Earlier quoted context omitted.
Thanks, didn't know about that. Sounds like it's very specific version of account and most default accounts with IBAN doesn't have this possibility.
No, anyone’s account can be debited from, but only specific accounts can be debited to. I can’t pull money from your account, even if you tell me your IBAN. But I can use your IBAN to order from amazon, and then amazon can just pull however much they want from your account. Luckily chargeback with direct debit works just as fast as with credit cards.
Amazon's customer service backdoor
351–360 of 366 posts
Re: Amazon's customer service backdoor
#352Earlier quoted context omitted.
Ssh ports are brute forceable, passwords have a much much larger search space.
Changed SSH port is not security measure. It's needed to keep your log files clear from random network scanning. When your SSH port is something like 53148 and you see password brute-force activity in logs it's almost always mean that somebody intentionally scanning your server.
https://www.shodan.io/report/uMZDnWfT
This is a long-running problem and one with various popular solutions: restrict the source networks which you accept traffic for, disable password authentication entirely, and add some sort of rate limiting (e.g. 2004's fail2ban) for failures. Trying to reduce log volume by obscurity is futile - you really need to address the root problem and use tools which allow you to filter and aggregate effectively.
Re: Amazon's customer service backdoor
#353Earlier quoted context omitted.
One method that I've seen used (heard it described by a guest one of Leo Laporte's podcasts a looooong time ago) is to iterate account names by year. For example, this year the email address would be pyre2016@example.com, and next year it will be pyre2017@example.com. Not sure how well it works, but the idea is that by that every year you start over with a fresh address (that takes a while to get onto spam lists). I'…
I believe the real issue here is its not uncommon for spam services to try to locate valid email addresses. Generally, an email server won't accept email to an invalid users and will probably start flagging the incoming server/domain as those attempts start to cross a threshold of some sort. OP is talking about *@example.com as a catchall which means a spammers script will sit there and email a dictionary of username…
Re: Amazon's customer service backdoor
#354Earlier quoted context omitted.
One method that I've seen used (heard it described by a guest one of Leo Laporte's podcasts a looooong time ago) is to iterate account names by year. For example, this year the email address would be pyre2016@example.com, and next year it will be pyre2017@example.com. Not sure how well it works, but the idea is that by that every year you start over with a fresh address (that takes a while to get onto spam lists). I'…
Not a big deal if using a password manager and email acts as username.
Re: Amazon's customer service backdoor
#355Earlier quoted context omitted.
Hey romanhn - so sorry for this. Can you share your ticket number? I think there was a definite mistake in the process here as that should have been broached and if it requires some updated training for the billing team, I'll put in my recommendation for that. I'm sorry as well for the parking page situation - my guess is it didn't immediately propagate, but I'd have to investigate further as to why that happened. Us…
I did upvote, don't think the downvotes are deserved. Sent my ticket number via the contact form on the website from your profile. I see that you spearheaded the SOPA membership surge - it's what got me to join in the first place.
Re: Amazon's customer service backdoor
#356Earlier quoted context omitted.
This already happened to Matt Honan back in 2012, where the hacker used social engineering on both Amazon and Apple to take over his twitter handle (oh and also wiping all his devices via iCloud). http://www.wired.com/2012/08/apple-amazon-mat-honan-hacking/ It looks like both Amazon and Apple have fixed _some_ issues since then - Amazon is no longer leaking last 4 digits, but instead they're still leaking other info.…
Apple set up 2FA for certain actions (changing passwords, adding or removing devices from an account, etc); Amazon has yet to do anything related to 2FA for normal customer accounts.
The option is only (at the moment) available for Amazon.com accounts, but if you enable it there is will also be turned on for other domains Amazon.co.uk etc.
Re: Amazon's customer service backdoor
#357Earlier quoted context omitted.
Hi tamar - thanks for reaching out! I was in contact with multiple members of the support team throughout this ordeal. Supposedly they consulted with senior management as well. Business reputation was never mentioned - it was always about paying a fee to the payment processor. At no point was chargeback reversal brought up. To be perfectly honest, I know nothing about chargebacks (this wasn't something I initiated, i…
Hey romanhn - so sorry for this. Can you share your ticket number? I think there was a definite mistake in the process here as that should have been broached and if it requires some updated training for the billing team, I'll put in my recommendation for that. I'm sorry as well for the parking page situation - my guess is it didn't immediately propagate, but I'd have to investigate further as to why that happened. Us…
I wish people wouldn't do that. It does appear that Namecheap has behaved very poorly in this case, intentionally or otherwise. Sadly, downvoting a person who works for an organisation has become a proxy for downvoting the organisation itself on HN recently, which doesn't seem constructive, particularly if that person is trying to share relevant information and/or improve the situation.
Re: Amazon's customer service backdoor
#358> migrating as much to Google services which seem significantly more robust at stopping these attacks. Because they don't have customer support?
Re: Amazon's customer service backdoor
#359Simply create an LLC and have it manager-managed, as opposed to member-managed, As long as you either do no business or legitimate business, the owner (member) into is protected, and it will list your registered agent and their office address as the site owner.