Just waiting for the day that a rogue team of AI agents gets unleashed on Meta, Twitter, or some other platform, using something like this to take over every account. Platform gone, just like that. It would be over before they figuered out what was happening.
The newest Instagram “exploit” is the goofiest I've seen
361–370 of 528 posts
Re: The newest Instagram “exploit” is the goofiest I've seen
#362Earlier quoted context omitted.
It's a tough problem, because people forget passwords, change phones, lose access to 2FA devices, but still need to use their accounts.
It's worse than "forgetting." Having seen older folks just set up new accounts for a move, they make zero attempt to even try to keep them! Oh, the phone company needs a login/pass? Just type in anything, don't write it down. If something goes wrong, they're going to call in anyway, not use the website.
If you ever need to interact with the service again, you initiate account recovery using a combination of your contact info and some codes printed on your monthly bill.
Re: The newest Instagram “exploit” is the goofiest I've seen
#363Earlier quoted context omitted.
I had a Threads account banned recently because I liked five posts too quickly and they said my account was "inauthentic", even though the attached Instagram account is just fine. I tried to use the Meta Verified support and they told me I had used my full quota of support already (!?) and refused any requests.
Also, never ever use a VPN and log in with your Instagram account on the web. They're highly likely to flag you as spam immediately even if your account is 10 years old and legitimate. You then will have to go through a process to remove the flag by taking a selfie with a paper written with some date and user name. Not guaranteed you'll get your account back. This happened a few times to my account. On the last time…
Re: The newest Instagram “exploit” is the goofiest I've seen
#364Earlier quoted context omitted.
There are no other online choices. If my Bank login goes totally Kaput, though, I can take my ID down to the Branch to get it sorted. Same with my telecom provider. I try to only depend on services which have this property. I don't succeed.
Seems like a business opportunity. Face to face authentication in every major city that can authenticate people when needed.
Re: The newest Instagram “exploit” is the goofiest I've seen
#365Earlier quoted context omitted.
Probably not news to anyone here, but partial step in this direction is to put down vetted official contact details for the institutions. Every time someone calls to say there's a problem with your account, you ask for their name and/or extension number, because recontacting through the institution is your only good way of verifying their identity.
Malware on your phone can reroute your calls to the attacker. So you think you're calling the official number at the correct institution, but you're actually talking to the attacker.
If some malware is that deep on the phone, able to redirect calls, then you've got much bigger problems and the attacker might not even need to trick any cooperation at all.
Re: The newest Instagram “exploit” is the goofiest I've seen
#366Earlier quoted context omitted.
Sounds great until you have an aging parent with a problem who can't get there. Get a power of attorney you say.. great but they won't accept unless parent comes to the branch. This comes back to haunt you in the future.
> until you have an aging parent with a problem who can't get there Or you get elected to high office and consequently getting to the branch is a bit ... faffy[0] [0] https://chicago.suntimes.com/pope-leo-xiv/2026/05/06/pope-le...
So humble that he was able to change his information over the phone by threatening directly to the president of the bank that he'd use a different bank if they didn't let him, and the president bent over backwards to meet this demand. He's just like us!
Re: The newest Instagram “exploit” is the goofiest I've seen
#367Re: The newest Instagram “exploit” is the goofiest I've seen
#368Earlier quoted context omitted.
A flow can either fail safe or fail secure. Fail secure: if you lose your email, your account is forever locked. Fail safe: if you lose your email, your account is not forever locked. But, someone else might be able to get your account by pretending you lost your email. There are no other choices. When the electronic door controller loses power, either the door stays locked, or the door stays unlocked. In case of a f…
There are a lot of other ways they could do it. You could provide a delay feature… if you request this sort of reset, it takes 3 days, and emails are sent to the primary address every day with the count down. If your email isn’t lost, you would see these warnings. You could let an account holder designate emergency contacts (other accounts) that are allowed to request a reset if you lose your primary email (again wit…
If you recover a microsoft account / submit a ticket to recover it and provide correct information, the active email gets an email letting them know about the request
You can deny it, or if you ignore it for 30 days the request goes through
Seems to be the best system IMO
Re: The newest Instagram “exploit” is the goofiest I've seen
#369This is false.
Important to note this did not work if your account had 2FA of any kind
e.g if you had a time based authenticator enabled, after the AI gave you the code to reset the password, it had no notable privileges beyond that
Tldr; if you had 2FA this wouldn’t work on you
Re: The newest Instagram “exploit” is the goofiest I've seen
#370> “In case you're wondering, because the system treats this high-privilege recovery flow as a total account reset by the "true" owner, the original 2FA gets thoroughly bypassed in the process.“ This is false. Important to note this did not work if your account had 2FA of any kind e.g if you had a time based authenticator enabled, after the AI gave you the code to reset the password, it had no notable privileges beyon…
What about what the op said?
> 2FA Doesn't Help
> In case you're wondering, because the system treats this high-privilege recovery flow as a total account reset by the "true" owner, the original 2FA gets thoroughly bypassed in the process.
> Existing sessions are revoked and the password changed with no email, text, or push notification. The actual owner can't initiate recovery because the email and phone numbers now map to the attacker. There's no human to escalate to, it's just you arguing with a chat hoping to take control back while praying they don't do it again.
> And if you're part of the A/B tested accounts on which the AI support option is active, tough luck, you can't even turn it off.