Live data from Hacker News

Amazon's customer service backdoor

medium.com

151–160 of 366 posts

Re: Amazon's customer service backdoor

#151

Earlier quoted context omitted.

How is it fraud if you have permission from the account owner to try and access it?

Fraud against Amazon, not the account owner.

Fraud requires personal or financial gain. This doesn't seem to apply.

Re: Amazon's customer service backdoor

#152
post #17

Whois is great for social engineering attackers. You get a name, email, address, and the first service to attack. Meanwhile, the ICANN is working around the clock to make it illegal for us to protect our personal information, and whois protection is becoming an increasingly niche service for registrars. For example, gandi.net (and thus Amazon) doesn't hide your name when you have it turned on. By the time you find th…

A related word of warning: Namecheap updated their registration page last year. Now, when you register a domain it tells you free Whoisguard is included, but it doesn't make it clear that it's disabled by default." Previously it just worked. Now you have to check another box to turn it on. This change makes no sense to me. (If you want free Whoisguard, why would you not want it turned on?) I was white-hot furious* wh…

I'm not sure how true this is.

I registered a new domain with Namecheap just last Thursday and it had whoisguard automatically turned on.

Re: Amazon's customer service backdoor

#153

The OP says he is "a security conscious user who follows the best practices like: using unique passwords, 2FA, only using a secure computer and being able to spot phishing attacks from a mile away..." yet I do not think he enabled 2FA on Amazon.com. If he did customer service would not have helped the hacker pretending to be him. As their help page says, "If you need help from Customer Service after enabling Two-Step…

I was excited about Amazon enabling 2FA. I started using it rightaway but it doesn't work with their extended applications. e.g. signing in on Roku, Amazon photos uploader app for Mac, Amazon video on Android/iOS.

Re: Amazon's customer service backdoor

#154
post #114
post #52

How to stop this: 1. Get a friend's permission to "hack" into his Amazon account (or "hack your own account"). 2. Contact Amazon's customer service, try the same social engineering techniques that the OP documented. 3. Once you obtain some sensitive information from the account, scare the CS rep by saying: "Haha! I am actually not the customer. I am a journalist/hacker/whatever and wanted to see how easy it was to so…

Please don't do this. You're much more likely to get your friend in trouble with Amazon and have the police called on you.

How do they know who did it though?

Re: Amazon's customer service backdoor

#155

Earlier quoted context omitted.

A related word of warning: Namecheap updated their registration page last year. Now, when you register a domain it tells you free Whoisguard is included, but it doesn't make it clear that it's disabled by default." Previously it just worked. Now you have to check another box to turn it on. This change makes no sense to me. (If you want free Whoisguard, why would you not want it turned on?) I was white-hot furious* wh…

I'm not sure how true this is. I registered a new domain with Namecheap just last Thursday and it had whoisguard automatically turned on.

Same here. I've registered a bunch of domain names with Namecheap over the last year and they all had whoisguard turned on.

Re: Amazon's customer service backdoor

#156
post #93

Earlier quoted context omitted.

Sadly, you can't even use PO boxes for all domains, some registries require a "full" address.

"The street finds its own uses for things." Where I am (Australia) theres a whole bunch of places that'll provide "non Post Office PO boxes" who're perfectly happy for you to address things to "Suite 306" or "Apartment 306" as well as "PO Box 306" at whatever address the box is located. Fools _most_ of the "must be a real address, not a PO Box" restrictions. (Interestingly StartSSL failed me on that once when I gave…

USA is a little different. To get mail using the street address of the PO, boxholders have to sign an additional agreement, BUT:

1) it's free, and

2) they will also accept UPS/FedEx/DHL/etc shipments on your behalf for no charge! (they will sign for packages, but if "Direct" signature (the named recipient) is required, they can't accept those.)

If you just try using "UNIT #" or "APT #" or whatever, or you don't have this additional agreement signed, they can and will return to sender.

Re: Amazon's customer service backdoor

#157
post #10

Earlier quoted context omitted.

Many people (including me) don't answer from unknown numbers, so that wouldn't work.

A text message / email might though. Just saying "Your account has been flagged for a lost/stolen phone which you use as your 2FA. Please contact support if this is not correct."

[deleted]

Re: Amazon's customer service backdoor

#158
post #44

Earlier quoted context omitted.

Note, though, that catch-all emails will also catch a ridiculous amount of spam. Creating each account name individually avoids that problem, at the cost of some extra trouble when registering a new service. An intermediate step that may work if you don't expect people to target you individually: have one or more required substrings for the email local part, and catch all mail to addresses containing that substring.

I created my catch-all on a subdomain. While it gives a problem with certain websites (don't consider it a valid e-mail address), I barely receive spam on it.

> While it gives a problem with certain websites (don't consider it a valid e-mail address)

Are you saying that there are sites out there which don't accept mailbox@subdomain.example.com a valid email address? If so, that's beyond broken...

Re: Amazon's customer service backdoor

#159
post #72

Earlier quoted context omitted.

Worse, they'll happily sell you Whoisguard for domains that don't support it. When you discover it's not usable, they'll give you a refund, then include it again in the next billing cycle. I switched to Namecheap based on recommendations here, and their previous stance on certain privacy issues, but I'm running out of alternatives.

Plus Whoisguard is only free for the first year. There's Google Domains for $12/yr but the dollar and some savings isn't worth the hassle of switching away from Namecheap.

[deleted]

Re: Amazon's customer service backdoor

#160
post #72

Earlier quoted context omitted.

A related word of warning: Namecheap updated their registration page last year. Now, when you register a domain it tells you free Whoisguard is included, but it doesn't make it clear that it's disabled by default." Previously it just worked. Now you have to check another box to turn it on. This change makes no sense to me. (If you want free Whoisguard, why would you not want it turned on?) I was white-hot furious* wh…

Worse, they'll happily sell you Whoisguard for domains that don't support it. When you discover it's not usable, they'll give you a refund, then include it again in the next billing cycle. I switched to Namecheap based on recommendations here, and their previous stance on certain privacy issues, but I'm running out of alternatives.

I'm happy with hover.com. They're part of Tucows, who I've been a fan of since the good ol' days.
Post reply on HN