Live data from Hacker News

The newest Instagram “exploit” is the goofiest I've seen

0xsid.com

361–370 of 528 posts

Re: The newest Instagram “exploit” is the goofiest I've seen

#361

Just waiting for the day that a rogue team of AI agents gets unleashed on Meta, Twitter, or some other platform, using something like this to take over every account. Platform gone, just like that. It would be over before they figuered out what was happening.

Interesting thought experiment but I'd presume they have backups to which they could revert, right?

Re: The newest Instagram “exploit” is the goofiest I've seen

#362

Earlier quoted context omitted.

It's a tough problem, because people forget passwords, change phones, lose access to 2FA devices, but still need to use their accounts.

It's worse than "forgetting." Having seen older folks just set up new accounts for a move, they make zero attempt to even try to keep them! Oh, the phone company needs a login/pass? Just type in anything, don't write it down. If something goes wrong, they're going to call in anyway, not use the website.

One-time logins actually sound useful for things like setting up utilities for a house. Sign up, log in, do whatever you need to do, log out and the account is immediately locked. Nobody expects you to log back in anytime soon, anyway.

If you ever need to interact with the service again, you initiate account recovery using a combination of your contact info and some codes printed on your monthly bill.

Re: The newest Instagram “exploit” is the goofiest I've seen

#363

Earlier quoted context omitted.

I had a Threads account banned recently because I liked five posts too quickly and they said my account was "inauthentic", even though the attached Instagram account is just fine. I tried to use the Meta Verified support and they told me I had used my full quota of support already (!?) and refused any requests.

Also, never ever use a VPN and log in with your Instagram account on the web. They're highly likely to flag you as spam immediately even if your account is 10 years old and legitimate. You then will have to go through a process to remove the flag by taking a selfie with a paper written with some date and user name. Not guaranteed you'll get your account back. This happened a few times to my account. On the last time…

Instagram is blocked in Russia so everyone here uses it through some sort of VPN. No one I know has ever got banned for that.

Re: The newest Instagram “exploit” is the goofiest I've seen

#364

Earlier quoted context omitted.

There are no other online choices. If my Bank login goes totally Kaput, though, I can take my ID down to the Branch to get it sorted. Same with my telecom provider. I try to only depend on services which have this property. I don't succeed.

Seems like a business opportunity. Face to face authentication in every major city that can authenticate people when needed.

This is actually one of the more useful services those horrible check-cashing storefronts provide.

Re: The newest Instagram “exploit” is the goofiest I've seen

#365
post #358
post #325

Earlier quoted context omitted.

Probably not news to anyone here, but partial step in this direction is to put down vetted official contact details for the institutions. Every time someone calls to say there's a problem with your account, you ask for their name and/or extension number, because recontacting through the institution is your only good way of verifying their identity.

Malware on your phone can reroute your calls to the attacker. So you think you're calling the official number at the correct institution, but you're actually talking to the attacker.

Well, yeah, and knowing first-aid is worthless if someone's been decapitated. :p

If some malware is that deep on the phone, able to redirect calls, then you've got much bigger problems and the attacker might not even need to trick any cooperation at all.

Re: The newest Instagram “exploit” is the goofiest I've seen

#366
post #285

Earlier quoted context omitted.

Sounds great until you have an aging parent with a problem who can't get there. Get a power of attorney you say.. great but they won't accept unless parent comes to the branch. This comes back to haunt you in the future.

> until you have an aging parent with a problem who can't get there Or you get elected to high office and consequently getting to the branch is a bit ... faffy[0] [0] https://chicago.suntimes.com/pope-leo-xiv/2026/05/06/pope-le...

> McCarthy, an Augustinian friar from the South Side who has known Pope Leo for 43 years, told the story as a reminder to parishioners that the pope “is like us,” and “a very humble guy.”

So humble that he was able to change his information over the phone by threatening directly to the president of the bank that he'd use a different bank if they didn't let him, and the president bent over backwards to meet this demand. He's just like us!

Re: The newest Instagram “exploit” is the goofiest I've seen

#368

Earlier quoted context omitted.

A flow can either fail safe or fail secure. Fail secure: if you lose your email, your account is forever locked. Fail safe: if you lose your email, your account is not forever locked. But, someone else might be able to get your account by pretending you lost your email. There are no other choices. When the electronic door controller loses power, either the door stays locked, or the door stays unlocked. In case of a f…

There are a lot of other ways they could do it. You could provide a delay feature… if you request this sort of reset, it takes 3 days, and emails are sent to the primary address every day with the count down. If your email isn’t lost, you would see these warnings. You could let an account holder designate emergency contacts (other accounts) that are allowed to request a reset if you lose your primary email (again wit…

This is actually what microsoft does for microsoft accounts

If you recover a microsoft account / submit a ticket to recover it and provide correct information, the active email gets an email letting them know about the request

You can deny it, or if you ignore it for 30 days the request goes through

Seems to be the best system IMO

Re: The newest Instagram “exploit” is the goofiest I've seen

#369
> “In case you're wondering, because the system treats this high-privilege recovery flow as a total account reset by the "true" owner, the original 2FA gets thoroughly bypassed in the process.“

This is false.

Important to note this did not work if your account had 2FA of any kind

e.g if you had a time based authenticator enabled, after the AI gave you the code to reset the password, it had no notable privileges beyond that

Tldr; if you had 2FA this wouldn’t work on you

Re: The newest Instagram “exploit” is the goofiest I've seen

#370

> “In case you're wondering, because the system treats this high-privilege recovery flow as a total account reset by the "true" owner, the original 2FA gets thoroughly bypassed in the process.“ This is false. Important to note this did not work if your account had 2FA of any kind e.g if you had a time based authenticator enabled, after the AI gave you the code to reset the password, it had no notable privileges beyon…

> Important to note this did not work if your account had 2FA of any kind

What about what the op said?

> 2FA Doesn't Help

> In case you're wondering, because the system treats this high-privilege recovery flow as a total account reset by the "true" owner, the original 2FA gets thoroughly bypassed in the process.

> Existing sessions are revoked and the password changed with no email, text, or push notification. The actual owner can't initiate recovery because the email and phone numbers now map to the attacker. There's no human to escalate to, it's just you arguing with a chat hoping to take control back while praying they don't do it again.

> And if you're part of the A/B tested accounts on which the AI support option is active, tough luck, you can't even turn it off.

Post reply on HN