Live data from Hacker News

Amazon's customer service backdoor

medium.com

111–120 of 366 posts

Re: Amazon's customer service backdoor

#111
The problem is Amazon has thousands of poorly trained first-level support staff with far too much power and information.

What we need is a global security standard for support staff, with a template as to what information is accessible by staff and what isn't. And what is available to better trained 2nd-level support, etc.

And then each company can say they are certified for this particular security standard, and then you can't get social engineering attacks where you attack one large corporation, get partial information, and then feed that into another large organization to get other information. This was done previously using Amazon, again, to get enough information to take someone's Twitter account, if i remember correctly.

Re: Amazon's customer service backdoor

#112
post #82
post #72

Earlier quoted context omitted.

Worse, they'll happily sell you Whoisguard for domains that don't support it. When you discover it's not usable, they'll give you a refund, then include it again in the next billing cycle. I switched to Namecheap based on recommendations here, and their previous stance on certain privacy issues, but I'm running out of alternatives.

I've always wondered why I never see pairNIC mentioned on the "everybody knows godaddy is garbage but who should I use to register domains?" threads on HN. I have used them since they opened (2002) and never used anybody else after that, because I have never been dissatisfied. (I don't remember if the box is checked by default, but they definitely offer whois privacy, along with services like custom/dynamic DNS and s…

Last I checked pairNIC was > $15/year for .com etc. That adds up when you have many domains. Therefore I use pairNIC for the domains I really care about, and Namecheap for the rest.

Re: Amazon's customer service backdoor

#113

Earlier quoted context omitted.

I fear that customer support might still accept emails without the suffix from the "customer". These are people, not robots, so if the address is close or in the vicinity of being correct, they might accept it. Same goes for the dot characters allowed in gmail addresses.

I strongly second this concern. I generate random strings as answers to my recovery questions. When I recently got asked one of the questions the support rep let out a sigh when asking (presumably because he saw the "crazy" answer) and then said "yeah yeah, alright" when I was about half way through the answer. That any company even suggests these insane security questions that anyone can trivially research is comple…

For those sort of "mother's maiden name" type questions, I generally use a fake but plausible name. Probably not as secure as a random string (especially as the name is reused across a few services), but makes it near impossible to research, and avoids a random string not being accepted/treated as an error/truncated like your example etc.

Re: Amazon's customer service backdoor

#114
post #52

How to stop this: 1. Get a friend's permission to "hack" into his Amazon account (or "hack your own account"). 2. Contact Amazon's customer service, try the same social engineering techniques that the OP documented. 3. Once you obtain some sensitive information from the account, scare the CS rep by saying: "Haha! I am actually not the customer. I am a journalist/hacker/whatever and wanted to see how easy it was to so…

Please don't do this. You're much more likely to get your friend in trouble with Amazon and have the police called on you.

Re: Amazon's customer service backdoor

#115
post #37

If you own a home in the U.S., anybody already can get your address legally and easily from your county or district property appraiser's/assessor's website. Along with how much you paid for it, and when you bought it. So calling Amazon CS rep is a hard way to go about it. :)

The amount of available data varies by state. In TX, for example, sale prices are not disclosed.

But the deed of trust the buyer signed is in the public record (every Texas county of medium-to-large population has scanned land records online) and has the amount of the mortgage issued on its front page so that gets you close. That goes double if the form has an FHA case number at the top because it usually means the deed of trust is within 5% of the purchase price.

No, not all of the time, but very often enough to make it useful for social engineering.

Re: Amazon's customer service backdoor

#116

Earlier quoted context omitted.

So, commit criminal fraud to prove a point? Bad idea.

How is it fraud if you have permission from the account owner to try and access it?

Fraud against Amazon, not the account owner.

Re: Amazon's customer service backdoor

#117
post #74

Earlier quoted context omitted.

Unfortunately, far more people think they want that than can take full personal responsibility for it. See also: people who don't understand that full-disk encryption means they lose their data if they forget their passphrase. That doesn't make full-disk encryption in any way bad, but if you train people to think that all accounts have a "forgotten password" option, they might get a nasty surprise.

Sure - it needs to be somewhat difficult to turn on, and turning it on needs to very clearly include an "I accept all responsibility for this" declaration. Most of "us" already deal with these things though - there's no "forgot password" for my ssh keys or my ssl keys or my topt seeds - there's no "forgot password: for my 1Password and Keypass safes. We occasionally get to laugh at out less diligent colleagues and pe…

very clearly include an "I accept all responsibility for this"

It can't be a simple checkbox, or an Agree button. Make someone type, exactly:

   I accept all responsibility for this
Even then, the majority of the general public (as opposed to computer nerds) would be awfully upset at being locked out.

You're exactly right: there'd probably be a whole lot of "Hold my beer and watch me turn on full personal responsibility here! Oh, hang on - shit. Oooops..."

Re: Amazon's customer service backdoor

#118
post #89
post #33

Earlier quoted context omitted.

They don't hide the name because you cannot hide the name while legally owning the domain yourself. Services that hide the name actually result in a company (e.g. "Domains by Proxy LLC") purchasing and holding domain ownership for you, which is a very different legal arrangement with different risks.

Treat a domain like money: if you want it held pseudonymously, you put it in the ownership of a shell corporation you control (through power of attorney to the board of directors), but don't own any equity in.

While I would love to do that it just isn't feasible for me and probably most others. ICANN really needs to provide better controls to avoid resorting to such workarounds.

Re: Amazon's customer service backdoor

#119
I am VERY interested in what you mentioned about fastmail. That seems like an amazing idea. I have never thought about it.

I think I need to make a script that can do that for me. A simple mail server to forward emails both ways.

Re: Amazon's customer service backdoor

#120
post #100
post #52

How to stop this: 1. Get a friend's permission to "hack" into his Amazon account (or "hack your own account"). 2. Contact Amazon's customer service, try the same social engineering techniques that the OP documented. 3. Once you obtain some sensitive information from the account, scare the CS rep by saying: "Haha! I am actually not the customer. I am a journalist/hacker/whatever and wanted to see how easy it was to so…

I think there is already enough here to shame Amazon into action if it gets on a major newspaper. Something like "Hackers break into Amazon account and Amazon will not do anything" Perhaps the Washington Post would be a good newspaper with credibility.

This already happened to Matt Honan back in 2012, where the hacker used social engineering on both Amazon and Apple to take over his twitter handle (oh and also wiping all his devices via iCloud). http://www.wired.com/2012/08/apple-amazon-mat-honan-hacking/

It looks like both Amazon and Apple have fixed _some_ issues since then - Amazon is no longer leaking last 4 digits, but instead they're still leaking other info. Apple now requires more information to reset accounts and to wipe devices.

Post reply on HN