Live data from Hacker News

Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

this.weekinsecurity.com

281–287 of 287 posts

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#281
post #265
post #129

Earlier quoted context omitted.

Incidents like this show how unenforceable GDPR is, and how it's been a net negative for users since its inception. It's idealogical back-patting, toothless when it matters.

How is this unenforceable? If any EU citizens were hacked they're gonna come down like a ton of bricks on Meta Dublin.

The DPC would disagree. All you need to show is that you took "reasonable steps to protect users," which is trivial to do, and not even a single fine will be levied.

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#282
post #23
post #11

Earlier quoted context omitted.

That sounds a lot like the justifications Claude and ChatGPT give when confronted about something they did wrong, or when asked to provide a customer support response about software issues

I've lost track of the number of times Claude has basically said "it was like that when i got here" in the face of a clearly bogus choice and easily disproved explanation.

There is no difference, from the model's point of view, between code it wrote and code someone else wrote. It's all just context.

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#283
post #222

Earlier quoted context omitted.

It did not, TFA clearly says it worked for accounts with no 2FA, as GP said.

The hack doesn't have much to do with it. Meta account recovery flow has always allowed bypassing 2FA.

Why did this not work for 2FA accounts then?

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#284
post #281
post #265

Earlier quoted context omitted.

How is this unenforceable? If any EU citizens were hacked they're gonna come down like a ton of bricks on Meta Dublin.

The DPC would disagree. All you need to show is that you took "reasonable steps to protect users," which is trivial to do, and not even a single fine will be levied.

What reasonable step was made when the exploit was left open for months?
Post reply on HN