The newest Instagram “exploit” is the goofiest I've seen
221–230 of 528 posts
Re: The newest Instagram “exploit” is the goofiest I've seen
#222wtf. this prompted me to attempt to open the app on my phone, and then realize my account was likely compromised (i received a bunch of password reset prompts over the weekend and now my password doesn't work). but, what now? how do i restore my account?
Re: The newest Instagram “exploit” is the goofiest I've seen
#223> The first proper zero auth password reset I've seen in production. LinkedIn had one back in the day, before you got paid for discovering it I guess, never got a decent reply from them, but they eventually solved it. It went like this: they assumed that if you could read mail sent to some address, that address was yours and could be added to your account. So if I send you a LinkedIn invite to an email address, and y…
IIRC, LinkedIn would email everyone in your "address book" (or anything else it could find) back in the day.
Re: The newest Instagram “exploit” is the goofiest I've seen
#224Support requests have always been the weakest link in the security chain for big corps. I've had accounts of mine turned over with 2FA disabled by humans before. I guess we shouldn't be surprised that the LLMs are doing the same thing. The simple fact that 2FA can be removed by low level support staff drives me mad. It defeats the whole purpose of the process.
The fact that if your account has had the SAME EMAIL AND NUMBER FOR 14 YEARS OR MORE and support still thinks you got hacked is more embarrassing to me.
Re: The newest Instagram “exploit” is the goofiest I've seen
#225This happened to my instagram yesterday night while I was asleep. I don't have a particularly high value username (it's probably worth somewhere in between $300-500), but still incredibly frustrating to deal with. True to the article, I had already enabled 2FA last night and it didn't matter. Thankfully, IG gave me the option of restoring my username when I logged back into my account today.
> Thankfully, IG gave me the option of restoring my username when I logged back into my account today. The hackers read all your formerly private messages, saw all your private photos, saw all the photos your friends wanted only their social circle to see. They could have social-engineered a thousand scamss. I'm glad it worked out for you. But honestly, your baseline is kind of off.
Re: The newest Instagram “exploit” is the goofiest I've seen
#226> The first proper zero auth password reset I've seen in production. In 2011 Dropbox briefly had an even easier "zero auth exploit". For a couple hours if you typed in any email on the login page, password checking was skipped and you could login to any account. Albeit, you still couldn't reset the user password, just login. https://techcrunch.com/2011/06/20/dropbox-security-bug-made-...
Re: The newest Instagram “exploit” is the goofiest I've seen
#227Re: The newest Instagram “exploit” is the goofiest I've seen
#228Support requests have always been the weakest link in the security chain for big corps. I've had accounts of mine turned over with 2FA disabled by humans before. I guess we shouldn't be surprised that the LLMs are doing the same thing. The simple fact that 2FA can be removed by low level support staff drives me mad. It defeats the whole purpose of the process.
Re: The newest Instagram “exploit” is the goofiest I've seen
#229wtf. this prompted me to attempt to open the app on my phone, and then realize my account was likely compromised (i received a bunch of password reset prompts over the weekend and now my password doesn't work). but, what now? how do i restore my account?
Tell the AI your email got hacked, here's a new one lol
Re: The newest Instagram “exploit” is the goofiest I've seen
#230What I want is simply a mode to "never, ever, under any circumstances, perform 'recovery' of any kind, through any channel, ever, unless the person requesting has my TOTP code or a passkey." And frankly I want that for pretty much every account everywhere. But no, we have to leave the social engineering door wide open. And now, put a gullible robot in that doorway. Great.