Live data from Hacker News

Amazon's customer service backdoor

medium.com

181–190 of 366 posts

Re: Amazon's customer service backdoor

#181
As someone who has trained customer support agents, I can attest to the fact that most agents have to be taught every scenario. If it slightly deviates from the one they have been trained on, they are clueless.

Not saying all customer support people are like this. However, majority of people are. They rely on pre-written scripts. When a question is asked, they search for the template question with the answer.

Re: Amazon's customer service backdoor

#182

Couldn't customer service just treat all sensitive information like the they treated the last 4 digits of the CC in this scenario? Verify only, reveal nothing. I'm sure almost all legit customers don't have even 5 possible addresses they may have shipped to, make them say what they think it is.

That would be the basic standard to which all CSRs are trained to, and deviating from that is 100% deviating from protocol in almost any case, they do it for individual reasons (speed, a good customer survey, whatever)

When I trained Apple techs the clear communication was that people use pretexting for not just mundane things like credit card theft, but to commit violence against other people (especially in the case of domestic violence where they have some personal details and can try to get more).

Anything but the strategy of verify only is putting people's lives in danger.

Re: Amazon's customer service backdoor

#184

Earlier quoted context omitted.

A related word of warning: Namecheap updated their registration page last year. Now, when you register a domain it tells you free Whoisguard is included, but it doesn't make it clear that it's disabled by default." Previously it just worked. Now you have to check another box to turn it on. This change makes no sense to me. (If you want free Whoisguard, why would you not want it turned on?) I was white-hot furious* wh…

I'm not sure how true this is. I registered a new domain with Namecheap just last Thursday and it had whoisguard automatically turned on.

I think it is enabled automatically for free for the first year, but does not automatically renew, because it is not free after the first year.

Re: Amazon's customer service backdoor

#185

Earlier quoted context omitted.

A related word of warning: Namecheap updated their registration page last year. Now, when you register a domain it tells you free Whoisguard is included, but it doesn't make it clear that it's disabled by default." Previously it just worked. Now you have to check another box to turn it on. This change makes no sense to me. (If you want free Whoisguard, why would you not want it turned on?) I was white-hot furious* wh…

Hiding your contact information is like security through obscurity. I'm not saying it's not a good extra step to decrease the frequency of attacks (much like changing an SSH port to 3857 or something), but it doesn't add any real security. This is the crux of the problem; our addressees and birthdays are treated like passwords by these companies.

Passwords are also security by obscurity.

Re: Amazon's customer service backdoor

#186
post #86
post #72

Earlier quoted context omitted.

Worse, they'll happily sell you Whoisguard for domains that don't support it. When you discover it's not usable, they'll give you a refund, then include it again in the next billing cycle. I switched to Namecheap based on recommendations here, and their previous stance on certain privacy issues, but I'm running out of alternatives.

A happy NameCheap user for years, I have started switching away. Their horrid "modern" 40px padding everywhere bubbly redesign makes GoDaddy look good in comparison. A major pain to manage more than a couple of domains, and numerous user feedback seems to fall on deaf ears, e.g. [1][2][3][4] Example weird feature: all domains are shown, even ones that you've let expire/sold years ago, and there is no way to hide them…

Same here - a satisfied Namecheap customer for years, but forced to move my domains away recently. Ironically, what originally brought me there was exactly the huge level of support for Namecheap in HN ranks (well, and few instances elsewhere.)

But their "redesign" and presumably the backend changes tied to it (or lack of them, whatever the real case is) resulted in the worst experience I've ever had with this kind of service in years, culminating in what was the last straw - one of my domains getting shut down five times in a single month due to bogus "domain contacts verification" procedures, which their support wasn't able to solve from early December to when I finally decided to move away in mid-January (from a short exchange after I moved away I assume it's still broken today as they were apparently "investigating it" even after I was gone. That after having it in some or some other way "fixed" for about three times during the previous support exchanges.) Honestly though during that time my tickets mostly kept bouncing back and forth through customer reps that insisted on politely suggesting things like "to check my spam folder", even though I specifically explained every time that I was in full control of my mail servers and that it is them who don't deliver any kind of verification emails to those servers, so there was really nothing that could even end up in "a spam folder" and that yes, I actually thoroughly checked that, several times over. Yet my requests for them to check their own mail logs because I'm here actually losing access to my domains without being able to do anything about it were each time politely swept under the rug with generic assurances like "they're working on it and will keep me informed"... Then quickly closed the ticket as fixed. Every time after the one particular domain went dark (and with another domain randomly flipping into bogus unverified states in the frontend interface, clearly lingering on the edge of the same fate), the domain was reactivated either by me or the customer support, was either set to have its contacts covered by WhoisGuard (which doesn't even use the contacts verification process at all), or at a later point even manually set back to fully verified by their techs (and one time completely having all my zone data wiped without explanation or apparently without whoever caused it having a backup at hand to restore it from) - only to again and again end up suspended as "unverified" several days later, losing me access to its emails, websites, everything...

Now I could still go on and on about how clunky the entire new interface compared to the old one is (yes, the original was lackluster, but not even remotely this level bad and in fact I've never had a single technical issue with it, other than being somewhat hard to navigate) and that ever since the redesign the new frontend frequently displays outdated or plain wrong information, crashes with cryptic errors, sometimes just decides to log you out five times in five minutes for no reason, but I think this is getting too long as it is anyway, so enough.

When I finally grew tired of running through their customer support in a neverending circle (to their credit, they were always very polite and nice, but it felt like that's all that Namecheap support was really trained for. And that clearly doesn't make my domains magically work there), I moved to Gandi just basing on their overall popularity and good reputation with a few people. Already in a week time I had two great support experiences with them and got my issues resolved each time in literally a single step of exchange. In the first case I've received about a page-length of actual technical reply from their support rep that not only bothered to carefully read through several issues that I ran into when trying to run a Python app on their web hosting platform that I ordered for the domains moved there, they even included a how-to custom tailored to my specific use case that was way beyond what I originally asked for and that ended up saving me quite some time discovering it on my own, and also acknowledged that they had a major issue in their documentation system and that they had it quickly fixed in meantime. Now second time was less technical, as I accidentally burned a discount code while customizing and re-customizing some orders in what was probably an unexpected way for their interface, that ended in the code never being applied to any order but still ended up as used and lost... I wrote down the problem in a few sentences, customer support quickly verified it and issued me a new replacement code right with the initial reply in what had to be less than an hour. Can't really say I'll be missing Namecheap any time soon.

Re: Amazon's customer service backdoor

#187
post #86

Earlier quoted context omitted.

A happy NameCheap user for years, I have started switching away. Their horrid "modern" 40px padding everywhere bubbly redesign makes GoDaddy look good in comparison. A major pain to manage more than a couple of domains, and numerous user feedback seems to fall on deaf ears, e.g. [1][2][3][4] Example weird feature: all domains are shown, even ones that you've let expire/sold years ago, and there is no way to hide them…

Do you mind sharing where you switched to?

Name.com has been legit for me for about 10 years. Use code PRIVACYPLEASE for free whois privacy (this code has worked for the past ~5 years). I've also used IWantMyName for some TLDs that name.com didn't have and I liked that they had 2FA, but overall it was much less polished.

Re: Amazon's customer service backdoor

#188
post #160
post #72

Earlier quoted context omitted.

Worse, they'll happily sell you Whoisguard for domains that don't support it. When you discover it's not usable, they'll give you a refund, then include it again in the next billing cycle. I switched to Namecheap based on recommendations here, and their previous stance on certain privacy issues, but I'm running out of alternatives.

I'm happy with hover.com. They're part of Tucows, who I've been a fan of since the good ol' days.

OpenSRS is also Tucows but only for resellers. Their reseller system works alright. Used to use it when I worked for a hosting co.

Re: Amazon's customer service backdoor

#189
post #82
post #72

Earlier quoted context omitted.

Worse, they'll happily sell you Whoisguard for domains that don't support it. When you discover it's not usable, they'll give you a refund, then include it again in the next billing cycle. I switched to Namecheap based on recommendations here, and their previous stance on certain privacy issues, but I'm running out of alternatives.

I've always wondered why I never see pairNIC mentioned on the "everybody knows godaddy is garbage but who should I use to register domains?" threads on HN. I have used them since they opened (2002) and never used anybody else after that, because I have never been dissatisfied. (I don't remember if the box is checked by default, but they definitely offer whois privacy, along with services like custom/dynamic DNS and s…

I used Pair right after they were accredited as a registrar in the 90's up till the mid 2000's but found they were expensive both for domain registration and for hosting. Great customer service but for a commodity like a domain name it's just not worth it for me.
Post reply on HN