Live data from Hacker News

Still locked out of my AWS account

docs.google.com

211–220 of 283 posts

Re: Still locked out of my AWS account

#211

Earlier quoted context omitted.

This is why I have my own domain. I have a catch-all email box that just accepts everything and can make up emails on the spot, service@example.com. It makes things a lot easier down the road if I have a problem with my current provider as I can change the MX records at will. This means though that my DNS service must be under another domain for safety though but that's less of an issue.

Do you have anything written about the components & configuration, by any chance?

That is actually pretty easy.

1. register domain at a registrar that supports email catch all (I use namecheap, not affiliated)

2. setup email catch all (https://imgur.com/a/PTlzv) with redirect to your "real" email

3. write email to foobar@example.org -> get's redirected to your "real" email

This has the big advantage that you can change your real email account (I switched away from GMail two years ago) quite easily, you can track who leaks your address and filter more easily. But be prepared to leave some people stunned, I registered at my electricity provider with electricity@example.org or at my hairdresser with hairdo@example.org

Re: Still locked out of my AWS account

#212

Earlier quoted context omitted.

If you aren't paying your bills, then you shouldn't be surprised that it gets shut down.

Who downvoted you for saying one shouldn't be surprised when an account gets shut down after not paying for 3 years? On that note: why hasn't the account been shut down for nonpayment?

Maybe the debt needs to be groomed on paper before it's sold.

Re: Still locked out of my AWS account

#213
post #56

Earlier quoted context omitted.

Doesn't this require separate gmail addresses? If so, then that's an extremely bad idea. I already had one gmail account completely banned with no notice. I wasn't doing anything abusive -- I used it for some npm projects and a github account. Actually, is there a reasonable free gmail alternative for situations like this? I'd like to migrate. FastMail is worth paying for, but it's too expensive for one-off side proj…

One trick I like is that you can use `account+ @example.com` and a lot of services will consider it a separate e-mail address, even though MTAs will transfer it to the same account; this has the added benefit of being easy to filter for on your e-mail client. I also use this tactic when signing up for web services that I anticipate will spam me. (I import a lot of merch from China/Japan; their unsubscribe systems ten…

I would recommend not using Linode and realize your e-mail will be terribly unreliable if you run your own e-mail server (even if you setup DKIM, SPF and DMARC. Google/Microsoft don't give a shit about any of that). I wrote a post about this a while back:

http://penguindreams.org/blog/how-google-and-microsoft-made-...

I've considered moving to Vultr since they block SMTP/25 by default and individual customers have to get it enabled (which seems like it should reduce false positive spam classification as more e-mail providers).

Re: Still locked out of my AWS account

#214
post #77

Earlier quoted context omitted.

In all seriousness, email jeff@amazon.com. The most likely outcome is that some relevant managers will receive one of the infamous "?" emails from him. If so, that'll result in two things: 1) Your problem will be resolved ASAP, managers right up the chain will be tracking it extremely closely, as they'll have to justify every action to Jeff. Everyone goes scrambling when one of those emails goes out. 2) A post-mortem…

I think that's gone the way of the dodo. Last I remember, he didn't read those anymore, and they were automatically just shunted into the normal escalation flow. Too many people got wind of it and abused it.

I emailed it a couple months back to complain about USPS, and got a reply and a result (all my packages arrive via UPS or some rinky dink carrier now.)

Re: Still locked out of my AWS account

#215

I've been locked out of my AWS account for almost 3 years now. I have 2FA enabled, tied to a phone number I no longer have access to. I receive two emails per month. One invoice, for $0.80 (I cannot remember what is running on there, but I guess it must be something). One threatening, "Your AWS Account is about to be suspended". I've been "about to be suspended" for the entire 3 years. I want to pay the bill, I can't…

Ask the office manager at your job if there's a notary public on staff.

It's not uncommon for one of the assistants or the office manager to get certified as a notary. It's very useful for small office situations and short deadlines.

Re: Still locked out of my AWS account

#217
post #126

Earlier quoted context omitted.

What is the purpose of 2FA when social engineering the support team circumvents it? This should not be possible! Lost your phone? That’s what 2FA backup codes are for.

Whats your proposed resolution for the two cases on this thread?

That if you lose access to all of the 2FA methods you have available, you should just lose access to your account and there be no way to recover it.

If there is a way to recover it, that has to be secured too and, there are only a limited number of ways you can do that (and the more that are enabled, the harder it is to secure). Most services with 2FA offer a set of one-time codes that you can write down and store securely at multiple locations (safes in different places, safe deposit box etc). It is not that hard to avoid losing access if you care. If you don't care enough about the account to do this, just accept losing access, cancel the card payment authorisation and, lose it.

Companies should not grant access to accounts with 2FA by letting you call support unless they at least take proper steps to ensure that you are the account owner, which is pretty impractical in most cases (it is either too costly to be worth it or, too hard to do well enough). Demonstrating that you are the account owner to recover it if you have lost 2FA access should at least require a visit, in person, with photo ID being checked with the relevant authorities (for example the passport service examining your passport to check it is not a forgery) and, multiple people who can attest that you are in fact the person in the photo, to recover an account, for which they would presumably have to charge hundreds of dollars. It seems easier to just not offer recovery in most cases.

Re: Still locked out of my AWS account

#218

Also having problem with AWS - can't access it and they keep billing me for something there I want to shut it down (EC2?) but I can't. I recently moved from Brazil to UK (new address) and changed phone + sim card (Authenticator after restore from backup lost all 2 factor auth entries). This is the moment when you realise that you're outside of predefined use cases of The Machine and you're fucked. Nobody is here to h…

Google Authenticator is a bad 2FA app. Authenticator+ costs a couple of bucks but has many features that make it much easier to use, including the ability to back up an encrypted copy of your 2FA keys (standard disclaimers about risk of compromise to this file, yadda yadda yadda). When you change phones, you just download that, decrypt, and pick up where you left off; no hassle trying to replace the 2FA generators, w…

Mobile phone authenticator apps are not that great anyway. They rely on the security of a phone that is connected to the net to keep the keys secure. If someone can get code running on the phone and exploit a privilege escalation vulnerability to get root, they can read the keys. A hardware token like a Yubikey or similar is probably more secure.

Another problem with the Google authenticator, at least for Google accounts, is that you have to add a phone number to your account to use it I think and, they then allow access by SMS, which is not so hard to circumvent.

Re: Still locked out of my AWS account

#219

I've been locked out of my AWS account for almost 3 years now. I have 2FA enabled, tied to a phone number I no longer have access to. I receive two emails per month. One invoice, for $0.80 (I cannot remember what is running on there, but I guess it must be something). One threatening, "Your AWS Account is about to be suspended". I've been "about to be suspended" for the entire 3 years. I want to pay the bill, I can't…

You're willing to pay the $30, $40, $50 AWS bill for services you aren't using but the $5 notary charge is some grave affront?
Post reply on HN