Live data from Hacker News

The newest Instagram “exploit” is the goofiest I've seen

0xsid.com

151–160 of 528 posts

Re: The newest Instagram “exploit” is the goofiest I've seen

#151
post #79

I'm among the first 6000 users of Instagram and my first name username was stolen a few years ago. Support for verified accounts acknowledged the issue, but couldn't do anything about it. This turn was an AI exploit, in my case was an outsourcing support 'exploit', where someone paid for my username to be manually changed and given to another user. There will always be a way to get access to accounts if human account…

Can you sue? I assume there is a financial motive with this crime.

Re: The newest Instagram “exploit” is the goofiest I've seen

#152

Security 101 when changing the email of an account for any reason: email the old account and let it know the change happened. The weird thing is I know the Instagram security team, and they are top notch. I have a feeling this was vibe coded by someone outside of security and security wasn't looped in.

Someone high up said something along the lines that they want to see some progress and someone down below looking for a promotion pushed this. This has always been happening but I think before it was more difficult to justify something like this as one would have needed to show the results of an algorithm, now it's easier to convince someone higher up that AI will solve it no worries

Re: The newest Instagram “exploit” is the goofiest I've seen

#153
Why isn't there a middle man service to do IRL verification.

Like - account is locked, you must use 2FA backup codes.

Else go to western union / 7-eleven / super-market, show ID proof, pay $10 for recovery service.

Wait 2 days (of someone not clicking on this-was-not-me)

If account is already hacked - pay $100 for expert support

Re: The newest Instagram “exploit” is the goofiest I've seen

#154

Earlier quoted context omitted.

> But it should only be able to "hit a button" to send a 2FA email to the address attached to the account, all run with hand-written code. Genuine question...why would that need to be hand-written? It makes absolute sense as a general statement and is kinda crazy that this wasn't a built-in limitation, but I'm not quite sure why the code for that bit must be hand-written (provided the code functionally does what you…

I think he likely means "code that is hand-reviewed" and not directly controlled by the agent. He's probably meaning to differentiate it against the in-process agent writing the code. It doesn't matter too much if that fixed code was written by an LLM under guidance and review of the SWE, outside the agent.

Ahh ok - that's fair enough - hand-reviewed/not controlled by the agent seems a sensible approach (wasn't sure if it was instructive of a complete distrust of AI generated code)

Re: The newest Instagram “exploit” is the goofiest I've seen

#155

Security 101 when changing the email of an account for any reason: email the old account and let it know the change happened. The weird thing is I know the Instagram security team, and they are top notch. I have a feeling this was vibe coded by someone outside of security and security wasn't looped in.

The fact that this can happen at all without the security team's knowledge is telling.

Important tech people on HN seem to be surrounded by technical excellence while the user data leaks and other sociological externalities happen to trail all the nearby paths.

Re: The newest Instagram “exploit” is the goofiest I've seen

#156
post #102
post #43

Earlier quoted context omitted.

This exploit has essentially nothing to do with AI and everything to do with a terribly designed account recovery flow. This exact same flow could have been (and may have been; I don’t know how much the chatbot here actually does) statically coded.

The AI part does seem relevant because it enabled incredibly low-effort “social” engineering. For what it’s worth I don’t think you can call this social engineering since there was no human on the other end, even though it appears similar. The question is, if there were actual human support agents, would they have built additional safeguards to prevent social engineering in this manner?

There's no social engineering here, since all they have to do is copy and paste. This is a complete process design fail.

Re: The newest Instagram “exploit” is the goofiest I've seen

#157
post #43
post #21

It's insane the AI has been provided the tooling to send emails to arbitrary addresses like that. Like, getting it to send a 2FA code at a user's request is one thing. But it should only be able to "hit a button" to send a 2FA email to the address attached to the account, all run with hand-written code. It shouldn't have access to the 2FA code itself, or the message subject, or body, or the recipient address, etc. Wh…

This exploit has essentially nothing to do with AI and everything to do with a terribly designed account recovery flow. This exact same flow could have been (and may have been; I don’t know how much the chatbot here actually does) statically coded.

An email address is making its way from a publicly available LLM prompt input to a sensitive email's recipient address. That's the problem I'm highlighting.

Re: The newest Instagram “exploit” is the goofiest I've seen

#159
post #102
post #43

Earlier quoted context omitted.

This exploit has essentially nothing to do with AI and everything to do with a terribly designed account recovery flow. This exact same flow could have been (and may have been; I don’t know how much the chatbot here actually does) statically coded.

The AI part does seem relevant because it enabled incredibly low-effort “social” engineering. For what it’s worth I don’t think you can call this social engineering since there was no human on the other end, even though it appears similar. The question is, if there were actual human support agents, would they have built additional safeguards to prevent social engineering in this manner?

Why did the account recovery system need AI. Surely just an email would do? What added value would AI add?

Re: The newest Instagram “exploit” is the goofiest I've seen

#160
post #19

This happened to my instagram yesterday night while I was asleep. I don't have a particularly high value username (it's probably worth somewhere in between $300-500), but still incredibly frustrating to deal with. True to the article, I had already enabled 2FA last night and it didn't matter. Thankfully, IG gave me the option of restoring my username when I logged back into my account today.

> Thankfully, IG gave me the option of restoring my username when I logged back into my account today.

The hackers read all your formerly private messages, saw all your private photos, saw all the photos your friends wanted only their social circle to see. They could have social-engineered a thousand scamss.

I'm glad it worked out for you. But honestly, your baseline is kind of off.

Post reply on HN