Live data from Hacker News

Still locked out of my AWS account

docs.google.com

91–100 of 283 posts

Re: Still locked out of my AWS account

#91

Also having problem with AWS - can't access it and they keep billing me for something there I want to shut it down (EC2?) but I can't. I recently moved from Brazil to UK (new address) and changed phone + sim card (Authenticator after restore from backup lost all 2 factor auth entries). This is the moment when you realise that you're outside of predefined use cases of The Machine and you're fucked. Nobody is here to h…

This is why, when creating a new 2FA login, you MUST write down the one time use backup codes, and store them in a safe and secure place.

Re: Still locked out of my AWS account

#92

Earlier quoted context omitted.

At some level you're always relying on other companies for a service. Even Google does -- they don't own the last mile. However, even if you expect people to CoLo, you're still relying on a the facility for power, cooling, networking, security. Moreover, AWS is a paid service, there should be some expectation of conflict resolution. It's not like Google where Gmail is free and there really isn't any reason you should…

As another responder astutely pointed out below, services like this aren't contractually-bound, they're subject to TOSes. Good luck getting any kind of conflict resolution with a giant company when all you have are TOS. Companies that rely on other companies for service, when they do it right, use contracts. Your point about having multiple providers is very sound though; if all you have available is AWS-like service…

> services like this aren't contractually-bound

By default, no. But you can get contracts in place.

Re: Still locked out of my AWS account

#93
post #73

Earlier quoted context omitted.

But then you're storing passwords in more services, which creates more surface area for breaches. If you shop with Amazon, host your services with Amazon, watch TV on Amazon...there's simply no way of getting around the fact that Amazon will only want to manage a password for you in one place. The issue is clearly over reliance on Amazon services.

I don't follow your logic about the breach risk. If you're using unique passwords per service (and you really should) then I would expect any breach that involved passwords would have less of an effect. If there is a breach with a centralized single sign on service then every other dependent service is also affected.

There's a big difference between what people should do, and what people actually do. Research consistently shows that a large percentage of people reuse passwords across many sites.

[1] http://www.jbonneau.com/doc/DBCBW14-NDSS-tangled_web.pdf

Re: Still locked out of my AWS account

#94

Earlier quoted context omitted.

Doesn't this require separate gmail addresses? If so, then that's an extremely bad idea. I already had one gmail account completely banned with no notice. I wasn't doing anything abusive -- I used it for some npm projects and a github account. Actually, is there a reasonable free gmail alternative for situations like this? I'd like to migrate. FastMail is worth paying for, but it's too expensive for one-off side proj…

> My point was, if you use a single account, it's far less likely to get banned Why do you think that? If anything, you have more activity you can be banned for... And also, why you say it like gmail is the only email provider? You need separate _email_ accounts, not gmail. It can be some other service or your own domain. Google can be service provider behind your own domain, but you will control address space etc. N…

It seems like Google uses some heuristics when deciding whether to ban an account. My theory is that if you stick with your personal gmail account, you have such a long history of activity that it's unlikely to be flagged by whatever "smart" algorithm they're using.

I was quite surprised that my gmail account was banned without doing anything remotely malicious. (Certainly not anything listed in https://www.google.com/intl/en-US/%2B/policy/content.html) I suppose it's my word against Google's, which isn't a happy position to be in, but to the best of my knowledge that's what happened.

Regarding other services, I was hoping to get some recommendations about which one everyone likes using. Gmail and FastMail seem to be the two HN favorites, but FastMail gets expensive quickly for side projects. You can host your own email, but people have shared some unpleasant experiences with that route. It's true that you can still use gmail without losing your address, but you'll still lose your emails if they decide to suspend you.

Re: Still locked out of my AWS account

#95
post #56

Earlier quoted context omitted.

One trick I like is that you can use `account+ @example.com` and a lot of services will consider it a separate e-mail address, even though MTAs will transfer it to the same account; this has the added benefit of being easy to filter for on your e-mail client. I also use this tactic when signing up for web services that I anticipate will spam me. (I import a lot of merch from China/Japan; their unsubscribe systems ten…

I used this trick for years. However, there are downsides. For example, sometimes a service will let you sign up with this just fine, but later when you need to do something else (such as password reset) or a phone agent has to enter it... it chokes. Not to mention after some time passes you may forget what the special bit was and have to fall back to searching your email. Being regimented about the naming system hel…

This is why I have my own domain. I have a catch-all email box that just accepts everything and can make up emails on the spot, service@example.com. It makes things a lot easier down the road if I have a problem with my current provider as I can change the MX records at will. This means though that my DNS service must be under another domain for safety though but that's less of an issue.

Re: Still locked out of my AWS account

#96

Earlier quoted context omitted.

Doesn't this require separate gmail addresses? If so, then that's an extremely bad idea. I already had one gmail account completely banned with no notice. I wasn't doing anything abusive -- I used it for some npm projects and a github account. Actually, is there a reasonable free gmail alternative for situations like this? I'd like to migrate. FastMail is worth paying for, but it's too expensive for one-off side proj…

Sometimes I feel like I'm last person on the planet who has their own domain and hosts their own email.

You aren't the only one. I host mine on linode and have no problems sending now that I have DKIM and SPF set up.

Re: Still locked out of my AWS account

#98
post #77

8 days ago I tried to log in to my Amazon retail account, and received a password invalid error. As it turned out my account had been closed, as it appeared to Amazon that it had received a suspicious log in. This is the same account that I use for AWS - hosting websites critical to my business. Today it appears I am no closer to gaining access back to my AWS account than I was on day 1, even though I have been bille…

In all seriousness, email jeff@amazon.com. The most likely outcome is that some relevant managers will receive one of the infamous "?" emails from him. If so, that'll result in two things: 1) Your problem will be resolved ASAP, managers right up the chain will be tracking it extremely closely, as they'll have to justify every action to Jeff. Everyone goes scrambling when one of those emails goes out. 2) A post-mortem…

Can you provide some links to stuff about the infamous "?" emails?

Re: Still locked out of my AWS account

#99
post #52

Earlier quoted context omitted.

And a similar thing has happened to me with Microsoft. I needed to get to my OneDrive. I go to log in, and it says invalid password. I go to reset the password, and it never sends me an email. I go through the alternate-email update process, answer the security questions, and it doesn't believe I am who I am. When I try to get access to real support (a person), it makes me login. Back to problem #1. Also, I should no…

Same here (email never arrived) with my Apple Developer Account.

I got into a similar situation when Apple prompted me to turn on 2-factor auth, and then after I accepted it wouldn't send 2-factor codes.

Thankfully the "we turned on 2-factor" email gives you a link to turn it back off within 30 days or I would have been in some trouble.

Re: Still locked out of my AWS account

#100

Earlier quoted context omitted.

This happened to me with instagram. I reset a password, then they detected "suspicious activity." I clicked "send pin via email" and the email never shows up. I've done it 3 or 4 times over the course of a week + it never works. It's a documented error + FB/Instagram refuse to addres it. https://medium.com/@joelrunyon/instagrams-security-features-...

And a similar thing has happened to me with Microsoft. I needed to get to my OneDrive. I go to log in, and it says invalid password. I go to reset the password, and it never sends me an email. I go through the alternate-email update process, answer the security questions, and it doesn't believe I am who I am. When I try to get access to real support (a person), it makes me login. Back to problem #1. Also, I should no…

This is worse because at least with mine, they send the reset password (so I know they have the right email on file).

Then, when they send the PIN to the same email - it never actually shows up. Ugh.

Post reply on HN