Live data from Hacker News

Amazon's customer service backdoor

medium.com

121–130 of 366 posts

Re: Amazon's customer service backdoor

#121
post #37

If you own a home in the U.S., anybody already can get your address legally and easily from your county or district property appraiser's/assessor's website. Along with how much you paid for it, and when you bought it. So calling Amazon CS rep is a hard way to go about it. :)

Hawaii county removed the ability to search by name several years ago. You can still get name and mailing address for any property, but you have to search based on the physical address or otherwise query the correct property record. You can't just do a "let's see what John Smith owns" type of search.

You MIGHT still be able to search by name in the old fashioned way, by going into the office, but I am uncertain about that.

Re: Amazon's customer service backdoor

#122
post #114
post #52

How to stop this: 1. Get a friend's permission to "hack" into his Amazon account (or "hack your own account"). 2. Contact Amazon's customer service, try the same social engineering techniques that the OP documented. 3. Once you obtain some sensitive information from the account, scare the CS rep by saying: "Haha! I am actually not the customer. I am a journalist/hacker/whatever and wanted to see how easy it was to so…

Please don't do this. You're much more likely to get your friend in trouble with Amazon and have the police called on you.

You think Amazon wants to arrest it's customers because they shared account information?

Re: Amazon's customer service backdoor

#123

If anyone wants to start a fund to sue Amazon for this, I am ready to pitch in a $100.

That's probably wishful thinking. I haven't checked Amazon's terms of service, but nowadays you can count on both of these being true:

- you agreed to arbitration

- you agreed to disallow class action lawsuits

I.e. thanks to the Supremes[1]:

   As a result, businesses that include arbitration
   agreements with class action waivers can require
   consumers to bring claims only in individual
   arbitrations, rather than in court as part of a
   class action.
[1] https://en.wikipedia.org/wiki/AT%26T_Mobility_LLC_v._Concepc...

Re: Amazon's customer service backdoor

#124

Earlier quoted context omitted.

If you had read the article you would know that they already had 2F turned on before the first intrusion and throughout the subsequent intrusions.

I might be being pedantic, but the only mention of 2FA in the OP is: "As a security conscious user who follows the best practices like: using unique passwords, 2FA, only using a secure computer and being able to spot phishing attacks from a mile away, I would have thought my accounts and details would be be pretty safe? Wrong." Are you sure the author enabled 2FA on his Amazon retail account, or was it only enabled o…

There's no reason to assume he wasn't using 2FA. The title says "backdoor" and that's the point: they didn't verify identity... they asked for name, email and a nearby address.

Re: Amazon's customer service backdoor

#125
Customer support is what Amazon adds to the otherwise simple service of operating an online catalogue, stocking products and sending them out when ordered.

As you can see here, they are not doing a good job even in that department. Taking huge profits for basically failing.

I have called this a lose-lose in the past.

So -- be good and stop using amazon!

Re: Amazon's customer service backdoor

#126
The OP says he is "a security conscious user who follows the best practices like: using unique passwords, 2FA, only using a secure computer and being able to spot phishing attacks from a mile away..." yet I do not think he enabled 2FA on Amazon.com. If he did customer service would not have helped the hacker pretending to be him. As their help page says, "If you need help from Customer Service after enabling Two-Step Verification, you'll need provide a security code similar to when trying to sign in to your account." https://www.amazon.com/gp/help/customer/display.html?nodeId=...

Re: Amazon's customer service backdoor

#127
post #86
post #72

Earlier quoted context omitted.

Worse, they'll happily sell you Whoisguard for domains that don't support it. When you discover it's not usable, they'll give you a refund, then include it again in the next billing cycle. I switched to Namecheap based on recommendations here, and their previous stance on certain privacy issues, but I'm running out of alternatives.

A happy NameCheap user for years, I have started switching away. Their horrid "modern" 40px padding everywhere bubbly redesign makes GoDaddy look good in comparison. A major pain to manage more than a couple of domains, and numerous user feedback seems to fall on deaf ears, e.g. [1][2][3][4] Example weird feature: all domains are shown, even ones that you've let expire/sold years ago, and there is no way to hide them…

css stylebot or a smiliar extension that allows you to create persistent stylesheets could help you! i think your grievance is legitamate

Re: Amazon's customer service backdoor

#128
post #43

Earlier quoted context omitted.

You can approximate this with gmail using the plus sign. Like myaccount+label@gmail.com. It's ignored for delivery, but gmail's filters can match on it in the to: address.

Every time I've tried to use that feature, the email field in the registration form I'm trying to fill out rejects it because they don't like + in an email address. There are a lot of not-quite-correct email form validation routines out there. Or maybe this is selection bias: the forms where I'm most likely to want to use the + are with the companies that are most likely to want to resell my email address, and they m…

Lots of programmers try to write regular expressions to validate e-mail addresses, but it's extremely difficult for them to get it right, because valid e-mail addresses as defined by RFCs 822 and 5322 fall outside the set of formal languages describable by most regular expression libraries. See this fun stackoverflow answer [0].

[0] http://stackoverflow.com/a/201378

Re: Amazon's customer service backdoor

#129
post #98
post #96

Earlier quoted context omitted.

I just do compapyname@mydomain.com. That's how I knew Broderbund sold my email address.

I was doing that but some companies think you are "hacking" if you put the company name in. Like I don't think you can do facebook@mydomain.com on Facebook.

fb@mydomain.com is perfectly usable though.

Re: Amazon's customer service backdoor

#130
post #124

Earlier quoted context omitted.

I might be being pedantic, but the only mention of 2FA in the OP is: "As a security conscious user who follows the best practices like: using unique passwords, 2FA, only using a secure computer and being able to spot phishing attacks from a mile away, I would have thought my accounts and details would be be pretty safe? Wrong." Are you sure the author enabled 2FA on his Amazon retail account, or was it only enabled o…

There's no reason to assume he wasn't using 2FA. The title says "backdoor" and that's the point: they didn't verify identity... they asked for name, email and a nearby address.

I don't think he was using 2FA; if he was, Amazon CS would not have given him the information (or at least should not have, based on their own policies): https://www.amazon.com/gp/help/customer/display.html?nodeId=....
Post reply on HN