The newest Instagram “exploit” is the goofiest I've seen
181–190 of 528 posts
Re: The newest Instagram “exploit” is the goofiest I've seen
#182LinkedIn had one back in the day, before you got paid for discovering it I guess, never got a decent reply from them, but they eventually solved it.
It went like this: they assumed that if you could read mail sent to some address, that address was yours and could be added to your account.
So if I send you a LinkedIn invite to an email address, and you click the accept invite button, that email address was added to your account. You could then send this email to any address you controlled (let’s say foo@example.com), then use the invite button link in a forged email and send it to someone else on their email, whenever they clicked foo@example.com was added to their account without them knowing.
When you got the response that you were friends, you also knew that you know had an email address added to that users account and you could do a full password reset by using the foo@example.com that you initially sent the email to.
I found it because someone invited a whole mailing list and after clicking it the mailing list email was suddenly added to various peoples accounts.
Re: The newest Instagram “exploit” is the goofiest I've seen
#183Earlier quoted context omitted.
Range != value, depending on use case. Doing more poorly does not make something better. Our customer identity capabilities are very close to login.gov (we don't have to support hundreds of agency customers and common access cards), and if its good enough for ~342M Americans, its good enough for our customer base. Broadly speaking, work for the sake of work is not valuable work. Show me outcomes for resources and tim…
> [login.gov] if its good enough for ~342M Americans I am very curious about the actual number of users of login.gov. I am a US citizen and my experience was … negative to the point of actively avoiding it.
"Login.gov has surpassed 100 million registered user accounts. The platform facilitates over 300 million sign-ins annually and sees more than 10 million monthly active users, acting as a secure single sign-on solution across nearly 50 federal, state, and local agencies."
https://www.login.gov/partners/faq/
(It is the primary identity provider for Social Security Administration, IRS will eventually adopt it [1])
[1] IRS to adopt Login.gov as user authentication tool - https://news.ycombinator.com/item?id=30430851 - February 2022 (182 comments)
Re: The newest Instagram “exploit” is the goofiest I've seen
#184A few hours back, I was spammed with ig.me links insisting I click it to check it out.
I did not have the opportunity to visit the link, but it appears to be related to belong to some Instagram password reset flow.
Re: The newest Instagram “exploit” is the goofiest I've seen
#185It's insane the AI has been provided the tooling to send emails to arbitrary addresses like that. Like, getting it to send a 2FA code at a user's request is one thing. But it should only be able to "hit a button" to send a 2FA email to the address attached to the account, all run with hand-written code. It shouldn't have access to the 2FA code itself, or the message subject, or body, or the recipient address, etc. Wh…
Some Jr engineer got tired of handling stupid support requests and automated the job with an agent. That’s how. Assigning Jr engineers for security support is ridiculous partly because young people don’t understand how critical security is sometimes. And partly because they don’t value privacy as much.
If our goal isn’t to make excuses for the top of the org chart, a more likely explanation is that senior management is heavily incentivizing shipping AI features and this went out as a high-impact change reviewed in a rush, probably by AI.
Re: The newest Instagram “exploit” is the goofiest I've seen
#186Earlier quoted context omitted.
The fact that if your account has had the SAME EMAIL AND NUMBER FOR 14 YEARS OR MORE and support still thinks you got hacked is more embarrassing to me.
I used my work email for everything for 14 years, now I'm retired/fired/laid off and I can't access it anymore and I forgot to change the email linked in my Facebook account.
Re: The newest Instagram “exploit” is the goofiest I've seen
#187Re: The newest Instagram “exploit” is the goofiest I've seen
#188What's funny about this to me is that I tried to sign up for insta once and could never get past their automated ID check that would fire after signup despite using a real ID. (So never did sign up. I suspect maybe they just really don't want you using web on mobile devices but ymmv.)
I will never install the Facebook app on my phone, so I use a browser instead. The experience is almost unusable. I can’t rate people. I’m not even sure if I can send messages. I can’t list things. The UI appears to support features that don’t work in practice.
No biggy because I just use a Firefox container and use my laptop instead, where the web version actually does work.
Re: The newest Instagram “exploit” is the goofiest I've seen
#189Earlier quoted context omitted.
This is not wrong but what’s really missing is cost: Meta did this so they can avoid paying people to do it. Lots of companies follow that decay spiral: your bank could shut phishers down cold by requiring wire transfers to be authorized in person but they don’t want to pay staff or risk you being upset by a transaction taking an extra hour so they don’t. Imagine an alternate universe where big tech companies worked…
The amount of hassle involved with regular physical checks is why it's not implemented, regardless of attack prevention. The cost of hiring a person is part of it but not really the core reason. People were sold on the Internet with "you can do things online conveniently" and reintroducing the need to physically go somewhere negates that angle entirely.
I do think friction causes a reflexive resistance to the idea but I think that might be an overreaction. This is a rare thing people should be doing no more than a few times in their life.
Re: The newest Instagram “exploit” is the goofiest I've seen
#190Earlier quoted context omitted.
This exploit has essentially nothing to do with AI and everything to do with a terribly designed account recovery flow. This exact same flow could have been (and may have been; I don’t know how much the chatbot here actually does) statically coded.
The reason all these meticulously designed flows have been done away with is because some manager believes that AI is omniscient and can just replace it all. Like, flagging VPN endpoints is bread and butter for this kind of thing and must already exist. But it's been bypassed