frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Instagram: Private Posts Exposed to Unauthenticated Requests

https://github.com/jatin-dot-py/instagram-private-bypass
2•jatin-dot-py•1h ago
Author here.

I released this disclosure today regarding a server-side authorization bypass I found in Instagram.

The Vulnerability: By sending a GET request to [instagram.com/](http://instagram.com/)<private_username> with specific mobile headers, the server returned the full polaris_timeline_connection JSON object containing direct CDN links to private posts, captions, and media. No login or follower relationship was required.

The Timeline & Contradiction:

- Oct 12: I reported the issue, with a video, poc script, and testing on my account [jatin.py](http://jatin.py/) - Oct 14: Meta requested specific vulnerable accounts to test. I provided a consenting third-party account where the POC script successfully extracted 30 private URLs. - Oct 16: The exploit stopped working on the accounts where it was previously working. - Oct 27: Meta closed the report as "Not Applicable," stating they "could not reproduce" the issue and that "no changes were made directly in response".

The Current State: While the exploit no longer functions on the accounts I tested, Meta officially maintains the bug never existed. They attributed the change in behavior to "infrastructure changes" or "unintended side effects".

Without a root cause analysis or acknowledgment from Meta, it is impossible to confirm if the underlying authorization failure was actually patched or if this was an accidental fix that could regress.

The repository contains the POC script poc.py , SHA256 hashes of the video evidence, and the full logs of the communication.

How to Preserve Your Writing for a Hundred Years

https://idiallo.com/blog/preserve-your-writing-for-a-hundred-years
1•foxfired•1m ago•0 comments

Time Management for Anarchists

https://jimmunroe.net/comics/pamphlets/time_management_for_anarchists/time_management_for_anarchi...
1•Refreeze5224•2m ago•0 comments

How do you evaluate a foundation model before you know what it's for?

https://galsapir.github.io/sparse-thoughts/2026/01/23/what-is-a-good-fm/
1•galsapir•3m ago•1 comments

Neko: History of a Software Pet (2022)

https://eliotakira.com/neko/
4•mifydev•3m ago•1 comments

Pinning Homebrew Dependencies

https://www.coryd.dev/posts/2026/pinning-homebrew-dependencies
1•cdrnsf•6m ago•0 comments

Unrolling the Codex Agent Loop

https://openai.com/index/unrolling-the-codex-agent-loop/
7•tosh•21m ago•1 comments

My Dive into the World of Telepathy

https://twitter.com/TylerAlterman/status/2014370228990308596
1•bilsbie•24m ago•1 comments

Idea to App Store in 6hrs with Revenue

https://www.youtube.com/watch?v=0CNXLEGM5aE
1•andrewjneumann•25m ago•2 comments

Alex Honnold Completes the Most Dangerous Free-Solo Ascent

https://www.nationalgeographic.com/adventure/article/most-dangerous-free-solo-climb-yosemite-nati...
2•FpUser•25m ago•2 comments

Trust, Delegation, and the Trap

https://metaist.com/blog/2026/01/coding-agents-interview.html
1•metaist•25m ago•0 comments

Show HN: Davia – Visual AI roleplay with image-based conversations

https://play.davia.ai/
3•ruben-davia•26m ago•0 comments

The new Alex Honnold climb

https://www.nytimes.com/2026/01/22/us/alex-honnold-netflix-taipei.html
1•paulpauper•27m ago•0 comments

Stack Overflow: The Architecture (2016 Edition)

https://nickcraver.com/blog/2016/02/17/stack-overflow-the-architecture-2016-edition/
1•tosh•27m ago•0 comments

Silver Museum Emptied in Overnight Heist

https://vblgoldfix.substack.com/p/silver-museum-emptied-in-massive
1•paulpauper•28m ago•0 comments

The GPT-2 moment for world models is here

https://odyssey.ml/the-gpt-2-moment-for-world-models
2•olivercameron•29m ago•0 comments

Elite overproduction, managerial feminism, and the death of mobility

https://www.radicallypragmatic.press/p/the-credential-cartel-how-the-professional
1•paulpauper•29m ago•0 comments

Mystery Prototaxites tower fossils may represent a newly discovered form of life

https://www.scientificamerican.com/article/mystery-prototaxites-tower-fossils-may-represent-a-new...
2•darth_avocado•30m ago•0 comments

Fun things to do with your VM/370 machine

https://rbanffy.github.io/fun-with-old-mainframes.github.io/fun-with-vm370.html
2•PaulHoule•34m ago•0 comments

Explainability Is a Product Feature

https://hashrocket.substack.com/p/explainability-is-a-product-feature
3•thehashrocket•35m ago•1 comments

Banned C++ Features in Chromium

https://chromium.googlesource.com/chromium/src/+/main/styleguide/c++/c++-features.md
2•szmarczak•36m ago•0 comments

Claude Code Is a Footgun

https://jonready.com/blog/posts/claude-code-is-a-footgun.html
4•mips_avatar•36m ago•1 comments

Compound Interest Calculator

https://www.investor.gov/financial-tools-calculators/calculators/compound-interest-calculator
1•kamaraju•38m ago•0 comments

Will AI Pet My Dog for Me?

https://eieio.games/blog/will-ai-pet-my-dog-for-me/
1•pavel_lishin•39m ago•0 comments

Monkey Selfie Copyright Dispute

https://en.wikipedia.org/wiki/Monkey_selfie_copyright_dispute
3•_vaporwave_•41m ago•0 comments

Rust 1.93.0

https://blog.rust-lang.org/2026/01/22/Rust-1.93.0/
2•birdculture•43m ago•0 comments

Show HN: Cryptography, JWT, and ASN1 Debuggers

https://crypto.qkation.com/
1•TheBestTvarynka•44m ago•0 comments

Show HN: Ctx – Context manager for Cloud,K8s VPNs, SSH tunnels, secret managers

https://github.com/vlebo/ctx
2•vlebo•45m ago•1 comments

Show HN: PolyMCP – Simplifying MCP Server Development and Agent Integration

2•justvugg•50m ago•0 comments

China tests hypergravity centrifuge that compresses time and space

https://www.futura-sciences.com/en/china-tests-the-unthinkable-with-a-centrifuge-that-compresses-...
4•walterbell•53m ago•1 comments

Show HN: Hexpiece – a daily chess coverage puzzle

https://hexpiece.com/
2•tothemoon•55m ago•0 comments