Live data from Hacker News

The newest Instagram “exploit” is the goofiest I've seen

0xsid.com

521–528 of 528 posts

Re: The newest Instagram “exploit” is the goofiest I've seen

#521
I'm not surprised that a company with a such a broken system before AI has such an embarrassing issue with AI. There was barely a human touch before. Good luck to anyone who has an issue that isn't a gigantic public spectacle.

A few years ago, someone stole my (previously deleted) Facebook account and support never followed up on my multiple complaints, even after uploading my ID/jumping through several hoops to prove my identity. Granted, this is just one case, but I'm not the only person with a story like this where I had a real issue and the response was crickets. Seems like it's representative of something systemic.

Re: The newest Instagram “exploit” is the goofiest I've seen

#523
post #21

It's insane the AI has been provided the tooling to send emails to arbitrary addresses like that. Like, getting it to send a 2FA code at a user's request is one thing. But it should only be able to "hit a button" to send a 2FA email to the address attached to the account, all run with hand-written code. It shouldn't have access to the 2FA code itself, or the message subject, or body, or the recipient address, etc. Wh…

No big tech company hands write code by default now. You’d get PIP’d very quickly when your manager notices your PRs don’t have AI as a co-committer.

Re: The newest Instagram “exploit” is the goofiest I've seen

#524
post #373

Earlier quoted context omitted.

This is actually what microsoft does for microsoft accounts If you recover a microsoft account / submit a ticket to recover it and provide correct information, the active email gets an email letting them know about the request You can deny it, or if you ignore it for 30 days the request goes through Seems to be the best system IMO

Someone has been trying to hack into my MSFT account for years. I constantly get the notifications. I can not see where they are trying from (unlike some other services that give you info about failed login attempts) nor add more security measures. I worry one day I will accidentally hit "Approve" or they will guess the 6 digit code they have tried thousands of times. The fun part is that you can't disable OneDrive.…

I know they’re always changing things but I’m 99% sure one drive can be disabled with a checkbox either in “turn windows features on or off” or via group policy editor.

Re: The newest Instagram “exploit” is the goofiest I've seen

#525

Earlier quoted context omitted.

fair enough, but what's the actual point of 2FA if it's so easy to override?

Personally it seems mostly about prizing the phone number out of my cold clammy hands. I recently tried to access my google account on a new browser install. Google did not believe my login/password was sufficient, and insisted on me surrendering my phone number: > To help keep your account safe, Google wants to make sure it’s really you trying to sign in [...] > Enter a phone number to get a text message with a veri…

I deleted my Google account but I’m pretty sure you can configure a Passkey on the device that lets you log in, and have that passkey in a password manager you’ve logged into on the new device and that will be considered good enough.

Setting aside my opinion that it’s asinine to upload passkeys to the cloud :)

Post reply on HN