Live data from Hacker News

Amazon's customer service backdoor

medium.com

271–280 of 366 posts

Re: Amazon's customer service backdoor

#271

Earlier quoted context omitted.

> While it gives a problem with certain websites (don't consider it a valid e-mail address) Are you saying that there are sites out there which don't accept mailbox@subdomain.example.com a valid email address? If so, that's beyond broken...

My school's student addresses ended in @u.northwestern.edu. You can imagine this was annoying sometimes when email addresses ending in .edu were used to verify student status.

And you can imagine how maddening it is when 90% of students worldwide don't have a .edu, but some do.

Only one university in Germany has a .edu, and their students obviously manage to get far more benefits than those of us with an @informatik.uni-kiel.de email.

Re: Amazon's customer service backdoor

#272
post #232

"The problem is, 9999 times out of 10000 support requests are legitimate, agents get trained to assume they’re legitimate. But in the 1 case they’re not, you can completely fuck someone over." That's why nothing will change if these estimates are even in the right universe. Nobody wants to inconvenience the vast majority of customers to prevent a minuscule number of issues.

I'm probably going against the flow here, but I value convenience over security. I had my identity stolen once, and it sure was annoying... if also a little fun. A credit was opened in my name, that I had to fight to close, and I was even interrogated by police because false me was associated with shady characters (surprise!) but in the end it wasn't the end of the world. Security "features" however, are usually so a…

As hesitant or ashamed as I am to admit it it, I must agree... convenience is king.

PGP/GPG comes to mind. Yes, technically superior but good god is it arduous.

Re: Amazon's customer service backdoor

#273

Earlier quoted context omitted.

That's probably wishful thinking. I haven't checked Amazon's terms of service, but nowadays you can count on both of these being true: - you agreed to arbitration - you agreed to disallow class action lawsuits I.e. thanks to the Supremes[1]: As a result, businesses that include arbitration agreements with class action waivers can require consumers to bring claims only in individual arbitrations, rather than in court…

I'm pretty sure those kind of terms, at least in The Netherlands and most of Europe, are illegal. So lets Class-action them in Europe instead? I'll pitch in 100 euros.

Any lawsuit, class action or otherwise, requires the claimants to have suffered whatever harm they're suing over. You can't sue a company because they injured someone else.

(IANAL and I'm only familiar with English law, but I'd be very surprised if there was anywhere where that isn't true, it's pretty fundamental)

Re: Amazon's customer service backdoor

#274

Amazon does not care. A fraudster used our startup bank account to pay at Amazon. We told them, they did not blacklist the user to use our account or take any actions beside removing the bank account (ours) from his Amazon account. The fraudster did this at least 3 times with increasing amounts of money. Amazon did not care. Only when we went to the police did this stop. Amazon sold me a phone, the box arrived empty…

I had a situation where Amazon couldn't bill my bank account, so they blocked logging in. I verified with just name and address to a customer service rep and asked for the steps I'd have to do to unlock it again, and they told me that (a) the transaction failed, (b) they told me my IBAN. In plaintext. The full IBAN. (c) and then they told me the steps to fix it (wire them the money that I was owing them, plus 6 EUR.…

Could you tell how knowing IBAN enables someone to take money from your account? As far as I understand, the only think that can happen with IBAN is to receive money.

Maybe you're thinking of credit card number? The CC's I had had different CC number and IBAN account.

Re: Amazon's customer service backdoor

#275
post #141

Earlier quoted context omitted.

Another Namecheap "gotcha" is they auto-renew any domains you have setup for auto-renewal a full month before you're due for expiration. So if you're thinking of moving away, and trying to decide as the expiration date approaches, make sure to disable auto-renew on those domains while you decide.

It was my understanding that the registration time you have with one registrar carries over with the next registrar. In other words, if your domain is automatically renewed for a year and you move to a different registrar and pay for one year, your domain will be registered for two years. I must say that I have never verified this myself, mostly because I've never needed it that bad. At least something worth looking…

Yep, that's exactly what happens: https://duckduckgo.com/?q="domain+transfer"+"remaining+time"

(Can actually confirm that from this month's experience, so it's even freshly verified :)

Re: Amazon's customer service backdoor

#276

Amazon does not care. A fraudster used our startup bank account to pay at Amazon. We told them, they did not blacklist the user to use our account or take any actions beside removing the bank account (ours) from his Amazon account. The fraudster did this at least 3 times with increasing amounts of money. Amazon did not care. Only when we went to the police did this stop. Amazon sold me a phone, the box arrived empty…

I had a situation where Amazon couldn't bill my bank account, so they blocked logging in. I verified with just name and address to a customer service rep and asked for the steps I'd have to do to unlock it again, and they told me that (a) the transaction failed, (b) they told me my IBAN. In plaintext. The full IBAN. (c) and then they told me the steps to fix it (wire them the money that I was owing them, plus 6 EUR.…

How would you pull money from an account by knowing just the IBAN? That's just the public address of your bank account and can be used to give you money, but you need all kinds of authentication to actually get money out of that account.

Re: Amazon's customer service backdoor

#277

Amazon does not care. A fraudster used our startup bank account to pay at Amazon. We told them, they did not blacklist the user to use our account or take any actions beside removing the bank account (ours) from his Amazon account. The fraudster did this at least 3 times with increasing amounts of money. Amazon did not care. Only when we went to the police did this stop. Amazon sold me a phone, the box arrived empty…

I had a similar experience buying a somewhat expensive watch through them - my wife was surprised to receive a very fancy, and empty, box. However to their credit they sent another one immediately, no questions asked. I really hope for Amazon to fix the issues OP pointed at, as an amazon.de customer I'm extremely happy with them.

Re: Amazon's customer service backdoor

#278
post #61

Earlier quoted context omitted.

> For example, gandi.net (and thus Amazon) Why do you say here and thus Amazon?

I assume it's because AWS uses Gandi as their registrar.[1] [1]: https://news.ycombinator.com/item?id=8116506

while Amazon itself uses Mark Monitor from CSC.

Re: Amazon's customer service backdoor

#279
post #17

Whois is great for social engineering attackers. You get a name, email, address, and the first service to attack. Meanwhile, the ICANN is working around the clock to make it illegal for us to protect our personal information, and whois protection is becoming an increasingly niche service for registrars. For example, gandi.net (and thus Amazon) doesn't hide your name when you have it turned on. By the time you find th…

In Denmark (.dk), any citizen can get their address information removed from publicly available records. That means that any private individual or company cannot get access to your address information unless you manually give it to them. (Note: Government agencies still have access to this information.)

.dk-domains are owned by persons, not the registrars, and therefore the whois-information for .dk-domains follow the same procedure as addresses. So if you have 'address protection' as it is called, your personal information is immediately removed from your whois information.

Re: Amazon's customer service backdoor

#280
post #86

Earlier quoted context omitted.

A happy NameCheap user for years, I have started switching away. Their horrid "modern" 40px padding everywhere bubbly redesign makes GoDaddy look good in comparison. A major pain to manage more than a couple of domains, and numerous user feedback seems to fall on deaf ears, e.g. [1][2][3][4] Example weird feature: all domains are shown, even ones that you've let expire/sold years ago, and there is no way to hide them…

Another ex-happy Namecheap customer here. Was going through credit card fraud issues back in July. In September out of nowhere get an email from Namecheap support that my July payment for one of the domains did not go through and I owe them $240 for the chargeback. No amount of reasoning got through to them - this is after several years of owning multiple domains with them. Dropped the penalty by $100, but that didn'…

Wow, I was just about to switch to Namecheap. More people need to hear this. How can a registrar make DNS changes without permission and blackmail?

Please write a blog post about this.

Post reply on HN