Live data from Hacker News

Amazon's customer service backdoor

medium.com

311–320 of 366 posts

Re: Amazon's customer service backdoor

#312

Earlier quoted context omitted.

Could you tell how knowing IBAN enables someone to take money from your account? As far as I understand, the only think that can happen with IBAN is to receive money. Maybe you're thinking of credit card number? The CC's I had had different CC number and IBAN account.

If you call a bank or another entity, that has your bank information on record, and claim to be someone specific, can answer basic questions and knows the full IBAN - perhaps they believe you are who you claim to be. This is social engineering, and it works.

I think parent specifically mentioned that just IBAN is enough which sounded very unprobable for me. Another comment explained that it's possible but in very specific accounts.

Re: Amazon's customer service backdoor

#313
post #290

It is rather unfortunate yet at the same time unsurprising. :( Two years ago I found out that Amazon allows multiple accounts to be set up using the same email address with different passwords (!!!) - which means that the potential attack vector is larger for no good reason. I don't recall how this happened but I can only assume at the time I signed up to AWS and I might have reset/changed the password somehow that r…

My email address also maps to two unique accounts. One of them has never had any information on it anyway but I agree it's very concerning.

Re: Amazon's customer service backdoor

#314
post #17

Whois is great for social engineering attackers. You get a name, email, address, and the first service to attack. Meanwhile, the ICANN is working around the clock to make it illegal for us to protect our personal information, and whois protection is becoming an increasingly niche service for registrars. For example, gandi.net (and thus Amazon) doesn't hide your name when you have it turned on. By the time you find th…

In the UK this and a lot more is public information. As an example of what is available about me online (without paying a penny) just by searching for my name: - The year I was born - The district I was born (not the exact town, although that wouldn't be hard to guess) - My mother's maiden name (which is what most banks et al ask as a security question...) - The areas I've lived (based upon the electoral register, wh…

At least Nominet allows you to opt out of public WHOIS information.

Although they planned to change this if you ran ads on your site:

http://www.theguardian.com/technology/2014/jun/11/nominet-ne...

Re: Amazon's customer service backdoor

#315
post #86

Earlier quoted context omitted.

A happy NameCheap user for years, I have started switching away. Their horrid "modern" 40px padding everywhere bubbly redesign makes GoDaddy look good in comparison. A major pain to manage more than a couple of domains, and numerous user feedback seems to fall on deaf ears, e.g. [1][2][3][4] Example weird feature: all domains are shown, even ones that you've let expire/sold years ago, and there is no way to hide them…

Do you mind sharing where you switched to?

I've been using Moniker for ages. I'm always surprised I don't see it recommended more often. They seem very steady and reliable.

Re: Amazon's customer service backdoor

#316

Earlier quoted context omitted.

Your remark about opting out of the electoral register is not quite correct. It is a requirement to register if requested, the fine for failing to do so is £80. However, it is always an option to not appear on the open register. The open register is publicly accessible, and being absent from it will not be detrimental to your credit rating.

>being absent from it will not be detrimental to your credit rating. But it will make identity checks with banks a little more complicated, normally they use the electoral register to confirm your address

I have always opted out of the open or edited register, and have never had a problem with this.

Seems like your details can still be used for credit checks and fraud prevention (which I imagine covers confirming identities and addresses) even when you opt out[1].

[1] http://www.electoralcommission.org.uk/faq/voting-and-registr...

Re: Amazon's customer service backdoor

#317
post #303

Earlier quoted context omitted.

SEPA direct debit allows you to pull money via IBAN (+ BIC, depending on the countries involved in the transaction). Specifics vary from country to country. Some require active approval from the customer (IIRC France, probably more), others "just work". Fraud is not as common, since bank accounts that are allowed to debit money this way are generally only available to companies who have to sign paperwork ensuring tha…

Thanks, didn't know about that. Sounds like it's very specific version of account and most default accounts with IBAN doesn't have this possibility.

No, anyone’s account can be debited from, but only specific accounts can be debited to.

I can’t pull money from your account, even if you tell me your IBAN.

But I can use your IBAN to order from amazon, and then amazon can just pull however much they want from your account.

Luckily chargeback with direct debit works just as fast as with credit cards.

Re: Amazon's customer service backdoor

#318
post #276

Earlier quoted context omitted.

I had a situation where Amazon couldn't bill my bank account, so they blocked logging in. I verified with just name and address to a customer service rep and asked for the steps I'd have to do to unlock it again, and they told me that (a) the transaction failed, (b) they told me my IBAN. In plaintext. The full IBAN. (c) and then they told me the steps to fix it (wire them the money that I was owing them, plus 6 EUR.…

How would you pull money from an account by knowing just the IBAN? That's just the public address of your bank account and can be used to give you money, but you need all kinds of authentication to actually get money out of that account.

SEPA Direct Debit, or "Elektronisches Lastschriftverfahren".

You can go to amazon, give them your IBAN, and buy things, and they’ll use direct debit to get the money from the account specified by the IBAN, no further authentication necessary.

Obviously, you can do chargebacks, but this is still something they shouldn’t publish.

Re: Amazon's customer service backdoor

#319

Earlier quoted context omitted.

It on average 24h or less, considering that mail through DHL is next-morning delivery everywhere, and same-day delivery in larger cities.

This may come as a shock to you but some people live outside the United States.

I’m in Germany, actually.

Re: Amazon's customer service backdoor

#320
post #100

Earlier quoted context omitted.

I think there is already enough here to shame Amazon into action if it gets on a major newspaper. Something like "Hackers break into Amazon account and Amazon will not do anything" Perhaps the Washington Post would be a good newspaper with credibility.

This already happened to Matt Honan back in 2012, where the hacker used social engineering on both Amazon and Apple to take over his twitter handle (oh and also wiping all his devices via iCloud). http://www.wired.com/2012/08/apple-amazon-mat-honan-hacking/ It looks like both Amazon and Apple have fixed _some_ issues since then - Amazon is no longer leaking last 4 digits, but instead they're still leaking other info.…

Apple set up 2FA for certain actions (changing passwords, adding or removing devices from an account, etc); Amazon has yet to do anything related to 2FA for normal customer accounts.
Post reply on HN