Live data from Hacker News

Amazon's customer service backdoor

medium.com

281–290 of 366 posts

Re: Amazon's customer service backdoor

#281
post #72

Earlier quoted context omitted.

A related word of warning: Namecheap updated their registration page last year. Now, when you register a domain it tells you free Whoisguard is included, but it doesn't make it clear that it's disabled by default." Previously it just worked. Now you have to check another box to turn it on. This change makes no sense to me. (If you want free Whoisguard, why would you not want it turned on?) I was white-hot furious* wh…

Worse, they'll happily sell you Whoisguard for domains that don't support it. When you discover it's not usable, they'll give you a refund, then include it again in the next billing cycle. I switched to Namecheap based on recommendations here, and their previous stance on certain privacy issues, but I'm running out of alternatives.

I have been happy with NameSilo.

They have a very strong privacy stance and take security seriously

Re: Amazon's customer service backdoor

#283
post #147

Earlier quoted context omitted.

Do you mind sharing where you switched to?

Ah, just Amazon (which uses Gandi under the hood.) Many pluses: predictable, can be administered using the AWS CLI, consolidated billing with other AWS services. Heck, can even register domains from the CLI. Only downside as others have pointed out is that Gandi doesn't make it at all easy to hide your name or company contact information.

>Ah, just Amazon

So you are recommending someone switch over privacy concerns from namecheap to Amazon in story about how Amazon is leaking private Customer data.....

Really...

Re: Amazon's customer service backdoor

#284
post #202

Earlier quoted context omitted.

At this point, 16 bits of entropy is more than the entropy of a lot of the passwords that I've seen.

You have 10 bits of entropy at best, unless you put it above 1024, at which point if it dies, any none privileged user on the box can sniff passwords.

If you are serious, you should limit SSH access to a bastion host with no unprivileged users.

Re: Amazon's customer service backdoor

#285
I find it a bit weird that address and even credit card number are confidential information. Credit card numbers are not really secret, you hand them out to random waiters in random restaurants. Maybe part of the fault lies with the other companies who accept that information as ID?

Re: Amazon's customer service backdoor

#286
post #52

How to stop this: 1. Get a friend's permission to "hack" into his Amazon account (or "hack your own account"). 2. Contact Amazon's customer service, try the same social engineering techniques that the OP documented. 3. Once you obtain some sensitive information from the account, scare the CS rep by saying: "Haha! I am actually not the customer. I am a journalist/hacker/whatever and wanted to see how easy it was to so…

4. Get arrested

Re: Amazon's customer service backdoor

#288
post #28

Earlier quoted context omitted.

If someone has your public name and address you're already at significant risk if you ever say anything controversial that gets attention. You're liable to being swatted, getting fake pizza orders, having people show up at your house, harassing you and much more. See Zoe Quinn, Brian Krebs, lots of less well known individuals, etc.

Which only proves your comment's parent's point even more. {SWAT, pizza orders, etc} assume that the phone number that shows up on caller ID is authentication of the identity of the phone line on the other end. They could call back the number on caller ID to verify the original caller matched the person who picked up, but they don't. Having knowledge of a Social Security number was assumed to be authentication, but i…

>Having knowledge of a Social Security number was assumed to be authentication

No the people that designed and implemented Social Security knew it was not secure for identification purposes, the first few decades of the program even had "Not to be used for Identification" on the card.

Then the government, and financial industry got lazy and said "well since the majority of people already have these numbers assigned to them lets just use them for Identification as well" and made it a defacto National ID. Something it was never designed for, nor secure enough to be,

Re: Amazon's customer service backdoor

#289
A possible solution to avoid people finding out the email you're using for a given service is to dump random word/phrase in your email address.

e.g. email+ifidontknowthisthisisnotme@youremail.com

Not sure how an agent would react to someone having part of the correct email though.

Re: Amazon's customer service backdoor

#290
It is rather unfortunate yet at the same time unsurprising. :(

Two years ago I found out that Amazon allows multiple accounts to be set up using the same email address with different passwords (!!!) - which means that the potential attack vector is larger for no good reason.

I don't recall how this happened but I can only assume at the time I signed up to AWS and I might have reset/changed the password somehow that resulted in the system creating another copy of my account.

So all the information (credit cards, addresses, etc) of the "old" account still existed until I deleted them. But let's say if someone who has no idea that they have more than one accounts with Amazon, they could easily leave their information intact in their "old" accounts, which if they have weak passwords can easily be compromised.

Unfortunately Amazon did not take this report seriously, and to this very day this issue still persists.

Post reply on HN