Live data from Hacker News

Still locked out of my AWS account

docs.google.com

71–80 of 283 posts

Re: Still locked out of my AWS account

#71

Earlier quoted context omitted.

Sometimes I feel like I'm last person on the planet who has their own domain and hosts their own email.

I don't host my own email (I've had terrible experiences trying to send), I do have my own domain and let someone else host my email (In this case Google :( but since it's my domain I can change it and it doesn't matter to anyone). Aside: It always frustrates me when I see a business with their own domain and then an @gmail.com or @aol.com address. What registrars don't offer basic email forwarding (often for free?)…

[deleted]

Re: Still locked out of my AWS account

#72

Send an email to jeff@amazon.com Jeff Bezos himself said if you are having problems you should mail him directly. Behind this address there is a full team investigating the issue and if it's something they want to handle will actually lead to improvements for all customers.

I think if Jeff actually cared he would have put some personnel in place to back up "Your feedback is helping us build Earth's Most Customer-Centric Company". It's odd though, in my experience customer support on Amazon is amazingly good.

Mine hasn't been. I've had all sorts of petty issues with their customer support. Basically any time something falls outside of the norm or if anything is genuinely wrong with site functionality, their remedial processes are poor.

Re: Still locked out of my AWS account

#73

Earlier quoted context omitted.

Because you're unlikey to trigger a violation on your cloud SaaS account, but could easily run afoul of other policies like "Real Name" or "Bought a Pixel Phone and Sold It" or posting something "offensive", getting reported by other users, etc. If the account is just for a cloud SaaS, then there's likely to be very few policies to disable your account.

But then you're storing passwords in more services, which creates more surface area for breaches. If you shop with Amazon, host your services with Amazon, watch TV on Amazon...there's simply no way of getting around the fact that Amazon will only want to manage a password for you in one place. The issue is clearly over reliance on Amazon services.

I don't follow your logic about the breach risk. If you're using unique passwords per service (and you really should) then I would expect any breach that involved passwords would have less of an effect. If there is a breach with a centralized single sign on service then every other dependent service is also affected.

Re: Still locked out of my AWS account

#74

If it's critical to your business, why not do your hosting elsewhere? Is it because you are locked in already? I am building a product that will help people migrate across cloud providers, so that's the context...

Presumably he built it with AWS in mind, using their proprietary services and APIs. I'm certain if it was easy to have transitioned away from AWS, he would've already done so.

Re: Still locked out of my AWS account

#75
"Who are you?" is the most expensive question in technology. No matter how you get it wrong, you're fucked.

Letting the wrong person in to an account? You're fucked.

Locking the right person out of an account? You're fucked.

Given that data can't be reversed as charges can, arresting an account may be slightly preferable, but it remains highly disrupting.

I've been through the experience a few times myself, largely with Google. Out of a fit of pique, the temporary account I created for myself (and through which I negotiated for recovery) was "The Real Slim Shady". Several of my G+ contacts noted that they could be pretty certain that this was in fact me, though I'm a little frightened whichever way that works out.

(I did have other profiles through which I could announce my plight.)

I still think that the matter of idientification, or rather, the more primary matters of authentication, authorisation, integrity, validation, payment authorisation, ownership, receipts rights, and similar associations, need to be worked out.

I'm also strongly in favour of a system in which a physical token -- and I think a signet ring with a very-near-field chip and accompanying sensors on mobile, laptop, and desktop devices would be just about perfect -- should be part of that systme.

Not an insertable device (as with Yubikey), or something requiring keying in a value (as with RSA fobs). But something which is worn (so: on you at all times), replaceable, destroyable, discardable, but also exceedingly difficult to duplicate or appropriate, or to read without intention on the part of the owner.

https://www.reddit.com/r/dredmorbius/comments/2w618r/how_to_...

Re: Still locked out of my AWS account

#76

Also having problem with AWS - can't access it and they keep billing me for something there I want to shut it down (EC2?) but I can't. I recently moved from Brazil to UK (new address) and changed phone + sim card (Authenticator after restore from backup lost all 2 factor auth entries). This is the moment when you realise that you're outside of predefined use cases of The Machine and you're fucked. Nobody is here to h…

>Something there in the process is missing like "next of kin" recovery that should be mandatory when enabling 2FAs.

wouldn't this just weaken the second factor? Services that have bypasses to 2FA wind up rendering it useless.

Re: Still locked out of my AWS account

#77

8 days ago I tried to log in to my Amazon retail account, and received a password invalid error. As it turned out my account had been closed, as it appeared to Amazon that it had received a suspicious log in. This is the same account that I use for AWS - hosting websites critical to my business. Today it appears I am no closer to gaining access back to my AWS account than I was on day 1, even though I have been bille…

In all seriousness, email jeff@amazon.com. The most likely outcome is that some relevant managers will receive one of the infamous "?" emails from him.

If so, that'll result in two things:

1) Your problem will be resolved ASAP, managers right up the chain will be tracking it extremely closely, as they'll have to justify every action to Jeff. Everyone goes scrambling when one of those emails goes out.

2) A post-mortem will be done of everything that happened, with processes and procedures improved to ensure it doesn't happen again.

Re: Still locked out of my AWS account

#78
post #9

Might sound obvious in hindsight, but _always_ create separate AWS accounts for your different projects.

Doesn't this require separate gmail addresses? If so, then that's an extremely bad idea. I already had one gmail account completely banned with no notice. I wasn't doing anything abusive -- I used it for some npm projects and a github account. Actually, is there a reasonable free gmail alternative for situations like this? I'd like to migrate. FastMail is worth paying for, but it's too expensive for one-off side proj…

> Doesn't this require separate gmail addresses?

It probably should, but I somehow ended up with two Amazon accounts (retail, not AWS) with the same email address. Changing the password I use changes which account I log in to.

Presumably it's a bug, but it's certainly confusing.

Re: Still locked out of my AWS account

#79

Earlier quoted context omitted.

At some level you're always relying on other companies for a service. Even Google does -- they don't own the last mile. However, even if you expect people to CoLo, you're still relying on a the facility for power, cooling, networking, security. Moreover, AWS is a paid service, there should be some expectation of conflict resolution. It's not like Google where Gmail is free and there really isn't any reason you should…

As another responder astutely pointed out below, services like this aren't contractually-bound, they're subject to TOSes. Good luck getting any kind of conflict resolution with a giant company when all you have are TOS. Companies that rely on other companies for service, when they do it right, use contracts. Your point about having multiple providers is very sound though; if all you have available is AWS-like service…

> As another responder astutely pointed out below, services like this aren't contractually-bound, they're subject to TOSes.

Yes, I did say it should be expected, not that it is :(

This is where large companies are most to blame -- they sell products and services, but have no support unless you pay extra. I can understand out-of-hours or technical support, but basic accounting and account issues (e.g. account lockouts) should really be unethical to not support for a paid service. (I don't quite want to say illegal, but it shouldn't be the norm like it is now.)

I've had significantly better dealings with "smaller" shops with this kind of thing. Basic account support always appears to be the first thing to the chopping block as they grow :(

Post reply on HN