Earlier quoted context omitted.
How is it fraud if you have permission from the account owner to try and access it?
Fraud against Amazon, not the account owner.
Amazon's customer service backdoor
151–160 of 366 posts
Re: Amazon's customer service backdoor
#152Whois is great for social engineering attackers. You get a name, email, address, and the first service to attack. Meanwhile, the ICANN is working around the clock to make it illegal for us to protect our personal information, and whois protection is becoming an increasingly niche service for registrars. For example, gandi.net (and thus Amazon) doesn't hide your name when you have it turned on. By the time you find th…
A related word of warning: Namecheap updated their registration page last year. Now, when you register a domain it tells you free Whoisguard is included, but it doesn't make it clear that it's disabled by default." Previously it just worked. Now you have to check another box to turn it on. This change makes no sense to me. (If you want free Whoisguard, why would you not want it turned on?) I was white-hot furious* wh…
I registered a new domain with Namecheap just last Thursday and it had whoisguard automatically turned on.
Re: Amazon's customer service backdoor
#153The OP says he is "a security conscious user who follows the best practices like: using unique passwords, 2FA, only using a secure computer and being able to spot phishing attacks from a mile away..." yet I do not think he enabled 2FA on Amazon.com. If he did customer service would not have helped the hacker pretending to be him. As their help page says, "If you need help from Customer Service after enabling Two-Step…
Re: Amazon's customer service backdoor
#154How to stop this: 1. Get a friend's permission to "hack" into his Amazon account (or "hack your own account"). 2. Contact Amazon's customer service, try the same social engineering techniques that the OP documented. 3. Once you obtain some sensitive information from the account, scare the CS rep by saying: "Haha! I am actually not the customer. I am a journalist/hacker/whatever and wanted to see how easy it was to so…
Please don't do this. You're much more likely to get your friend in trouble with Amazon and have the police called on you.
Re: Amazon's customer service backdoor
#155Earlier quoted context omitted.
A related word of warning: Namecheap updated their registration page last year. Now, when you register a domain it tells you free Whoisguard is included, but it doesn't make it clear that it's disabled by default." Previously it just worked. Now you have to check another box to turn it on. This change makes no sense to me. (If you want free Whoisguard, why would you not want it turned on?) I was white-hot furious* wh…
I'm not sure how true this is. I registered a new domain with Namecheap just last Thursday and it had whoisguard automatically turned on.
Re: Amazon's customer service backdoor
#156Earlier quoted context omitted.
Sadly, you can't even use PO boxes for all domains, some registries require a "full" address.
"The street finds its own uses for things." Where I am (Australia) theres a whole bunch of places that'll provide "non Post Office PO boxes" who're perfectly happy for you to address things to "Suite 306" or "Apartment 306" as well as "PO Box 306" at whatever address the box is located. Fools _most_ of the "must be a real address, not a PO Box" restrictions. (Interestingly StartSSL failed me on that once when I gave…
1) it's free, and
2) they will also accept UPS/FedEx/DHL/etc shipments on your behalf for no charge! (they will sign for packages, but if "Direct" signature (the named recipient) is required, they can't accept those.)
If you just try using "UNIT #" or "APT #" or whatever, or you don't have this additional agreement signed, they can and will return to sender.
Re: Amazon's customer service backdoor
#157Earlier quoted context omitted.
Many people (including me) don't answer from unknown numbers, so that wouldn't work.
A text message / email might though. Just saying "Your account has been flagged for a lost/stolen phone which you use as your 2FA. Please contact support if this is not correct."
Re: Amazon's customer service backdoor
#158Earlier quoted context omitted.
Note, though, that catch-all emails will also catch a ridiculous amount of spam. Creating each account name individually avoids that problem, at the cost of some extra trouble when registering a new service. An intermediate step that may work if you don't expect people to target you individually: have one or more required substrings for the email local part, and catch all mail to addresses containing that substring.
I created my catch-all on a subdomain. While it gives a problem with certain websites (don't consider it a valid e-mail address), I barely receive spam on it.
Are you saying that there are sites out there which don't accept mailbox@subdomain.example.com a valid email address? If so, that's beyond broken...
Re: Amazon's customer service backdoor
#159Earlier quoted context omitted.
Worse, they'll happily sell you Whoisguard for domains that don't support it. When you discover it's not usable, they'll give you a refund, then include it again in the next billing cycle. I switched to Namecheap based on recommendations here, and their previous stance on certain privacy issues, but I'm running out of alternatives.
Plus Whoisguard is only free for the first year. There's Google Domains for $12/yr but the dollar and some savings isn't worth the hassle of switching away from Namecheap.
Re: Amazon's customer service backdoor
#160Earlier quoted context omitted.
A related word of warning: Namecheap updated their registration page last year. Now, when you register a domain it tells you free Whoisguard is included, but it doesn't make it clear that it's disabled by default." Previously it just worked. Now you have to check another box to turn it on. This change makes no sense to me. (If you want free Whoisguard, why would you not want it turned on?) I was white-hot furious* wh…
Worse, they'll happily sell you Whoisguard for domains that don't support it. When you discover it's not usable, they'll give you a refund, then include it again in the next billing cycle. I switched to Namecheap based on recommendations here, and their previous stance on certain privacy issues, but I'm running out of alternatives.