Earlier quoted context omitted.
On the other hand, 2FA opens up the "I lost my phone" customer support channel which might be just as weak. For example, you can turn on 2FA for sending money via Bank of America's webpanel. As in, you log in with username/password and need 2FA for some restricted actions. Well, phone up customer support and they'll remove your 2FA if you can provide them some secret details... all of which are displayed on the webpa…
If they were following a script and the script were careful, saying "I lost my phone" would cause them to try to contact your phone, and when you answered and said you still had it, would put a fraud alert on the account and stop all further attempts to social engineer customer service. But most companies aren't anywhere near that careful.
Amazon's customer service backdoor
31–40 of 366 posts
Re: Amazon's customer service backdoor
#32Earlier quoted context omitted.
Wouldn't that allow somebody who stole your phone to lock you out of your bank if they answered the call? Seems like that'd make a stressful situation potentially worse if thieves knew they could do that. Especially if they called from a number that's linked to the bank anywhere and something like Google's dialer surfaces who it is - your bank calling seems like a potential "maybe I can get more" for a thief so they…
I would prefer that my bank, if it detects fraudsters trying to pull some sort of trick involving my account, to freeze things until I show up and present ID. That's inconvenient, but clearly better than the alternative.
Re: Amazon's customer service backdoor
#33Whois is great for social engineering attackers. You get a name, email, address, and the first service to attack. Meanwhile, the ICANN is working around the clock to make it illegal for us to protect our personal information, and whois protection is becoming an increasingly niche service for registrars. For example, gandi.net (and thus Amazon) doesn't hide your name when you have it turned on. By the time you find th…
Services that hide the name actually result in a company (e.g. "Domains by Proxy LLC") purchasing and holding domain ownership for you, which is a very different legal arrangement with different risks.
Re: Amazon's customer service backdoor
#34Earlier quoted context omitted.
Wouldn't that allow somebody who stole your phone to lock you out of your bank if they answered the call? Seems like that'd make a stressful situation potentially worse if thieves knew they could do that. Especially if they called from a number that's linked to the bank anywhere and something like Google's dialer surfaces who it is - your bank calling seems like a potential "maybe I can get more" for a thief so they…
I would prefer that my bank, if it detects fraudsters trying to pull some sort of trick involving my account, to freeze things until I show up and present ID. That's inconvenient, but clearly better than the alternative.
And even if you make sure your bank has a local branches (which really, I've not gone to one in years, why would I need one?), what happens when you are on a trip, and your accounts are frozen? I've had my CCs frozen because the bank considered my expenses during a trip to be potentially fraudulent, but I could clear it up over the phone. Do we have to devolve back to carrying thousands in cash, like in the old days?
Security is always a tradeoff between avoiding fraud and being usable, and the tradeoffs that are great for some people in some situations are unacceptable for others.
Re: Amazon's customer service backdoor
#35What you may want is a catch-all email - which lets you do @domain.com -> nmjohn@domain.com (where is everything besides already defined addresses) - that way you can make up emails on the fly without having to setup the alias beforehand.
I've had that setup for 5 or 6 years now, and it works extremely well. A handy side-effect of this is it makes it easy to see which companies sell your email address to spammers when you included the name of the original company in the email you register with
Re: Amazon's customer service backdoor
#36Earlier quoted context omitted.
Came here to say just that. I did general customer support for a telco for a few months a while back, and most of the general public can't really deal with high security for personal information. If you were as strict with security as you should be, you'd be locking half of your subscribers out of their accounts eventually. This would create a phenomenal amount of follow-up paperwork for your company, meaning higher…
While that's true, and perhaps even needs to be "the default", there really needs to be a way to say "Hey, I'm concerned, and am prepared to take responsibility for my own access credentials. I demand you categorically _do not_ disclose any of my personal information to anyone without a warrant or court order." And for that sort of demand to have appropriate legal teeth to ensure people collecting that data are suffi…
I wonder how long it'll be before (or how long ago it became) sensible to register a shell company as the holder of any public record you're legally required to make public? It's probably much easier to roll your shell companies "registered address" if you discover it's been compromised than it is to move house every time Amazon's customer service goes "above and beyond" on your behalf to your attackers...
Re: Amazon's customer service backdoor
#37Re: Amazon's customer service backdoor
#38Earlier quoted context omitted.
Came here to say just that. I did general customer support for a telco for a few months a while back, and most of the general public can't really deal with high security for personal information. If you were as strict with security as you should be, you'd be locking half of your subscribers out of their accounts eventually. This would create a phenomenal amount of follow-up paperwork for your company, meaning higher…
While that's true, and perhaps even needs to be "the default", there really needs to be a way to say "Hey, I'm concerned, and am prepared to take responsibility for my own access credentials. I demand you categorically _do not_ disclose any of my personal information to anyone without a warrant or court order." And for that sort of demand to have appropriate legal teeth to ensure people collecting that data are suffi…
See also: people who don't understand that full-disk encryption means they lose their data if they forget their passphrase. That doesn't make full-disk encryption in any way bad, but if you train people to think that all accounts have a "forgotten password" option, they might get a nasty surprise.
Re: Amazon's customer service backdoor
#39> services should allow me to easily create lots of aliases. Right now the best defense against social engineering seems to be my fastmail account which allows me to create 1 email address alias per service What you may want is a catch-all email - which lets you do @domain.com -> nmjohn@domain.com (where is everything besides already defined addresses) - that way you can make up emails on the fly without having to se…
An intermediate step that may work if you don't expect people to target you individually: have one or more required substrings for the email local part, and catch all mail to addresses containing that substring.
Re: Amazon's customer service backdoor
#40Whois is great for social engineering attackers. You get a name, email, address, and the first service to attack. Meanwhile, the ICANN is working around the clock to make it illegal for us to protect our personal information, and whois protection is becoming an increasingly niche service for registrars. For example, gandi.net (and thus Amazon) doesn't hide your name when you have it turned on. By the time you find th…
I think the bigger problem is that public information like your name and address is sufficient for proving your identity. If we make whois information private, what about phone books, property records, direct mail databases, etc. etc.
It does make good sense to not use your primary "personal" email address in whois, nor your home address. PO Box rentals are fairly cheap and that's what I use for whois registrations.