HACKER Q&A
📣 jph

Security bug in Threads-Instagram-Meta signup?


I'm trying Threads, and seem to hit a security issue. Is anyone here seeing similar? And/or how to diagnose this issue?

1. I install Threads on a typical Google Pixel. Threads successfully connects to my Instagram account.

2. The next time I use Instagram is on my Mac. There's a warning that says Meta suspects unauthorized access to my Instagram account, and directs me to change my password.

3. When I follow the directions, I see Meta account account settings. However, everything is in Swedish, which I don't speak, and don't use. There's no obvious way to change to English.

Questions: Is anyone else here getting these kinds of warnings? And does anyone here have backchannels at Threads/Instagram/Meta to let the security team know, and the i18n-l10n team know too?


  👤 toast0 Accepted Answer ✓
The best way to get in touch with their security team is probably the whitehat program:

https://m.facebook.com/whitehat

This doesn't specifically list Threads, but if I understand the branding, Threads is part of Instagram, so it should qualify.

These usually get triaged quickly, and then assigned to the appropriate teams, and there's at least internal follow through.