Live data from Hacker News

Amazon's customer service backdoor

medium.com

11–20 of 366 posts

Re: Amazon's customer service backdoor

#11
post #4

Earlier quoted context omitted.

On the other hand, 2FA opens up the "I lost my phone" customer support channel which might be just as weak. For example, you can turn on 2FA for sending money via Bank of America's webpanel. As in, you log in with username/password and need 2FA for some restricted actions. Well, phone up customer support and they'll remove your 2FA if you can provide them some secret details... all of which are displayed on the webpa…

If they were following a script and the script were careful, saying "I lost my phone" would cause them to try to contact your phone, and when you answered and said you still had it, would put a fraud alert on the account and stop all further attempts to social engineer customer service. But most companies aren't anywhere near that careful.

Wouldn't that allow somebody who stole your phone to lock you out of your bank if they answered the call? Seems like that'd make a stressful situation potentially worse if thieves knew they could do that. Especially if they called from a number that's linked to the bank anywhere and something like Google's dialer surfaces who it is - your bank calling seems like a potential "maybe I can get more" for a thief so they might be inclined to answer and impersonate.

Re: Amazon's customer service backdoor

#12

Earlier quoted context omitted.

If they were following a script and the script were careful, saying "I lost my phone" would cause them to try to contact your phone, and when you answered and said you still had it, would put a fraud alert on the account and stop all further attempts to social engineer customer service. But most companies aren't anywhere near that careful.

Wouldn't that allow somebody who stole your phone to lock you out of your bank if they answered the call? Seems like that'd make a stressful situation potentially worse if thieves knew they could do that. Especially if they called from a number that's linked to the bank anywhere and something like Google's dialer surfaces who it is - your bank calling seems like a potential "maybe I can get more" for a thief so they…

[deleted]

Re: Amazon's customer service backdoor

#13
"The problem is, 9999 times out of 10000 support requests are legitimate, agents get trained to assume they’re legitimate. But in the 1 case they’re not, you can completely fuck someone over."

That's why nothing will change if these estimates are even in the right universe. Nobody wants to inconvenience the vast majority of customers to prevent a minuscule number of issues.

Re: Amazon's customer service backdoor

#14

Earlier quoted context omitted.

If they were following a script and the script were careful, saying "I lost my phone" would cause them to try to contact your phone, and when you answered and said you still had it, would put a fraud alert on the account and stop all further attempts to social engineer customer service. But most companies aren't anywhere near that careful.

Wouldn't that allow somebody who stole your phone to lock you out of your bank if they answered the call? Seems like that'd make a stressful situation potentially worse if thieves knew they could do that. Especially if they called from a number that's linked to the bank anywhere and something like Google's dialer surfaces who it is - your bank calling seems like a potential "maybe I can get more" for a thief so they…

I would prefer that my bank, if it detects fraudsters trying to pull some sort of trick involving my account, to freeze things until I show up and present ID. That's inconvenient, but clearly better than the alternative.

Re: Amazon's customer service backdoor

#16
The vast majority of services use email address to identify you so diversifying your email addresses helps a lot. I've known about every hack/info leak ahead of everyone else for that reason - I use a unique email for every service.

I also use different cards for the major online retailers / tech giants so knowing the last four digits from my Amazon account is useless to validate anything else (though this does require having several credit cards or debit cards).

Whois privacy is absolutely required.

Unfortunately if someone is determined enough, almost all ISPs, cell companies, retailers, etc will happily give them control of your entire digital life. You can only minimize the risk somewhat.

Re: Amazon's customer service backdoor

#17
Whois is great for social engineering attackers. You get a name, email, address, and the first service to attack.

Meanwhile, the ICANN is working around the clock to make it illegal for us to protect our personal information, and whois protection is becoming an increasingly niche service for registrars.

For example, gandi.net (and thus Amazon) doesn't hide your name when you have it turned on. By the time you find this out, it might occur to you to just type in a different name, but now you're violating ICANN policy. And it's already been scraped by any of those whois history websites.

Re: Amazon's customer service backdoor

#19
post #18

On your Amazon home page, go to: Your Account › Change Account Settings › Advanced Security Settings Turn on 2-step Verification. It won't completely solve social engineering, but it can't hurt.

If you had read the article you would know that they already had 2F turned on before the first intrusion and throughout the subsequent intrusions.

Re: Amazon's customer service backdoor

#20
post #17

Whois is great for social engineering attackers. You get a name, email, address, and the first service to attack. Meanwhile, the ICANN is working around the clock to make it illegal for us to protect our personal information, and whois protection is becoming an increasingly niche service for registrars. For example, gandi.net (and thus Amazon) doesn't hide your name when you have it turned on. By the time you find th…

I think the bigger problem is that public information like your name and address is sufficient for proving your identity. If we make whois information private, what about phone books, property records, direct mail databases, etc. etc.
Post reply on HN