Live data from Hacker News

The newest Instagram “exploit” is the goofiest I've seen

0xsid.com

371–380 of 528 posts

Re: The newest Instagram “exploit” is the goofiest I've seen

#371

Earlier quoted context omitted.

A flow can either fail safe or fail secure. Fail secure: if you lose your email, your account is forever locked. Fail safe: if you lose your email, your account is not forever locked. But, someone else might be able to get your account by pretending you lost your email. There are no other choices. When the electronic door controller loses power, either the door stays locked, or the door stays unlocked. In case of a f…

There are a lot of other ways they could do it. You could provide a delay feature… if you request this sort of reset, it takes 3 days, and emails are sent to the primary address every day with the count down. If your email isn’t lost, you would see these warnings. You could let an account holder designate emergency contacts (other accounts) that are allowed to request a reset if you lose your primary email (again wit…

Apple does this.

Re: The newest Instagram “exploit” is the goofiest I've seen

#373

Earlier quoted context omitted.

There are a lot of other ways they could do it. You could provide a delay feature… if you request this sort of reset, it takes 3 days, and emails are sent to the primary address every day with the count down. If your email isn’t lost, you would see these warnings. You could let an account holder designate emergency contacts (other accounts) that are allowed to request a reset if you lose your primary email (again wit…

This is actually what microsoft does for microsoft accounts If you recover a microsoft account / submit a ticket to recover it and provide correct information, the active email gets an email letting them know about the request You can deny it, or if you ignore it for 30 days the request goes through Seems to be the best system IMO

Someone has been trying to hack into my MSFT account for years. I constantly get the notifications. I can not see where they are trying from (unlike some other services that give you info about failed login attempts) nor add more security measures. I worry one day I will accidentally hit "Approve" or they will guess the 6 digit code they have tried thousands of times.

The fun part is that you can't disable OneDrive. No matter how many times I turn it off it always keeps turning OneDrive back on to put my private data in the cloud for the attackers. Of course I can't block the methods that are obviously under attack either.

And the lack of a login history view means I have no way to know if they were successful yet. Support has never been good (for legitimate users) and is basically non-existent with AI now.

Re: The newest Instagram “exploit” is the goofiest I've seen

#374

> “In case you're wondering, because the system treats this high-privilege recovery flow as a total account reset by the "true" owner, the original 2FA gets thoroughly bypassed in the process.“ This is false. Important to note this did not work if your account had 2FA of any kind e.g if you had a time based authenticator enabled, after the AI gave you the code to reset the password, it had no notable privileges beyon…

> Important to note this did not work if your account had 2FA of any kind What about what the op said? > 2FA Doesn't Help > In case you're wondering, because the system treats this high-privilege recovery flow as a total account reset by the "true" owner, the original 2FA gets thoroughly bypassed in the process. > Existing sessions are revoked and the password changed with no email, text, or push notification. The ac…

It’s just incorrect

It’s true that existing sessions are revoked; because the password was reset

The reason the target wouldn’t get any notifications at all would be in the case they never setup any additional verification methods to receive these notifications to, since this only worked on accounts w/o 2FA

You can test this on your own account, if you have 2FA enabled and reset your password, you’ll receive notifications to whatever option you have enabled

Also, if you reset the password, it doesn’t remove all 2FA methods on the account (you can test this)

So assuming a threat actor reset the password, they would attempt to login with the correct password but would still need the 2FA code or approval

Re: The newest Instagram “exploit” is the goofiest I've seen

#375
I'd have loved to try this. There's a 4 letter (my short name; my favourite username) Instagram account registered by someone years ago and being squatted upon. Not private and totally unused. Oh, but then I don't use instagram. Still wouldn't have minded snatching it

Re: The newest Instagram “exploit” is the goofiest I've seen

#376
post #373

Earlier quoted context omitted.

This is actually what microsoft does for microsoft accounts If you recover a microsoft account / submit a ticket to recover it and provide correct information, the active email gets an email letting them know about the request You can deny it, or if you ignore it for 30 days the request goes through Seems to be the best system IMO

Someone has been trying to hack into my MSFT account for years. I constantly get the notifications. I can not see where they are trying from (unlike some other services that give you info about failed login attempts) nor add more security measures. I worry one day I will accidentally hit "Approve" or they will guess the 6 digit code they have tried thousands of times. The fun part is that you can't disable OneDrive.…

You can view the recent activity on your Microsoft account @ account(dot)live(dot)com/Activity

Would show any logins or security info updates etc

Re: The newest Instagram “exploit” is the goofiest I've seen

#377
post #325

Earlier quoted context omitted.

On the other hand, the best anti-scam feature for older relatives is to tell them to "go there in person". Get a call from the bank, they simply tell them "ok, I'm coming to the bank tomorrow, in person", and they're done. Scam call? Legit call? Doesn't matter, they'll sort it out at the bank. There's a whole wide age and knowledge/competence where older people can still fall for scams (or can't know if it's legit or…

Probably not news to anyone here, but partial step in this direction is to put down vetted official contact details for the institutions. Every time someone calls to say there's a problem with your account, you ask for their name and/or extension number, because recontacting through the institution is your only good way of verifying their identity.

That works when the system is setup to allow that.

I've encountered banks that don't have that setup — hilariously one bank felt the need to cold call me about my complaint about cold calling from unverifiable numbers. When I asked how I could call them on a verifiable number, they claimed I couldn't. :/

Re: The newest Instagram “exploit” is the goofiest I've seen

#378
post #373

Earlier quoted context omitted.

Someone has been trying to hack into my MSFT account for years. I constantly get the notifications. I can not see where they are trying from (unlike some other services that give you info about failed login attempts) nor add more security measures. I worry one day I will accidentally hit "Approve" or they will guess the 6 digit code they have tried thousands of times. The fun part is that you can't disable OneDrive.…

You can view the recent activity on your Microsoft account @ account(dot)live(dot)com/Activity Would show any logins or security info updates etc

Those login attempts which trigger 2fa app does not generate a log entry if unsuccessful. Only attempts with username/password does. For some strange reason.

So there is no way to flag them as malicious and if you accidentally accept, then it’s already too late.

Pretty annoying setup.

Re: The newest Instagram “exploit” is the goofiest I've seen

#379
post #191
post #73

Earlier quoted context omitted.

Then you get trusted parties selling account access. Even if you remove them for a single false positive they will do it. A bit like a % packages "vanishing". The least terrible seem digital id.

> Then you get trusted parties selling account access How many bank tellers or USPS employees do that, though? It’s possible but quite rare because people know they’ll be running a big risk of being caught and no individual transaction is worth that much.

Interstingly, since 2008 Dutch bankers need to take an oath and whilst I don't think that in itself deters fraud, being fired for fraud would preclude going back to work for another bank (tuchtrecht / disciplinairy law)

Re: The newest Instagram “exploit” is the goofiest I've seen

#380
post #358
post #325

Earlier quoted context omitted.

Probably not news to anyone here, but partial step in this direction is to put down vetted official contact details for the institutions. Every time someone calls to say there's a problem with your account, you ask for their name and/or extension number, because recontacting through the institution is your only good way of verifying their identity.

Malware on your phone can reroute your calls to the attacker. So you think you're calling the official number at the correct institution, but you're actually talking to the attacker.

What kind of malware are we talking about here? On a non-rooted phone?
Post reply on HN