Hacker News new | ask | show | jobs
by donmcronald 1467 days ago
> In other words, some accounts steal the pictures of real people and then send follow requests to friends, and try to get them to tap on links that can give the bad actor access to the friends' accounts or buy cryptocurrencies.

How would me sending them a picture change that when it says right in the email that:

> Even if this account does not contain and pictures of yourself or it represents somebody or something else, we can only help you when we receive a picture of you which fulfills these criteria.

So I can send Instagram a real picture and post someone else's picture all over the account.

3 comments

> How would me sending them a picture change that

It doesn't. It's just a barrier that inconveniences low effort scammers. Most scammers don't want to associate their face with their scams, and/or they aren't skilled enough to photoshop some other photo. Instagram is overwhelmed with garbage and it's logical to 80/20 rule as much as they can.

Are you sure that you can just send in a picture? Had this happen recently and I had to install the iOS app and then the app took video of me with the front facing camera.

I think my account was flagged because I follow a lot of people but I don't have a profile picture, never post anything, and I only use the web app (and sometimes from a "suspicious" OS named Linux) so basically I look like a follow-bot.

This impersonation is only really useful when one person can create multiple fake accounts.

If Facebook can simply run image comparison between the the face used and other accounts while knowing that picture isn’t copied from elsewhere because it includes their onetime key it could prevent duplicate accounts.

In practice I doubt it’s more effective than a new CAPTCHA.

Not to mention that scammers are relatively unlikely to want to show their face for ID purposes even if it's their only account (whereas ordinary people that want to join a service for posting pictures of themselves on the Internet generally don't mind), especially not when there's a wide world of other scams they can be getting on with that don't involve showing their face.