Amazon's customer service backdoor
91–100 of 366 posts
Re: Amazon's customer service backdoor
#92Whois is great for social engineering attackers. You get a name, email, address, and the first service to attack. Meanwhile, the ICANN is working around the clock to make it illegal for us to protect our personal information, and whois protection is becoming an increasingly niche service for registrars. For example, gandi.net (and thus Amazon) doesn't hide your name when you have it turned on. By the time you find th…
They don't hide the name because you cannot hide the name while legally owning the domain yourself. Services that hide the name actually result in a company (e.g. "Domains by Proxy LLC") purchasing and holding domain ownership for you, which is a very different legal arrangement with different risks.
Besides, my primary domain is my full name dot com, so anyone who has any interest in the domain already knows my name.
Re: Amazon's customer service backdoor
#93Earlier quoted context omitted.
I think the bigger problem is that public information like your name and address is sufficient for proving your identity. If we make whois information private, what about phone books, property records, direct mail databases, etc. etc.
Agree. Your contact info in whois adds little to any number of other public records that will contain your name, address, phone number. It does make good sense to not use your primary "personal" email address in whois, nor your home address. PO Box rentals are fairly cheap and that's what I use for whois registrations.
Re: Amazon's customer service backdoor
#94Any recommendation what one (as a customer of Amazon) can do today ? 2FA does not help here as someone goes through support channel which looks like bypasses 2FA Also concerned if the same trick can be applied to Amazon Cloud services, as there one can also run up a big bill pretty quickly.
Using a unique email address.
Using a unique physical address (both for my account details and for my delivery addresses).
Use a unique credit card (I'd probably get a refillable prepaid gift card, and set up some auto topup to ensure it's got my expected monthly Amazon bill available as "credit", but not much more).
I'd probably move any AWS billing to a different Amazon account.
If I were more paranoid (or being actively targeted), I'd probably also try to go unique on _everything_ I tell Amazon; phone numbers, different city/state/zipcode (as well as street address), company name, website url, alternate contacts - then I'd set up "Security questions" with unguessable questions/answers (perhaps diceware/xkcd style "correct horse battery staple" type ones, that a CS rep could easily read out and verify - rather than a base64 GUID...).
Not that I trust the "security questions", but if Amazon lets you use freeform questions as well as answers, it might help to make your first security question "Have you noticed this account has two factor authentication turned on?" with an answer like "Yes, so Amazon Customer Service will take additional care when being asked to reveal account information, right?"
Re: Amazon's customer service backdoor
#95Earlier quoted context omitted.
Startup idea: Whitehat Social Engineering (as a service). You authorise a whitehat team to attempt to social engineer all your discoverable internet presence/accounts to see what personal information their systems and/or customer service will disclose based on existing publicly available data. (I suspect legally that'd at least be on the white-ish side of grey rather than blackhat...) I wonder how long it'll be befor…
> Startup idea: Whitehat Social Engineering (as a service). You authorise a whitehat team to attempt to social engineer all your discoverable internet presence/accounts to see what personal information their systems and/or customer service will disclose based on existing publicly available data. (I suspect legally that'd at least be on the white-ish side of grey rather than blackhat...) You'd need to take care to avo…
Re: Amazon's customer service backdoor
#96> services should allow me to easily create lots of aliases. Right now the best defense against social engineering seems to be my fastmail account which allows me to create 1 email address alias per service What you may want is a catch-all email - which lets you do @domain.com -> nmjohn@domain.com (where is everything besides already defined addresses) - that way you can make up emails on the fly without having to se…
Make sure you keep a list somewhere of which site got which email address. I used to do this too and it was great, but then when I started trying to recover accounts that were a few years old, I had a heck of a time remembering what email address I had actually given them in the first place!
Re: Amazon's customer service backdoor
#97Earlier quoted context omitted.
I think the bigger problem is that public information like your name and address is sufficient for proving your identity. If we make whois information private, what about phone books, property records, direct mail databases, etc. etc.
Agree. Your contact info in whois adds little to any number of other public records that will contain your name, address, phone number. It does make good sense to not use your primary "personal" email address in whois, nor your home address. PO Box rentals are fairly cheap and that's what I use for whois registrations.
Re: Amazon's customer service backdoor
#98Earlier quoted context omitted.
Make sure you keep a list somewhere of which site got which email address. I used to do this too and it was great, but then when I started trying to recover accounts that were a few years old, I had a heck of a time remembering what email address I had actually given them in the first place!
I just do compapyname@mydomain.com. That's how I knew Broderbund sold my email address.
Re: Amazon's customer service backdoor
#99Earlier quoted context omitted.
Fastmail and Gmail support a local suffix of the form yourname+amazon@gmail.com. That's a plus character between the local name and local suffix. If you use a password manager, you can replace a predictable suffix like "amazon" with random hex value. Unfortunately, many sites borked their e-mail address validation and do not accept the plus character. (Amazon permits it.) Also, you'll ocassionally find a customer ser…
Also a lot of systems strip anything after the + now, especially spam systems.
Re: Amazon's customer service backdoor
#100How to stop this: 1. Get a friend's permission to "hack" into his Amazon account (or "hack your own account"). 2. Contact Amazon's customer service, try the same social engineering techniques that the OP documented. 3. Once you obtain some sensitive information from the account, scare the CS rep by saying: "Haha! I am actually not the customer. I am a journalist/hacker/whatever and wanted to see how easy it was to so…