A few years ago, someone stole my (previously deleted) Facebook account and support never followed up on my multiple complaints, even after uploading my ID/jumping through several hoops to prove my identity. Granted, this is just one case, but I'm not the only person with a story like this where I had a real issue and the response was crickets. Seems like it's representative of something systemic.
The newest Instagram “exploit” is the goofiest I've seen
521–528 of 528 posts
Re: The newest Instagram “exploit” is the goofiest I've seen
#522Re: The newest Instagram “exploit” is the goofiest I've seen
#523It's insane the AI has been provided the tooling to send emails to arbitrary addresses like that. Like, getting it to send a 2FA code at a user's request is one thing. But it should only be able to "hit a button" to send a 2FA email to the address attached to the account, all run with hand-written code. It shouldn't have access to the 2FA code itself, or the message subject, or body, or the recipient address, etc. Wh…
Re: The newest Instagram “exploit” is the goofiest I've seen
#524Earlier quoted context omitted.
This is actually what microsoft does for microsoft accounts If you recover a microsoft account / submit a ticket to recover it and provide correct information, the active email gets an email letting them know about the request You can deny it, or if you ignore it for 30 days the request goes through Seems to be the best system IMO
Someone has been trying to hack into my MSFT account for years. I constantly get the notifications. I can not see where they are trying from (unlike some other services that give you info about failed login attempts) nor add more security measures. I worry one day I will accidentally hit "Approve" or they will guess the 6 digit code they have tried thousands of times. The fun part is that you can't disable OneDrive.…
Re: The newest Instagram “exploit” is the goofiest I've seen
#525Earlier quoted context omitted.
fair enough, but what's the actual point of 2FA if it's so easy to override?
Personally it seems mostly about prizing the phone number out of my cold clammy hands. I recently tried to access my google account on a new browser install. Google did not believe my login/password was sufficient, and insisted on me surrendering my phone number: > To help keep your account safe, Google wants to make sure it’s really you trying to sign in [...] > Enter a phone number to get a text message with a veri…
Setting aside my opinion that it’s asinine to upload passkeys to the cloud :)