Live data from Hacker News

The newest Instagram “exploit” is the goofiest I've seen

0xsid.com

1–10 of 528 posts

Re: The newest Instagram “exploit” is the goofiest I've seen

#2
>Once it looks like the request is coming from the correct region, they tell the Meta support AI that the account is hacked and ask it to send the verification codes to an arbitrary email address they control.

Dear Instagram, wtf. Why not send the reset to the account in question? Arbitrary email, wow.

Re: The newest Instagram “exploit” is the goofiest I've seen

#4
post #2

>Once it looks like the request is coming from the correct region, they tell the Meta support AI that the account is hacked and ask it to send the verification codes to an arbitrary email address they control. Dear Instagram, wtf. Why not send the reset to the account in question? Arbitrary email, wow.

Perhaps the attacker says that they email was also hacked and "this is my new email now". It sounds like this was a result of AI support and not a real person "And if you're part of the A/B tested accounts on which the AI support option is active, tough luck, you can't even turn it off."

Re: The newest Instagram “exploit” is the goofiest I've seen

#9
Support requests have always been the weakest link in the security chain for big corps. I've had accounts of mine turned over with 2FA disabled by humans before. I guess we shouldn't be surprised that the LLMs are doing the same thing.

The simple fact that 2FA can be removed by low level support staff drives me mad. It defeats the whole purpose of the process.

Post reply on HN