Live data from Hacker News

Amazon's customer service backdoor

medium.com

81–90 of 366 posts

Re: Amazon's customer service backdoor

#81
post #54

Earlier quoted context omitted.

> On the other hand, 2FA opens up the "I lost my phone" customer support channel which might be just as weak. "I lost my phone" (or "my phone stopped working") does need some solution, though. The right way to handle "I lost my phone" seems like one of two possibilities: either come into a branch and provide legal identification matching what you used to open the account (and get "yourself" on camera doing so), or ha…

Shout out here to NearlyFreeSpeech who do this right. They give you a set of verification actions: You provide a scanned copy of a government-issued photo ID. You provide a scanned copy of a statement showing both the most recent deposit and a name and address matching one of your accounts. You complete SMS verification. (SMS must be previously configured.) You complete 2-factor verification. (2-factor auth must be p…

Nah. Them having a set of your scanned docs just means that if something like what happened to OPM happens, the attacker now conveniently have scanned copies of your docs.

So yeah, bad idea.

Re: Amazon's customer service backdoor

#82
post #72

Earlier quoted context omitted.

A related word of warning: Namecheap updated their registration page last year. Now, when you register a domain it tells you free Whoisguard is included, but it doesn't make it clear that it's disabled by default." Previously it just worked. Now you have to check another box to turn it on. This change makes no sense to me. (If you want free Whoisguard, why would you not want it turned on?) I was white-hot furious* wh…

Worse, they'll happily sell you Whoisguard for domains that don't support it. When you discover it's not usable, they'll give you a refund, then include it again in the next billing cycle. I switched to Namecheap based on recommendations here, and their previous stance on certain privacy issues, but I'm running out of alternatives.

I've always wondered why I never see pairNIC mentioned on the "everybody knows godaddy is garbage but who should I use to register domains?" threads on HN.

I have used them since they opened (2002) and never used anybody else after that, because I have never been dissatisfied. (I don't remember if the box is checked by default, but they definitely offer whois privacy, along with services like custom/dynamic DNS and some other stuff, at no extra charge).

Their site is kinda barebones and old-school, but there are real humans in the rare case you actually need one, and they've never done me wrong.

So for whatever that's worth: another recommendation on HN.

[1]: https://www.pairnic.com/about.html

Re: Amazon's customer service backdoor

#83
post #46
post #35

> services should allow me to easily create lots of aliases. Right now the best defense against social engineering seems to be my fastmail account which allows me to create 1 email address alias per service What you may want is a catch-all email - which lets you do @domain.com -> nmjohn@domain.com (where is everything besides already defined addresses) - that way you can make up emails on the fly without having to se…

Fastmail and Gmail support a local suffix of the form yourname+amazon@gmail.com. That's a plus character between the local name and local suffix. If you use a password manager, you can replace a predictable suffix like "amazon" with random hex value. Unfortunately, many sites borked their e-mail address validation and do not accept the plus character. (Amazon permits it.) Also, you'll ocassionally find a customer ser…

Also a lot of systems strip anything after the + now, especially spam systems.

Re: Amazon's customer service backdoor

#84
post #46

Earlier quoted context omitted.

Fastmail and Gmail support a local suffix of the form yourname+amazon@gmail.com. That's a plus character between the local name and local suffix. If you use a password manager, you can replace a predictable suffix like "amazon" with random hex value. Unfortunately, many sites borked their e-mail address validation and do not accept the plus character. (Amazon permits it.) Also, you'll ocassionally find a customer ser…

I fear that customer support might still accept emails without the suffix from the "customer". These are people, not robots, so if the address is close or in the vicinity of being correct, they might accept it. Same goes for the dot characters allowed in gmail addresses.

I strongly second this concern. I generate random strings as answers to my recovery questions. When I recently got asked one of the questions the support rep let out a sigh when asking (presumably because he saw the "crazy" answer) and then said "yeah yeah, alright" when I was about half way through the answer. That any company even suggests these insane security questions that anyone can trivially research is completely beyond me.

Re: Amazon's customer service backdoor

#85
post #35

> services should allow me to easily create lots of aliases. Right now the best defense against social engineering seems to be my fastmail account which allows me to create 1 email address alias per service What you may want is a catch-all email - which lets you do @domain.com -> nmjohn@domain.com (where is everything besides already defined addresses) - that way you can make up emails on the fly without having to se…

Make sure you keep a list somewhere of which site got which email address.

I used to do this too and it was great, but then when I started trying to recover accounts that were a few years old, I had a heck of a time remembering what email address I had actually given them in the first place!

Re: Amazon's customer service backdoor

#86
post #72

Earlier quoted context omitted.

A related word of warning: Namecheap updated their registration page last year. Now, when you register a domain it tells you free Whoisguard is included, but it doesn't make it clear that it's disabled by default." Previously it just worked. Now you have to check another box to turn it on. This change makes no sense to me. (If you want free Whoisguard, why would you not want it turned on?) I was white-hot furious* wh…

Worse, they'll happily sell you Whoisguard for domains that don't support it. When you discover it's not usable, they'll give you a refund, then include it again in the next billing cycle. I switched to Namecheap based on recommendations here, and their previous stance on certain privacy issues, but I'm running out of alternatives.

A happy NameCheap user for years, I have started switching away. Their horrid "modern" 40px padding everywhere bubbly redesign makes GoDaddy look good in comparison. A major pain to manage more than a couple of domains, and numerous user feedback seems to fall on deaf ears, e.g. [1][2][3][4]

Example weird feature: all domains are shown, even ones that you've let expire/sold years ago, and there is no way to hide them.

[1] https://community.namecheap.com/forums/viewtopic.php?f=10&t=...

[2] https://community.namecheap.com/forums/viewtopic.php?f=10&t=...

[3] https://community.namecheap.com/forums/viewtopic.php?f=10&t=...

[4] https://community.namecheap.com/forums/viewtopic.php?f=10&t=...

Re: Amazon's customer service backdoor

#87
post #52

How to stop this: 1. Get a friend's permission to "hack" into his Amazon account (or "hack your own account"). 2. Contact Amazon's customer service, try the same social engineering techniques that the OP documented. 3. Once you obtain some sensitive information from the account, scare the CS rep by saying: "Haha! I am actually not the customer. I am a journalist/hacker/whatever and wanted to see how easy it was to so…

If any journalist is interested in trying contact me (email in profile) and I will give you permission to use my account.

Re: Amazon's customer service backdoor

#89
post #33
post #17

Whois is great for social engineering attackers. You get a name, email, address, and the first service to attack. Meanwhile, the ICANN is working around the clock to make it illegal for us to protect our personal information, and whois protection is becoming an increasingly niche service for registrars. For example, gandi.net (and thus Amazon) doesn't hide your name when you have it turned on. By the time you find th…

They don't hide the name because you cannot hide the name while legally owning the domain yourself. Services that hide the name actually result in a company (e.g. "Domains by Proxy LLC") purchasing and holding domain ownership for you, which is a very different legal arrangement with different risks.

Treat a domain like money: if you want it held pseudonymously, you put it in the ownership of a shell corporation you control (through power of attorney to the board of directors), but don't own any equity in.

Re: Amazon's customer service backdoor

#90
post #37

If you own a home in the U.S., anybody already can get your address legally and easily from your county or district property appraiser's/assessor's website. Along with how much you paid for it, and when you bought it. So calling Amazon CS rep is a hard way to go about it. :)

The amount of available data varies by state. In TX, for example, sale prices are not disclosed.
Post reply on HN