Executive Summary
- Instagram’s AI-powered support system has a significant flaw.
- This flaw allows attackers to bypass 2FA and gain access to accounts.
- Experts are criticizing the implementation of this feature.
The Buzz Score
The Internet’s Verdict: 70% Hyped, 30% Skeptical
Expert Reactions
Security experts are shocked by the level of access granted to the AI system.
It’s insane the AI has been provided the tooling to send emails to arbitrary addresses like that. Like, getting it to send a 2FA code at a user’s request is one thing. But it should only be able to ‘hit a button’ to send a 2FA email to the address attached to the account, all run with hand-written code.
Others are drawing comparisons to past security incidents.
The first proper zero auth password reset I’ve seen in production. LinkedIn had one back in the day, before you got paid for discovering it I guess, never got a decent reply from them, but they eventually solved it.
There are concerns about the potential consequences of this exploit.
Support requests have always been a weak point in security, and this incident highlights the need for more robust measures.
Focus Keyword: Instagram Exploit