Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. New, by me: Meta has filed a data breach notice confirming that *thousands* of people had their Instagram accounts hacked as part of a months-long campaign abusing its Meta AI chatbot.

New, by me: Meta has filed a data breach notice confirming that *thousands* of people had their Instagram accounts hacked as part of a months-long campaign abusing its Meta AI chatbot.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
14 Indlæg 13 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • zackwhittaker@mastodon.socialZ zackwhittaker@mastodon.social

    New, by me: Meta has filed a data breach notice confirming that *thousands* of people had their Instagram accounts hacked as part of a months-long campaign abusing its Meta AI chatbot.

    Meta's breach notice shows the hacks were far more widespread than first thought.

    More: https://this.weekinsecurity.com/meta-confirms-thousands-of-instagram-accounts-were-hacked-by-abusing-its-ai-chatbot/

    Sign up/RSS for my free weekly newsletter: https://this.weekinsecurity.com/

    inguin@nerdculture.deI This user is from outside of this forum
    inguin@nerdculture.deI This user is from outside of this forum
    inguin@nerdculture.de
    wrote sidst redigeret af
    #4

    @zackwhittaker How the hell can this go on unnoticed for maybe six weeks? When some high-profile user has their account password changed that should have raised a lot of red flags.

    1 Reply Last reply
    0
    • zackwhittaker@mastodon.socialZ zackwhittaker@mastodon.social

      New, by me: Meta has filed a data breach notice confirming that *thousands* of people had their Instagram accounts hacked as part of a months-long campaign abusing its Meta AI chatbot.

      Meta's breach notice shows the hacks were far more widespread than first thought.

      More: https://this.weekinsecurity.com/meta-confirms-thousands-of-instagram-accounts-were-hacked-by-abusing-its-ai-chatbot/

      Sign up/RSS for my free weekly newsletter: https://this.weekinsecurity.com/

      aubreyclark@mastodon.socialA This user is from outside of this forum
      aubreyclark@mastodon.socialA This user is from outside of this forum
      aubreyclark@mastodon.social
      wrote sidst redigeret af
      #5

      @zackwhittaker This reminds me of a friend who tests AI systems for a living. Her job is basically to see whether an AI can be tricked into doing things it wasn't supposed to do.

      Is this the same general idea, or is it a completely different kind of vulnerability? 😲

      benroyce@mastodon.socialB dalias@hachyderm.ioD 2 Replies Last reply
      0
      • zackwhittaker@mastodon.socialZ zackwhittaker@mastodon.social

        New, by me: Meta has filed a data breach notice confirming that *thousands* of people had their Instagram accounts hacked as part of a months-long campaign abusing its Meta AI chatbot.

        Meta's breach notice shows the hacks were far more widespread than first thought.

        More: https://this.weekinsecurity.com/meta-confirms-thousands-of-instagram-accounts-were-hacked-by-abusing-its-ai-chatbot/

        Sign up/RSS for my free weekly newsletter: https://this.weekinsecurity.com/

        M This user is from outside of this forum
        M This user is from outside of this forum
        mrhcj@toot.community
        wrote sidst redigeret af
        #6

        @zackwhittaker Having ai do support tasks automatically was always a recipe for disaster

        1 Reply Last reply
        0
        • jwcph@helvede.netJ jwcph@helvede.net

          @zackwhittaker Correction: It's not a bug & the AI wasn't "tricked". It worked exactly like it was supposed to - Meta just didn't care to consider that anyone could ask it to do so.

          It's a tech bug in the same sense that a person plowing a pickup truck through a kindergarten is the car's fault.

          - which also means the "bug" is "fixed" until somebody stumbles upon the next vulnerability, because the underlying issue, as the book said, is carelessness.

          sab@hostux.socialS This user is from outside of this forum
          sab@hostux.socialS This user is from outside of this forum
          sab@hostux.social
          wrote sidst redigeret af
          #7

          Meta literally claims that "The tool itself worked properly and functioned as intended". Incredible.

          If your tool allows for people to hack your users by simply asking politely for it, reasonable people might argue that this tool is not, in fact, "working as intended".
          @jwcph @zackwhittaker

          jwcph@helvede.netJ benaveling@mastodon.worldB 2 Replies Last reply
          0
          • aubreyclark@mastodon.socialA aubreyclark@mastodon.social

            @zackwhittaker This reminds me of a friend who tests AI systems for a living. Her job is basically to see whether an AI can be tricked into doing things it wasn't supposed to do.

            Is this the same general idea, or is it a completely different kind of vulnerability? 😲

            benroyce@mastodon.socialB This user is from outside of this forum
            benroyce@mastodon.socialB This user is from outside of this forum
            benroyce@mastodon.social
            wrote sidst redigeret af
            #8

            @aubreyclark @zackwhittaker

            it's really, really stupid

            it's based on "AI is magic, yay! just turn it on, no problems, yay!":

            "hackers abused a flaw in Meta's chatbot that allowed anyone to reset the password of any account that did not have two-factor authentication switched on. The bug tricked the chatbot into sending a verification code to an email address controlled by the hacker, rather than the account holder's email address on file, simply by asking it. The chatbot complied anyway"

            1 Reply Last reply
            0
            • aubreyclark@mastodon.socialA aubreyclark@mastodon.social

              @zackwhittaker This reminds me of a friend who tests AI systems for a living. Her job is basically to see whether an AI can be tricked into doing things it wasn't supposed to do.

              Is this the same general idea, or is it a completely different kind of vulnerability? 😲

              dalias@hachyderm.ioD This user is from outside of this forum
              dalias@hachyderm.ioD This user is from outside of this forum
              dalias@hachyderm.io
              wrote sidst redigeret af
              #9

              @aubreyclark @zackwhittaker In this case, "the AI being able to be tricked into doing things it wasn't supposed to" isn't the problem. The problem is that it was given permission the same wrong permissions that human support staff were wrongly given, to bypass access controls on user accounts.

              If this kind of access exists at all, it should require escalation to approval by multiple parties, long mandatory waiting periods for the account owner to see it's happening if they still have access, and something to impose financial and/or legal risk on the party requesting access if it turns out to be fraudulent. Not something human or slopbot support agent can do unilaterally.

              1 Reply Last reply
              0
              • zackwhittaker@mastodon.socialZ zackwhittaker@mastodon.social

                New, by me: Meta has filed a data breach notice confirming that *thousands* of people had their Instagram accounts hacked as part of a months-long campaign abusing its Meta AI chatbot.

                Meta's breach notice shows the hacks were far more widespread than first thought.

                More: https://this.weekinsecurity.com/meta-confirms-thousands-of-instagram-accounts-were-hacked-by-abusing-its-ai-chatbot/

                Sign up/RSS for my free weekly newsletter: https://this.weekinsecurity.com/

                berkan_dogan@mastodon.socialB This user is from outside of this forum
                berkan_dogan@mastodon.socialB This user is from outside of this forum
                berkan_dogan@mastodon.social
                wrote sidst redigeret af
                #10

                @zackwhittaker I had the same reaction when I came across this screenshot last time: I wasn't surprised at all; Meta is a company that only gains power by holding onto data. It's no different from the original reason the concept of a company was used.

                1 Reply Last reply
                0
                • zackwhittaker@mastodon.socialZ zackwhittaker@mastodon.social

                  New, by me: Meta has filed a data breach notice confirming that *thousands* of people had their Instagram accounts hacked as part of a months-long campaign abusing its Meta AI chatbot.

                  Meta's breach notice shows the hacks were far more widespread than first thought.

                  More: https://this.weekinsecurity.com/meta-confirms-thousands-of-instagram-accounts-were-hacked-by-abusing-its-ai-chatbot/

                  Sign up/RSS for my free weekly newsletter: https://this.weekinsecurity.com/

                  fullywoolly@mastodon.socialF This user is from outside of this forum
                  fullywoolly@mastodon.socialF This user is from outside of this forum
                  fullywoolly@mastodon.social
                  wrote sidst redigeret af
                  #11

                  @zackwhittaker I don't know if it is related but I got several texts and an email presumably from Facebook with codes and a reset link. I don't have access to the account because it was locked behind a 2fa I no longer have access to the generator. I went and tried to change the password just in case but kept getting thwarted by a prompt to submit my photo id. I never could get it to replicate the sending of codes or email. Very interesting this exploit came up after.

                  1 Reply Last reply
                  0
                  • sab@hostux.socialS sab@hostux.social

                    Meta literally claims that "The tool itself worked properly and functioned as intended". Incredible.

                    If your tool allows for people to hack your users by simply asking politely for it, reasonable people might argue that this tool is not, in fact, "working as intended".
                    @jwcph @zackwhittaker

                    jwcph@helvede.netJ This user is from outside of this forum
                    jwcph@helvede.netJ This user is from outside of this forum
                    jwcph@helvede.net
                    wrote sidst redigeret af jwcph@helvede.net
                    #12

                    @sab @zackwhittaker - or, more likely, that your intent fucking sucks.

                    1 Reply Last reply
                    0
                    • sab@hostux.socialS sab@hostux.social

                      Meta literally claims that "The tool itself worked properly and functioned as intended". Incredible.

                      If your tool allows for people to hack your users by simply asking politely for it, reasonable people might argue that this tool is not, in fact, "working as intended".
                      @jwcph @zackwhittaker

                      benaveling@mastodon.worldB This user is from outside of this forum
                      benaveling@mastodon.worldB This user is from outside of this forum
                      benaveling@mastodon.world
                      wrote sidst redigeret af
                      #13

                      The burglar entered via a door with no lock. The door functioned as intended.
                      @sab @jwcph @zackwhittaker

                      1 Reply Last reply
                      1
                      0
                      • zackwhittaker@mastodon.socialZ zackwhittaker@mastodon.social

                        New, by me: Meta has filed a data breach notice confirming that *thousands* of people had their Instagram accounts hacked as part of a months-long campaign abusing its Meta AI chatbot.

                        Meta's breach notice shows the hacks were far more widespread than first thought.

                        More: https://this.weekinsecurity.com/meta-confirms-thousands-of-instagram-accounts-were-hacked-by-abusing-its-ai-chatbot/

                        Sign up/RSS for my free weekly newsletter: https://this.weekinsecurity.com/

                        iveyline@mastodon.nzI This user is from outside of this forum
                        iveyline@mastodon.nzI This user is from outside of this forum
                        iveyline@mastodon.nz
                        wrote sidst redigeret af
                        #14

                        @zackwhittaker Another reason we should be very wary of AI.

                        1 Reply Last reply
                        0
                        Svar
                        • Svar som emne
                        Login for at svare
                        • Ældste til nyeste
                        • Nyeste til ældste
                        • Most Votes


                        • Log ind

                        • Har du ikke en konto? Tilmeld

                        • Login or register to search.
                        Powered by NodeBB Contributors
                        Graciously hosted by data.coop
                        • First post
                          Last post
                        0
                        • Hjem
                        • Seneste
                        • Etiketter
                        • Populære
                        • Verden
                        • Bruger
                        • Grupper