Live data from Hacker News

Amazon's customer service backdoor

medium.com

21–30 of 366 posts

Re: Amazon's customer service backdoor

#21
>Email services should allow me to easily create lots of aliases

I use blur from Abine.com, gives me a new email that forwards to my main, as many as I want, integrated with a browser plugin that barely adds time to signup.

Re: Amazon's customer service backdoor

#22
post #10

Earlier quoted context omitted.

If they were following a script and the script were careful, saying "I lost my phone" would cause them to try to contact your phone, and when you answered and said you still had it, would put a fraud alert on the account and stop all further attempts to social engineer customer service. But most companies aren't anywhere near that careful.

Many people (including me) don't answer from unknown numbers, so that wouldn't work.

It wouldn't work /for you/. But for people who do answer their phone, it would add protection.

Re: Amazon's customer service backdoor

#23
post #18

On your Amazon home page, go to: Your Account › Change Account Settings › Advanced Security Settings Turn on 2-step Verification. It won't completely solve social engineering, but it can't hurt.

If you had read the article you would know that they already had 2F turned on before the first intrusion and throughout the subsequent intrusions.

Sorry, I did skim it but must have missed it! :-}

In any case, I will leave my comment so that folks who come across this thread have a handy reference for turning on 2FA on their Amazon accounts.

Re: Amazon's customer service backdoor

#24
post #17

Whois is great for social engineering attackers. You get a name, email, address, and the first service to attack. Meanwhile, the ICANN is working around the clock to make it illegal for us to protect our personal information, and whois protection is becoming an increasingly niche service for registrars. For example, gandi.net (and thus Amazon) doesn't hide your name when you have it turned on. By the time you find th…

Yes, it's awful. Fortunately, at least one registrar (Google Domains) has free whois privacy for all registrations and I think they prompt you about it by default, too (to agree to some legal terms).

Re: Amazon's customer service backdoor

#25
post #18

On your Amazon home page, go to: Your Account › Change Account Settings › Advanced Security Settings Turn on 2-step Verification. It won't completely solve social engineering, but it can't hurt.

This was probably downvoted as it didn't help OP, however, this is really good advice. I'm doing it now - 2FA is enabled for all my work stuff but I hadn't gotten around to enabling it on Amazon. Didn't know they had it.

Re: Amazon's customer service backdoor

#26

"The problem is, 9999 times out of 10000 support requests are legitimate, agents get trained to assume they’re legitimate. But in the 1 case they’re not, you can completely fuck someone over." That's why nothing will change if these estimates are even in the right universe. Nobody wants to inconvenience the vast majority of customers to prevent a minuscule number of issues.

Came here to say just that. I did general customer support for a telco for a few months a while back, and most of the general public can't really deal with high security for personal information. If you were as strict with security as you should be, you'd be locking half of your subscribers out of their accounts eventually. This would create a phenomenal amount of follow-up paperwork for your company, meaning higher costs on your end and greater resentment on the customer's end - costs go up for you and customers head elsewhere.

It's why banks still use laughably short and simple PIN codes.

Re: Amazon's customer service backdoor

#27

"The problem is, 9999 times out of 10000 support requests are legitimate, agents get trained to assume they’re legitimate. But in the 1 case they’re not, you can completely fuck someone over." That's why nothing will change if these estimates are even in the right universe. Nobody wants to inconvenience the vast majority of customers to prevent a minuscule number of issues.

Until/unless we can find and implement a workable way to make this a problem Amazon is financially on-the-hook for, instead of Amazon (et al) customers.

I wonder what the PCI implications are if it's true that Amazon gave away his last four cc digits over the phone?

I wonder if there are applicable PII laws in his jurisdiction that'd have Amazon able to be held liable for disclosing his address? (I think there are here in Australia(1), but that doesn't mean regular Amazon customers have any chance of prevailing in court against Amazon's in-house legal team...)

(1) 6.67 of this says your address is "individually identifying data": http://www.alrc.gov.au/publications/6.%20The%20Privacy%20Act...

Re: Amazon's customer service backdoor

#28
post #20
post #17

Whois is great for social engineering attackers. You get a name, email, address, and the first service to attack. Meanwhile, the ICANN is working around the clock to make it illegal for us to protect our personal information, and whois protection is becoming an increasingly niche service for registrars. For example, gandi.net (and thus Amazon) doesn't hide your name when you have it turned on. By the time you find th…

I think the bigger problem is that public information like your name and address is sufficient for proving your identity. If we make whois information private, what about phone books, property records, direct mail databases, etc. etc.

If someone has your public name and address you're already at significant risk if you ever say anything controversial that gets attention. You're liable to being swatted, getting fake pizza orders, having people show up at your house, harassing you and much more. See Zoe Quinn, Brian Krebs, lots of less well known individuals, etc.

Re: Amazon's customer service backdoor

#29
post #26

"The problem is, 9999 times out of 10000 support requests are legitimate, agents get trained to assume they’re legitimate. But in the 1 case they’re not, you can completely fuck someone over." That's why nothing will change if these estimates are even in the right universe. Nobody wants to inconvenience the vast majority of customers to prevent a minuscule number of issues.

Came here to say just that. I did general customer support for a telco for a few months a while back, and most of the general public can't really deal with high security for personal information. If you were as strict with security as you should be, you'd be locking half of your subscribers out of their accounts eventually. This would create a phenomenal amount of follow-up paperwork for your company, meaning higher…

While that's true, and perhaps even needs to be "the default", there really needs to be a way to say "Hey, I'm concerned, and am prepared to take responsibility for my own access credentials. I demand you categorically _do not_ disclose any of my personal information to anyone without a warrant or court order." And for that sort of demand to have appropriate legal teeth to ensure people collecting that data are sufficiently motivated to act properly on it.

Re: Amazon's customer service backdoor

#30
post #17

Whois is great for social engineering attackers. You get a name, email, address, and the first service to attack. Meanwhile, the ICANN is working around the clock to make it illegal for us to protect our personal information, and whois protection is becoming an increasingly niche service for registrars. For example, gandi.net (and thus Amazon) doesn't hide your name when you have it turned on. By the time you find th…

A related word of warning: Namecheap updated their registration page last year.

Now, when you register a domain it tells you free Whoisguard is included, but it doesn't make it clear that it's disabled by default."

Previously it just worked. Now you have to check another box to turn it on.

This change makes no sense to me. (If you want free Whoisguard, why would you not want it turned on?)

I was white-hot furious* when I discovered that a handful of new domain regs had leaked my contact details, and I began getting the inevitable spam calls and texts.

Post reply on HN