Live data from Hacker News

Amazon admits it exposed customer email addresses, but refuses to give details

techcrunch.com

101–110 of 160 posts

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#101
post #97

Earlier quoted context omitted.

Uh, that just sounds completely unrelated. You didn't get your "email" "exposed", your account got pwned.

Why so? This is how somebody's data was exposed to me, and how my data was exposed to somebody else.

Ah, I see what you mean, at least about the other person's data being exposed to you. I interpreted your story as someone making unauthorized purchases on your account. Do you think they accidentally merged your account or order history with this other person's? That's much worse than what they're currently admitting to, to say the least.

My other question is where you saw the email address on the order record. I'm looking at my order history and can't even find my own email.

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#102

Earlier quoted context omitted.

The Amazon store I ran when I worked for a VAR was the best lead generation tool the company I worked for had ever found. I sold a part that if you bought indicated to us that your annual IT spend was minimum 150K a year, and I sold dozens of these parts a week. Most companies have a customer acquisition cost, we got paid to get new customers. It's super against Amazon's TOS for resellers to contact customers outside…

That is likely the model of many resellers on Amazon Marketplace. Some products are so cheap (including free shipping) that they must be making money by selling my information to direct marketers. I recently started making up random names when buying from Amazon Marketplace, to see if I can spot a pattern of who's buying and who's selling databases. I'll know better in a few months...

Please report your findings. This sounds like great research.

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#103
post #62

This is how it looked for me: I few days ago I was shopping on Amazon and they showed me a message, you already purchased this product. See order details. I was surprised since I did not buy it before. After clicking the link, I was shown details of not my order, including name, address and email where a product was shipped to.

One thing I wanted to add is that I wanted to report this issue to Amazon right away, it was very concerning to me. So, I clicked Ctrl+F to search for "contact" then "support", I went quickly through a few drop downs on the navbar, and I found nowhere any indication I can easily contact Amazon support to report it. I moved on and forgotten about this. So many companies make it super hard to contact their support.

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#104
post #82

Earlier quoted context omitted.

4. the machine that executes the code is ill-defined and will change far before the code you write is retired.

IMO legislators should spend most of their time (at least until a reasonable "break even" is achieved") striking old, erroneous, irrelevant laws.

Better yet, attach a sunset clause to every law, proportional to the number of votes it gets (and maybe unanimously passed = no sunset). Now they'll have to spend some of their time renewing old laws, and if anything is too toxic for the majority to vote for, it goes away.

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#105
post #11

"Besides the brevity, what's giving people pause is they sign the email http://Amazon.com Why cap the "a" and why no https:// ? Strange" This one is easy to answer: the customer support people aren't particularly technical. In many ways, Amazon is a weird mashup of a traditional retailer and a tech company.

To add insult to injury, http://amazon.com redirects (301) to https://amazon.com, but does not publish HSTS headers nor is it in the hstspreload list (but www.amazon.com is).

https://hstspreload.org/?domain=amazon.com https://hstspreload.org/?domain=www.amazon.com

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#106
post #28

Earlier quoted context omitted.

> any online retailer has to be trusted Well that is down right crazy. Most sellers are people in their garages drop shipping 3PL. I'd trust them if they were background checked....maybe

The internet is based on trust. There is nothing stopping anyone that has an e-commerce website from recording a clear version of your passwords along with all of your billing address and credit card informations. There's no audits or anything.

There are audits a large enough retailer would need a QSA audited PCI compliance report and while they can have 2 versions to avoid being flagged by the auditor their liability when getting caught would be colossal.

Credit Card companies are very good at identifying the source of the leak from only a handful of fraud complaints you’ll be surprised how few places would be shared across even a small batch of cards say If the retailer is large enough to make an impact they’ll get caught and dealt with very quickly and the value of credit cards and matching PII/CHD today is very low a few million cards might be worth only a few 1000’s of dollars depending on their age, source and estimated credit limit.

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#107

Earlier quoted context omitted.

The Amazon store I ran when I worked for a VAR was the best lead generation tool the company I worked for had ever found. I sold a part that if you bought indicated to us that your annual IT spend was minimum 150K a year, and I sold dozens of these parts a week. Most companies have a customer acquisition cost, we got paid to get new customers. It's super against Amazon's TOS for resellers to contact customers outside…

That is likely the model of many resellers on Amazon Marketplace. Some products are so cheap (including free shipping) that they must be making money by selling my information to direct marketers. I recently started making up random names when buying from Amazon Marketplace, to see if I can spot a pattern of who's buying and who's selling databases. I'll know better in a few months...

Seems unlikely. What's more likely is people launch products at a loss in hopes of getting good reviews and expecting to be able to raise prices later. People are fine losing money for months to build up a product.

Could also be bad quality, liquidating goods on failed launches, etc

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#108
post #12

When I started selling the first gadget I ever made on Amazon I was so excited and was only getting a couple sales a month. If you were one of my customers I looked at your house, judged your grass, found you on LinkedIn and Facebook, Instagram, mortgages, mugshots, everything lol. The sellers also get your full name and address even on fulfilled by Amazon. If you have been on the net long enough this will creep you…

"If you have been on the net long enough this will creep you out: https://haveibeenpwned.com/"

Ahh, the most useful tool made by Troy Hunt, who doesn't even realize that we've been using his database to exploit known-leaked credentials for years.

Thanks, Troy. Your desire to be an internet hero has actually resulted in more victims because you gave us a large database of searchable targets to go after, even if on a hunch. Not very smart, after all, are you? Don't realize how many people aren't going to be bothered to see if they've actually been pwned, even after being told about it?

BTW, Corporate MITMs are still a full security concern, no matter how you try to dismiss them. If a gov't entity gets inside, and gets MITM creds, game over. So much for your supposition of security in that scenario, like you try to ascertain against your detractors.

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#109

based on spam email i have received, that i clearly should not have, i believe this was an exposure to marketplace sellers from whom you have bought a product. I am very careful with my email. i’m not just guessing here. i actually reported it to amazon security. (no answer from them of course.)

Some AI laughed at your email, put a +1 on a category threshold counter and then deleted it. I hope you didn't put too much effort into it.

Do Perl scripts qualify as AI?

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#110
post #82

Earlier quoted context omitted.

Writing laws is like writing software in every way except: 1. You have hundreds of code reviewers, many of whom will have their own motivations 2. The code base is hundreds of years old, poorly maintained and often contradictory in its goals. 3. You have hundreds of millions users.

4. the machine that executes the code is ill-defined and will change far before the code you write is retired.

An program written in an ill-defined language being run by a malicious interpreter with an agenda would be a really interesting project in seeing how far you could twist the meaning of the original program.
Post reply on HN