Live data from Hacker News

Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

this.weekinsecurity.com

151–160 of 287 posts

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#151
post #21

Earlier quoted context omitted.

Sounds like they are saying the agent did not malfunction, and this vuln could have been triggered by a human support agent too.

It probably could have been, but how likely is that compared to with the AI agent? I'd assume (and I'm ready to look like an idiot if I'm wrong) that the humans are trained to send the verification code to the email address on file, rather than any address the client asks them to. I'd certainly assume most of them are more afraid of the consequences than the AI is.

For sure. Social engineering attacks on human support staff are common and well known, but the skill floor is non-trivial; you need to actually be able to convince a human of your ruse.

Having a support agent likely made it easier to enumerate the vuln, and certainly made it easier to scale out exploitation once it was discovered.

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#152
post #3

> "The tool itself worked properly and functioned as intended; however due to a bug in a separate code path, the system did not properly verify that the email address provided by the individual requesting a password reset matched the email address associated with that user’s Instagram account," said Meta in its breach notice. I'm not sure "worked properly" and "as intended" accurately describe this situation.

Error: Success!

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#153
post #143

Earlier quoted context omitted.

There's a pattern I noticed, especially on this site, where people claim various VC/ad/tech dark patterns, enshitification, privacy violations, dishonest marketing, etc MUST be allowed, otherwise open source or 'the internet' will face some sort of existential risk. No bro - open source and the internet existed long before SV tech parasitism did and will exist long after.

I don't disagree, that pattern exists, but it is essentially true. Just not in the way the folks saying it is true understand it. If the "VC/ad/tech dark patterns, enshitification, privacy violations, dishonest marketing, Etc." wasn't allowed then their job might not exist. That can be true. What is missed is that if there is value in the thing, then it will exist. When I reflect back to someone making this argument…

Very well put.

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#154
post #80

Earlier quoted context omitted.

This is extremely common, unfortunately, to a point where it's a known/expected outcome when you're first creating a brand or product page among those in the biz. If this doesn't work, I'd encourage you to reach out to a brand/ad agency and pay them $100 to ask their meta contact to help you get unblocked. You pretty much have to know someone who knows someone at meta in order to create these. Tip: Do not post about…

Lots of Meta contacts on swapd.com who will take your money and unlock your account. Poster is already at the permanently banned stage, though, which means it's not a simple ticket for a Meta employee, which is normally the $500-1000 range. It's gonna be a $2000+ job. Can also try here: https://www.reddit.com/r/MetaLawsuits/

What an interesting site. The number of sellers offering services to get YouTube videos and accounts removed (by spamming fake reports) for hundreds of thousands of dollars is amazing.

I would not assume those people have contacts with Meta employees. They might have a connection with a contracted worker who does account reviews who is willing to risk their job for a few thousand extra bucks, but I also suspect many of them are just scams. When I scrolled the subforum there were many new accounts claiming to offer 100% success rate for unbans. Easy way to scam desperate people.

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#155

Earlier quoted context omitted.

Lots of Meta contacts on swapd.com who will take your money and unlock your account. Poster is already at the permanently banned stage, though, which means it's not a simple ticket for a Meta employee, which is normally the $500-1000 range. It's gonna be a $2000+ job. Can also try here: https://www.reddit.com/r/MetaLawsuits/

What an interesting site. The number of sellers offering services to get YouTube videos and accounts removed (by spamming fake reports) for hundreds of thousands of dollars is amazing. I would not assume those people have contacts with Meta employees. They might have a connection with a contracted worker who does account reviews who is willing to risk their job for a few thousand extra bucks, but I also suspect many…

All the tasks on that site are done through escrow, IIRC, so however they are doing the unbans, they are getting done!

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#156
post #30

Earlier quoted context omitted.

In italian we say "l'operazione è riuscita perfettamente, ma il paziente è morto" -> "the surgery was a complete success, but the patient died"

Both this and what Meta said reminds me of "Clarke and Dawe - The Front Fell Off" ( https://www.youtube.com/watch?v=3m5qxZm_JqM ) I also can't believe the people who were involved with writing this response from Meta, didn't realize how obviously bad it sounds. It's like there is no humans working and writing there anymore.

> like there is no humans working and writing there anymore

Meta has never been a place for people with empathy to thrive or succeed. They literally enabled a genocide. Despite being warned by internal employees, profits were more important.

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#157

"abusing" by using it's built in insecurity to do insecure things. It's like, people abusing an open door. "Guys, just because we left the door open to your bedroom doesn't mean we're responsible". God can only hope this is a business ending lawsuit.

> God can only hope this is a business ending lawsuit. You realize this is the company that enabled a genocide and got away with it? Not to mention accelerating teenager suicides with full knowledge.

why epse would i invoke a mythical diety

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#158
post #3

> "The tool itself worked properly and functioned as intended; however due to a bug in a separate code path, the system did not properly verify that the email address provided by the individual requesting a password reset matched the email address associated with that user’s Instagram account," said Meta in its breach notice. I'm not sure "worked properly" and "as intended" accurately describe this situation.

[deleted]

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#159
post #10

Earlier quoted context omitted.

The argument here is that the AI is a glorified input page. The input field asks for your username and email and sends it to a backend function. Such an input page is working as intended. The problem is when the backend function doesn't verify that the email matches the username.

Why on earth would the backend function even take an email? Or perhaps said different: use the submitted info to identify the account; send any sensitive messages (recovery codes, password resets whatever) to only the contact info on file. If the chat bot can send such email it should do so via an API that sends only to contact info on file for the associated account and not to an email that's provided by the bot.

Some sites do this to prevent password recovery spam; you need to provide two pieces of information. Ideally not telling the client if they wrote the wrong email, that'd be a security issue of its own.

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#160

Earlier quoted context omitted.

The US car deaths stat is also completely insane and way higher than other countries. I can recognize that at scale, securing every account is a very difficult task, but with scale comes responsibility. Meta plays fast and loose rushing in unsupervised vibeslop agents to save a penny. They should be significantly penalized for such a massive failure, particularly for how long this exploit was live and for how the vic…

1.2M car-related deaths worldwide every year. WW1 worth every decade.

[flagged]
Post reply on HN