Live data from Hacker News

Amazon's customer service backdoor

medium.com

231–240 of 366 posts

Re: Amazon's customer service backdoor

#231
post #17

Whois is great for social engineering attackers. You get a name, email, address, and the first service to attack. Meanwhile, the ICANN is working around the clock to make it illegal for us to protect our personal information, and whois protection is becoming an increasingly niche service for registrars. For example, gandi.net (and thus Amazon) doesn't hide your name when you have it turned on. By the time you find th…

In the UK this and a lot more is public information. As an example of what is available about me online (without paying a penny) just by searching for my name:

- The year I was born

- The district I was born (not the exact town, although that wouldn't be hard to guess)

- My mother's maiden name (which is what most banks et al ask as a security question...)

- The areas I've lived (based upon the electoral register, which you can opt out of but supposedly this impacts your credit rating)

- That I am a director of a company

This is just what is available for free - you can get the full records this is extracted from by paying a small fee.

If you know the name of my company (which isn't hard to find out), you can also find for free:

- My full name

- My address

- My date of birth

- Roughly how much I make a year

TL;DR; If you rely on this to 'identify' someone, you are doing it wrong.

Re: Amazon's customer service backdoor

#232

"The problem is, 9999 times out of 10000 support requests are legitimate, agents get trained to assume they’re legitimate. But in the 1 case they’re not, you can completely fuck someone over." That's why nothing will change if these estimates are even in the right universe. Nobody wants to inconvenience the vast majority of customers to prevent a minuscule number of issues.

I'm probably going against the flow here, but I value convenience over security.

I had my identity stolen once, and it sure was annoying... if also a little fun. A credit was opened in my name, that I had to fight to close, and I was even interrogated by police because false me was associated with shady characters (surprise!) but in the end it wasn't the end of the world.

Security "features" however, are usually so annoying they destroy the will to live. They would be tolerable once, but they're constant, and constantly remind you that you are, in fact, a suspect. They pretend to "protect" you but actually dehumanize you and every interaction you have with other humans (not to mention security theater, where the features don't increase security in any way but are simply there to make you "feel" safe).

Being alive is to be at risk, and at the mercy of bad guys. We should accept it and enjoy life before we all die in the end anyway.

Re: Amazon's customer service backdoor

#233
Amazon does not care. A fraudster used our startup bank account to pay at Amazon. We told them, they did not blacklist the user to use our account or take any actions beside removing the bank account (ours) from his Amazon account.

The fraudster did this at least 3 times with increasing amounts of money. Amazon did not care. Only when we went to the police did this stop.

Amazon sold me a phone, the box arrived empty (I wonder why they do not check the weight when it leaves their warehouse, DHL printed a weight on the box that was less than the phone alone). It took Amazon support months to solve this, especially they could or would not cancel the attached mobile phone contract for months.

Re: Amazon's customer service backdoor

#234
post #17

Whois is great for social engineering attackers. You get a name, email, address, and the first service to attack. Meanwhile, the ICANN is working around the clock to make it illegal for us to protect our personal information, and whois protection is becoming an increasingly niche service for registrars. For example, gandi.net (and thus Amazon) doesn't hide your name when you have it turned on. By the time you find th…

In Germany you have to publish a full address on your website, so even if you don't own the domain, anybody can get you IRL. http://www.gesetze-im-internet.de/tmg/__5.html

Ditto for TLDs controlled by the Indian Government.

Re: Amazon's customer service backdoor

#235

Earlier quoted context omitted.

In Germany you have to publish a full address on your website, so even if you don't own the domain, anybody can get you IRL. http://www.gesetze-im-internet.de/tmg/__5.html

Only if you have a commercial site.

According to the Wikipedia the word "geschäftsmäßig" includes private use website if it is even theoretically possible to get income from them, for example via ads. It quotes the ministry:

„Die Anbieterkennzeichnungspflicht muss praktisch von jedem, der ein Online-Angebot bereithält, erfüllt werden. Etwas anderes gilt nur bei Angeboten, die ausschließlich privaten oder familiären Zwecken dienen und die keine Auswirkung auf den Markt haben. Im Zweifel sollten Sie davon ausgehen, dass die Anbieterkennzeichnungspflicht besteht.“

Which roughly translates to: everyone has to do it, unless its a purely private service. So I guess you don't need it for you web-enabled password protected security cam, but you definitely need it for your blog.

https://de.wikipedia.org/wiki/Impressumspflicht

Re: Amazon's customer service backdoor

#236
Wow. I had a similar experience with Skype too. They couldn't care less that someone had got access to my account and made calls. The attacker even added his own mobile number (in a different country) but Skype wouldn't bother investigating or escalating...

Re: Amazon's customer service backdoor

#237
post #46

Earlier quoted context omitted.

Fastmail and Gmail support a local suffix of the form yourname+amazon@gmail.com. That's a plus character between the local name and local suffix. If you use a password manager, you can replace a predictable suffix like "amazon" with random hex value. Unfortunately, many sites borked their e-mail address validation and do not accept the plus character. (Amazon permits it.) Also, you'll ocassionally find a customer ser…

Gmail also allows yourname.amazon@gmail.com

No they don't, since I could register that. Maybe your confusing the period with a plus?

Re: Amazon's customer service backdoor

#238
post #24
post #17

Whois is great for social engineering attackers. You get a name, email, address, and the first service to attack. Meanwhile, the ICANN is working around the clock to make it illegal for us to protect our personal information, and whois protection is becoming an increasingly niche service for registrars. For example, gandi.net (and thus Amazon) doesn't hide your name when you have it turned on. By the time you find th…

Yes, it's awful. Fortunately, at least one registrar (Google Domains) has free whois privacy for all registrations and I think they prompt you about it by default, too (to agree to some legal terms).

Hover also has free whois privacy by default.

Re: Amazon's customer service backdoor

#239
This article has taught me a valuable lesson: I should be using the email+suffix@gmail.com feature in each service I'm signed up for. Seems like an easy enough change.

Ideally, the suffix would be some non obvious function of the service name, which I can remember easily. Like taking the second letter of the service name and relating it to an object I encounter a lot in my life.

Re: Amazon's customer service backdoor

#240

Earlier quoted context omitted.

In Germany you have to publish a full address on your website, so even if you don't own the domain, anybody can get you IRL. http://www.gesetze-im-internet.de/tmg/__5.html

Only if you have a commercial site.

At one point in the past it was argued that hosting your site with a provider that injects ads was sufficient to consider the page "commercial". I don't know what came of it, or what is now required for a page to be commercial.
Post reply on HN