Live data from Hacker News

The newest Instagram “exploit” is the goofiest I've seen

0xsid.com

221–230 of 528 posts

Re: The newest Instagram “exploit” is the goofiest I've seen

#222
post #143

wtf. this prompted me to attempt to open the app on my phone, and then realize my account was likely compromised (i received a bunch of password reset prompts over the weekend and now my password doesn't work). but, what now? how do i restore my account?

Tell the AI your email got hacked, here's a new one lol

Re: The newest Instagram “exploit” is the goofiest I've seen

#223
post #182

> The first proper zero auth password reset I've seen in production. LinkedIn had one back in the day, before you got paid for discovering it I guess, never got a decent reply from them, but they eventually solved it. It went like this: they assumed that if you could read mail sent to some address, that address was yours and could be added to your account. So if I send you a LinkedIn invite to an email address, and y…

> someone invited a whole mailing list

IIRC, LinkedIn would email everyone in your "address book" (or anything else it could find) back in the day.

Re: The newest Instagram “exploit” is the goofiest I've seen

#224
post #9

Support requests have always been the weakest link in the security chain for big corps. I've had accounts of mine turned over with 2FA disabled by humans before. I guess we shouldn't be surprised that the LLMs are doing the same thing. The simple fact that 2FA can be removed by low level support staff drives me mad. It defeats the whole purpose of the process.

The fact that if your account has had the SAME EMAIL AND NUMBER FOR 14 YEARS OR MORE and support still thinks you got hacked is more embarrassing to me.

That doesn't sound that unlikely to me personally, not everybody has the best tech habits and some life events can result in losing access to both very quickly. It doesn't have to happen often for it to still be a common event in support cases.

Re: The newest Instagram “exploit” is the goofiest I've seen

#225
post #19

This happened to my instagram yesterday night while I was asleep. I don't have a particularly high value username (it's probably worth somewhere in between $300-500), but still incredibly frustrating to deal with. True to the article, I had already enabled 2FA last night and it didn't matter. Thankfully, IG gave me the option of restoring my username when I logged back into my account today.

> Thankfully, IG gave me the option of restoring my username when I logged back into my account today. The hackers read all your formerly private messages, saw all your private photos, saw all the photos your friends wanted only their social circle to see. They could have social-engineered a thousand scamss. I'm glad it worked out for you. But honestly, your baseline is kind of off.

While I agree with this, the hackers have an incentive to get in and out as soon as possible (at least, with accounts that have valuable usernames), because they want to swap the username over to an account they fully control before the rightful owner takes the account back. While DMs were read during this exploit in some cases (I've seen this be the case for several musicians), valuable usernames were likely signed into, swapped, and then signed out of. That's how rare username theft on Instagram generally works, anyways.

Re: The newest Instagram “exploit” is the goofiest I've seen

#226
post #212

> The first proper zero auth password reset I've seen in production. In 2011 Dropbox briefly had an even easier "zero auth exploit". For a couple hours if you typed in any email on the login page, password checking was skipped and you could login to any account. Albeit, you still couldn't reset the user password, just login. https://techcrunch.com/2011/06/20/dropbox-security-bug-made-...

What about Hotmail's "eh" flaw of 1999? I'd say a two-letter password is practically "zero auth".

Re: The newest Instagram “exploit” is the goofiest I've seen

#228
post #9

Support requests have always been the weakest link in the security chain for big corps. I've had accounts of mine turned over with 2FA disabled by humans before. I guess we shouldn't be surprised that the LLMs are doing the same thing. The simple fact that 2FA can be removed by low level support staff drives me mad. It defeats the whole purpose of the process.

[deleted]

Re: The newest Instagram “exploit” is the goofiest I've seen

#229
post #143

wtf. this prompted me to attempt to open the app on my phone, and then realize my account was likely compromised (i received a bunch of password reset prompts over the weekend and now my password doesn't work). but, what now? how do i restore my account?

Tell the AI your email got hacked, here's a new one lol

well, it seems to have transferred back to me (or at least i could login through another method). but, i can't reset the password right now ("Something went wrong, please try again"). though, it tells me that the password was last changed yesterday… hmm.

Re: The newest Instagram “exploit” is the goofiest I've seen

#230
This is very worrying to me, since I have a three-letter IG account and I already get daily recovery emails triggered by unknown actors. They have this system which after some number of these you'll also get a second link like "you can _limit password resets from devices you haven't used before_" but it's only for like 60 days, then it resets to the normal "anyone who types in your username can request resets" mode.

What I want is simply a mode to "never, ever, under any circumstances, perform 'recovery' of any kind, through any channel, ever, unless the person requesting has my TOTP code or a passkey." And frankly I want that for pretty much every account everywhere. But no, we have to leave the social engineering door wide open. And now, put a gullible robot in that doorway. Great.

Post reply on HN