Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. New, by me: Meta has filed a data breach notice confirming that *thousands* of people had their Instagram accounts hacked as part of a months-long campaign abusing its Meta AI chatbot.

New, by me: Meta has filed a data breach notice confirming that *thousands* of people had their Instagram accounts hacked as part of a months-long campaign abusing its Meta AI chatbot.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
14 Indlæg 13 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • zackwhittaker@mastodon.socialZ This user is from outside of this forum
    zackwhittaker@mastodon.socialZ This user is from outside of this forum
    zackwhittaker@mastodon.social
    wrote sidst redigeret af
    #1

    New, by me: Meta has filed a data breach notice confirming that *thousands* of people had their Instagram accounts hacked as part of a months-long campaign abusing its Meta AI chatbot.

    Meta's breach notice shows the hacks were far more widespread than first thought.

    More: https://this.weekinsecurity.com/meta-confirms-thousands-of-instagram-accounts-were-hacked-by-abusing-its-ai-chatbot/

    Sign up/RSS for my free weekly newsletter: https://this.weekinsecurity.com/

    jwcph@helvede.netJ peachmcd@union.placeP inguin@nerdculture.deI aubreyclark@mastodon.socialA M 8 Replies Last reply
    1
    0
    • jwcph@helvede.netJ jwcph@helvede.net shared this topic
    • zackwhittaker@mastodon.socialZ zackwhittaker@mastodon.social

      New, by me: Meta has filed a data breach notice confirming that *thousands* of people had their Instagram accounts hacked as part of a months-long campaign abusing its Meta AI chatbot.

      Meta's breach notice shows the hacks were far more widespread than first thought.

      More: https://this.weekinsecurity.com/meta-confirms-thousands-of-instagram-accounts-were-hacked-by-abusing-its-ai-chatbot/

      Sign up/RSS for my free weekly newsletter: https://this.weekinsecurity.com/

      jwcph@helvede.netJ This user is from outside of this forum
      jwcph@helvede.netJ This user is from outside of this forum
      jwcph@helvede.net
      wrote sidst redigeret af
      #2

      @zackwhittaker Correction: It's not a bug & the AI wasn't "tricked". It worked exactly like it was supposed to - Meta just didn't care to consider that anyone could ask it to do so.

      It's a tech bug in the same sense that a person plowing a pickup truck through a kindergarten is the car's fault.

      - which also means the "bug" is "fixed" until somebody stumbles upon the next vulnerability, because the underlying issue, as the book said, is carelessness.

      sab@hostux.socialS 1 Reply Last reply
      0
      • zackwhittaker@mastodon.socialZ zackwhittaker@mastodon.social

        New, by me: Meta has filed a data breach notice confirming that *thousands* of people had their Instagram accounts hacked as part of a months-long campaign abusing its Meta AI chatbot.

        Meta's breach notice shows the hacks were far more widespread than first thought.

        More: https://this.weekinsecurity.com/meta-confirms-thousands-of-instagram-accounts-were-hacked-by-abusing-its-ai-chatbot/

        Sign up/RSS for my free weekly newsletter: https://this.weekinsecurity.com/

        peachmcd@union.placeP This user is from outside of this forum
        peachmcd@union.placeP This user is from outside of this forum
        peachmcd@union.place
        wrote sidst redigeret af
        #3

        @zackwhittaker

        ShOcKiNg 😏🙄

        1 Reply Last reply
        0
        • zackwhittaker@mastodon.socialZ zackwhittaker@mastodon.social

          New, by me: Meta has filed a data breach notice confirming that *thousands* of people had their Instagram accounts hacked as part of a months-long campaign abusing its Meta AI chatbot.

          Meta's breach notice shows the hacks were far more widespread than first thought.

          More: https://this.weekinsecurity.com/meta-confirms-thousands-of-instagram-accounts-were-hacked-by-abusing-its-ai-chatbot/

          Sign up/RSS for my free weekly newsletter: https://this.weekinsecurity.com/

          inguin@nerdculture.deI This user is from outside of this forum
          inguin@nerdculture.deI This user is from outside of this forum
          inguin@nerdculture.de
          wrote sidst redigeret af
          #4

          @zackwhittaker How the hell can this go on unnoticed for maybe six weeks? When some high-profile user has their account password changed that should have raised a lot of red flags.

          1 Reply Last reply
          0
          • zackwhittaker@mastodon.socialZ zackwhittaker@mastodon.social

            New, by me: Meta has filed a data breach notice confirming that *thousands* of people had their Instagram accounts hacked as part of a months-long campaign abusing its Meta AI chatbot.

            Meta's breach notice shows the hacks were far more widespread than first thought.

            More: https://this.weekinsecurity.com/meta-confirms-thousands-of-instagram-accounts-were-hacked-by-abusing-its-ai-chatbot/

            Sign up/RSS for my free weekly newsletter: https://this.weekinsecurity.com/

            aubreyclark@mastodon.socialA This user is from outside of this forum
            aubreyclark@mastodon.socialA This user is from outside of this forum
            aubreyclark@mastodon.social
            wrote sidst redigeret af
            #5

            @zackwhittaker This reminds me of a friend who tests AI systems for a living. Her job is basically to see whether an AI can be tricked into doing things it wasn't supposed to do.

            Is this the same general idea, or is it a completely different kind of vulnerability? 😲

            benroyce@mastodon.socialB dalias@hachyderm.ioD 2 Replies Last reply
            0
            • zackwhittaker@mastodon.socialZ zackwhittaker@mastodon.social

              New, by me: Meta has filed a data breach notice confirming that *thousands* of people had their Instagram accounts hacked as part of a months-long campaign abusing its Meta AI chatbot.

              Meta's breach notice shows the hacks were far more widespread than first thought.

              More: https://this.weekinsecurity.com/meta-confirms-thousands-of-instagram-accounts-were-hacked-by-abusing-its-ai-chatbot/

              Sign up/RSS for my free weekly newsletter: https://this.weekinsecurity.com/

              M This user is from outside of this forum
              M This user is from outside of this forum
              mrhcj@toot.community
              wrote sidst redigeret af
              #6

              @zackwhittaker Having ai do support tasks automatically was always a recipe for disaster

              1 Reply Last reply
              0
              • jwcph@helvede.netJ jwcph@helvede.net

                @zackwhittaker Correction: It's not a bug & the AI wasn't "tricked". It worked exactly like it was supposed to - Meta just didn't care to consider that anyone could ask it to do so.

                It's a tech bug in the same sense that a person plowing a pickup truck through a kindergarten is the car's fault.

                - which also means the "bug" is "fixed" until somebody stumbles upon the next vulnerability, because the underlying issue, as the book said, is carelessness.

                sab@hostux.socialS This user is from outside of this forum
                sab@hostux.socialS This user is from outside of this forum
                sab@hostux.social
                wrote sidst redigeret af
                #7

                Meta literally claims that "The tool itself worked properly and functioned as intended". Incredible.

                If your tool allows for people to hack your users by simply asking politely for it, reasonable people might argue that this tool is not, in fact, "working as intended".
                @jwcph @zackwhittaker

                jwcph@helvede.netJ benaveling@mastodon.worldB 2 Replies Last reply
                0
                • aubreyclark@mastodon.socialA aubreyclark@mastodon.social

                  @zackwhittaker This reminds me of a friend who tests AI systems for a living. Her job is basically to see whether an AI can be tricked into doing things it wasn't supposed to do.

                  Is this the same general idea, or is it a completely different kind of vulnerability? 😲

                  benroyce@mastodon.socialB This user is from outside of this forum
                  benroyce@mastodon.socialB This user is from outside of this forum
                  benroyce@mastodon.social
                  wrote sidst redigeret af
                  #8

                  @aubreyclark @zackwhittaker

                  it's really, really stupid

                  it's based on "AI is magic, yay! just turn it on, no problems, yay!":

                  "hackers abused a flaw in Meta's chatbot that allowed anyone to reset the password of any account that did not have two-factor authentication switched on. The bug tricked the chatbot into sending a verification code to an email address controlled by the hacker, rather than the account holder's email address on file, simply by asking it. The chatbot complied anyway"

                  1 Reply Last reply
                  0
                  • aubreyclark@mastodon.socialA aubreyclark@mastodon.social

                    @zackwhittaker This reminds me of a friend who tests AI systems for a living. Her job is basically to see whether an AI can be tricked into doing things it wasn't supposed to do.

                    Is this the same general idea, or is it a completely different kind of vulnerability? 😲

                    dalias@hachyderm.ioD This user is from outside of this forum
                    dalias@hachyderm.ioD This user is from outside of this forum
                    dalias@hachyderm.io
                    wrote sidst redigeret af
                    #9

                    @aubreyclark @zackwhittaker In this case, "the AI being able to be tricked into doing things it wasn't supposed to" isn't the problem. The problem is that it was given permission the same wrong permissions that human support staff were wrongly given, to bypass access controls on user accounts.

                    If this kind of access exists at all, it should require escalation to approval by multiple parties, long mandatory waiting periods for the account owner to see it's happening if they still have access, and something to impose financial and/or legal risk on the party requesting access if it turns out to be fraudulent. Not something human or slopbot support agent can do unilaterally.

                    1 Reply Last reply
                    0
                    • zackwhittaker@mastodon.socialZ zackwhittaker@mastodon.social

                      New, by me: Meta has filed a data breach notice confirming that *thousands* of people had their Instagram accounts hacked as part of a months-long campaign abusing its Meta AI chatbot.

                      Meta's breach notice shows the hacks were far more widespread than first thought.

                      More: https://this.weekinsecurity.com/meta-confirms-thousands-of-instagram-accounts-were-hacked-by-abusing-its-ai-chatbot/

                      Sign up/RSS for my free weekly newsletter: https://this.weekinsecurity.com/

                      berkan_dogan@mastodon.socialB This user is from outside of this forum
                      berkan_dogan@mastodon.socialB This user is from outside of this forum
                      berkan_dogan@mastodon.social
                      wrote sidst redigeret af
                      #10

                      @zackwhittaker I had the same reaction when I came across this screenshot last time: I wasn't surprised at all; Meta is a company that only gains power by holding onto data. It's no different from the original reason the concept of a company was used.

                      1 Reply Last reply
                      0
                      • zackwhittaker@mastodon.socialZ zackwhittaker@mastodon.social

                        New, by me: Meta has filed a data breach notice confirming that *thousands* of people had their Instagram accounts hacked as part of a months-long campaign abusing its Meta AI chatbot.

                        Meta's breach notice shows the hacks were far more widespread than first thought.

                        More: https://this.weekinsecurity.com/meta-confirms-thousands-of-instagram-accounts-were-hacked-by-abusing-its-ai-chatbot/

                        Sign up/RSS for my free weekly newsletter: https://this.weekinsecurity.com/

                        fullywoolly@mastodon.socialF This user is from outside of this forum
                        fullywoolly@mastodon.socialF This user is from outside of this forum
                        fullywoolly@mastodon.social
                        wrote sidst redigeret af
                        #11

                        @zackwhittaker I don't know if it is related but I got several texts and an email presumably from Facebook with codes and a reset link. I don't have access to the account because it was locked behind a 2fa I no longer have access to the generator. I went and tried to change the password just in case but kept getting thwarted by a prompt to submit my photo id. I never could get it to replicate the sending of codes or email. Very interesting this exploit came up after.

                        1 Reply Last reply
                        0
                        • sab@hostux.socialS sab@hostux.social

                          Meta literally claims that "The tool itself worked properly and functioned as intended". Incredible.

                          If your tool allows for people to hack your users by simply asking politely for it, reasonable people might argue that this tool is not, in fact, "working as intended".
                          @jwcph @zackwhittaker

                          jwcph@helvede.netJ This user is from outside of this forum
                          jwcph@helvede.netJ This user is from outside of this forum
                          jwcph@helvede.net
                          wrote sidst redigeret af jwcph@helvede.net
                          #12

                          @sab @zackwhittaker - or, more likely, that your intent fucking sucks.

                          1 Reply Last reply
                          0
                          • sab@hostux.socialS sab@hostux.social

                            Meta literally claims that "The tool itself worked properly and functioned as intended". Incredible.

                            If your tool allows for people to hack your users by simply asking politely for it, reasonable people might argue that this tool is not, in fact, "working as intended".
                            @jwcph @zackwhittaker

                            benaveling@mastodon.worldB This user is from outside of this forum
                            benaveling@mastodon.worldB This user is from outside of this forum
                            benaveling@mastodon.world
                            wrote sidst redigeret af
                            #13

                            The burglar entered via a door with no lock. The door functioned as intended.
                            @sab @jwcph @zackwhittaker

                            1 Reply Last reply
                            1
                            0
                            • zackwhittaker@mastodon.socialZ zackwhittaker@mastodon.social

                              New, by me: Meta has filed a data breach notice confirming that *thousands* of people had their Instagram accounts hacked as part of a months-long campaign abusing its Meta AI chatbot.

                              Meta's breach notice shows the hacks were far more widespread than first thought.

                              More: https://this.weekinsecurity.com/meta-confirms-thousands-of-instagram-accounts-were-hacked-by-abusing-its-ai-chatbot/

                              Sign up/RSS for my free weekly newsletter: https://this.weekinsecurity.com/

                              iveyline@mastodon.nzI This user is from outside of this forum
                              iveyline@mastodon.nzI This user is from outside of this forum
                              iveyline@mastodon.nz
                              wrote sidst redigeret af
                              #14

                              @zackwhittaker Another reason we should be very wary of AI.

                              1 Reply Last reply
                              0
                              Svar
                              • Svar som emne
                              Login for at svare
                              • Ældste til nyeste
                              • Nyeste til ældste
                              • Most Votes


                              • Log ind

                              • Har du ikke en konto? Tilmeld

                              • Login or register to search.
                              Powered by NodeBB Contributors
                              Graciously hosted by data.coop
                              • First post
                                Last post
                              0
                              • Hjem
                              • Seneste
                              • Etiketter
                              • Populære
                              • Verden
                              • Bruger
                              • Grupper