Private Instagram Posts Are Not So Private



Photos and videos posted to private accounts on Instagram and Facebook can be accessed, downloaded, and distributed publicly by friends and followers via source code
The hack — which works on Instagram stories as well — requires only a rudimentary understanding of HTML and a browser. It can be done in a handful of clicks. A user simply inspects the images and videos that are being loaded on the page and then pulls out the source URL. This public URL can then be shared with people who are not logged in to Instagram or do not follow that private user.
“The behavior described here is the same as taking a screenshot of a friend’s photo on Facebook and Instagram and sharing it with other people,” a Facebook spokesperson told BuzzFeed News. “It doesn’t give people access to a person’s private account.”
But it’s not exactly the same. There is a difference between being able to screenshot a private image from a webpage and being able to easily publicly share the URL of that private image with un-authenticated users.
The hack also works when images and videos in a private Instagram story, which are meant to last for only 24 hours, expire or are deleted. Linking URLs to content from stories seems to be valid for a couple days; links to photos on the feed remain live for potentially even longer. The same is true for stories that have purportedly expired.


































You must be logged in to post a comment.