🏫 MY COURSES Sign-up for my FREE 3-Day C Course: https://lowlevel.academy 🧙♂️ HACK YOUR CAREER Wanna learn to hack? Join my new CTF platform: https://stacksmash.io ⌨️ KEYBOARD Like what you hear? Grab a Q5 at https://go.lowlevel.tv/keyboard 🔥COME HANG OUT Check out my other stuff: https://lowlevel.tv
ADVERTISEMENT
"tricking" You mean, asking.
a bit disappointed you didn't discuss if Rust could have prevented this
People with AI psychosis seem to be in charge of security features now
New LLM attack pattern: Prompt -injection-
why the hell is a AI chatbot given such privileged access. even employee doesn't have that.
"AI being shoved into assholes by assholes" is the most succinct description of our current times.
lawsuit should be slammed at them that's insane
As a 20+ year IT security vet having worked primarily in FinTech security companies and PCI-DSS security, these sorts of things makes me laugh and cry at the same time....
"Quantum computing will break all encryption and cyber security" little did we know... it was just 12 year old Jimmy asking a god damned chat bot
Letting AI do things at scale without oversight is the stupidest thing I've ever seen. Companies will do anything to cut costs than hire people.
This is not even a prompt injection! They literally build a tool for the chatbot that allows it to connect new emails to an account your NOT EVEN LOGGED IN and CHANGE IT'S PASSWORD, That's not prompt injection, that's just the most stupid vulnerabiliy I saw for years... Try to imagine this but without the chatbot layer, that's just insane
Dave: Open the pod bay door HAL. HAL: Okay.
It's like building a house full of locks, cameras and alarms. And then hiring a dumb butler that can open the door and let the burglars in.
The "fix" was just as stupid. The ability was removed from the UI...but the Account Recovery API is still up and available. So, you can actually still do this if you know the correct API calls.
You forgot the most important question: Would Rust Have Fixed This? My answer: yes, if those sloppy AI datacenters rust over and stop working, this would be fixed.
I don't think Two Factor Authentication is any kind of reliable defense against a development environment *this* stupid. It might work in this case, but there's absolutely nothing stopping Instagram from letting their chatbot turn off 2FA or set it to a different device like they already did with the email address.
Why does the AI even have the ability to reset the passwords? That's gross negligence, file a lawsuit
Meta is the type of company to give a monkey a loaded gun and then call gunshots uncharted, unfamiliar territory.
man they should have used rust
sounds like AI needs to go through the annual security training