Live data from Hacker News

Amazon's customer service backdoor

medium.com

201–210 of 366 posts

Re: Amazon's customer service backdoor

#201
post #86

Earlier quoted context omitted.

A happy NameCheap user for years, I have started switching away. Their horrid "modern" 40px padding everywhere bubbly redesign makes GoDaddy look good in comparison. A major pain to manage more than a couple of domains, and numerous user feedback seems to fall on deaf ears, e.g. [1][2][3][4] Example weird feature: all domains are shown, even ones that you've let expire/sold years ago, and there is no way to hide them…

Do you mind sharing where you switched to?

What about Google domains?

Re: Amazon's customer service backdoor

#202
post #185

Earlier quoted context omitted.

Passwords are also security by obscurity.

Ssh ports are brute forceable, passwords have a much much larger search space.

At this point, 16 bits of entropy is more than the entropy of a lot of the passwords that I've seen.

Re: Amazon's customer service backdoor

#203
post #17

Whois is great for social engineering attackers. You get a name, email, address, and the first service to attack. Meanwhile, the ICANN is working around the clock to make it illegal for us to protect our personal information, and whois protection is becoming an increasingly niche service for registrars. For example, gandi.net (and thus Amazon) doesn't hide your name when you have it turned on. By the time you find th…

Fighting online thieves by putting more innocent people at risk doesn't sound like a way to fight online thieves.

Re: Amazon's customer service backdoor

#204
Working in the same neighborhood as Amazon's new headquarters, I've become convinced that not all is well with their security. All those blue badges with their employees' full names dangling from their belts while they're in line at the local food trucks is a social engineer's dream come true. Expect to see some high-profile breaches.

Re: Amazon's customer service backdoor

#205
post #86
post #72

Earlier quoted context omitted.

Worse, they'll happily sell you Whoisguard for domains that don't support it. When you discover it's not usable, they'll give you a refund, then include it again in the next billing cycle. I switched to Namecheap based on recommendations here, and their previous stance on certain privacy issues, but I'm running out of alternatives.

A happy NameCheap user for years, I have started switching away. Their horrid "modern" 40px padding everywhere bubbly redesign makes GoDaddy look good in comparison. A major pain to manage more than a couple of domains, and numerous user feedback seems to fall on deaf ears, e.g. [1][2][3][4] Example weird feature: all domains are shown, even ones that you've let expire/sold years ago, and there is no way to hide them…

Another ex-happy Namecheap customer here. Was going through credit card fraud issues back in July. In September out of nowhere get an email from Namecheap support that my July payment for one of the domains did not go through and I owe them $240 for the chargeback. No amount of reasoning got through to them - this is after several years of owning multiple domains with them. Dropped the penalty by $100, but that didn't exactly make it right. As I was considering my options, they locked all of my domains and redirected to parking pages. Had to pay up to get them back. Avoid at all costs.

TL;DR: Credit card was stolen, Namecheap penalized me for that and then blackmailed by locking all domains.

Re: Amazon's customer service backdoor

#206
post #86
post #72

Earlier quoted context omitted.

Worse, they'll happily sell you Whoisguard for domains that don't support it. When you discover it's not usable, they'll give you a refund, then include it again in the next billing cycle. I switched to Namecheap based on recommendations here, and their previous stance on certain privacy issues, but I'm running out of alternatives.

A happy NameCheap user for years, I have started switching away. Their horrid "modern" 40px padding everywhere bubbly redesign makes GoDaddy look good in comparison. A major pain to manage more than a couple of domains, and numerous user feedback seems to fall on deaf ears, e.g. [1][2][3][4] Example weird feature: all domains are shown, even ones that you've let expire/sold years ago, and there is no way to hide them…

But everyone's using a 10" Surface tablet now! We all need that 40px padding for our sausage fingers while tapping our screen at work.

Re: Amazon's customer service backdoor

#207
post #35

> services should allow me to easily create lots of aliases. Right now the best defense against social engineering seems to be my fastmail account which allows me to create 1 email address alias per service What you may want is a catch-all email - which lets you do @domain.com -> nmjohn@domain.com (where is everything besides already defined addresses) - that way you can make up emails on the fly without having to se…

I've done this and once had a phone rep from Geico who was convinced I worked for them because my email was something like geico@example.com. This was probably in the late 90s when email was still new to many people. She was really confused that I wasn't getting the employee discount. "Are you sure? Does a family member work for Geico? No? Are you sure?..." I don't think she ever did really understand what was going on.

Perhaps I could have saved even more than 15% if I'd just gone with it. :D

Re: Amazon's customer service backdoor

#208
post #198

There's also no way to separate AWS account from Amazon account it seems: https://forums.aws.amazon.com/thread.jspa?threadID=85882 This is really bad. The security implications are different between the two.

Sure there is. Sign up with a different email account. I hear they're free these days...

I meant that there isn't a supported way by Amazon. What about purchase history? Kindle books? Coupon credits? You're gonna manually migrate all AWS services you use one by one? What about AWS credits you might have gotten?

While you can certainly register two accounts and start all over, it's clear I meant an intentional support by the system to allow one to separate the two.

Re: Amazon's customer service backdoor

#209
post #72

Earlier quoted context omitted.

Worse, they'll happily sell you Whoisguard for domains that don't support it. When you discover it's not usable, they'll give you a refund, then include it again in the next billing cycle. I switched to Namecheap based on recommendations here, and their previous stance on certain privacy issues, but I'm running out of alternatives.

What's wrong with name.com?

Depends on who you're asking and from what timeframe you're asking about. They used to be absolutely horrid in the age of alternate and meta-TLDs when the real rush to nab a domain was on. I can't speak about present times, however.

Re: Amazon's customer service backdoor

#210
post #141
post #86

Earlier quoted context omitted.

A happy NameCheap user for years, I have started switching away. Their horrid "modern" 40px padding everywhere bubbly redesign makes GoDaddy look good in comparison. A major pain to manage more than a couple of domains, and numerous user feedback seems to fall on deaf ears, e.g. [1][2][3][4] Example weird feature: all domains are shown, even ones that you've let expire/sold years ago, and there is no way to hide them…

Another Namecheap "gotcha" is they auto-renew any domains you have setup for auto-renewal a full month before you're due for expiration. So if you're thinking of moving away, and trying to decide as the expiration date approaches, make sure to disable auto-renew on those domains while you decide.

It was my understanding that the registration time you have with one registrar carries over with the next registrar. In other words, if your domain is automatically renewed for a year and you move to a different registrar and pay for one year, your domain will be registered for two years.

I must say that I have never verified this myself, mostly because I've never needed it that bad. At least something worth looking into if that problem arises.

Post reply on HN