Hacker News new | ask | show | jobs
by ols 1428 days ago
I have a short instagram handle.

In 2016 someone figured out how to successfully repeatedly reset the password without my knowledge (via support maybe?). But since my e-mail was not compromised they didn't manage to change the password (or I was quick enough to set it again before they executed some second step of their scheme). I upgraded the security measures to 2FA and some insanely long password and it ceased.

Since November 2020 I am subjected to a brute-force attack - someone is trying to log in and I am getting an email notification about it each time. In the beginning it was once every five (!) minutes, later every 15 minutes. It went like this for over a year, now it seems to be throttled with emails arriving once every few days.

I am suprised that for such a long time Instagram didn't implement anything to counter such activities.

But luckily, no pizzas yet.

2 comments

You would think there would be some account-based flag for that.. Even something insane like 10 reset requests within 2 hours.

This should be standard stuff really!

Time to filter that email notification