Y
Hacker News
new
|
ask
|
show
|
jobs
by
ivan_gammel
165 days ago
If mailboxes of some people were breached, those reset emails can be used to steal their Instagram accounts. So it can be some other breach being exploited, rather than a vulnerability in Instagram account itself.
4 comments
thunderbong
165 days ago
If my mailbox is breached, Instagram will be the least of my worries.
link
gloxkiqcza
165 days ago
Password reset emails usually contain a token that expires rather quickly so unless I’m missing something, this should be a non-issue.
link
Fire-Dragon-DoL
165 days ago
But you can generate such emails with a public username
link
SkyPuncher
165 days ago
Yep. And if you also have access to my email, you can already look at it to figure out exactly what services I have an account with.
If you’ve pawned my email address, you can get my user names, send email reset, etc, etc.
link
ipaddr
165 days ago
Or the email address you have already hacked into. Why both with the username at that point.
link
stackghost
165 days ago
It wouldn't be reported as an Instagram breach, in that case.
link
faust201
165 days ago
And that would also apply to everything. What else? Banks.
link