Live data from Hacker News

The newest Instagram “exploit” is the goofiest I've seen

0xsid.com

511–520 of 528 posts

Re: The newest Instagram “exploit” is the goofiest I've seen

#511

Earlier quoted context omitted.

100% agree. Agents should have the same permissions as the user prompting them, nothing else. No rules will stop agents of accessing data or modifying content if the agent have permissions to do it. That does not make the agent "safe" from the perspective that it still can and eventually will cause havoc, delete critical data, etc. But it makes the system safe as it isolates that user access and it is not worse that…

> Agents should have the same permissions as the user prompting them, nothing else. In user support work, it won’t make them very useful. User support is the fallback when self-serve tools and public documentation, the one you have permission to read and use directly, are not allowing a solution. By definition useful user support allows operations that are beyond the user’s permissions

> By definition useful user support allows operations that are beyond the user’s permissions

And this is where most of the vulnerabilities come FROM, AI or no AI.

You can't expect entry-level support workers to be responsible. Either you codify a process (which you can still do with an AI), or you become like a cell carrier, extremely vulnerable to SIM swapping attacks.

Re: The newest Instagram “exploit” is the goofiest I've seen

#512

Earlier quoted context omitted.

I love this thread. So: Useful support agents = can do things user doesn’t have permission for = are a vulnerable attack vector. Or they don’t have permission and are just glorified KB search.

Almost like AI support agents aren't viable

They're viable, you just have to think about them differently than how you think about support employees.

With humans, it's acceptable to have an "authenticate a customer" tool and a "reset the customer's password" tool as two separate applications. You can put in the manual that the latter can only be used after the former.

With agents, you can achieve the same outcome, but the constraint needs to be enforced by code, not job training and employee handbooks.

Re: The newest Instagram “exploit” is the goofiest I've seen

#513
post #491
post #482

Earlier quoted context omitted.

First off, this is shit position for you to be in. I perused your comment history as I often do with HNers. Some guy was predicting this exact situation in 2009 and your comment was that this would all sort itself out due to market forces. The market forces have spoken and the market lacks empathy. Hope you get your account back and then when you do you hop on to the the other side of the fence. We can all stand to l…

I'm in Canada where we can't even see or share news on Facebook

I'm sorry, what? What happens if you try to share news on Facebook? Does it bury it in the algorithm?

Re: The newest Instagram “exploit” is the goofiest I've seen

#514

Earlier quoted context omitted.

Never delete an account in protest of not liking a company, when you could instead give it away to a spam operation, which hurts the company even more.

Or sell it, and pocket some cash for yourself. If this person has a short or otherwise valuable username, they could sell it for possibly thousands or tens of thousands of dollars.

it's my name formatted firstmlast, nine characters long, and I'm not famous. I would absolutely sell it if it wasn't tied to me like that

Re: The newest Instagram “exploit” is the goofiest I've seen

#515
post #71

I'm sitting here wondering why the Chief Master Sergeant of the U.S. Space Force has an Instagram account to begin with. I understand it's the office itself, but still don't see the reason to expand the attack surface of government offices. X makes sense, Instagram, I'm not so sure as much

I see no difference between X and Instagram in this regard whatsoever. Think NASA, for example; it's also a government agency, and they are doing great job posting photos in Instagram, do you think anything is wrong with it?

I think one has historically been more text based vs image based. so for comms, i think X makes more sense. Space Force is under DoD so funding not much an issue. NASA, not so much. They have to fight for every nickle they get, so appealing to audiences via images/videos makes sense. I'm more so questioning why HE needed an account, instead of just the organization. Like Space Force posting makes more sense than him using it. I think what you're getting at is that the medium of communication has changed to social media. I get that. I just think it expands the attack surface for that org. Just have one account and post through that

Re: The newest Instagram “exploit” is the goofiest I've seen

#516

Earlier quoted context omitted.

You mean admin or Administrator ? Horrific, people should be jailed for cyberattacks when they carelessly just give out this word. The experiences I meant were mostly - password reset requests (admittedly, we had a protocol even then to strictly require a "physical signature", normally meaning Fax or internal snail mail) - medical protocols: don't wanna go into too much detail here, but: 1) Windows requires a lot of…

I support radiologies...I have seen things, patients wouldn't believe. MRI in helium off the shoulder of the CS student. I watched DICOMs corrupt in the dark near the PACS gateway. All those moments will be lost in time...like unsaved reports in rain. Time to reboot

Well done.

Maybe this is spoiling the effect, but for people who don't recognize it instantly:

> I've seen things you people wouldn't believe. Attack ships on fire off the shoulder of Orion. I watched C-beams glitter in the dark near the Tannhäuser Gate. All those moments will be lost in time, like tears in rain. Time to die.

https://en.wikipedia.org/wiki/Tears_in_rain_monologue

Re: The newest Instagram “exploit” is the goofiest I've seen

#517
post #513
post #491

Earlier quoted context omitted.

I'm in Canada where we can't even see or share news on Facebook

I'm sorry, what? What happens if you try to share news on Facebook? Does it bury it in the algorithm?

Just gives you an error if you have a link to a “news” site in your post.

> News content can't be shared in Canada In response to Canadian government legislation, news content can't be shared. Learn more (links to https://m.facebook.com/help/2579891418969617/)

https://cbc.radio-canada.ca/en/media-centre/blocking-of-news...

Re: The newest Instagram “exploit” is the goofiest I've seen

#518
post #325

Earlier quoted context omitted.

Probably not news to anyone here, but partial step in this direction is to put down vetted official contact details for the institutions. Every time someone calls to say there's a problem with your account, you ask for their name and/or extension number, because recontacting through the institution is your only good way of verifying their identity.

That works when the system is setup to allow that. I've encountered banks that don't have that setup — hilariously one bank felt the need to cold call me about my complaint about cold calling from unverifiable numbers. When I asked how I could call them on a verifiable number, they claimed I couldn't. :/

Bank-be-crazy Anecdote: I used a paper check to send money to a relative. My bank balance went down, but a week later my relative still hadn't received anything. Eventually the relative's bank said that something went wrong, and I thought: "Well, OK, I'll transfer it some other way when it gets returned to me." Except a month later it was still in limbo.

The kicker is that Bank X's website was simply... mathematically wrong. There weren't any transactions or notes to explain it, my balance was just magically smaller as the funds had never existed, last month's statement could not be reconciled with the current statement, etc. This was several thousand dollars.

I was eventually able to fix it with support, and they explained that Bank X had been bought by Bank Y, and somehow my old checkbook was still valid-enough to pull money out of my account, but somehow not valid-enough to finish the job nor to fail "cleanly."

I expressed to the representative that--while I had immense professional sympathy for the problems of mergers and system integrations--it's probably bad PR and perhaps a regulatory issue for any bank to lose track of customers' money and present them with what is either a false set of transactions or a false balance...

Post reply on HN