Earlier quoted context omitted.
On the other hand, 2FA opens up the "I lost my phone" customer support channel which might be just as weak. For example, you can turn on 2FA for sending money via Bank of America's webpanel. As in, you log in with username/password and need 2FA for some restricted actions. Well, phone up customer support and they'll remove your 2FA if you can provide them some secret details... all of which are displayed on the webpa…
If they were following a script and the script were careful, saying "I lost my phone" would cause them to try to contact your phone, and when you answered and said you still had it, would put a fraud alert on the account and stop all further attempts to social engineer customer service. But most companies aren't anywhere near that careful.
Amazon's customer service backdoor
11–20 of 366 posts
Re: Amazon's customer service backdoor
#12Earlier quoted context omitted.
If they were following a script and the script were careful, saying "I lost my phone" would cause them to try to contact your phone, and when you answered and said you still had it, would put a fraud alert on the account and stop all further attempts to social engineer customer service. But most companies aren't anywhere near that careful.
Wouldn't that allow somebody who stole your phone to lock you out of your bank if they answered the call? Seems like that'd make a stressful situation potentially worse if thieves knew they could do that. Especially if they called from a number that's linked to the bank anywhere and something like Google's dialer surfaces who it is - your bank calling seems like a potential "maybe I can get more" for a thief so they…
Re: Amazon's customer service backdoor
#13That's why nothing will change if these estimates are even in the right universe. Nobody wants to inconvenience the vast majority of customers to prevent a minuscule number of issues.
Re: Amazon's customer service backdoor
#14Earlier quoted context omitted.
If they were following a script and the script were careful, saying "I lost my phone" would cause them to try to contact your phone, and when you answered and said you still had it, would put a fraud alert on the account and stop all further attempts to social engineer customer service. But most companies aren't anywhere near that careful.
Wouldn't that allow somebody who stole your phone to lock you out of your bank if they answered the call? Seems like that'd make a stressful situation potentially worse if thieves knew they could do that. Especially if they called from a number that's linked to the bank anywhere and something like Google's dialer surfaces who it is - your bank calling seems like a potential "maybe I can get more" for a thief so they…
Re: Amazon's customer service backdoor
#15Re: Amazon's customer service backdoor
#16I also use different cards for the major online retailers / tech giants so knowing the last four digits from my Amazon account is useless to validate anything else (though this does require having several credit cards or debit cards).
Whois privacy is absolutely required.
Unfortunately if someone is determined enough, almost all ISPs, cell companies, retailers, etc will happily give them control of your entire digital life. You can only minimize the risk somewhat.
Re: Amazon's customer service backdoor
#17Meanwhile, the ICANN is working around the clock to make it illegal for us to protect our personal information, and whois protection is becoming an increasingly niche service for registrars.
For example, gandi.net (and thus Amazon) doesn't hide your name when you have it turned on. By the time you find this out, it might occur to you to just type in a different name, but now you're violating ICANN policy. And it's already been scraped by any of those whois history websites.
Re: Amazon's customer service backdoor
#18Your Account › Change Account Settings › Advanced Security Settings
Turn on 2-step Verification.
It won't completely solve social engineering, but it can't hurt.
Re: Amazon's customer service backdoor
#19On your Amazon home page, go to: Your Account › Change Account Settings › Advanced Security Settings Turn on 2-step Verification. It won't completely solve social engineering, but it can't hurt.
Re: Amazon's customer service backdoor
#20Whois is great for social engineering attackers. You get a name, email, address, and the first service to attack. Meanwhile, the ICANN is working around the clock to make it illegal for us to protect our personal information, and whois protection is becoming an increasingly niche service for registrars. For example, gandi.net (and thus Amazon) doesn't hide your name when you have it turned on. By the time you find th…