Live data from Hacker News

The newest Instagram “exploit” is the goofiest I've seen

0xsid.com

351–360 of 528 posts

Re: The newest Instagram “exploit” is the goofiest I've seen

#351

Security 101 when changing the email of an account for any reason: email the old account and let it know the change happened. The weird thing is I know the Instagram security team, and they are top notch. I have a feeling this was vibe coded by someone outside of security and security wasn't looped in.

If you know them, ask them how this happened?

Re: The newest Instagram “exploit” is the goofiest I've seen

#352

I’ve got one cool story to tell. One of my Facebook alt credentials is somehow “merged” with another alt that I used to use, that is, I can use the email of one account to login to another account. The merge seems to be persistent. Meta somehow determined the two accounts are the same person.

This is normal. If you have one Instagram account, you can create another with the existing accounts email.

Re: The newest Instagram “exploit” is the goofiest I've seen

#353
post #82

Earlier quoted context omitted.

recovery is always the weakest link in any authentication system

It's a hard problem. How do you prove you own an account if you lost all proof of ownership? Especially so if an account was never tied to your real name, in which case you could at least rely on government ids.

Well the obvious solution is to prevent accounts not using a real name or registered organization name from being recovered.

Re: The newest Instagram “exploit” is the goofiest I've seen

#355

Earlier quoted context omitted.

A flow can either fail safe or fail secure. Fail secure: if you lose your email, your account is forever locked. Fail safe: if you lose your email, your account is not forever locked. But, someone else might be able to get your account by pretending you lost your email. There are no other choices. When the electronic door controller loses power, either the door stays locked, or the door stays unlocked. In case of a f…

There are a lot of other ways they could do it. You could provide a delay feature… if you request this sort of reset, it takes 3 days, and emails are sent to the primary address every day with the count down. If your email isn’t lost, you would see these warnings. You could let an account holder designate emergency contacts (other accounts) that are allowed to request a reset if you lose your primary email (again wit…

1. Provide a delay of a week. 2. Notify via all addresses on file. 3. Make an admin post (by the account in question) explaining that a 2FA override has been requested. Something you and all your followers can see.

Re: The newest Instagram “exploit” is the goofiest I've seen

#356

Security 101 when changing the email of an account for any reason: email the old account and let it know the change happened. The weird thing is I know the Instagram security team, and they are top notch. I have a feeling this was vibe coded by someone outside of security and security wasn't looped in.

LLMs don't understand security 101, or anything else for that matter. It shouldn't be surprising if they do something like this.

Re: The newest Instagram “exploit” is the goofiest I've seen

#358
post #325

Earlier quoted context omitted.

On the other hand, the best anti-scam feature for older relatives is to tell them to "go there in person". Get a call from the bank, they simply tell them "ok, I'm coming to the bank tomorrow, in person", and they're done. Scam call? Legit call? Doesn't matter, they'll sort it out at the bank. There's a whole wide age and knowledge/competence where older people can still fall for scams (or can't know if it's legit or…

Probably not news to anyone here, but partial step in this direction is to put down vetted official contact details for the institutions. Every time someone calls to say there's a problem with your account, you ask for their name and/or extension number, because recontacting through the institution is your only good way of verifying their identity.

Malware on your phone can reroute your calls to the attacker. So you think you're calling the official number at the correct institution, but you're actually talking to the attacker.

Re: The newest Instagram “exploit” is the goofiest I've seen

#359

Earlier quoted context omitted.

Delete the accounts and move on... They don't deserve your time and business.

Can you delete your accounts if you've been banned?

There are only two buttons available to me:

- Download your data

- Log out

Re: The newest Instagram “exploit” is the goofiest I've seen

#360

Earlier quoted context omitted.

I had a Threads account banned recently because I liked five posts too quickly and they said my account was "inauthentic", even though the attached Instagram account is just fine. I tried to use the Meta Verified support and they told me I had used my full quota of support already (!?) and refused any requests.

Also, never ever use a VPN and log in with your Instagram account on the web. They're highly likely to flag you as spam immediately even if your account is 10 years old and legitimate. You then will have to go through a process to remove the flag by taking a selfie with a paper written with some date and user name. Not guaranteed you'll get your account back. This happened a few times to my account. On the last time…

I had an account in 2023 and it one day asked me to upload the selfie with the paper. Literally the second I hit submit it returned within a microsecond to say I was now permanently banned.

I was tempted to pay a Meta employee with this one, but the going rate is about $500-2000 right now. And it's too late because I took the gamble of trying to appeal it. Once you appeal and lose Meta employees can just use the internal ticket system to get it back. It's a more convoluted process and usually they want $5-10K to do it at that point.

Post reply on HN