Live data from Hacker News

Amazon's customer service backdoor

medium.com

91–100 of 366 posts

Re: Amazon's customer service backdoor

#91
Couldn't customer service just treat all sensitive information like the they treated the last 4 digits of the CC in this scenario? Verify only, reveal nothing. I'm sure almost all legit customers don't have even 5 possible addresses they may have shipped to, make them say what they think it is.

Re: Amazon's customer service backdoor

#92
post #33
post #17

Whois is great for social engineering attackers. You get a name, email, address, and the first service to attack. Meanwhile, the ICANN is working around the clock to make it illegal for us to protect our personal information, and whois protection is becoming an increasingly niche service for registrars. For example, gandi.net (and thus Amazon) doesn't hide your name when you have it turned on. By the time you find th…

They don't hide the name because you cannot hide the name while legally owning the domain yourself. Services that hide the name actually result in a company (e.g. "Domains by Proxy LLC") purchasing and holding domain ownership for you, which is a very different legal arrangement with different risks.

I actually like Gandi for this reason. Registrars have gone down in the past, and I don't want to have any difficulty proving that I'm the owner if that happens.

Besides, my primary domain is my full name dot com, so anyone who has any interest in the domain already knows my name.

Re: Amazon's customer service backdoor

#93
post #40
post #20

Earlier quoted context omitted.

I think the bigger problem is that public information like your name and address is sufficient for proving your identity. If we make whois information private, what about phone books, property records, direct mail databases, etc. etc.

Agree. Your contact info in whois adds little to any number of other public records that will contain your name, address, phone number. It does make good sense to not use your primary "personal" email address in whois, nor your home address. PO Box rentals are fairly cheap and that's what I use for whois registrations.

Sadly, you can't even use PO boxes for all domains, some registries require a "full" address.

Re: Amazon's customer service backdoor

#94
post #7

Any recommendation what one (as a customer of Amazon) can do today ? 2FA does not help here as someone goes through support channel which looks like bypasses 2FA Also concerned if the same trick can be applied to Amazon Cloud services, as there one can also run up a big bill pretty quickly.

If I were the OP or someone equally sure I was likely to be targeted via my Amazon account, I'd consider:

Using a unique email address.

Using a unique physical address (both for my account details and for my delivery addresses).

Use a unique credit card (I'd probably get a refillable prepaid gift card, and set up some auto topup to ensure it's got my expected monthly Amazon bill available as "credit", but not much more).

I'd probably move any AWS billing to a different Amazon account.

If I were more paranoid (or being actively targeted), I'd probably also try to go unique on _everything_ I tell Amazon; phone numbers, different city/state/zipcode (as well as street address), company name, website url, alternate contacts - then I'd set up "Security questions" with unguessable questions/answers (perhaps diceware/xkcd style "correct horse battery staple" type ones, that a CS rep could easily read out and verify - rather than a base64 GUID...).

Not that I trust the "security questions", but if Amazon lets you use freeform questions as well as answers, it might help to make your first security question "Have you noticed this account has two factor authentication turned on?" with an answer like "Yes, so Amazon Customer Service will take additional care when being asked to reveal account information, right?"

Re: Amazon's customer service backdoor

#95
post #36

Earlier quoted context omitted.

Startup idea: Whitehat Social Engineering (as a service). You authorise a whitehat team to attempt to social engineer all your discoverable internet presence/accounts to see what personal information their systems and/or customer service will disclose based on existing publicly available data. (I suspect legally that'd at least be on the white-ish side of grey rather than blackhat...) I wonder how long it'll be befor…

> Startup idea: Whitehat Social Engineering (as a service). You authorise a whitehat team to attempt to social engineer all your discoverable internet presence/accounts to see what personal information their systems and/or customer service will disclose based on existing publicly available data. (I suspect legally that'd at least be on the white-ish side of grey rather than blackhat...) You'd need to take care to avo…

Whitehat Social Engineering won't be "a unicorn", so don't expect Sandhill Rd to invest, but it's not like whitehat pentesting is a unicorn type idea either, and there's lots of people running successful and profitable lifestyle businesses doing that.

Re: Amazon's customer service backdoor

#96
post #85
post #35

> services should allow me to easily create lots of aliases. Right now the best defense against social engineering seems to be my fastmail account which allows me to create 1 email address alias per service What you may want is a catch-all email - which lets you do @domain.com -> nmjohn@domain.com (where is everything besides already defined addresses) - that way you can make up emails on the fly without having to se…

Make sure you keep a list somewhere of which site got which email address. I used to do this too and it was great, but then when I started trying to recover accounts that were a few years old, I had a heck of a time remembering what email address I had actually given them in the first place!

I just do compapyname@mydomain.com. That's how I knew Broderbund sold my email address.

Re: Amazon's customer service backdoor

#97
post #40
post #20

Earlier quoted context omitted.

I think the bigger problem is that public information like your name and address is sufficient for proving your identity. If we make whois information private, what about phone books, property records, direct mail databases, etc. etc.

Agree. Your contact info in whois adds little to any number of other public records that will contain your name, address, phone number. It does make good sense to not use your primary "personal" email address in whois, nor your home address. PO Box rentals are fairly cheap and that's what I use for whois registrations.

Yes, but the new piece of information is that you are the one who owns that domain

Re: Amazon's customer service backdoor

#98
post #96
post #85

Earlier quoted context omitted.

Make sure you keep a list somewhere of which site got which email address. I used to do this too and it was great, but then when I started trying to recover accounts that were a few years old, I had a heck of a time remembering what email address I had actually given them in the first place!

I just do compapyname@mydomain.com. That's how I knew Broderbund sold my email address.

I was doing that but some companies think you are "hacking" if you put the company name in. Like I don't think you can do facebook@mydomain.com on Facebook.

Re: Amazon's customer service backdoor

#99
post #83
post #46

Earlier quoted context omitted.

Fastmail and Gmail support a local suffix of the form yourname+amazon@gmail.com. That's a plus character between the local name and local suffix. If you use a password manager, you can replace a predictable suffix like "amazon" with random hex value. Unfortunately, many sites borked their e-mail address validation and do not accept the plus character. (Amazon permits it.) Also, you'll ocassionally find a customer ser…

Also a lot of systems strip anything after the + now, especially spam systems.

Fastmail supports a@fastmail.com -> anything@a.fastmail.com, which is even better

Re: Amazon's customer service backdoor

#100
post #52

How to stop this: 1. Get a friend's permission to "hack" into his Amazon account (or "hack your own account"). 2. Contact Amazon's customer service, try the same social engineering techniques that the OP documented. 3. Once you obtain some sensitive information from the account, scare the CS rep by saying: "Haha! I am actually not the customer. I am a journalist/hacker/whatever and wanted to see how easy it was to so…

I think there is already enough here to shame Amazon into action if it gets on a major newspaper. Something like "Hackers break into Amazon account and Amazon will not do anything" Perhaps the Washington Post would be a good newspaper with credibility.
Post reply on HN