Live data from Hacker News

Amazon admits it exposed customer email addresses, but refuses to give details

techcrunch.com

91–100 of 160 posts

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#91
post #80
post #74

Earlier quoted context omitted.

But they have european entities (AWS, fulfilment centres, etc). If they don't choose to put themselves somewhere, everyone may go after them separately.

... and then they can negotiate with the country that gives them the smallest punishment. (under gdpr only one will go after them at a time).

Negotiating with every country in the EU serially is not that much better than in parallel.

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#92
post #64

I don't understand this. In the American startup I'm working we're extremely careful with respectful data practices due to ethics and GDPR (we have a lot European customers). Why doesn't Amazon give a shit about GDPR? Do they have a leverage?

amazon doesn't have european headquarters

They do, so they can avoid taxes all over the world. Not only do they have an EU incorporated company, if you believe their tax filings their primary business is based in Luxembourg. This is obviously bullshit, and is done to avoid taxes, but they have structured their company in a way that makes them very much an EU company.

If they weren't an EU company they couldn't take advantage of Luxembourg's tax laws. So it follows that they have to follow all EU laws. Because they're incorporated in the EU.

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#93

Earlier quoted context omitted.

> It sounds like they did Which parts of the specific GDPR requirements did they comply with?

GDPR isn't a US law.

But Amazon is an EU company.

They're incorporated in Luxembourg in order to avoid taxes, making them subject to EU laws (after all, they are subject to Luxembourg tax laws -- that's why they structured their business that way).

You can't have your cake and eat it.

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#94
post #70

Earlier quoted context omitted.

This is irrelevant as long as they have customers whose rights are protected by GDPR.

i am mistaken. But the idea is , if they were not based in europe , which country's DPA is going to go after them? Where will the money be paid?

Likely Luxembourg, where they are headquartered. Unfortunately (as we found in the DieselGate scandal -- where car companies directly caused thousands of deaths), Luxembourg doesn't have very strong regulatory teeth. Here's hoping they're more strict.

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#95
post #62

This is how it looked for me: I few days ago I was shopping on Amazon and they showed me a message, you already purchased this product. See order details. I was surprised since I did not buy it before. After clicking the link, I was shown details of not my order, including name, address and email where a product was shipped to.

Uh, that just sounds completely unrelated. You didn't get your "email" "exposed", your account got pwned.

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#96
post #12

When I started selling the first gadget I ever made on Amazon I was so excited and was only getting a couple sales a month. If you were one of my customers I looked at your house, judged your grass, found you on LinkedIn and Facebook, Instagram, mortgages, mugshots, everything lol. The sellers also get your full name and address even on fulfilled by Amazon. If you have been on the net long enough this will creep you…

The Amazon store I ran when I worked for a VAR was the best lead generation tool the company I worked for had ever found. I sold a part that if you bought indicated to us that your annual IT spend was minimum 150K a year, and I sold dozens of these parts a week. Most companies have a customer acquisition cost, we got paid to get new customers. It's super against Amazon's TOS for resellers to contact customers outside…

That is likely the model of many resellers on Amazon Marketplace. Some products are so cheap (including free shipping) that they must be making money by selling my information to direct marketers.

I recently started making up random names when buying from Amazon Marketplace, to see if I can spot a pattern of who's buying and who's selling databases. I'll know better in a few months...

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#97
post #62

This is how it looked for me: I few days ago I was shopping on Amazon and they showed me a message, you already purchased this product. See order details. I was surprised since I did not buy it before. After clicking the link, I was shown details of not my order, including name, address and email where a product was shipped to.

Uh, that just sounds completely unrelated. You didn't get your "email" "exposed", your account got pwned.

Why so? This is how somebody's data was exposed to me, and how my data was exposed to somebody else.

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#98
post #12

When I started selling the first gadget I ever made on Amazon I was so excited and was only getting a couple sales a month. If you were one of my customers I looked at your house, judged your grass, found you on LinkedIn and Facebook, Instagram, mortgages, mugshots, everything lol. The sellers also get your full name and address even on fulfilled by Amazon. If you have been on the net long enough this will creep you…

For anyone who is curious why a seller gets this much information, you have to be able to confirm the shipping address is correct. Google Maps can quicken this process.

Yes, this process is automated and usually works, however, the systems don't know everything, and you have to manually override the error to ship the product.

With that said, I think it's grossly irresponsible to look people up on all their social media. This is part of considering customer trust.

I've yet to hear about sellers stalking customers in the real world, but IMO, there isn't any difference between doing this stuff online and the real world. Please don't do this if you are planning to be a seller.

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#99
post #62

This is how it looked for me: I few days ago I was shopping on Amazon and they showed me a message, you already purchased this product. See order details. I was surprised since I did not buy it before. After clicking the link, I was shown details of not my order, including name, address and email where a product was shipped to.

I'll share a similar experience with Asics (the running shoe company) a couple of weeks ago.

Out of nowhere, I received an email from Asics that contained another customer's name, their email address, phone number, and that customer's private message (apparently part of a customer service case). Bizarre. I informed the other customer, who was equally surprised but somewhat grateful for the notification. And I spent an hour or so reporting the incident to various levels of Asics worldwide (I'm in Canada, this customer was in the USA, and their privacy office apparently resides in the EU), partly out of curiosity to see how a small but concerning issue might be handled.

Summary: Asics' privacy office got a customer service manager to contact me for details of the incident. They said "sorry" and "it won't happen again". Okay. ?

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#100
post #62

This is how it looked for me: I few days ago I was shopping on Amazon and they showed me a message, you already purchased this product. See order details. I was surprised since I did not buy it before. After clicking the link, I was shown details of not my order, including name, address and email where a product was shipped to.

This sounds like a possible reason why they can’t disclose the full extent of it. Cloudbleed was pretty tough to ascertain the extent of. Not a lot of caches I’ve had experience with have deep tools for introspection and auditing. I don’t believe they’re developed that way.
Post reply on HN