's the innovation. That's security.

Deeply underrated comedy post.

Re: The newest Instagram “exploit” is the goofiest I've seen

#426
post #424

Passkeys are not going to fix this. The only thing that will fix this is some kind of notarization backed identity that people can go to as a recourse. The EU Should force them to do this.

This is an inherently human problem.

Those are exceedingly difficult to solve via technology.

Re: The newest Instagram “exploit” is the goofiest I've seen

#427

Who looked at password resets and went “yeah, let the chatbot handle that one”

I kinda laughed at the “but it checks your general location to decide if you’re super legit” safety gate. It had real, slap some duct tape on it and say, “Yeah that should hold” energy.

"Remaining Devs! You have AI so you need to be 10x faster and AI the AI with AI energy"

Re: The newest Instagram “exploit” is the goofiest I've seen

#428
post #43
post #21

It's insane the AI has been provided the tooling to send emails to arbitrary addresses like that. Like, getting it to send a 2FA code at a user's request is one thing. But it should only be able to "hit a button" to send a 2FA email to the address attached to the account, all run with hand-written code. It shouldn't have access to the 2FA code itself, or the message subject, or body, or the recipient address, etc. Wh…

This exploit has essentially nothing to do with AI and everything to do with a terribly designed account recovery flow. This exact same flow could have been (and may have been; I don’t know how much the chatbot here actually does) statically coded.

How the hell does "being gullible enough to believe that's the actual Obama" NOT have to do with AI?

Re: The newest Instagram “exploit” is the goofiest I've seen

#429

Earlier quoted context omitted.

We need an update to the CIA "Simple Sabatoge Field Manuel" but for the digital field. https://www.cia.gov/static/5c875f3ec660e092cf893f60b4a288df/...

It only needs a minor update, maybe even just a foreword. So much of the actual manual is still completely applicable.

A modern edition desperately needs an AI chapter
Post reply on HN