Live data from Hacker News

Amazon's customer service backdoor

medium.com

291–300 of 366 posts

Re: Amazon's customer service backdoor

#291

Worth checking out: someone reproduces using a fake address to get a real address. https://medium.com/@amaz/thank-you-for-sharing-this-but-i-co... (contains pretty great screencaptures)

Wow, that second rep was really struggling to find the line in his script that fit the situation (without much success).

Re: Amazon's customer service backdoor

#292
post #86

Earlier quoted context omitted.

A happy NameCheap user for years, I have started switching away. Their horrid "modern" 40px padding everywhere bubbly redesign makes GoDaddy look good in comparison. A major pain to manage more than a couple of domains, and numerous user feedback seems to fall on deaf ears, e.g. [1][2][3][4] Example weird feature: all domains are shown, even ones that you've let expire/sold years ago, and there is no way to hide them…

Another ex-happy Namecheap customer here. Was going through credit card fraud issues back in July. In September out of nowhere get an email from Namecheap support that my July payment for one of the domains did not go through and I owe them $240 for the chargeback. No amount of reasoning got through to them - this is after several years of owning multiple domains with them. Dropped the penalty by $100, but that didn'…

Hey romanhn - did you contact support and try to make it right by reversing the chargeback?

This isn't about blackmail as jewsin writes in the comments, it's about the reputation a business suffers with a chargeback. All you would need to do is reverse the chargeback and the full charge would go away.

Disclosure: I work for Namecheap.

Re: Amazon's customer service backdoor

#293
post #86
post #72

Earlier quoted context omitted.

Worse, they'll happily sell you Whoisguard for domains that don't support it. When you discover it's not usable, they'll give you a refund, then include it again in the next billing cycle. I switched to Namecheap based on recommendations here, and their previous stance on certain privacy issues, but I'm running out of alternatives.

A happy NameCheap user for years, I have started switching away. Their horrid "modern" 40px padding everywhere bubbly redesign makes GoDaddy look good in comparison. A major pain to manage more than a couple of domains, and numerous user feedback seems to fall on deaf ears, e.g. [1][2][3][4] Example weird feature: all domains are shown, even ones that you've let expire/sold years ago, and there is no way to hide them…

lpsz - Tamar from Namecheap here. We're working on the padding. It's not that it's falling on deaf ears; it's just that it's taking time for us to implement and QA.

Also, the issue with all domains being shown is a bug. If you have a ticket number regarding this, please let me know and I'll investigate this further because it should be resolved.

Re: Amazon's customer service backdoor

#294
post #280

Earlier quoted context omitted.

Another ex-happy Namecheap customer here. Was going through credit card fraud issues back in July. In September out of nowhere get an email from Namecheap support that my July payment for one of the domains did not go through and I owe them $240 for the chargeback. No amount of reasoning got through to them - this is after several years of owning multiple domains with them. Dropped the penalty by $100, but that didn'…

Wow, I was just about to switch to Namecheap. More people need to hear this. How can a registrar make DNS changes without permission and blackmail? Please write a blog post about this.

"If you don't pay us, we'll turn it off" isn't blackmail.

Re: Amazon's customer service backdoor

#295
post #202

Earlier quoted context omitted.

At this point, 16 bits of entropy is more than the entropy of a lot of the passwords that I've seen.

You have 10 bits of entropy at best, unless you put it above 1024, at which point if it dies, any none privileged user on the box can sniff passwords.

Why are you using passwords for SSH?

Do you actually have untrusted users on the box?

Why would you not secure the custom port to root-only?

Re: Amazon's customer service backdoor

#296

Earlier quoted context omitted.

> For example, gandi.net (and thus Amazon) doesn't hide your name when you have it turned on. Well, yeah, I've been with Gandi for years, that's their published policy: https://www.gandi.net/domain/whois/ > By the time you find this out You realize you should have done your homework and read your registrar's policies beforehand? I understand your overall point, but don't make it sound like Gandi did anything wrong he…

I would have left this very comment if you hadn't beaten me to it. :) Gandi is very up-front about every aspect of their services. I found out that Gandi's whois privacy doesn't hide the name you provide as the registrant long before I entered my credit card details to provide payment information. Their whois privacy is structured in this way because for many (all?) TLDs ICANN requires that the entity listed as the r…

I love Gandi because they live by their motto: No Bullshit.

Re: Amazon's customer service backdoor

#297
post #141
post #86

Earlier quoted context omitted.

A happy NameCheap user for years, I have started switching away. Their horrid "modern" 40px padding everywhere bubbly redesign makes GoDaddy look good in comparison. A major pain to manage more than a couple of domains, and numerous user feedback seems to fall on deaf ears, e.g. [1][2][3][4] Example weird feature: all domains are shown, even ones that you've let expire/sold years ago, and there is no way to hide them…

Another Namecheap "gotcha" is they auto-renew any domains you have setup for auto-renewal a full month before you're due for expiration. So if you're thinking of moving away, and trying to decide as the expiration date approaches, make sure to disable auto-renew on those domains while you decide.

Not really a gotcha. Some TLDs require that early renewal and one month is how we handle to avoid any disconnection in service. But yes, if you move away after a domain is renewed (e.g. your domain expires in 2017, most registrars -- but not all -- will add a year to renew in 2018).

(Full disclosure: I work at Namecheap)

Re: Amazon's customer service backdoor

#298
Same sh#t happens with Apple Support all the time, for few years in a row. Someone was after my last 4 digits, requesting password resets to Apple ID, like 14 times a day, and then impersonating me, talking to support.

Re: Amazon's customer service backdoor

#299
post #89
post #33

Earlier quoted context omitted.

They don't hide the name because you cannot hide the name while legally owning the domain yourself. Services that hide the name actually result in a company (e.g. "Domains by Proxy LLC") purchasing and holding domain ownership for you, which is a very different legal arrangement with different risks.

Treat a domain like money: if you want it held pseudonymously, you put it in the ownership of a shell corporation you control (through power of attorney to the board of directors), but don't own any equity in.

Sounds expensive, though.

Re: Amazon's customer service backdoor

#300
post #17

Whois is great for social engineering attackers. You get a name, email, address, and the first service to attack. Meanwhile, the ICANN is working around the clock to make it illegal for us to protect our personal information, and whois protection is becoming an increasingly niche service for registrars. For example, gandi.net (and thus Amazon) doesn't hide your name when you have it turned on. By the time you find th…

In the UK this and a lot more is public information. As an example of what is available about me online (without paying a penny) just by searching for my name: - The year I was born - The district I was born (not the exact town, although that wouldn't be hard to guess) - My mother's maiden name (which is what most banks et al ask as a security question...) - The areas I've lived (based upon the electoral register, wh…

Your remark about opting out of the electoral register is not quite correct.

It is a requirement to register if requested, the fine for failing to do so is £80. However, it is always an option to not appear on the open register. The open register is publicly accessible, and being absent from it will not be detrimental to your credit rating.

Post reply on HN