9 ms·
I was doxxed and harassed for my Insta account. Eventually one day it was just taken even though I had 2 factor auth on Insta and email. There is basically no r
by hansolosays 5y ago
I was doxxed and harassed for my Insta account. Eventually one day it was just taken even though I had 2 factor auth on Insta and email. There is basically no recourse.
Oh and it was given to one of mr beasts (from YouTube) helpers…
- echelon 5y agoWhat was your account? Can you prove it?
- hansolosays 5y agoInstagram.com/chucky I have old password reset emails and probably some screen shots somewhere
- echelon 5y agoPlease post this on Medium and submit it to HN. I'd be glad to help this get seen. You were robbed and deserve the handle back. And potentially compensation if an audit trail reveals an inside job.
- aspenmayer 5y agoWas it SMS based 2fa or did you use some other method?
- hansolosays 5y agoSMS 2fac to a google voice account with 2 fac
- latchkey 5y agoStill not secure.
- neatze 5y agoWhy ?
- ARCarr 5y agohttps://www.vice.com/en/article/y3g8wb/hacker-got-my-texts-16-dollars-sakari-netnumber https://www.vice.com/en/article/y3g8wb/hacker-got-my-texts-1...
- Hnrobert42 5y agoThat is SMS hijacking. That’s why @epitom3 says 2FA with an app.
- irq 5y agoAll SMS 2FA is insecure by design / default
- neatze 5y agoWith one big assumption attacker know you 2FA SMS number, it is not hard to have second number.
- nikanj 5y agoBecause you can keep dialing customer service with various stories. ”A shark ate my phone”. ”It’s my husbands account. A shark ate him and I want to post a funeral invitation on his page”. Just keep dialing, and you’ll find a compassionate and helpful person at some point
- gambiting 5y agoFor that reason I'm very happy I'm with Giffgaff in the UK - they literally don't have any telephone based support. If you need support you need to message them.....from your account online. Oh and any request to transfer the number takes at least a few days to go through, and you get notification that it's happening - same if you are being sent a replacement SIM. I imagine a number takeover attack would be very difficult due to this.
- Epitom3 5y agoalways use 12-18 digit random passwords and an authenticator app for 2fa.
- path411 5y agoIf you are using a random password generator, don't be doing 12 character lol. Do 20+
- wohfab 5y agoYeah, true. I do 64 on default, except the service doesn't allow it, then I'll do the max allowed characters.
- jspash 5y agoBe care with that! I've created accounts in the past with a 40+ random character password and everything went swimmingly. Until I tried to log in. Bzzzt! Couldn't get in. Apparently the password had a character limit that wasn't mentioned when signing up and was silently truncated server-side. A bit of investigation showed the <input> had maxlength="20" which is only enforced when typing characters. When using Javascript to fill a form will just ignore this attribute. https://codepen.io/jspash/pen/XWerVzY https://codepen.io/jspash/pen/XWerVzY
- zo1 5y agoI've noticed my bank doing shenanigans in order to prevent password managers from working well. It appears to be JS scripts that uppercase or lowercase the input field after posting but before the browser saves it. So it perpetually looks like I'm updating my password when I'm not. It literally just got populated by the browser.
- tossaway9000 5y agoWhat is the deal with banks being actively hostile to password managers? One bank specifically I have to deal with will: - Not allow you to paste a username/password (ctr+c/ctrl+v, right click disabled) - Lastpass autofill doesn't work - If the page loses focus, both user/password inputs are cleared, you get to start all over. There is also a very small subset of special characters that are allowed. If you do not reset your password as often as they'd like, you have to agree to waive any responsibility for any issues with your account before logging in. SMS 2FA required, there's no other 2FA option. After entering your 2FA code, the "proceed" and "cancel" buttons are the exact same shape and color and I've hit the wrong one multiple times, in which case there is also SMS 2FA cool down and you have to wait 15 mins to start all over again. It's absolute insanity and every time I have to login its an adventure.
- nabakin 5y agoThis account? https://www.instagram.com/chucky/ https://www.instagram.com/chucky/ Are you sure the account and username were given and not just the username?
- hansolosays 5y agoAccount was deleted and user name handed over
- jagged-chisel 5y agoDefinitely reeks of an inside job, if not an outright hack of the Instagram service.
- bredren 5y agoWas the account active?
- hansolosays 5y agoYes. I was using it when it was taken away. I was literally kicked out while logged in.
- whywhywhywhy 5y agoProbably inside job at IG tbh. Multiple reports over the years of desirable IG usernames being taken from legit users and handed to the friends of IG employees
- mitemte 5y agoPretty disgusting behaviour. Reminds me of this high profile case: https://www.businessinsider.com/andres-iniesta-claims-instagram-deleted-his-account-give-to-footballer-mistake-2015-7 https://www.businessinsider.com/andres-iniesta-claims-instag...
- quickthrower2 5y agoHow does this mafia operate inside IG? Is there an honour code “don’t steal an account that a superior has stolen already”
- resonious 5y agoI remember Facebook used to let any dev access the whole production DB as an effort to "remove red tape" and allow quick solutions to problems. That lack of red tape resulted in multiple stories of employees using that privilege to stalk people in real life.
- evgen 5y agoThis is why most of the FB security infrastructure is actually inward-facing. The actual infra is so complex that it would take an outsider quite a while to figure out how to get the data they might want. For an insider is it much easier to get improper access to data that you want or that someone might pay you for (real name or ip addr of a dissident, who your ex-girlfriend is now sleeping with, advising ad scammers on how to avoid detection, celebrity chats and private pics, etc.) The initial problems back in the day were the employee stalkers, but as the platform became more important the threat model changed to nation states compromising insiders. The red tape is not completely back, but as of five or so years ago there was a lot more monitoring of data access patterns and zero-trust gates on certain bits of data. OTOH, it meant that privacy and actual app security ended up falling into shit (a devsecops model where the head of privacy and security was someone completely unqualified for the role but ready to do whatever Zuck et al asked) but you win some and you lose some...
- ineedasername 5y agoFortunately, that's not something the current company Meta would allow to happen. That sounds like something that only Facebook would let fall through the cracks.
- anm89 5y agoI can't tell if you are joking but I desperately hope you are.
- csee 5y agoThat's an obvious joke.
- forty 5y agoA nice illustration of Poe's law :) I'm pretty sure it's a joke :D https://en.m.wikipedia.org/wiki/Poe%27s_law https://en.m.wikipedia.org/wiki/Poe%27s_law
- ineedasername 5y agoYes I should probably be more careful with an /s on some things. But that also seems to defeat part of the purpose of parody, automatically signalling that you don't need to think more about what I'm saying because I already told you. Sort of like explaining a joke makes it not funny (most times), signalling parody or sarcastic intent seems to dull the pointy end of it. The most extreme will say "yes, this person gets it, they're one of us!" But those a little further from that edge might take a step back and think "wait, is that really what I sound like, really the end conclusion of all this?" Anyway, I'm probably overthinking it.
- cutemonster 5y agoI've also been thinking a bit about that :-) And, it's happened in real life that I said something sarcastically, without indicating this, instead assuming the others would realize -- and instead they thought I was crazy. Maybe my voice sounded too serious
- ineedasername 5y agoWriteup details etc in a medium post & repost here to HN? Not much, but at least a little extra bad publicity for IG & Mrbeast/associates
- leeroyjenkins11 5y agoMy insta got hacked from not original Instagram password after I had linked my account to Facebook. They were able to login with my username and password, but I was able to get in via FB. They disabled my account because they were noticing my baccount doing botlike things.