Live data from Hacker News

Amazon's customer service backdoor

medium.com

261–270 of 366 posts

Re: Amazon's customer service backdoor

#261
post #66

Earlier quoted context omitted.

Which only proves your comment's parent's point even more. {SWAT, pizza orders, etc} assume that the phone number that shows up on caller ID is authentication of the identity of the phone line on the other end. They could call back the number on caller ID to verify the original caller matched the person who picked up, but they don't. Having knowledge of a Social Security number was assumed to be authentication, but i…

Keep in mind too that Caller ID is trivially blockable (and blocked caller id isn't remarkable enough to be super suspicious), and it's also easily within the capability of many of the 4chan/gg griefers to spoof "correct" Caller ID numbers as well.

[deleted]

Re: Amazon's customer service backdoor

#263
post #212

Earlier quoted context omitted.

My school's student addresses ended in @u.northwestern.edu. You can imagine this was annoying sometimes when email addresses ending in .edu were used to verify student status.

>My school's student addresses ended in @u.northwestern.edu. You can imagine this was annoying sometimes when email addresses ending in .edu were used to verify student status. Sorry, could you repeat that? yourname@u.northwestern.edu certainly matches \.edu$. Unless you're worried about the false-positive for a non-student with a different subdomain?

It doesnt match \w\.edu$

Re: Amazon's customer service backdoor

#265
post #17

Whois is great for social engineering attackers. You get a name, email, address, and the first service to attack. Meanwhile, the ICANN is working around the clock to make it illegal for us to protect our personal information, and whois protection is becoming an increasingly niche service for registrars. For example, gandi.net (and thus Amazon) doesn't hide your name when you have it turned on. By the time you find th…

A related word of warning: Namecheap updated their registration page last year. Now, when you register a domain it tells you free Whoisguard is included, but it doesn't make it clear that it's disabled by default." Previously it just worked. Now you have to check another box to turn it on. This change makes no sense to me. (If you want free Whoisguard, why would you not want it turned on?) I was white-hot furious* wh…

Please can you tell me how I can verify whether my details have been leaked?

I've recently purchased a domain from namecheap, with whoisguard, and if I recall correctly I didn't have to turn it on. I whois'd myself and found that it didn't leak anything. It didn't occur to me that scrapers can get at the info before you protect it.

Perhaps this has changed since your experience? Please could anybody else verify one way or another?

Cheers

Re: Amazon's customer service backdoor

#266
post #185

Earlier quoted context omitted.

Hiding your contact information is like security through obscurity. I'm not saying it's not a good extra step to decrease the frequency of attacks (much like changing an SSH port to 3857 or something), but it doesn't add any real security. This is the crux of the problem; our addressees and birthdays are treated like passwords by these companies.

Passwords are also security by obscurity.

Passwords are explicitly keys and not used for any other purpose.

Re: Amazon's customer service backdoor

#267
post #28

Earlier quoted context omitted.

If someone has your public name and address you're already at significant risk if you ever say anything controversial that gets attention. You're liable to being swatted, getting fake pizza orders, having people show up at your house, harassing you and much more. See Zoe Quinn, Brian Krebs, lots of less well known individuals, etc.

Which only proves your comment's parent's point even more. {SWAT, pizza orders, etc} assume that the phone number that shows up on caller ID is authentication of the identity of the phone line on the other end. They could call back the number on caller ID to verify the original caller matched the person who picked up, but they don't. Having knowledge of a Social Security number was assumed to be authentication, but i…

Not that I order pizza more than once a few months, but I would probably switch the pizza place that would call back to confirm order each time.

Re: Amazon's customer service backdoor

#268
post #17

Whois is great for social engineering attackers. You get a name, email, address, and the first service to attack. Meanwhile, the ICANN is working around the clock to make it illegal for us to protect our personal information, and whois protection is becoming an increasingly niche service for registrars. For example, gandi.net (and thus Amazon) doesn't hide your name when you have it turned on. By the time you find th…

OVH did this to me, I registered a .pw domain and I though it was WHOIS secure, but after registering... I found my full name, address and email were all public, forever. (Domaintools keeps a record of it)

I will never again register a domain with my real info. Sorry ICANN, I don't give a about you or your policy.

Re: Amazon's customer service backdoor

#269

Amazon does not care. A fraudster used our startup bank account to pay at Amazon. We told them, they did not blacklist the user to use our account or take any actions beside removing the bank account (ours) from his Amazon account. The fraudster did this at least 3 times with increasing amounts of money. Amazon did not care. Only when we went to the police did this stop. Amazon sold me a phone, the box arrived empty…

I had a situation where Amazon couldn't bill my bank account, so they blocked logging in.

I verified with just name and address to a customer service rep and asked for the steps I'd have to do to unlock it again, and they told me that (a) the transaction failed, (b) they told me my IBAN. In plaintext. The full IBAN. (c) and then they told me the steps to fix it (wire them the money that I was owing them, plus 6 EUR. Standard procedure in Germany).

In the end, everything worked again, but, the fact that they gave out by IBAN — enough info for anyone to go and pull money from my account — is making me so angry.

Re: Amazon's customer service backdoor

#270

Earlier quoted context omitted.

No they don't, since I could register that. Maybe your confusing the period with a plus?

EDIT: I am stupid, disregard thread

That's radically different to what you presented in your previous example.
Post reply on HN