Live data from Hacker News

Amazon's customer service backdoor

medium.com

31–40 of 366 posts

Re: Amazon's customer service backdoor

#31
post #4

Earlier quoted context omitted.

On the other hand, 2FA opens up the "I lost my phone" customer support channel which might be just as weak. For example, you can turn on 2FA for sending money via Bank of America's webpanel. As in, you log in with username/password and need 2FA for some restricted actions. Well, phone up customer support and they'll remove your 2FA if you can provide them some secret details... all of which are displayed on the webpa…

If they were following a script and the script were careful, saying "I lost my phone" would cause them to try to contact your phone, and when you answered and said you still had it, would put a fraud alert on the account and stop all further attempts to social engineer customer service. But most companies aren't anywhere near that careful.

Just DoS the phone then?

Re: Amazon's customer service backdoor

#32

Earlier quoted context omitted.

Wouldn't that allow somebody who stole your phone to lock you out of your bank if they answered the call? Seems like that'd make a stressful situation potentially worse if thieves knew they could do that. Especially if they called from a number that's linked to the bank anywhere and something like Google's dialer surfaces who it is - your bank calling seems like a potential "maybe I can get more" for a thief so they…

I would prefer that my bank, if it detects fraudsters trying to pull some sort of trick involving my account, to freeze things until I show up and present ID. That's inconvenient, but clearly better than the alternative.

So... what about banks with no actual physical branches?

Re: Amazon's customer service backdoor

#33
post #17

Whois is great for social engineering attackers. You get a name, email, address, and the first service to attack. Meanwhile, the ICANN is working around the clock to make it illegal for us to protect our personal information, and whois protection is becoming an increasingly niche service for registrars. For example, gandi.net (and thus Amazon) doesn't hide your name when you have it turned on. By the time you find th…

They don't hide the name because you cannot hide the name while legally owning the domain yourself.

Services that hide the name actually result in a company (e.g. "Domains by Proxy LLC") purchasing and holding domain ownership for you, which is a very different legal arrangement with different risks.

Re: Amazon's customer service backdoor

#34

Earlier quoted context omitted.

Wouldn't that allow somebody who stole your phone to lock you out of your bank if they answered the call? Seems like that'd make a stressful situation potentially worse if thieves knew they could do that. Especially if they called from a number that's linked to the bank anywhere and something like Google's dialer surfaces who it is - your bank calling seems like a potential "maybe I can get more" for a thief so they…

I would prefer that my bank, if it detects fraudsters trying to pull some sort of trick involving my account, to freeze things until I show up and present ID. That's inconvenient, but clearly better than the alternative.

Banks would never do that, if just because they'd risk losing business in places where there's no local branches. Many of the national banks that offer the best conditions have no presence in a lot of metro areas.

And even if you make sure your bank has a local branches (which really, I've not gone to one in years, why would I need one?), what happens when you are on a trip, and your accounts are frozen? I've had my CCs frozen because the bank considered my expenses during a trip to be potentially fraudulent, but I could clear it up over the phone. Do we have to devolve back to carrying thousands in cash, like in the old days?

Security is always a tradeoff between avoiding fraud and being usable, and the tradeoffs that are great for some people in some situations are unacceptable for others.

Re: Amazon's customer service backdoor

#35
> services should allow me to easily create lots of aliases. Right now the best defense against social engineering seems to be my fastmail account which allows me to create 1 email address alias per service

What you may want is a catch-all email - which lets you do @domain.com -> nmjohn@domain.com (where is everything besides already defined addresses) - that way you can make up emails on the fly without having to setup the alias beforehand.

I've had that setup for 5 or 6 years now, and it works extremely well. A handy side-effect of this is it makes it easy to see which companies sell your email address to spammers when you included the name of the original company in the email you register with

Re: Amazon's customer service backdoor

#36
post #29
post #26

Earlier quoted context omitted.

Came here to say just that. I did general customer support for a telco for a few months a while back, and most of the general public can't really deal with high security for personal information. If you were as strict with security as you should be, you'd be locking half of your subscribers out of their accounts eventually. This would create a phenomenal amount of follow-up paperwork for your company, meaning higher…

While that's true, and perhaps even needs to be "the default", there really needs to be a way to say "Hey, I'm concerned, and am prepared to take responsibility for my own access credentials. I demand you categorically _do not_ disclose any of my personal information to anyone without a warrant or court order." And for that sort of demand to have appropriate legal teeth to ensure people collecting that data are suffi…

Startup idea: Whitehat Social Engineering (as a service). You authorise a whitehat team to attempt to social engineer all your discoverable internet presence/accounts to see what personal information their systems and/or customer service will disclose based on existing publicly available data. (I suspect legally that'd at least be on the white-ish side of grey rather than blackhat...)

I wonder how long it'll be before (or how long ago it became) sensible to register a shell company as the holder of any public record you're legally required to make public? It's probably much easier to roll your shell companies "registered address" if you discover it's been compromised than it is to move house every time Amazon's customer service goes "above and beyond" on your behalf to your attackers...

Re: Amazon's customer service backdoor

#37
If you own a home in the U.S., anybody already can get your address legally and easily from your county or district property appraiser's/assessor's website. Along with how much you paid for it, and when you bought it. So calling Amazon CS rep is a hard way to go about it. :)

Re: Amazon's customer service backdoor

#38
post #29
post #26

Earlier quoted context omitted.

Came here to say just that. I did general customer support for a telco for a few months a while back, and most of the general public can't really deal with high security for personal information. If you were as strict with security as you should be, you'd be locking half of your subscribers out of their accounts eventually. This would create a phenomenal amount of follow-up paperwork for your company, meaning higher…

While that's true, and perhaps even needs to be "the default", there really needs to be a way to say "Hey, I'm concerned, and am prepared to take responsibility for my own access credentials. I demand you categorically _do not_ disclose any of my personal information to anyone without a warrant or court order." And for that sort of demand to have appropriate legal teeth to ensure people collecting that data are suffi…

Unfortunately, far more people think they want that than can take full personal responsibility for it.

See also: people who don't understand that full-disk encryption means they lose their data if they forget their passphrase. That doesn't make full-disk encryption in any way bad, but if you train people to think that all accounts have a "forgotten password" option, they might get a nasty surprise.

Re: Amazon's customer service backdoor

#39
post #35

> services should allow me to easily create lots of aliases. Right now the best defense against social engineering seems to be my fastmail account which allows me to create 1 email address alias per service What you may want is a catch-all email - which lets you do @domain.com -> nmjohn@domain.com (where is everything besides already defined addresses) - that way you can make up emails on the fly without having to se…

Note, though, that catch-all emails will also catch a ridiculous amount of spam. Creating each account name individually avoids that problem, at the cost of some extra trouble when registering a new service.

An intermediate step that may work if you don't expect people to target you individually: have one or more required substrings for the email local part, and catch all mail to addresses containing that substring.

Re: Amazon's customer service backdoor

#40
post #20
post #17

Whois is great for social engineering attackers. You get a name, email, address, and the first service to attack. Meanwhile, the ICANN is working around the clock to make it illegal for us to protect our personal information, and whois protection is becoming an increasingly niche service for registrars. For example, gandi.net (and thus Amazon) doesn't hide your name when you have it turned on. By the time you find th…

I think the bigger problem is that public information like your name and address is sufficient for proving your identity. If we make whois information private, what about phone books, property records, direct mail databases, etc. etc.

Agree. Your contact info in whois adds little to any number of other public records that will contain your name, address, phone number.

It does make good sense to not use your primary "personal" email address in whois, nor your home address. PO Box rentals are fairly cheap and that's what I use for whois registrations.

Post reply on HN