Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
parable
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
31.
▲
by
parable
4mo ago
Meta has the capability to find out who authorized the change to this person's account. They log every change done in their administrator panel with a scary level of granularity, as far as I know, and they're able to take actions
32.
▲
by
parable
4mo ago
What about Hotmail's "eh" flaw of 1999? I'd say a two-letter password is practically "zero auth".
33.
▲
by
parable
4mo ago
While I agree with this, the hackers have an incentive to get in and out as soon as possible (at least, with accounts that have valuable usernames), because they want to swap the username over to an account they fully control before the rig
34.
▲
by
parable
4mo ago
This is how account recovery procedures used to work at a certain gaming company. They used to train support agents on what makes an account high-value and apply additional scrutiny to those recovery cases, while letting low-value accounts
35.
▲
by
parable
4mo ago
I've said this before, too. Several people I know have used various tricks and exploits to fix problems that support teams supposedly couldn't fix.
36.
▲
by
parable
4mo ago
You might be interested in reading the court case against Eric Meiggs and Declan Harrington, which includes charges against the two involving extortion and SIM swapping for usernames. See page 10: https://storage.courtlistener.co
37.
▲
by
parable
4mo ago
Those are just bots sending reset attempts to obtain your email or phone hint. I receive hundreds per year. All you need to send a password reset link is the account's username, which is, of course, publicly accessible.
38.
▲
by
parable
4mo ago
I'm inclined to believe it. As someone who studies this side of the Internet quite often and has seen equally trivial exploits stay active for weeks or months without being patched, I have no trouble believing this claim. I'm sure
39.
▲
by
parable
4mo ago
I actually quite like this solution. Beats asking users to add a "recovery selfie" (something Meta actually does now) - I'd rather choose 3 of my friends and have them approve some notification in-app. Seems like better UX an
40.
▲
by
parable
4mo ago
As a "young person" (under 30), my thoughts: There's a minority of us that do genuinely care, possibly more than most - so hiring someone from this minority would be helpful - but the vast majority of my peers don't care
41.
▲
by
parable
4mo ago
I'm glad they've seemingly made some sort of public statement on X and to media outlets, though they haven't emailed affected users yet. They have yet to acknowledge the recovery method disclosure vulnerability which was expl
42.
▲
by
parable
4mo ago
That's strange, the timing seems to be after the vulnerability was supposedly patched (roughly 4:30 PM PDT). Is your username short or valuable?
43.
▲
by
parable
4mo ago
As far as I'm concerned, failing to report breaches like this is illegal in some jurisdictions. They already didn't report the other email address disclosure bug that was widely abused, and they likely won't report this eithe
44.
▲
by
parable
4mo ago
My account was also stolen but my username wasn't changed. I had TFA enabled which likely saved me, but I'm hearing that can be bypassed too. I guess I was just lucky. The attackers rate limited my account so I couldn't send
45.
▲
by
parable
4mo ago
No, you're forced into the A/B test. I assume they'll enable this on every account at some point. Maybe there's a way to edit your account's flags via some undocumented API endpoint, but I'm not sure. Even if t
46.
▲
Tell HN: Meta's AI support feature allows Instagram accounts to be stolen
44 points
by
parable
4mo ago
|
11 comments
47.
▲
by
parable
5mo ago
Yes, all 8000+ institutions that use Canvas.
48.
▲
by
parable
7mo ago
This happens to me several times a month. I'm more concerned about account termination, in that if their Gmail account is terminated for some reason, mine would be as well due to it being the backup email address.
49.
▲
by
parable
8mo ago
This is actually a great analogy for why companies should take small data leaks seriously. A leak is a leak. Also, to clarify, I don't mean to appear as though I'm discrediting this leak or downplaying its severity. I only mention
50.
▲
by
parable
8mo ago
As far as I know, it only contains users who have made Substack profiles. Regular subscribers don't seem to be included, though I could be wrong.
51.
▲
by
parable
8mo ago
I'd edit my other reply to this comment but can't anymore. Here are the columns from the CSV file I've seen being shared around on forums, including the "internal metadata". This mostly boils down to full name on fi
52.
▲
by
parable
8mo ago
I'm fairly sure even mentioning the name of the forum isn't allowed on HN. It should be trivial to find it yourself, though. I also replied to someone else with the CSV headers if you're only trying to find out what exactly w
53.
▲
by
parable
8mo ago
I've seen the leaked data posted on forums. I'm assuming they're trying to minimize the bad PR from this incident by only doing what's legally required, which is to notify affected users. They're likely not obligate
54.
▲
by
parable
8mo ago
This is what I've been saying for years. I really could care less if my passwords were leaked. My phone number, on the other hand, is near-impossible to change. The fact that VoIP/virtual numbers are blacklisted from use almost ev
55.
▲
by
parable
8mo ago
The post where the data is available for download states that "the scraping method used was noisy and patched fast", leading one to believe that Substack was aware of the breach early on, yet they never alerted a single user until
56.
▲
by
parable
8mo ago
My apologies, I clearly missed that. If I could edit my post, I'd change it to "It seems that the website has been blocked in Finland in the past, though the block was later lifted."
57.
▲
by
parable
8mo ago
It seems that the website has been blocked in Finland since at least August of 2023, see https://news.ycombinator.com/item?id=37011955 .
58.
▲
by
parable
8mo ago
This likely means nothing, but the .is webmaster seems to have some sort of existing issue with Finland (where gyrovague is from), see https://news.ycombinator.com/item?id=37011955 . I thought I would point it out. Also, as
59.
▲
by
parable
8mo ago
There are several other posts made recently on the archive.is blog as well, some of which appear to be quite nonsensical or are otherwise irrelevant to the discourse at hand. They all appear to be LLM-generated. It's all very confusing
60.
▲
by
parable
8mo ago
They still seem to use past email addresses for marketing communications, despite the email address on file having been changed months ago. They definitely still keep old data around and fail to sync data between vendors. Whether that'
More ›