Support requests have always been the weakest link in the security chain for big corps. I've had accounts of mine turned over with 2FA disabled by humans before. I guess we shouldn't be surprised that the LLMs are doing the same thing. The simple fact that 2FA can be removed by low level support staff drives me mad. It defeats the whole purpose of the process.
The strangest/scariest and honestly in the end all that surprising one of these I had was with a major storage appliance provider that most in the space on HN would know by name. We needed to delete a storage volume to urgently free up space, and apparently this was locked in a way the storage vendor was required to act as a "second key" to ours to make the destructive action. We had never properly set this up, and I…
The newest Instagram “exploit” is the goofiest I've seen
381–390 of 528 posts
Re: The newest Instagram “exploit” is the goofiest I've seen
#382Earlier quoted context omitted.
The fact that this can happen at all without the security team's knowledge is telling.
Probably not as telling as you think it is. The security team at any organization is always considered an enemy to product and innovation. It wouldn't be surprising if management made it impossible for them to put in place the monitoring necessary to know this was happening. Especially at somewhere whose motto is "move fast and break things".
Re: The newest Instagram “exploit” is the goofiest I've seen
#383Re: The newest Instagram “exploit” is the goofiest I've seen
#384Here is a video showing it being done. ( https://xcancel.com/DarkWebInformer/status/20612535997583155... )
Warning: NSFW video audio, suggest people mute.
Re: The newest Instagram “exploit” is the goofiest I've seen
#385Support requests have always been the weakest link in the security chain for big corps. I've had accounts of mine turned over with 2FA disabled by humans before. I guess we shouldn't be surprised that the LLMs are doing the same thing. The simple fact that 2FA can be removed by low level support staff drives me mad. It defeats the whole purpose of the process.
Re: The newest Instagram “exploit” is the goofiest I've seen
#386Earlier quoted context omitted.
This is actually what microsoft does for microsoft accounts If you recover a microsoft account / submit a ticket to recover it and provide correct information, the active email gets an email letting them know about the request You can deny it, or if you ignore it for 30 days the request goes through Seems to be the best system IMO
Someone has been trying to hack into my MSFT account for years. I constantly get the notifications. I can not see where they are trying from (unlike some other services that give you info about failed login attempts) nor add more security measures. I worry one day I will accidentally hit "Approve" or they will guess the 6 digit code they have tried thousands of times. The fun part is that you can't disable OneDrive.…
Re: The newest Instagram “exploit” is the goofiest I've seen
#387Just waiting for the day that a rogue team of AI agents gets unleashed on Meta, Twitter, or some other platform, using something like this to take over every account. Platform gone, just like that. It would be over before they figuered out what was happening.
Interesting thought experiment but I'd presume they have backups to which they could revert, right?
Re: The newest Instagram “exploit” is the goofiest I've seen
#388I'll laugh even harder if they wrote tests for it and only made tests for the happy path and not the error cases or just ignored the latter.
Re: The newest Instagram “exploit” is the goofiest I've seen
#389If you still use Meta products in 2026, you kinda deserve it.
Re: The newest Instagram “exploit” is the goofiest I've seen
#390Security 101 when changing the email of an account for any reason: email the old account and let it know the change happened. The weird thing is I know the Instagram security team, and they are top notch. I have a feeling this was vibe coded by someone outside of security and security wasn't looped in.