Live data from Hacker News

The newest Instagram “exploit” is the goofiest I've seen

0xsid.com

331–340 of 528 posts

Re: The newest Instagram “exploit” is the goofiest I've seen

#331
post #230

This is very worrying to me, since I have a three-letter IG account and I already get daily recovery emails triggered by unknown actors. They have this system which after some number of these you'll also get a second link like "you can _limit password resets from devices you haven't used before_" but it's only for like 60 days, then it resets to the normal "anyone who types in your username can request resets" mode.…

You're lucky you weren't affected by this. Several people I know with three-letter usernames had theirs stolen over the last few days. When I recovered my account that had been stolen through this exploit (luckily, my username hadn't been changed), I was sent a code to my email address and then asked to use my TOTP code, backup code, or a video selfie. I used my TOTP code and was let in just fine. They certainly have…

Very interesting. I found it odd that when I happened to open IG yesterday, I was prompted to log in, and my password didn't work. I asked it to send me a link to my email and got in that way, and didn't have time to look into it further.

So I went to check it again just now after reading your comment, and I was immediately as soon as I opened the app, prompted to create a new password, which I did.

very very sketchy things going on here. But I'm glad that they didn't fully allow my account to be stolen :/

Re: The newest Instagram “exploit” is the goofiest I've seen

#332

So the AI agent had privileged access to remove 2FA, ignore the account email, and just hands accounts to whoever asked? Honestly that’s so highly negligent I wonder if the implementation team for that “feature” was intentionally trying to do as much subtle damage to meta as possible before their inventible layoff. It’s a shame nobody tried to get it to drop the production table entirely! (mostly joking). Just claim…

Honestly, you’re right. — it’s not simple ai chat bot — it’s ai chat bot with guardrails removed.

Re: The newest Instagram “exploit” is the goofiest I've seen

#335

Earlier quoted context omitted.

Delete the accounts and move on... They don't deserve your time and business.

Can you delete your accounts if you've been banned?

Definitely yes, if you mention the magic words "GDPR".

Re: The newest Instagram “exploit” is the goofiest I've seen

#336
post #79

I'm among the first 6000 users of Instagram and my first name username was stolen a few years ago. Support for verified accounts acknowledged the issue, but couldn't do anything about it. This turn was an AI exploit, in my case was an outsourcing support 'exploit', where someone paid for my username to be manually changed and given to another user. There will always be a way to get access to accounts if human account…

> with criminal consequences for employees that violate it lol, no. The day someone is criminally charged with "stealing" a username is the day that humanity has lost

People are criminally charged for stealing food to feed themselves. I'd argue that's more a sign of lost humanity than stealing something which has a non-negligible economic value.

Re: The newest Instagram “exploit” is the goofiest I've seen

#337

I get that account recovery for sites with hundreds of millions of users is a huge burden they're struggling to manage but I'm shocked they didn't restrict such loose verification to the >90% of lower value accounts that aren't worth stealing and keep the stricter verif on high-value accounts. The next obvious thing would be to let accounts the algorithm judges to be low-value still opt-in to strict verif. The vast m…

They probably did limit it somewhat, but to 99.99% lower value accounts. This isn’t the top story of international news because a former president got “hacked”, not Trump, Elon, etc. that literally set national policy via social media post

Re: The newest Instagram “exploit” is the goofiest I've seen

#339
post #79

I'm among the first 6000 users of Instagram and my first name username was stolen a few years ago. Support for verified accounts acknowledged the issue, but couldn't do anything about it. This turn was an AI exploit, in my case was an outsourcing support 'exploit', where someone paid for my username to be manually changed and given to another user. There will always be a way to get access to accounts if human account…

ive had rappers offer me $10k for my ig username. i'm holding out for the bank to buy it.

It's against Meta's terms to buy and sell accounts, thus the bank would never do such a deal unless you structured it a certain way: create a business, the account becomes property of the business, then Chase buys the business and thus the account. This is how certain Twitter accounts were sold a long time ago. $10k for @chasebank (which is what I assume your handle is) is quite good regardless, though.

Re: The newest Instagram “exploit” is the goofiest I've seen

#340
post #123

Earlier quoted context omitted.

Seems like the most plausible explanation. OTOH it feels like this is the sort of thing that might have been discovered/mitigated more quickly had there been a human in the loop.

OTOH one could previously pay an Instagram support contractor to do an account swap, so having a human in the loop allows for other avenues of exploit: https://www.wsj.com/articles/meta-employees-security-guards-...

This still happens. Meta doesn't do much to protect against this, they just fire more people and hire new agents when they find out one was bribed.
Post reply on HN