Live data from Hacker News

Amazon's customer service backdoor

medium.com

41–50 of 366 posts

Re: Amazon's customer service backdoor

#41
post #36
post #29

Earlier quoted context omitted.

While that's true, and perhaps even needs to be "the default", there really needs to be a way to say "Hey, I'm concerned, and am prepared to take responsibility for my own access credentials. I demand you categorically _do not_ disclose any of my personal information to anyone without a warrant or court order." And for that sort of demand to have appropriate legal teeth to ensure people collecting that data are suffi…

Startup idea: Whitehat Social Engineering (as a service). You authorise a whitehat team to attempt to social engineer all your discoverable internet presence/accounts to see what personal information their systems and/or customer service will disclose based on existing publicly available data. (I suspect legally that'd at least be on the white-ish side of grey rather than blackhat...) I wonder how long it'll be befor…

> Startup idea: Whitehat Social Engineering (as a service). You authorise a whitehat team to attempt to social engineer all your discoverable internet presence/accounts to see what personal information their systems and/or customer service will disclose based on existing publicly available data. (I suspect legally that'd at least be on the white-ish side of grey rather than blackhat...)

You'd need to take care to avoid getting people locked out of their accounts, but otherwise that sounds like a useful service for the small fraction of people who have a high enough profile that others may actively target them. I don't know if that represents a large enough target market for a sustainable business, but it might.

> I wonder how long it'll be before (or how long ago it became) sensible to register a shell company as the holder of any public record you're legally required to make public? It's probably much easier to roll your shell companies "registered address" if you discover it's been compromised than it is to move house every time Amazon's customer service goes "above and beyond" on your behalf to your attackers...

Depends on how easily you can register a shell company that doesn't itself have easily traceable public records of ownership. Little point in the indirection if you can then look up the shell company and its official owners and legal contacts.

Re: Amazon's customer service backdoor

#42
post #37

If you own a home in the U.S., anybody already can get your address legally and easily from your county or district property appraiser's/assessor's website. Along with how much you paid for it, and when you bought it. So calling Amazon CS rep is a hard way to go about it. :)

Although they probably can't get this information if all they know is your domain name.

Re: Amazon's customer service backdoor

#43
post #35

> services should allow me to easily create lots of aliases. Right now the best defense against social engineering seems to be my fastmail account which allows me to create 1 email address alias per service What you may want is a catch-all email - which lets you do @domain.com -> nmjohn@domain.com (where is everything besides already defined addresses) - that way you can make up emails on the fly without having to se…

You can approximate this with gmail using the plus sign. Like myaccount+label@gmail.com.

It's ignored for delivery, but gmail's filters can match on it in the to: address.

Re: Amazon's customer service backdoor

#44
post #35

> services should allow me to easily create lots of aliases. Right now the best defense against social engineering seems to be my fastmail account which allows me to create 1 email address alias per service What you may want is a catch-all email - which lets you do @domain.com -> nmjohn@domain.com (where is everything besides already defined addresses) - that way you can make up emails on the fly without having to se…

Note, though, that catch-all emails will also catch a ridiculous amount of spam. Creating each account name individually avoids that problem, at the cost of some extra trouble when registering a new service. An intermediate step that may work if you don't expect people to target you individually: have one or more required substrings for the email local part, and catch all mail to addresses containing that substring.

I created my catch-all on a subdomain. While it gives a problem with certain websites (don't consider it a valid e-mail address), I barely receive spam on it.

Re: Amazon's customer service backdoor

#45
post #4

Someone hacked my Amazon account once. I'm surprised they don't have 2-step verification.

On the other hand, 2FA opens up the "I lost my phone" customer support channel which might be just as weak. For example, you can turn on 2FA for sending money via Bank of America's webpanel. As in, you log in with username/password and need 2FA for some restricted actions. Well, phone up customer support and they'll remove your 2FA if you can provide them some secret details... all of which are displayed on the webpa…

> On the other hand, 2FA opens up the "I lost my phone" customer support channel which might be just as weak.

"I lost my phone" (or "my phone stopped working") does need some solution, though.

The right way to handle "I lost my phone" seems like one of two possibilities: either come into a branch and provide legal identification matching what you used to open the account (and get "yourself" on camera doing so), or have a token mailed to your physical address on file (which you cannot change at the same time as a lost phone claim).

Re: Amazon's customer service backdoor

#46
post #35

> services should allow me to easily create lots of aliases. Right now the best defense against social engineering seems to be my fastmail account which allows me to create 1 email address alias per service What you may want is a catch-all email - which lets you do @domain.com -> nmjohn@domain.com (where is everything besides already defined addresses) - that way you can make up emails on the fly without having to se…

Fastmail and Gmail support a local suffix of the form yourname+amazon@gmail.com. That's a plus character between the local name and local suffix. If you use a password manager, you can replace a predictable suffix like "amazon" with random hex value.

Unfortunately, many sites borked their e-mail address validation and do not accept the plus character. (Amazon permits it.) Also, you'll ocassionally find a customer service ticketing system that expects replies to come "From" your account's e-mail address. (Many mail clients can alter that header, but it's a pain.)

Re: Amazon's customer service backdoor

#47
This is exactly the same thing that let someone delete Mat Honan's (Wired author) accounts back in 2012:

Apple tech support gave the hackers access to my iCloud account. Amazon tech support gave them the ability to see a piece of information — a partial credit card number — that Apple used to release information.

http://www.wired.com/2012/08/apple-amazon-mat-honan-hacking/

Re: Amazon's customer service backdoor

#48
post #4

Earlier quoted context omitted.

On the other hand, 2FA opens up the "I lost my phone" customer support channel which might be just as weak. For example, you can turn on 2FA for sending money via Bank of America's webpanel. As in, you log in with username/password and need 2FA for some restricted actions. Well, phone up customer support and they'll remove your 2FA if you can provide them some secret details... all of which are displayed on the webpa…

> On the other hand, 2FA opens up the "I lost my phone" customer support channel which might be just as weak. "I lost my phone" (or "my phone stopped working") does need some solution, though. The right way to handle "I lost my phone" seems like one of two possibilities: either come into a branch and provide legal identification matching what you used to open the account (and get "yourself" on camera doing so), or ha…

> have a token mailed to your physical address on file

This is the worst for the customer point of view. Takes a long time.

Re: Amazon's customer service backdoor

#49
post #28
post #20

Earlier quoted context omitted.

I think the bigger problem is that public information like your name and address is sufficient for proving your identity. If we make whois information private, what about phone books, property records, direct mail databases, etc. etc.

If someone has your public name and address you're already at significant risk if you ever say anything controversial that gets attention. You're liable to being swatted, getting fake pizza orders, having people show up at your house, harassing you and much more. See Zoe Quinn, Brian Krebs, lots of less well known individuals, etc.

Which only proves your comment's parent's point even more.

{SWAT, pizza orders, etc} assume that the phone number that shows up on caller ID is authentication of the identity of the phone line on the other end. They could call back the number on caller ID to verify the original caller matched the person who picked up, but they don't.

Having knowledge of a Social Security number was assumed to be authentication, but it's increasingly obvious that such an authentication scheme is antiquated and was destined to fail from the beginning. When an identity thief can get a mortgage under my name with little more than credit bureau data on me, it costs only a little more than $15 to destroy my credit, my time, and my future because transactions don't have sufficient authentication.

These awfully designed authentication schemes will only magnify the problems as more companies (especially credit bureaus and data marketers) pass around data on me and make it easier for someone to buy it on demand.

Re: Amazon's customer service backdoor

#50
post #10

Earlier quoted context omitted.

If they were following a script and the script were careful, saying "I lost my phone" would cause them to try to contact your phone, and when you answered and said you still had it, would put a fraud alert on the account and stop all further attempts to social engineer customer service. But most companies aren't anywhere near that careful.

Many people (including me) don't answer from unknown numbers, so that wouldn't work.

A text message / email might though.

Just saying "Your account has been flagged for a lost/stolen phone which you use as your 2FA. Please contact support if this is not correct."

Post reply on HN