Live data from Hacker News

Amazon's customer service backdoor

medium.com

171–180 of 366 posts

Re: Amazon's customer service backdoor

#171
post #138
post #35

> services should allow me to easily create lots of aliases. Right now the best defense against social engineering seems to be my fastmail account which allows me to create 1 email address alias per service What you may want is a catch-all email - which lets you do @domain.com -> nmjohn@domain.com (where is everything besides already defined addresses) - that way you can make up emails on the fly without having to se…

but then the spammers use BCC and you don't know what email they used?

There's Envelope-to, which is the only thing you should at. To, From etc. could be forged.

Re: Amazon's customer service backdoor

#172
post #17

Whois is great for social engineering attackers. You get a name, email, address, and the first service to attack. Meanwhile, the ICANN is working around the clock to make it illegal for us to protect our personal information, and whois protection is becoming an increasingly niche service for registrars. For example, gandi.net (and thus Amazon) doesn't hide your name when you have it turned on. By the time you find th…

A related word of warning: Namecheap updated their registration page last year. Now, when you register a domain it tells you free Whoisguard is included, but it doesn't make it clear that it's disabled by default." Previously it just worked. Now you have to check another box to turn it on. This change makes no sense to me. (If you want free Whoisguard, why would you not want it turned on?) I was white-hot furious* wh…

Hiding your contact information is like security through obscurity. I'm not saying it's not a good extra step to decrease the frequency of attacks (much like changing an SSH port to 3857 or something), but it doesn't add any real security. This is the crux of the problem; our addressees and birthdays are treated like passwords by these companies.

Re: Amazon's customer service backdoor

#173
post #112
post #82

Earlier quoted context omitted.

I've always wondered why I never see pairNIC mentioned on the "everybody knows godaddy is garbage but who should I use to register domains?" threads on HN. I have used them since they opened (2002) and never used anybody else after that, because I have never been dissatisfied. (I don't remember if the box is checked by default, but they definitely offer whois privacy, along with services like custom/dynamic DNS and s…

Last I checked pairNIC was > $15/year for .com etc. That adds up when you have many domains. Therefore I use pairNIC for the domains I really care about, and Namecheap for the rest.

it seems they are down to $9.99/year: https://www.pairnic.com/prices.html

Re: Amazon's customer service backdoor

#174
post #164
post #17

Whois is great for social engineering attackers. You get a name, email, address, and the first service to attack. Meanwhile, the ICANN is working around the clock to make it illegal for us to protect our personal information, and whois protection is becoming an increasingly niche service for registrars. For example, gandi.net (and thus Amazon) doesn't hide your name when you have it turned on. By the time you find th…

If WHOIS is destroyed, your contact information will still be known by everybody you're in contact with, many you've only met, possibly many you haven't met but want to meet, and millions of employees of companies you've interacted with. There is no meaningful difference between that and public information. It is Amazon's absurd assumption that your contact information is private that is at fault here. Trying to amel…

There is definitely a meaningful difference between contact info being public and informal disclosure through normal contact. There's a reason doxxing is a thing.

Re: Amazon's customer service backdoor

#175
post #17

Whois is great for social engineering attackers. You get a name, email, address, and the first service to attack. Meanwhile, the ICANN is working around the clock to make it illegal for us to protect our personal information, and whois protection is becoming an increasingly niche service for registrars. For example, gandi.net (and thus Amazon) doesn't hide your name when you have it turned on. By the time you find th…

> For example, gandi.net (and thus Amazon) doesn't hide your name when you have it turned on.

Well, yeah, I've been with Gandi for years, that's their published policy: https://www.gandi.net/domain/whois/

> By the time you find this out

You realize you should have done your homework and read your registrar's policies beforehand? I understand your overall point, but don't make it sound like Gandi did anything wrong here, just because you don't like it.

Re: Amazon's customer service backdoor

#176
post #72

Earlier quoted context omitted.

A related word of warning: Namecheap updated their registration page last year. Now, when you register a domain it tells you free Whoisguard is included, but it doesn't make it clear that it's disabled by default." Previously it just worked. Now you have to check another box to turn it on. This change makes no sense to me. (If you want free Whoisguard, why would you not want it turned on?) I was white-hot furious* wh…

Worse, they'll happily sell you Whoisguard for domains that don't support it. When you discover it's not usable, they'll give you a refund, then include it again in the next billing cycle. I switched to Namecheap based on recommendations here, and their previous stance on certain privacy issues, but I'm running out of alternatives.

I've been a happy user of Google Domains since closed beta. I'll never go anywhere else for domains again.

Re: Amazon's customer service backdoor

#177
post #29

Earlier quoted context omitted.

While that's true, and perhaps even needs to be "the default", there really needs to be a way to say "Hey, I'm concerned, and am prepared to take responsibility for my own access credentials. I demand you categorically _do not_ disclose any of my personal information to anyone without a warrant or court order." And for that sort of demand to have appropriate legal teeth to ensure people collecting that data are suffi…

Unfortunately, far more people think they want that than can take full personal responsibility for it. See also: people who don't understand that full-disk encryption means they lose their data if they forget their passphrase. That doesn't make full-disk encryption in any way bad, but if you train people to think that all accounts have a "forgotten password" option, they might get a nasty surprise.

Then again, in this case it might be salvageable by having an option of turning up with an ID in person. Could still be faked, but it would be a lot more work at least.

Re: Amazon's customer service backdoor

#178
Yes, Amazon is doing it wrong. But the much bigger problem is that your bank lets fraudsters impersonate you using easily obtained information such as your name and address. It is completely backwards that you need an impenetrable wall and moat around the place where you buy books and groceries, because, once you get past it, then the place where you store all your money and get your mortgage is as easy to penetrate as a piece of tissue paper. The root cause of all identity theft are the incredibly lax security policies of the financial system.

Re: Amazon's customer service backdoor

#179
post #37

If you own a home in the U.S., anybody already can get your address legally and easily from your county or district property appraiser's/assessor's website. Along with how much you paid for it, and when you bought it. So calling Amazon CS rep is a hard way to go about it. :)

Ah... if you're a resident of Sweden, anybody can get your full name, address, date of birth, civil status, list of company engagements (e.g., board member, owner of a firm, etc.) and the make and year of any cars registered by going to one of several websites - http://www.ratsit.se/ being one of the most popular ones. No login needed. This information is public data straight from the government. (Exceptions: people…

Though, I would wager that very few Swedish companies consider any of that information as a "password", as seen in the article...

Re: Amazon's customer service backdoor

#180
post #98
post #96

Earlier quoted context omitted.

I just do compapyname@mydomain.com. That's how I knew Broderbund sold my email address.

I was doing that but some companies think you are "hacking" if you put the company name in. Like I don't think you can do facebook@mydomain.com on Facebook.

I would tell you that my FB email address has that format, but maybe I'd be leaking too much information by doing so....
Post reply on HN