Live data from Hacker News

The newest Instagram “exploit” is the goofiest I've seen

0xsid.com

181–190 of 528 posts

Re: The newest Instagram “exploit” is the goofiest I've seen

#182
> The first proper zero auth password reset I've seen in production.

LinkedIn had one back in the day, before you got paid for discovering it I guess, never got a decent reply from them, but they eventually solved it.

It went like this: they assumed that if you could read mail sent to some address, that address was yours and could be added to your account.

So if I send you a LinkedIn invite to an email address, and you click the accept invite button, that email address was added to your account. You could then send this email to any address you controlled (let’s say foo@example.com), then use the invite button link in a forged email and send it to someone else on their email, whenever they clicked foo@example.com was added to their account without them knowing.

When you got the response that you were friends, you also knew that you know had an email address added to that users account and you could do a full password reset by using the foo@example.com that you initially sent the email to.

I found it because someone invited a whole mailing list and after clicking it the mailing list email was suddenly added to various peoples accounts.

Re: The newest Instagram “exploit” is the goofiest I've seen

#183

Earlier quoted context omitted.

Range != value, depending on use case. Doing more poorly does not make something better. Our customer identity capabilities are very close to login.gov (we don't have to support hundreds of agency customers and common access cards), and if its good enough for ~342M Americans, its good enough for our customer base. Broadly speaking, work for the sake of work is not valuable work. Show me outcomes for resources and tim…

> [login.gov] if its good enough for ~342M Americans I am very curious about the actual number of users of login.gov. I am a US citizen and my experience was … negative to the point of actively avoiding it.

> I am very curious about the actual number of users of login.gov.

"Login.gov has surpassed 100 million registered user accounts. The platform facilitates over 300 million sign-ins annually and sees more than 10 million monthly active users, acting as a secure single sign-on solution across nearly 50 federal, state, and local agencies."

https://www.login.gov/partners/faq/

(It is the primary identity provider for Social Security Administration, IRS will eventually adopt it [1])

[1] IRS to adopt Login.gov as user authentication tool - https://news.ycombinator.com/item?id=30430851 - February 2022 (182 comments)

Re: The newest Instagram “exploit” is the goofiest I've seen

#185
post #21

It's insane the AI has been provided the tooling to send emails to arbitrary addresses like that. Like, getting it to send a 2FA code at a user's request is one thing. But it should only be able to "hit a button" to send a 2FA email to the address attached to the account, all run with hand-written code. It shouldn't have access to the 2FA code itself, or the message subject, or body, or the recipient address, etc. Wh…

Some Jr engineer got tired of handling stupid support requests and automated the job with an agent. That’s how. Assigning Jr engineers for security support is ridiculous partly because young people don’t understand how critical security is sometimes. And partly because they don’t value privacy as much.

If a single junior engineer can do this, it’s an even bigger indictment of Facebook’s senior management than this exploit. A well-designed system doesn’t rely on individuals never making mistakes and if our hypothetical junior developer can make critical security policy changes without oversight, that should be a C-level job loss event.

If our goal isn’t to make excuses for the top of the org chart, a more likely explanation is that senior management is heavily incentivizing shipping AI features and this went out as a high-impact change reviewed in a rush, probably by AI.

Re: The newest Instagram “exploit” is the goofiest I've seen

#186

Earlier quoted context omitted.

The fact that if your account has had the SAME EMAIL AND NUMBER FOR 14 YEARS OR MORE and support still thinks you got hacked is more embarrassing to me.

I used my work email for everything for 14 years, now I'm retired/fired/laid off and I can't access it anymore and I forgot to change the email linked in my Facebook account.

I would expect your IP to not change as drastically as some VPN IP being your only evidence that you're you.

Re: The newest Instagram “exploit” is the goofiest I've seen

#187
Fun fact: I once got a security bounty because they sent the 2FA emails through click (some email monitoring SAAS thing) with "view in web" enabled, and it was set up so that the emails under a given template used an auto incrementing ID, so you just had to request a 2FA email and then access it through click's web UI.

Re: The newest Instagram “exploit” is the goofiest I've seen

#188

What's funny about this to me is that I tried to sign up for insta once and could never get past their automated ID check that would fire after signup despite using a real ID. (So never did sign up. I suspect maybe they just really don't want you using web on mobile devices but ymmv.)

On mobile, Meta absolutely doesn’t want you to use web. I created my Facebook account in 2004, deleted it in 2018 (Cambridge Analytica scandal), and later created a fake one just to use FB marketplace to sell things.

I will never install the Facebook app on my phone, so I use a browser instead. The experience is almost unusable. I can’t rate people. I’m not even sure if I can send messages. I can’t list things. The UI appears to support features that don’t work in practice.

No biggy because I just use a Firefox container and use my laptop instead, where the web version actually does work.

Re: The newest Instagram “exploit” is the goofiest I've seen

#189
post #41
post #36

Earlier quoted context omitted.

This is not wrong but what’s really missing is cost: Meta did this so they can avoid paying people to do it. Lots of companies follow that decay spiral: your bank could shut phishers down cold by requiring wire transfers to be authorized in person but they don’t want to pay staff or risk you being upset by a transaction taking an extra hour so they don’t. Imagine an alternate universe where big tech companies worked…

The amount of hassle involved with regular physical checks is why it's not implemented, regardless of attack prevention. The cost of hiring a person is part of it but not really the core reason. People were sold on the Internet with "you can do things online conveniently" and reintroducing the need to physically go somewhere negates that angle entirely.

To be clear, I was thinking cost as more than just payroll - e.g. my bank can do this because they have paid for a branch near my house, Facebook does not - but another way to look at it is that many of the costs due to errors have been shifted to the user.

I do think friction causes a reflexive resistance to the idea but I think that might be an overreaction. This is a rare thing people should be doing no more than a few times in their life.

Re: The newest Instagram “exploit” is the goofiest I've seen

#190
post #170
post #43

Earlier quoted context omitted.

This exploit has essentially nothing to do with AI and everything to do with a terribly designed account recovery flow. This exact same flow could have been (and may have been; I don’t know how much the chatbot here actually does) statically coded.

The reason all these meticulously designed flows have been done away with is because some manager believes that AI is omniscient and can just replace it all. Like, flagging VPN endpoints is bread and butter for this kind of thing and must already exist. But it's been bypassed

Residential proxies won’t get flagged and are easy to obtain, if expensive.
Post reply on HN