Hacker News new | ask | show | jobs
by ermis 193 days ago
I was sharing an old Turkish pop track on Spotify (“Füsun Önal – Ah Nerede”, 2004). Instead of the expected album art, Instagram showed a completely unrelated person’s Instagram profile screenshot, basically a silent injected ad.

I dug into how Spotify generates Instagram story assets and mapped possible attack vectors in the legacy catalog pipeline. Curious if anyone’s seen similar behavior with older metadata ingestion paths.