Live data from Hacker News

Amazon admits it exposed customer email addresses, but refuses to give details

techcrunch.com

121–130 of 160 posts

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#121
post #113
post #12

When I started selling the first gadget I ever made on Amazon I was so excited and was only getting a couple sales a month. If you were one of my customers I looked at your house, judged your grass, found you on LinkedIn and Facebook, Instagram, mortgages, mugshots, everything lol. The sellers also get your full name and address even on fulfilled by Amazon. If you have been on the net long enough this will creep you…

The exact same goes for PayPal. We were routinely getting emails saying "I'm not comfortable sharing my CC info with you" (even though it goes through a processor), so ended up adding PP as an alternative. Guess what - now we get to see their full name and physical address, neither of which we need, because we sell software licenses. I'm guessing that people are more concerned with needing to deal with compromised ca…

American payment providers are the tools of the devil. I have a CC because its basically the only way to pay in the US but I will never use it anywhere else.

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#122
post #62

This is how it looked for me: I few days ago I was shopping on Amazon and they showed me a message, you already purchased this product. See order details. I was surprised since I did not buy it before. After clicking the link, I was shown details of not my order, including name, address and email where a product was shipped to.

I'll share a similar experience with Asics (the running shoe company) a couple of weeks ago. Out of nowhere, I received an email from Asics that contained another customer's name, their email address, phone number, and that customer's private message (apparently part of a customer service case). Bizarre. I informed the other customer, who was equally surprised but somewhat grateful for the notification. And I spent a…

This is already a better response than I would expect from most multinationals. Thanks for sharing.

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#123

Earlier quoted context omitted.

IMO legislators should spend most of their time (at least until a reasonable "break even" is achieved") striking old, erroneous, irrelevant laws.

Better yet, attach a sunset clause to every law, proportional to the number of votes it gets (and maybe unanimously passed = no sunset). Now they'll have to spend some of their time renewing old laws, and if anything is too toxic for the majority to vote for, it goes away.

That would get rid of obsolete laws, but I'm not sure people would enjoy all the side-effects such a law would have, at least in the United States.

For example, many more opportunities to cause government shutdowns, and many more must-pass bills that can be loaded with pork.

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#124

based on spam email i have received, that i clearly should not have, i believe this was an exposure to marketplace sellers from whom you have bought a product. I am very careful with my email. i’m not just guessing here. i actually reported it to amazon security. (no answer from them of course.)

Great reason to setup wildcard e-mails so you can do something like amazon@yourdomain.com!

I would also not suggest using the exact company name/URL in the email address used to sign up. One time I couldn't log in to my password manager service and after a _lot_ of back and forth it turned out that after some years my email was somehow scraped from their DB for using their domain name in my email... So now I always go with something obscure but still traceable back to the service it was used for.

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#125
post #113

Earlier quoted context omitted.

The exact same goes for PayPal. We were routinely getting emails saying "I'm not comfortable sharing my CC info with you" (even though it goes through a processor), so ended up adding PP as an alternative. Guess what - now we get to see their full name and physical address, neither of which we need, because we sell software licenses. I'm guessing that people are more concerned with needing to deal with compromised ca…

Why would anyone care if you had their address, or email address? Why would Amazon be interested in going into details about an email address leak? Outside of a handful of people who get excited by every leak no matter what, nobody cares. It's an email address. You get some more spam maybe? Big deal.

> nobody cares. It's an email address. You get some more spam maybe? Big deal.

Go on then... post your e-mail address.

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#126
post #12

When I started selling the first gadget I ever made on Amazon I was so excited and was only getting a couple sales a month. If you were one of my customers I looked at your house, judged your grass, found you on LinkedIn and Facebook, Instagram, mortgages, mugshots, everything lol. The sellers also get your full name and address even on fulfilled by Amazon. If you have been on the net long enough this will creep you…

I love that site.

Thankfully I'm in the habit of using throwaway passwords for sites I consider throwaway.

I have noticed recently that I've been getting a lot of extortion spam, demanding bitcoin and saying that they know my passwords have compromising footage of me, having pwned all my devices. For proof they include a password I used on something like pandora, to the service-specific email address I set up for pandora. It's quite funny but I bet it's caught quite a few people with a guilty conscience out.

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#127
post #12

When I started selling the first gadget I ever made on Amazon I was so excited and was only getting a couple sales a month. If you were one of my customers I looked at your house, judged your grass, found you on LinkedIn and Facebook, Instagram, mortgages, mugshots, everything lol. The sellers also get your full name and address even on fulfilled by Amazon. If you have been on the net long enough this will creep you…

For anyone who is curious why a seller gets this much information, you have to be able to confirm the shipping address is correct. Google Maps can quicken this process. Yes, this process is automated and usually works, however, the systems don't know everything, and you have to manually override the error to ship the product. With that said, I think it's grossly irresponsible to look people up on all their social med…

> I think it's grossly irresponsible to look people up on all their social media.

While I agree with you in one sense, this wouldn't even be an issue if people didn't willingly post their entire lives to social media. I don't understand how one can be too upset about someone looking at data that they themselves decided to make public.

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#128
post #94
post #70

Earlier quoted context omitted.

i am mistaken. But the idea is , if they were not based in europe , which country's DPA is going to go after them? Where will the money be paid?

Likely Luxembourg, where they are headquartered. Unfortunately (as we found in the DieselGate scandal -- where car companies directly caused thousands of deaths), Luxembourg doesn't have very strong regulatory teeth. Here's hoping they're more strict.

Not really? Any EU customer could report them to their own DPA who would have to investigate the issue and resolve it. There's no reason any DPA in Luxembourg would have to be involved the way I understand it (except for customers in Luxembourg of course).

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#129

Earlier quoted context omitted.

For anyone who is curious why a seller gets this much information, you have to be able to confirm the shipping address is correct. Google Maps can quicken this process. Yes, this process is automated and usually works, however, the systems don't know everything, and you have to manually override the error to ship the product. With that said, I think it's grossly irresponsible to look people up on all their social med…

> I think it's grossly irresponsible to look people up on all their social media. While I agree with you in one sense, this wouldn't even be an issue if people didn't willingly post their entire lives to social media. I don't understand how one can be too upset about someone looking at data that they themselves decided to make public.

"Their window curtains were open, Officer! I just stood outside, on the grass, with my camera and a news crew."

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#130
post #73

Earlier quoted context omitted.

Amazon employee here, but the statement I'm making is of my own. Internally we treat customer names and email addresses as the second highest data classification. The highest one is credit card/financial/password data. What does it mean? It means that there are a bunch of requirements that a software team must fulfill and pass (reviewed by an SDE trained in the process outside the team). This makes accessing this sor…

I can confirm that names and email addresses are classified as saltysugar states, and the security reviews. So they do have to pass all those requirements for secure storage and transmission, but then names and emails are made visible by default through mechanisms like reviews, profile, wishlists, and that passes the review because it is the user's choice. I don't even think this is anything nefarious by Amazon. It's…

> saltysugar

Can you elaborate? I've never heard this phrase before and google results aren't very helpful.

Post reply on HN