Live data from Hacker News

The newest Instagram “exploit” is the goofiest I've seen

0xsid.com

481–490 of 528 posts

Re: The newest Instagram “exploit” is the goofiest I've seen

#481
I think login.gov needs to offer a way for others to use them. They have a pretty good system where you can bring your identification to the post office to get verified. Though I'm sure there are loopholes in the other options, but physically going to a federally owned building with cameras and providing ID has got to be one of the more secure ways to handle it.

Re: The newest Instagram “exploit” is the goofiest I've seen

#482
post #471

HELP? I woke up to a bunch of notifications on my phone from the past 30-60 mins, indicating that people in in Montreal, Argentina, and Kathmandu had attempted to login to my account, and at least one had succeeded. I'm nowhere near any of those locations, and I didn't get any 2FA messages. I tapped Instagram, and it asked me for a new password, so I set one, and it just hung and did nothing. My Instagram, Facebook,…

First off, this is shit position for you to be in.

I perused your comment history as I often do with HNers.

Some guy was predicting this exact situation in 2009 and your comment was that this would all sort itself out due to market forces. The market forces have spoken and the market lacks empathy.

Hope you get your account back and then when you do you hop on to the the other side of the fence. We can all stand to learn from your experience here and 2009 was a long time ago.

If you are in the EU or an EU citizen you will have options (you can email them from the email associated with your account asking for all your data). If you are in the US (assumption) you will be stuck with their ToS and hope some guy in Meta with leverage reads this who simply wants to help.

For reference I proudly do not use any Meta products exactly for these reasons. This is an absurd and dystopian position to find yourself in.

Re: The newest Instagram “exploit” is the goofiest I've seen

#483

I think login.gov needs to offer a way for others to use them. They have a pretty good system where you can bring your identification to the post office to get verified. Though I'm sure there are loopholes in the other options, but physically going to a federally owned building with cameras and providing ID has got to be one of the more secure ways to handle it.

Can you explain more? From a quick google search it seems login.gov is a password and 2fa. What would be the benefit of them opening up their service?

Re: The newest Instagram “exploit” is the goofiest I've seen

#484

I think login.gov needs to offer a way for others to use them. They have a pretty good system where you can bring your identification to the post office to get verified. Though I'm sure there are loopholes in the other options, but physically going to a federally owned building with cameras and providing ID has got to be one of the more secure ways to handle it.

Can you explain more? From a quick google search it seems login.gov is a password and 2fa. What would be the benefit of them opening up their service?

It would be a very useful service for them to provide a "User forgot password and can't log in" flow for important accounts for private companies.

Re: The newest Instagram “exploit” is the goofiest I've seen

#485
post #471

HELP? I woke up to a bunch of notifications on my phone from the past 30-60 mins, indicating that people in in Montreal, Argentina, and Kathmandu had attempted to login to my account, and at least one had succeeded. I'm nowhere near any of those locations, and I didn't get any 2FA messages. I tapped Instagram, and it asked me for a new password, so I set one, and it just hung and did nothing. My Instagram, Facebook,…

There is nothing to do. Game over.

You must rebuild your contacts via some alternative medium of communication.

Re: The newest Instagram “exploit” is the goofiest I've seen

#486

I think login.gov needs to offer a way for others to use them. They have a pretty good system where you can bring your identification to the post office to get verified. Though I'm sure there are loopholes in the other options, but physically going to a federally owned building with cameras and providing ID has got to be one of the more secure ways to handle it.

Turn over access to all your personal accounts to the US government? Sure. What could possibly go wrong.

Re: The newest Instagram “exploit” is the goofiest I've seen

#487

Earlier quoted context omitted.

> I am very curious about the actual number of users of login.gov. "Login.gov has surpassed 100 million registered user accounts. The platform facilitates over 300 million sign-ins annually and sees more than 10 million monthly active users, acting as a secure single sign-on solution across nearly 50 federal, state, and local agencies." https://www.login.gov/partners/faq/ (It is the primary identity provider for Soci…

I have multiple login.gov accounts. They don’t let you change your primary email, so if you’re using corporate account and switch jobs the normal thing is to create new accounts. I’m sure this is padding their numbers.

If you must use login.gov for Social Security, and you will eventually be required to use it for the IRS (and everyone who has a US tax liability), I think the numbers are somewhat irrelevant. Almost everyone over the age of 18 will be a customer of it (for federal tax and benefits logistics). It is the idp you must use, and again, it is good enough (based on all available evidence).

Re: The newest Instagram “exploit” is the goofiest I've seen

#488
My girlfriend's Facebook got stolen via a novel technique a few years ago: https://www.reddit.com/r/facebook/comments/14nbp1a/major_fac...

Once the hacker got in, they enabled PGP with a random key to prevent the account recovery process from working. It took many, many months to get the account back after the attacker used the account to max out advertising spend. Meta did and does not care.

I realize now: why would they change anything? They made money off of the interaction

Re: The newest Instagram “exploit” is the goofiest I've seen

#489
post #471

HELP? I woke up to a bunch of notifications on my phone from the past 30-60 mins, indicating that people in in Montreal, Argentina, and Kathmandu had attempted to login to my account, and at least one had succeeded. I'm nowhere near any of those locations, and I didn't get any 2FA messages. I tapped Instagram, and it asked me for a new password, so I set one, and it just hung and did nothing. My Instagram, Facebook,…

You've gotta leverage your network and find friends you know who work at Meta/IG. I was able to get my account back without asking friends at IG (because mine wasn't fully disabled just password changed), but people I know who lost their accounts have had to ask multiple people very up the chain at IG to do some special restoration.

Re: The newest Instagram “exploit” is the goofiest I've seen

#490

I think login.gov needs to offer a way for others to use them. They have a pretty good system where you can bring your identification to the post office to get verified. Though I'm sure there are loopholes in the other options, but physically going to a federally owned building with cameras and providing ID has got to be one of the more secure ways to handle it.

I think that's the goal of Id.me?
Post reply on HN