Live data from Hacker News

Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

this.weekinsecurity.com

221–230 of 287 posts

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#222

Earlier quoted context omitted.

Large influencer accounts without two factor authentication... The only useful reaction to this is to point and laugh.

I think the hack bypassed 2FA. If you can call “asking for account access” a hack lmao

It did not, TFA clearly says it worked for accounts with no 2FA, as GP said.

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#224
post #30
post #3

> "The tool itself worked properly and functioned as intended; however due to a bug in a separate code path, the system did not properly verify that the email address provided by the individual requesting a password reset matched the email address associated with that user’s Instagram account," said Meta in its breach notice. I'm not sure "worked properly" and "as intended" accurately describe this situation.

In italian we say "l'operazione è riuscita perfettamente, ma il paziente è morto" -> "the surgery was a complete success, but the patient died"

Haha.. This reminds me of a classic Windows MessageBox meme that goes: "Operation failed successfully!"

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#225

Earlier quoted context omitted.

Twenty _thousand_ people had their personal data stolen, many of them relied on these accounts to run their business, many put at risk of hackers impersonating them. Meta in a fair world should be forced to financially compensate these people. They built a world where many people basically have to use their products for their jobs and then failed to look after the data because they wanted to replace customer support…

Over forty _thousand_ people die every year in the US from car accidents. Plenty of other preventable injustices happen in all areas of life. I wonder how many fathers are unjustly taken away from their children by a corrupt family court system, how many people die of treatable diseases denied treatment by insurance companies, how many kids lose interest in school because of bad teachers, how many customer service wo…

Fathers who ask for custody are massively successfull statistically.

Also, taking kids from father requires quite a lot. And no, actually proven domestic violence issue is not enough if it was not provably against the kid itself.

Familly courts have flaws, but fathers with interest in kids having them stolwn en mass is not one of them.

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#226

Earlier quoted context omitted.

Both this and what Meta said reminds me of "Clarke and Dawe - The Front Fell Off" ( https://www.youtube.com/watch?v=3m5qxZm_JqM ) I also can't believe the people who were involved with writing this response from Meta, didn't realize how obviously bad it sounds. It's like there is no humans working and writing there anymore.

> like there is no humans working and writing there anymore Meta has never been a place for people with empathy to thrive or succeed. They literally enabled a genocide. Despite being warned by internal employees, profits were more important.

Which one. They have several under their blood soaked belt now

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#227

Earlier quoted context omitted.

No fan of Meta, but I think "staggering" is properly determined by the percent of users affected rather than the absolute number. It's staggering to an SMB with 100k customers; it's bad, but not "staggering" to an internet juggernaught with 3B MAU.

Twenty _thousand_ people had their personal data stolen, many of them relied on these accounts to run their business, many put at risk of hackers impersonating them. Meta in a fair world should be forced to financially compensate these people. They built a world where many people basically have to use their products for their jobs and then failed to look after the data because they wanted to replace customer support…

If you're relying on Meta to operate your business you're on shaky ground and it's a strong hint it was never viable to begin with.

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#228
post #19

Earlier quoted context omitted.

To be fair, that quote in the original article could have more context. By "The tool" they meant "AI-assisted support tool"[1]; perhaps they meant that the issue was not an AI hallucination inherent of the tool, but a fixable bug. [1]: https://www.documentcloud.org/documents/28202858-meta-ai-ag-...

It seems to me like they're saying the agent made the tool call they expected, but the harness didn't reject it like they expected it to.

But it sounds like it's not even a harness issue if they have a process where they send a reset email to an address that isn't associated with the account.

This isn't (just) a validation issue, and shouldn't be at the harness level.

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#229
post #35

>AI-assisted account recovery system oh no...Meta what are you doing

Account recovery is by far the #1 kind of ticket any service will get. Either because people forget their credentials, lose their credentials, get hacked or get impersonated - and that's just the legitimate tickets, on top of that come illegitimate tickets from everyday script kiddies over ransom extortioners (i.e. the people that aim to steal "valuable" handles) to nation-state actors that, say, want to get access t…

I get automating most of the interaction but giving the LLM rights to actually grant strangers access to accounts is insane

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#230

I got a suspicious password reset request email today from Meta but it landed in my inbox. Luckily I have MFA and after checking audit logs inside IG upon logging in, I did not see anything suspicious.

2FA did not help according to the primary finding https://news.ycombinator.com/item?id=48359102

In that case it sounds like the last waves of malicious reset attempts happened after the patch was put in place
Post reply on HN