Live data from Hacker News

The newest Instagram “exploit” is the goofiest I've seen

0xsid.com

381–390 of 528 posts

Re: The newest Instagram “exploit” is the goofiest I've seen

#381
post #327
post #9

Support requests have always been the weakest link in the security chain for big corps. I've had accounts of mine turned over with 2FA disabled by humans before. I guess we shouldn't be surprised that the LLMs are doing the same thing. The simple fact that 2FA can be removed by low level support staff drives me mad. It defeats the whole purpose of the process.

The strangest/scariest and honestly in the end all that surprising one of these I had was with a major storage appliance provider that most in the space on HN would know by name. We needed to delete a storage volume to urgently free up space, and apparently this was locked in a way the storage vendor was required to act as a "second key" to ours to make the destructive action. We had never properly set this up, and I…

Ubiquiti or Synology?

Re: The newest Instagram “exploit” is the goofiest I've seen

#382

Earlier quoted context omitted.

The fact that this can happen at all without the security team's knowledge is telling.

Probably not as telling as you think it is. The security team at any organization is always considered an enemy to product and innovation. It wouldn't be surprising if management made it impossible for them to put in place the monitoring necessary to know this was happening. Especially at somewhere whose motto is "move fast and break things".

IG's security team is top-notch, but there's just not enough people.

Re: The newest Instagram “exploit” is the goofiest I've seen

#384

Here is a video showing it being done. ( https://xcancel.com/DarkWebInformer/status/20612535997583155... )

Warning: NSFW video audio, suggest people mute.

Damn yeah I didn't even notice the lyrics.

https://dm.vern.cc/Helen-12-gauge-shotgun-shell-lyrics

Re: The newest Instagram “exploit” is the goofiest I've seen

#385
post #9

Support requests have always been the weakest link in the security chain for big corps. I've had accounts of mine turned over with 2FA disabled by humans before. I guess we shouldn't be surprised that the LLMs are doing the same thing. The simple fact that 2FA can be removed by low level support staff drives me mad. It defeats the whole purpose of the process.

I don't think it is AI. Instagram had a similar issue before. Maybe it still exists. If you ever logged in on a phone you could then use that phone to reset the password.

Re: The newest Instagram “exploit” is the goofiest I've seen

#386
post #373

Earlier quoted context omitted.

This is actually what microsoft does for microsoft accounts If you recover a microsoft account / submit a ticket to recover it and provide correct information, the active email gets an email letting them know about the request You can deny it, or if you ignore it for 30 days the request goes through Seems to be the best system IMO

Someone has been trying to hack into my MSFT account for years. I constantly get the notifications. I can not see where they are trying from (unlike some other services that give you info about failed login attempts) nor add more security measures. I worry one day I will accidentally hit "Approve" or they will guess the 6 digit code they have tried thousands of times. The fun part is that you can't disable OneDrive.…

I think the best defense against this is to delete the Microsoft account and enjoy a better life. (Unless, of course, you need it for Minecraft.)

Re: The newest Instagram “exploit” is the goofiest I've seen

#387

Just waiting for the day that a rogue team of AI agents gets unleashed on Meta, Twitter, or some other platform, using something like this to take over every account. Platform gone, just like that. It would be over before they figuered out what was happening.

Interesting thought experiment but I'd presume they have backups to which they could revert, right?

Assuming the agent doesn't have access to the backups right?

Re: The newest Instagram “exploit” is the goofiest I've seen

#388
why do I feel like they basically added their AI support chatbot to the same group / mailing list that the human support belonged to along with the same permissions set and just called it a day?

I'll laugh even harder if they wrote tests for it and only made tests for the happy path and not the error cases or just ignored the latter.

Re: The newest Instagram “exploit” is the goofiest I've seen

#390

Security 101 when changing the email of an account for any reason: email the old account and let it know the change happened. The weird thing is I know the Instagram security team, and they are top notch. I have a feeling this was vibe coded by someone outside of security and security wasn't looped in.

I work at Meta. The security team was recently gutted. 50% were either laid off or moved to data labeling.
Post reply on HN