The newest Instagram "exploit" is the goofiest I've seen
www.0xsid.com - 136 poäng - 26 kommentarer - 2460 sekunder sedan
Kommentarer (13)
- hbn - 451 sekunder sedanIt's insane the AI has been provided the tooling to send emails to arbitrary addresses like that. Like, getting it to send a 2FA code at a user's request is one thing. But it should only be able to "hit a button" to send a 2FA email to the address attached to the account, all run with hand-written code. It shouldn't have access to the 2FA code itself, or the message subject, or body, or the recipient address, etc.
Why did they give it any of that?!
- sosodev - 1524 sekunder sedanSupport requests have always been the weakest link in the security chain for big corps. I've had accounts of mine turned over with 2FA disabled by humans before. I guess we shouldn't be surprised that the LLMs are doing the same thing.
The simple fact that 2FA can be removed by low level support staff drives me mad. It defeats the whole purpose of the process.
- patmcc - 349 sekunder sedanAlways a bit illuminating to me how many exploits seem to so dumb I'd never even bother to attempt them. You're telling me I can just...ask for the password? And that works?
- pixl97 - 2030 sekunder sedan>Once it looks like the request is coming from the correct region, they tell the Meta support AI that the account is hacked and ask it to send the verification codes to an arbitrary email address they control.
Dear Instagram, wtf. Why not send the reset to the account in question? Arbitrary email, wow.
- avnfish - 1623 sekunder sedanThe implications of this are quite unsettling. Meta gave an agent privileged read AND write access to user accounts with no human in the loop?
- r721 - 269 sekunder sedanRelated discussion: https://news.ycombinator.com/item?id=48350239
- rd - 557 sekunder sedanThis happened to my instagram yesterday night while I was asleep. I don't have a particularly high value username (it's probably worth somewhere in between $300-500), but still incredibly frustrating to deal with. True to the article, I had already enabled 2FA last night and it didn't matter.
Thankfully, IG gave me the option of restoring my username when I logged back into my account today.
- tantalor - 743 sekunder sedanThey're just one tiny step from the AI emailing itself all the account recovery links, and locking out the entire userbase.
It might even do that preemptively if it thinks they're going to shut it down.
- king_zee - 877 sekunder sedanIf the LLM has knowledge of something, by design it can't help but divulge it. When will companies learn granting any kind of sensitive information access to an LLM is a moot point
- mtoner23 - 1938 sekunder sedanwow thats extremely embarassing for meta
- sleepybrett - 962 sekunder sedanThe only thing worse than a naive customer support rep is an even more naive customer support ai.
- WhyIsItAlwaysHN - 1640 sekunder sedan"Social engineering is all you need"
- Hugsbox - 1635 sekunder sedanJeez, straight up amateur shit. Genuinely hard to believe.
Nördnytt! 🤓