Live data from Hacker News

The newest Instagram “exploit” is the goofiest I've seen

0xsid.com

431–440 of 528 posts

Re: The newest Instagram “exploit” is the goofiest I've seen

#431
post #421

Earlier quoted context omitted.

There is a third option. Most banks here in Sweden solve this by forcing you to show up in person (with a ID card) if you loose your password. I get that this also is technically a 2FA bypass but the cost is extreme and its really hard to impersonate someone in real life.

How would that even work for internet companies without physical stores? Go to Menlo Park, CA to recover your account?

Facebook already requires verifying your ID in some cases, it's absolutely feasible for them to do it online.

If it's not feasible, I can see an argument that large enough companies should be required to provide in person support options.

Facebook defintely has enough money to facilitate this.

Re: The newest Instagram “exploit” is the goofiest I've seen

#432
post #79

I'm among the first 6000 users of Instagram and my first name username was stolen a few years ago. Support for verified accounts acknowledged the issue, but couldn't do anything about it. This turn was an AI exploit, in my case was an outsourcing support 'exploit', where someone paid for my username to be manually changed and given to another user. There will always be a way to get access to accounts if human account…

ive had rappers offer me $10k for my ig username. i'm holding out for the bank to buy it.

Just make sure to keep satiritizing chase bank there.

Re: The newest Instagram “exploit” is the goofiest I've seen

#433
post #9

Support requests have always been the weakest link in the security chain for big corps. I've had accounts of mine turned over with 2FA disabled by humans before. I guess we shouldn't be surprised that the LLMs are doing the same thing. The simple fact that 2FA can be removed by low level support staff drives me mad. It defeats the whole purpose of the process.

A flow can either fail safe or fail secure. Fail secure: if you lose your email, your account is forever locked. Fail safe: if you lose your email, your account is not forever locked. But, someone else might be able to get your account by pretending you lost your email. There are no other choices. When the electronic door controller loses power, either the door stays locked, or the door stays unlocked. In case of a f…

A compromise solution would be to fail safe with a cook-off period and a notification for any active users.

It would mean that someone can't gank an account from under you while you're using it, but you could recover it after a week if you lose access to your email.

Re: The newest Instagram “exploit” is the goofiest I've seen

#434
When thinking about the security of AI agents, one should ignore the agent entirely. Consider only the tools that the agent has access to. Assume that, if the attacker can interact with this agent, they have full and unfettered access to these tools. If those tools are secure, the agent is secure.

This framing doesn't consider context poisoning attacks, on which much has been written already and which merit their own defenses.

Re: The newest Instagram “exploit” is the goofiest I've seen

#435

Earlier quoted context omitted.

I had a Threads account banned recently because I liked five posts too quickly and they said my account was "inauthentic", even though the attached Instagram account is just fine. I tried to use the Meta Verified support and they told me I had used my full quota of support already (!?) and refused any requests.

Also, never ever use a VPN and log in with your Instagram account on the web. They're highly likely to flag you as spam immediately even if your account is 10 years old and legitimate. You then will have to go through a process to remove the flag by taking a selfie with a paper written with some date and user name. Not guaranteed you'll get your account back. This happened a few times to my account. On the last time…

I lost my 10 years old account this way after being flagged about 2-3 times due to travel.

My account really isn't that important but still makes my blood boil at the time.

Re: The newest Instagram “exploit” is the goofiest I've seen

#436

When thinking about the security of AI agents, one should ignore the agent entirely. Consider only the tools that the agent has access to. Assume that, if the attacker can interact with this agent, they have full and unfettered access to these tools. If those tools are secure, the agent is secure. This framing doesn't consider context poisoning attacks, on which much has been written already and which merit their own…

may you please elaborate on poisoning?

Re: The newest Instagram “exploit” is the goofiest I've seen

#438

Earlier quoted context omitted.

I used my work email for everything for 14 years, now I'm retired/fired/laid off and I can't access it anymore and I forgot to change the email linked in my Facebook account.

I would expect your IP to not change as drastically as some VPN IP being your only evidence that you're you.

Unless you changed both job and country.

Re: The newest Instagram “exploit” is the goofiest I've seen

#439
post #9

Support requests have always been the weakest link in the security chain for big corps. I've had accounts of mine turned over with 2FA disabled by humans before. I guess we shouldn't be surprised that the LLMs are doing the same thing. The simple fact that 2FA can be removed by low level support staff drives me mad. It defeats the whole purpose of the process.

A flow can either fail safe or fail secure. Fail secure: if you lose your email, your account is forever locked. Fail safe: if you lose your email, your account is not forever locked. But, someone else might be able to get your account by pretending you lost your email. There are no other choices. When the electronic door controller loses power, either the door stays locked, or the door stays unlocked. In case of a f…

> There are no other choices.

Fail safe noisily and implement a cooldown period.

Post reply on HN