Earlier quoted context omitted.
They intentionally provide this information to marketplace sellers. It's arguably poor design but it's definitely not an unintentional security flaw. Marketplace/FBA sellers have talked about strategies for utilizing customer email address for years [1] [1] https://sellercentral.amazon.com/forums/t/how-to-access-all-...
Also, your Amazon profile is public by default, especially any wishlists.
Amazon admits it exposed customer email addresses, but refuses to give details
41–50 of 160 posts
Re: Amazon admits it exposed customer email addresses, but refuses to give details
#42Earlier quoted context omitted.
> any online retailer has to be trusted Well that is down right crazy. Most sellers are people in their garages drop shipping 3PL. I'd trust them if they were background checked....maybe
The internet is based on trust. There is nothing stopping anyone that has an e-commerce website from recording a clear version of your passwords along with all of your billing address and credit card informations. There's no audits or anything.
Re: Amazon admits it exposed customer email addresses, but refuses to give details
#43If Amazon exposed any data fields more sensitive than email address, I would call that stonewalling/covering up as TC seems to be implying. But otherwise it kind of just sounds like TC being all petulant that Amazon wouldn't tell it everything it wanted to know. And the motivation there is likely to be the generation of clicks, not the protection of customers.
Take the "number of users affected" for example. Knowing that info doesn't help any individual customer. But it does help journalists drum up pageviews, or at least I feel like they believe it does. Having a big number in there is like this (dubious) Holy Grail of page-irresistability. I'm just judging from how, for example, the reporters on the TV news always bug their eyes out and raise their voice and talk really slowly and emphatically any time they come to a number. "The pool was reported to be FOURTEEN FEET DEEP..." "The petition has THIRTY THOUSAND signatures..." Wow! A number! I'm supposed to be all impressed I guess! ZOMG let me throw all my money at you right now!!!!
Re: Amazon admits it exposed customer email addresses, but refuses to give details
#44When I started selling the first gadget I ever made on Amazon I was so excited and was only getting a couple sales a month. If you were one of my customers I looked at your house, judged your grass, found you on LinkedIn and Facebook, Instagram, mortgages, mugshots, everything lol. The sellers also get your full name and address even on fulfilled by Amazon. If you have been on the net long enough this will creep you…
I realized an attack method where:
1. Find an unusual but generic product used by niche group such as a particilar adult toy.
2. Order product and sell in using existing amazon SKU (very common) at below market price point.
3. You now have difficult to procure personal data on a very specific customer segment, paid for in lost margins on the product.
Reminds me somewhat of the old days of Facebooks demographic targeting to get page likes. You could build interesting lists indirectly on the cheap.
Re: Amazon admits it exposed customer email addresses, but refuses to give details
#45An email address isn't secret, is it? It's sent back and forth in clear text through any number of relay servers. I consider my name and email address to be basically public information. Along with (unfortunately) my Social Security number. If Amazon exposed any data fields more sensitive than email address, I would call that stonewalling/covering up as TC seems to be implying. But otherwise it kind of just sounds li…
Internally we treat customer names and email addresses as the second highest data classification. The highest one is credit card/financial/password data.
What does it mean? It means that there are a bunch of requirements that a software team must fulfill and pass (reviewed by an SDE trained in the process outside the team). This makes accessing this sort of data a PITA for a lot of people, and I can see why they why they would send out notifications when a breach like this happen. Amazon takes security very seriously, and it in fact creates quite a bit of friction to many engineers. However, I'd rather than than the break things and ask for forgiveness model like some other companies (not going to name names here)
Re: Amazon admits it exposed customer email addresses, but refuses to give details
#46I don't understand this. In the American startup I'm working we're extremely careful with respectful data practices due to ethics and GDPR (we have a lot European customers). Why doesn't Amazon give a shit about GDPR? Do they have a leverage?
I would assume perceived toothlessness. A better question is why should they? Or else what? Is that "what" absorbable by them to not eagerly spend a bunch of money and be shown to kowtow to governments making very large internet laws? Can they just pay it some lip service for now like their peers?
Re: Amazon admits it exposed customer email addresses, but refuses to give details
#47Re: Amazon admits it exposed customer email addresses, but refuses to give details
#48Hmm... it seems this drip of bad news in big tech is setting up for some heated debates on regulation. It will be interesting how proactive the Europeans are with GDPR.
- traditional media and anti-big-web-tech
Re: Amazon admits it exposed customer email addresses, but refuses to give details
#49Earlier quoted context omitted.
It sounds like they did that but TC wants more. I'm not really sure why HN allows techcrunch stories on the front page. TC is tabloid journalism at its finest.
They did not disclose any of the following as specified by the data breach notification requirements of the GDPR: The name and contact details of the data protection officer or other contact point where more information can be obtained The likely consequences of the personal data breach The measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, meas…
Re: Amazon admits it exposed customer email addresses, but refuses to give details
#50This is one of the less appreciated clauses of the GDPR: That companies are required to disclose data breaches within a reasonable time-frame, and users have the right to know about any exposure of their data.
One wonders if this clause should have instead been its own, separate, narrowly focused legislation and enforced specifically as such.