Live data from Hacker News

The newest Instagram “exploit” is the goofiest I've seen

0xsid.com

341–350 of 528 posts

Re: The newest Instagram “exploit” is the goofiest I've seen

#341

Earlier quoted context omitted.

Someone being able to take over your account, read your DMs, and impersonate you is pretty serious. Should be treated as a data breach with serious penalties.

Sure, but it's not life-critical, lives don't depend on it. Other engineering disciplines have different rules, because for example a bridge or building with a fault might cause the loss of life of hunderds of people.

Another commenter noted that stalkers and ex partners could absolutely weaponise account takeover in a life threatening way.

Tech companies don’t want to take responsibility for the incredibly sensitive data they have collected and are trusted with guarding.

Re: The newest Instagram “exploit” is the goofiest I've seen

#342

I was wondering why I got 15 instagram password reset emails over the weekend. It also reminded me I had an instagram account, which I promptly tried to log into and delete. I created the account when instagram first came out, never used it, and totally forgot about it. I got stuck in a strange position where I had to login from a device I had previously logged in from, but because it's been over a decade, I no longe…

I got locked out of some old gmail accounts in a similar way - they were created without phone numbers and while I have the passwords, I get flagged for suspicious activity when I try to log in, and there's no actionable recovery flow.

If there's no recovery email address set, or that email has expired, there are no recovery methods to verify with. The account is locked "for good". I use quotes because in some cases I've been able to recover Gmail accounts with similar characteristics by simply trying often on my home IP address using Google Chrome.

Re: The newest Instagram “exploit” is the goofiest I've seen

#343

Interesting article. A few hours back, I was spammed with ig.me links insisting I click it to check it out. I did not have the opportunity to visit the link, but it appears to be related to belong to some Instagram password reset flow.

I suggest you try signing into your Instagram account via the app or website to check if you've been compromised. It could very well be a bot trying to obtain your recovery method hints but you could've also fallen victim to this exploit, especially if you have a short or valuable username.

Re: The newest Instagram “exploit” is the goofiest I've seen

#344
post #310

Link 1 says > In case you're wondering, because the system treats this high-privilege recovery flow as a total account reset by the "true" owner, the original 2FA gets thoroughly bypassed in the process. But link 2 says > The hackers who released the video on Telegram said their exploit failed to work against any accounts that had MFA enabled. So which one is true?

The original 2FA did not get thoroughly bypassed, because otherwise I would've lost my username, so that's false - at least, based on my experience.

However, there are separate vulnerabilities that allow for 2FA to be bypassed on Instagram. I assume they were chained to take over specific high-value accounts. The 2FA removal happens as a service - most people charge around $1,000+ - so it wasn't viable for most lower-value accounts. Anything that was worth over $1k probably had the bypass applied to it.

Re: The newest Instagram “exploit” is the goofiest I've seen

#347
post #79

I'm among the first 6000 users of Instagram and my first name username was stolen a few years ago. Support for verified accounts acknowledged the issue, but couldn't do anything about it. This turn was an AI exploit, in my case was an outsourcing support 'exploit', where someone paid for my username to be manually changed and given to another user. There will always be a way to get access to accounts if human account…

I had a Threads account banned recently because I liked five posts too quickly and they said my account was "inauthentic", even though the attached Instagram account is just fine. I tried to use the Meta Verified support and they told me I had used my full quota of support already (!?) and refused any requests.

Also, never ever use a VPN and log in with your Instagram account on the web. They're highly likely to flag you as spam immediately even if your account is 10 years old and legitimate.

You then will have to go through a process to remove the flag by taking a selfie with a paper written with some date and user name. Not guaranteed you'll get your account back.

This happened a few times to my account. On the last time it happened, I had to ask my friend who works at Meta to file an internal ticket to try to get my account back.

Meta's antispam seriously sucks. It's so primitive and so easy for a real user to get flagged.

Re: The newest Instagram “exploit” is the goofiest I've seen

#348
post #9

Support requests have always been the weakest link in the security chain for big corps. I've had accounts of mine turned over with 2FA disabled by humans before. I guess we shouldn't be surprised that the LLMs are doing the same thing. The simple fact that 2FA can be removed by low level support staff drives me mad. It defeats the whole purpose of the process.

well. I lost my 2FA dongle once (left it on a different continent). Which I used to secure my domain name on which I received mail. suddenly I was happy that low level support staff could remove it. (I needed to scan my passport and photo. This was way before modern image generation.)

This is why you should have at least two MFA options enabled.

Re: The newest Instagram “exploit” is the goofiest I've seen

#349
>In this case, even using the least robust form of MFA that Instagram offers — a one-time code sent via SMS — likely would have blocked the exploit: The hackers who released the video on Telegram said their exploit failed to work against any accounts that had MFA enabled.

Why would they not have this set up?

Re: The newest Instagram “exploit” is the goofiest I've seen

#350
post #9

Support requests have always been the weakest link in the security chain for big corps. I've had accounts of mine turned over with 2FA disabled by humans before. I guess we shouldn't be surprised that the LLMs are doing the same thing. The simple fact that 2FA can be removed by low level support staff drives me mad. It defeats the whole purpose of the process.

> The simple fact that 2FA can be removed by low level support staff drives me mad. It defeats the whole purpose of the process. Crazy Domains (one of the few registrars for my ccTLD) removed 2FA from my account (that was in the process of getting hijacked) despite me being on the phone with them specifically telling them not to do so [1][2]. What's worse was that my account got targeted by the same hijacker again wh…

Wait… why did you continue trusting them for there to be a second time?

If they didn’t care at all about your instructions the first time?

Post reply on HN