Live data from Hacker News

Amazon's customer service backdoor

medium.com

101–110 of 366 posts

Re: Amazon's customer service backdoor

#101
post #93
post #40

Earlier quoted context omitted.

Agree. Your contact info in whois adds little to any number of other public records that will contain your name, address, phone number. It does make good sense to not use your primary "personal" email address in whois, nor your home address. PO Box rentals are fairly cheap and that's what I use for whois registrations.

Sadly, you can't even use PO boxes for all domains, some registries require a "full" address.

"The street finds its own uses for things."

Where I am (Australia) theres a whole bunch of places that'll provide "non Post Office PO boxes" who're perfectly happy for you to address things to "Suite 306" or "Apartment 306" as well as "PO Box 306" at whatever address the box is located. Fools _most_ of the "must be a real address, not a PO Box" restrictions.

(Interestingly StartSSL failed me on that once when I gave one of those as a personal address - they mailed me saying "that looks like a business address, we need a personal home address for personal identity validation") - I dunno of they Google Street-viewed it or of they've got some automated system that flagged it...)

Re: Amazon's customer service backdoor

#102
post #88

Why didn't the OP turn on two step verification? Amazon does support this.

His Amazon account wasn't even logged into, the CS rep gave up his information without the attacker being authenticated, and the attacker used that to login to other non-Amazon systems.

Re: Amazon's customer service backdoor

#104

Earlier quoted context omitted.

I fear that customer support might still accept emails without the suffix from the "customer". These are people, not robots, so if the address is close or in the vicinity of being correct, they might accept it. Same goes for the dot characters allowed in gmail addresses.

I strongly second this concern. I generate random strings as answers to my recovery questions. When I recently got asked one of the questions the support rep let out a sigh when asking (presumably because he saw the "crazy" answer) and then said "yeah yeah, alright" when I was about half way through the answer. That any company even suggests these insane security questions that anyone can trivially research is comple…

An idea I just had which is buried in a deep thread lower down...

Not that I trust the "security questions", but if Amazon lets you use freeform questions as well as answers, it might help to make your first security question "Have you noticed this account has two factor authentication turned on?" with an answer like "Yes, so Amazon Customer Service will take additional care when being asked to reveal account information, right?"

Even if you can't do freeform questions, perhaps the answer to "What's your mother's maiden name?" could be something like "Have you noticed this account has two factor authentication turned on? Please take extra care before disclosing account details to anyone, Thanks."

Re: Amazon's customer service backdoor

#105
post #100
post #52

How to stop this: 1. Get a friend's permission to "hack" into his Amazon account (or "hack your own account"). 2. Contact Amazon's customer service, try the same social engineering techniques that the OP documented. 3. Once you obtain some sensitive information from the account, scare the CS rep by saying: "Haha! I am actually not the customer. I am a journalist/hacker/whatever and wanted to see how easy it was to so…

I think there is already enough here to shame Amazon into action if it gets on a major newspaper. Something like "Hackers break into Amazon account and Amazon will not do anything" Perhaps the Washington Post would be a good newspaper with credibility.

Not sure if you were being sarcastic or not, but Jeff Bezos bought Washington Post...

Re: Amazon's customer service backdoor

#106

"The problem is, 9999 times out of 10000 support requests are legitimate, agents get trained to assume they’re legitimate. But in the 1 case they’re not, you can completely fuck someone over." That's why nothing will change if these estimates are even in the right universe. Nobody wants to inconvenience the vast majority of customers to prevent a minuscule number of issues.

At least until we hear something like "Donald Trump's personal Amazon account was hacked, and it was because Amazon's weak security."

Then Trump will even use this incident to say "I will force Amazon to become great again, after I'm president."

So a "small issue" could help Donald Trump get that much closer to becoming the most powerful man in the world. So, thanks Amazon?!

Obviously, it's all tongue-in-cheek, but I think you see my point. If it can be done, eventually we'll hear about a celebrity being hacked like this.

Re: Amazon's customer service backdoor

#107
post #48

Earlier quoted context omitted.

> On the other hand, 2FA opens up the "I lost my phone" customer support channel which might be just as weak. "I lost my phone" (or "my phone stopped working") does need some solution, though. The right way to handle "I lost my phone" seems like one of two possibilities: either come into a branch and provide legal identification matching what you used to open the account (and get "yourself" on camera doing so), or ha…

> have a token mailed to your physical address on file This is the worst for the customer point of view. Takes a long time.

It on average 24h or less, considering that mail through DHL is next-morning delivery everywhere, and same-day delivery in larger cities.

Re: Amazon's customer service backdoor

#108
post #27

"The problem is, 9999 times out of 10000 support requests are legitimate, agents get trained to assume they’re legitimate. But in the 1 case they’re not, you can completely fuck someone over." That's why nothing will change if these estimates are even in the right universe. Nobody wants to inconvenience the vast majority of customers to prevent a minuscule number of issues.

Until/unless we can find and implement a workable way to make this a problem Amazon is financially on-the-hook for, instead of Amazon (et al) customers. I wonder what the PCI implications are if it's true that Amazon gave away his last four cc digits over the phone? I wonder if there are applicable PII laws in his jurisdiction that'd have Amazon able to be held liable for disclosing his address? (I think there are he…

> I wonder what the PCI implications are if it's true that Amazon gave away his last four cc digits over the phone?

Absolutely none, unfortunately. Merchants are specifically allowed to store the first six and last four digits of a credit card number in any form they like.

Re: Amazon's customer service backdoor

#109
post #10

Earlier quoted context omitted.

Many people (including me) don't answer from unknown numbers, so that wouldn't work.

It wouldn't work /for you/. But for people who do answer their phone, it would add protection.

Possibly but you'd want to be damn sure it was actually the bank calling you. What's to stop a scammer claiming to be from the bank calling you.

"Hi I'm from bank xxxx calling to warn about some potentially fraudulent transactions we've detected on your credit card before we can continue please answer a few security questions to verify your identity."

I suspect some people would fall for that and tell the 'bank' their personal details.

Re: Amazon's customer service backdoor

#110
post #52

How to stop this: 1. Get a friend's permission to "hack" into his Amazon account (or "hack your own account"). 2. Contact Amazon's customer service, try the same social engineering techniques that the OP documented. 3. Once you obtain some sensitive information from the account, scare the CS rep by saying: "Haha! I am actually not the customer. I am a journalist/hacker/whatever and wanted to see how easy it was to so…

So, commit criminal fraud to prove a point? Bad idea.

How is it fraud if you have permission from the account owner to try and access it?
Post reply on HN