Hackers Used Meta's AI Support Bot to Seize Instagram Accounts
11–20 of 22 posts
Re: Hackers Used Meta's AI Support Bot to Seize Instagram Accounts
#12Re: Hackers Used Meta's AI Support Bot to Seize Instagram Accounts
#13Re: Hackers Used Meta's AI Support Bot to Seize Instagram Accounts
#14"Hackers"? No. There's no hacking involved. It's literally just politely asking the bot to send you the login link.
Re: Hackers Used Meta's AI Support Bot to Seize Instagram Accounts
#15"Hackers"? No. There's no hacking involved. It's literally just politely asking the bot to send you the login link.
Sounds like exploiting a system to access unauthorized data to me. I'd call it hacking.
Re: Hackers Used Meta's AI Support Bot to Seize Instagram Accounts
#16Already on the front page: The newest Instagram “exploit” is the goofiest I've seen https://news.ycombinator.com/item?id=48359102 - 180 comments
Re: Hackers Used Meta's AI Support Bot to Seize Instagram Accounts
#17And, yes, the current tech is pretty dumb.
But this is a blatant misapplication of the technology in an obviously sensitive use case with an implementation that's so exploitable the people driving it have certainly never heard the term "jailbreak" once in their lives.
Reminds me of a consulting call that I had with a very large internet provider about their new agentic chat support system.
"We're going to start with the request routing layer and move that to AI agents, and then work though the individual services."
I thought it was a wild architectural decision that they would choose to roll every single action that the system handled through an experimental layer. My advice was to start with a safe, repeatable process to validate the effectiveness in the wild, and then expand in the same manner, bringing edges in as they had "solved" the individual implementations.
So, while this is almost the exact opposite of that, choosing a high-value target with real repercussions as their leaf implementation still baffles me. Step zero of any AI integration plan should be prioritization. Companies are routinely failing at this very simple, not-even-technical aspect.
Re: Hackers Used Meta's AI Support Bot to Seize Instagram Accounts
#18"Hackers"? No. There's no hacking involved. It's literally just politely asking the bot to send you the login link.
Most hacks can be expressed in terms of "literally just" something.
Kinda like how it ain't "breaking & entering" if you found the victim's diamond necklace in a plastic bin sitting at the curb.
Re: Hackers Used Meta's AI Support Bot to Seize Instagram Accounts
#19Already on the front page: The newest Instagram “exploit” is the goofiest I've seen https://news.ycombinator.com/item?id=48359102 - 180 comments
I know that HN requests that we don't editorialize the titles, but I feel like the article title for this thread better expresses what's happened at a glance than the "goofy exploit" article.
Re: Hackers Used Meta's AI Support Bot to Seize Instagram Accounts
#20This simultaneously seems like: 1) such an obvious attack vector that it is extreme negligence to not have had planned for appropriate security protections against this, and 2) the most obvious outcome for Meta to be this security lax and stupid. If it doesn't hurt their ad sales, it doesn't matter to Meta.