Live data from Hacker News

The newest Instagram “exploit” is the goofiest I've seen

0xsid.com

441–450 of 528 posts

Re: The newest Instagram “exploit” is the goofiest I've seen

#441

Earlier quoted context omitted.

recovery is always the weakest link in any authentication system

fair enough, but what's the actual point of 2FA if it's so easy to override?

Personally it seems mostly about prizing the phone number out of my cold clammy hands.

I recently tried to access my google account on a new browser install. Google did not believe my login/password was sufficient, and insisted on me surrendering my phone number:

> To help keep your account safe, Google wants to make sure it’s really you trying to sign in [...]

> Enter a phone number to get a text message with a verification code.

I have never given my phone number to Google for that account (I have a separate account on my Android phone).

So how on earth this will "make sure it's really you" I have no idea.

I am unable to access Google from my new browser install so am stuck with using my old one for anything which requires a Google login.

I guess at some point I'll try and resolve it by adding a recovery email or something, but.. my inclination is to throw Google and the account in the trash right now.

Re: The newest Instagram “exploit” is the goofiest I've seen

#442

When thinking about the security of AI agents, one should ignore the agent entirely. Consider only the tools that the agent has access to. Assume that, if the attacker can interact with this agent, they have full and unfettered access to these tools. If those tools are secure, the agent is secure. This framing doesn't consider context poisoning attacks, on which much has been written already and which merit their own…

100% agree.

Agents should have the same permissions as the user prompting them, nothing else.

No rules will stop agents of accessing data or modifying content if the agent have permissions to do it.

That does not make the agent "safe" from the perspective that it still can and eventually will cause havoc, delete critical data, etc. But it makes the system safe as it isolates that user access and it is not worse that having an unruly/malicious user.

Re: The newest Instagram “exploit” is the goofiest I've seen

#443

When thinking about the security of AI agents, one should ignore the agent entirely. Consider only the tools that the agent has access to. Assume that, if the attacker can interact with this agent, they have full and unfettered access to these tools. If those tools are secure, the agent is secure. This framing doesn't consider context poisoning attacks, on which much has been written already and which merit their own…

But the agent could be trained on sensitive data that could leak which could enable a different attack.

Saying it's safe to "ignore" anything that exposes information is dangerous. You might as well claim social engineering isn't real as long as the person doesn't have direct access to the thing you want.

Re: The newest Instagram “exploit” is the goofiest I've seen

#444

When thinking about the security of AI agents, one should ignore the agent entirely. Consider only the tools that the agent has access to. Assume that, if the attacker can interact with this agent, they have full and unfettered access to these tools. If those tools are secure, the agent is secure. This framing doesn't consider context poisoning attacks, on which much has been written already and which merit their own…

may you please elaborate on poisoning?

i think what they're talking about is an attacker poisoning the data the agent is trained upon to include functionality/a backdoor that can later, after training and when the agent is deployed, be used to induce unwanted behaviour.

Re: The newest Instagram “exploit” is the goofiest I've seen

#445

When thinking about the security of AI agents, one should ignore the agent entirely. Consider only the tools that the agent has access to. Assume that, if the attacker can interact with this agent, they have full and unfettered access to these tools. If those tools are secure, the agent is secure. This framing doesn't consider context poisoning attacks, on which much has been written already and which merit their own…

But the agent could be trained on sensitive data that could leak which could enable a different attack. Saying it's safe to "ignore" anything that exposes information is dangerous. You might as well claim social engineering isn't real as long as the person doesn't have direct access to the thing you want.

They are suggesting that you should assume the user has full access to the same tools as the agent, which is a helpful way to approach it. You mentioned the prompt side of things, and I think you should use a similar mindset there—just assume the user can read the entire prompt exactly as it’s sent.

Re: The newest Instagram “exploit” is the goofiest I've seen

#446

When thinking about the security of AI agents, one should ignore the agent entirely. Consider only the tools that the agent has access to. Assume that, if the attacker can interact with this agent, they have full and unfettered access to these tools. If those tools are secure, the agent is secure. This framing doesn't consider context poisoning attacks, on which much has been written already and which merit their own…

But the agent could be trained on sensitive data that could leak which could enable a different attack. Saying it's safe to "ignore" anything that exposes information is dangerous. You might as well claim social engineering isn't real as long as the person doesn't have direct access to the thing you want.

Agreed. The agent and tools are different types of vulnerabilities. Both are important especially if you have dedicated finetuning (which won't be user dependent of course).

But also stuff like RAG: usually support agents have access to all internal support kbase material. Including stuff you don't want to leak verbatim. And there's other things to consider too like your agent being used to run other people's prompts. Not a data loss issue but could be a financial issue.

But yes I do agree that for the tools' security the agent shouldn't be considered as part of the security model. Any protections there are nice to have but shouldn't be relied upon.

Re: The newest Instagram “exploit” is the goofiest I've seen

#448
I mean the implications and ramifications are fascinating, but .. I just need to take a few moments to absorb the sheer spectacular stupendous glorious DUMBNESS of a multibillion dollar corp with its generously paid staff utilising $multibillion SOTA tech to ignore any reasonable security checks and give prized accounts away for nothing to random hackers. It is difficult to comprehend in its enormity.

A breach which surely will go down in computer history as one of the most egregious and avoidable corporate IT failures of all time.

Re: The newest Instagram “exploit” is the goofiest I've seen

#449

Earlier quoted context omitted.

There are a lot of other ways they could do it. You could provide a delay feature… if you request this sort of reset, it takes 3 days, and emails are sent to the primary address every day with the count down. If your email isn’t lost, you would see these warnings. You could let an account holder designate emergency contacts (other accounts) that are allowed to request a reset if you lose your primary email (again wit…

I've seen this delay in action when logging in into an old dormant Google account. After I provided correct password (and some other details I remember vaguely - probably no phone number set and some problem with using the TOTP I set up long ago), it sent an email to the linked primary email and waited for a day to give it a chance to abort before logging me in. The delay is quite a bother but it's surely better than…

I quite like that idea also. And I would not have thought it would be that difficult to implement in most systems these days

Having 1 or 2 backup email accounts and/or an SMS sent to a registered mobile phone number seems to me to be relatively simple to implement

Along with a built-in delay, the inconvenience of having to wait is way better than losing access to critical accounts

Re: The newest Instagram “exploit” is the goofiest I've seen

#450
post #373

Earlier quoted context omitted.

Someone has been trying to hack into my MSFT account for years. I constantly get the notifications. I can not see where they are trying from (unlike some other services that give you info about failed login attempts) nor add more security measures. I worry one day I will accidentally hit "Approve" or they will guess the 6 digit code they have tried thousands of times. The fun part is that you can't disable OneDrive.…

You can disable the email you use publicly as a login email. I would recommend you look at some other guides before you do this but the gist is My Account > Your Account > Manage Account Information. Then you can add a new email that you do not share as your primary login email, and disable login from the email you use to send emails.

I have about a dozen email aliases associated with my Microsoft account. On the "Your info" page, under "Account info", one of them is described as "The email address you use to sign in to your Microsoft Account".

However, I can use any of them to initiate a login attempt. I have my account set to passwordless, I don't know if that is relevant (every login attempt triggers an MFA prompt).

If I click on "Edit account info" I am taken to a page where I can choose which address in the "Primary", but given that ANY of the aliases can be used to intiate a sign-in, I don't see any benefit in changing that.

EDIT: I wasn't being adventurous enough. The option to change which aliases can be used to sign in is under (surprisingly) "Sign-in preferences".

In my defence, that page wasn't loading properly in Firefox with all my privacy add-ons enabled. I was able to access it in Edge.

EDIT2: I've changed my primary alias to a newly created one. If I am still able to sign in OK in a couple of days, I will disable the old primary for sign-in. I hope I don't live to regret this!

Post reply on HN