Live data from Hacker News

Amazon's customer service backdoor

medium.com

351–360 of 366 posts

Re: Amazon's customer service backdoor

#351

Earlier quoted context omitted.

Thanks, didn't know about that. Sounds like it's very specific version of account and most default accounts with IBAN doesn't have this possibility.

No, anyone’s account can be debited from, but only specific accounts can be debited to. I can’t pull money from your account, even if you tell me your IBAN. But I can use your IBAN to order from amazon, and then amazon can just pull however much they want from your account. Luckily chargeback with direct debit works just as fast as with credit cards.

Thanks! That's something new that I didn't hear before. For interested parties seems [0] has some information. I need to check with my bank then to see how it works in my country.

[0] https://gocardless.com/guides/sepa/introduction/

Re: Amazon's customer service backdoor

#352
post #227

Earlier quoted context omitted.

Ssh ports are brute forceable, passwords have a much much larger search space.

Changed SSH port is not security measure. It's needed to keep your log files clear from random network scanning. When your SSH port is something like 53148 and you see password brute-force activity in logs it's almost always mean that somebody intentionally scanning your server.

That's a somewhat obsolete belief – people have been scanning arbitrary ports for many, many years and SSH daemons helpfully announce themselves to search engines:

https://www.shodan.io/report/uMZDnWfT

This is a long-running problem and one with various popular solutions: restrict the source networks which you accept traffic for, disable password authentication entirely, and add some sort of rate limiting (e.g. 2004's fail2ban) for failures. Trying to reduce log volume by obscurity is futile - you really need to address the root problem and use tools which allow you to filter and aggregate effectively.

Re: Amazon's customer service backdoor

#353
post #59

Earlier quoted context omitted.

One method that I've seen used (heard it described by a guest one of Leo Laporte's podcasts a looooong time ago) is to iterate account names by year. For example, this year the email address would be pyre2016@example.com, and next year it will be pyre2017@example.com. Not sure how well it works, but the idea is that by that every year you start over with a fresh address (that takes a while to get onto spam lists). I'…

I believe the real issue here is its not uncommon for spam services to try to locate valid email addresses. Generally, an email server won't accept email to an invalid users and will probably start flagging the incoming server/domain as those attempts start to cross a threshold of some sort. OP is talking about *@example.com as a catchall which means a spammers script will sit there and email a dictionary of username…

I was talking about making those actual accounts vs. aliases to the catchall address. That method makes no sense if each pyre@example.com email address was just an alias to the catchall because pyre@example.com would still be caught by the catch-all, even if you disabled the alias.

Re: Amazon's customer service backdoor

#354
post #59

Earlier quoted context omitted.

One method that I've seen used (heard it described by a guest one of Leo Laporte's podcasts a looooong time ago) is to iterate account names by year. For example, this year the email address would be pyre2016@example.com, and next year it will be pyre2017@example.com. Not sure how well it works, but the idea is that by that every year you start over with a fresh address (that takes a while to get onto spam lists). I'…

Not a big deal if using a password manager and email acts as username.

Using it as your mail email for personal/business purposes could run you into trouble though. Most people aren't used to a rotating email address.

Re: Amazon's customer service backdoor

#355
post #346

Earlier quoted context omitted.

Hey romanhn - so sorry for this. Can you share your ticket number? I think there was a definite mistake in the process here as that should have been broached and if it requires some updated training for the billing team, I'll put in my recommendation for that. I'm sorry as well for the parking page situation - my guess is it didn't immediately propagate, but I'd have to investigate further as to why that happened. Us…

I did upvote, don't think the downvotes are deserved. Sent my ticket number via the contact form on the website from your profile. I see that you spearheaded the SOPA membership surge - it's what got me to join in the first place.

Looks like things are working out right now - feel free to keep me posted. You know where to find me now ;)

Re: Amazon's customer service backdoor

#356

Earlier quoted context omitted.

This already happened to Matt Honan back in 2012, where the hacker used social engineering on both Amazon and Apple to take over his twitter handle (oh and also wiping all his devices via iCloud). http://www.wired.com/2012/08/apple-amazon-mat-honan-hacking/ It looks like both Amazon and Apple have fixed _some_ issues since then - Amazon is no longer leaking last 4 digits, but instead they're still leaking other info.…

Apple set up 2FA for certain actions (changing passwords, adding or removing devices from an account, etc); Amazon has yet to do anything related to 2FA for normal customer accounts.

2FA is now available for Amazon customer accounts: http://betanews.com/2015/11/18/how-to-enable-two-factor-auth...

The option is only (at the moment) available for Amazon.com accounts, but if you enable it there is will also be turned on for other domains Amazon.co.uk etc.

Re: Amazon's customer service backdoor

#357
post #346

Earlier quoted context omitted.

Hi tamar - thanks for reaching out! I was in contact with multiple members of the support team throughout this ordeal. Supposedly they consulted with senior management as well. Business reputation was never mentioned - it was always about paying a fee to the payment processor. At no point was chargeback reversal brought up. To be perfectly honest, I know nothing about chargebacks (this wasn't something I initiated, i…

Hey romanhn - so sorry for this. Can you share your ticket number? I think there was a definite mistake in the process here as that should have been broached and if it requires some updated training for the billing team, I'll put in my recommendation for that. I'm sorry as well for the parking page situation - my guess is it didn't immediately propagate, but I'd have to investigate further as to why that happened. Us…

p.s. I love how trying to genuinely be helpful has resulted in an onslaught of downvotes.

I wish people wouldn't do that. It does appear that Namecheap has behaved very poorly in this case, intentionally or otherwise. Sadly, downvoting a person who works for an organisation has become a proxy for downvoting the organisation itself on HN recently, which doesn't seem constructive, particularly if that person is trying to share relevant information and/or improve the situation.

Re: Amazon's customer service backdoor

#359

Simply create an LLC and have it manager-managed, as opposed to member-managed, As long as you either do no business or legitimate business, the owner (member) into is protected, and it will list your registered agent and their office address as the site owner.

So I need to pay the state of California $800/yr to stop Amazon from giving away my personal info? No.

Re: Amazon's customer service backdoor

#360
post #114

Earlier quoted context omitted.

Please don't do this. You're much more likely to get your friend in trouble with Amazon and have the police called on you.

Have the police called on you for what, exactly?

Stealing free shipping. You monster.
Post reply on HN