Live data from Hacker News

Amazon admits it exposed customer email addresses, but refuses to give details

techcrunch.com

151–160 of 160 posts

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#151
post #62

This is how it looked for me: I few days ago I was shopping on Amazon and they showed me a message, you already purchased this product. See order details. I was surprised since I did not buy it before. After clicking the link, I was shown details of not my order, including name, address and email where a product was shipped to.

Even more fun I recently had someone outfitting their brand new restaurant in New Jersey using my email address on a bunch of different sites like Amazon and Walmart. It was getting annoying so I was going to send them a text message telling them to get their own damn gmail account but they seemed to have stopped.

Just imagining the damage I could have caused using the 'forgot password' link and their stored CC info...

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#152
post #113

Earlier quoted context omitted.

The exact same goes for PayPal. We were routinely getting emails saying "I'm not comfortable sharing my CC info with you" (even though it goes through a processor), so ended up adding PP as an alternative. Guess what - now we get to see their full name and physical address, neither of which we need, because we sell software licenses. I'm guessing that people are more concerned with needing to deal with compromised ca…

Why would anyone care if you had their address, or email address? Why would Amazon be interested in going into details about an email address leak? Outside of a handful of people who get excited by every leak no matter what, nobody cares. It's an email address. You get some more spam maybe? Big deal.

> Why would anyone care if you had their address, or email address?

It's for the same reason that you don't post your name, address, and email address in a signature of your posts on HN.

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#153
post #111

Earlier quoted context omitted.

If you have been on the net long enough this will creep you out: https://haveibeenpwned.com/ Checked with lol@gmail.com, you have to add 14 other 'l's (lolllllllllllllll@gmail.com) in order to result in a green good news. How can I validate the claims? I'm a bit skeptical seeing it doubles as a sales front for 1password.com.

Do a bit more research: you'll find that Troy (the guy who runs the service) has been working on this for several years before any involvement with 1password, and so far he's been very transparent about what he does with breach data and also about his relationship with 1password. Whenever he gets access to an unverified dump he first tries to verify its authenticity with the company or service that was pwned, then ge…

I'm aware, but my question is how can I verify it myself instead of taking his word for it.

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#154
post #76
post #43

An email address isn't secret, is it? It's sent back and forth in clear text through any number of relay servers. I consider my name and email address to be basically public information. Along with (unfortunately) my Social Security number. If Amazon exposed any data fields more sensitive than email address, I would call that stonewalling/covering up as TC seems to be implying. But otherwise it kind of just sounds li…

I notice you don't have your email address in your HN profile.

I do though.

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#155

Earlier quoted context omitted.

Better yet, attach a sunset clause to every law, proportional to the number of votes it gets (and maybe unanimously passed = no sunset). Now they'll have to spend some of their time renewing old laws, and if anything is too toxic for the majority to vote for, it goes away.

That would get rid of obsolete laws, but I'm not sure people would enjoy all the side-effects such a law would have, at least in the United States. For example, many more opportunities to cause government shutdowns, and many more must-pass bills that can be loaded with pork.

It would be an interesting test of what is actually "must pass", though.

I also think it would encourage less partisan and more consensus-built legislation if the number of votes it passes with extends the amount of time before it sunsets, esp. if the relationship is not linear. Right now, if you have 50%+1 vote in the House, and 60 in the Senate, you don't have to care about the rest, so you can make legislation as extreme as you can while remaining within those boundaries. But if the difference in getting extra votes is a renewal vote in 25 years (with, say, 3/4 supermajority passing) versus just 5 years (50%+1), those extra votes may well be worth fighting for with some concessions.

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#156
post #84

Earlier quoted context omitted.

Just a billing/customer name but no address. Email communication goes via Amazon so they can cut you off from the customer and also so they can remove email addresses and link, but they can't do much if a seller wants to call up or send promotional material in the package.

Hmm, I see. In the past I ordered what ended up being a scam/"mistake"-priced item on Amazon, and I left negative feedback for the seller seemingly purposely baiting & switching customers by pricing items substantially low, cancelling the order on them, and offering them a store discount if they remove the negative review (this appears to be their long-term MO, as per the countless other reviewers experiencing the sa…

Yeah the only reason Amazon provides the phone number is because a lot of carriers require a number to be on the label.

There are some rules around it listed here: https://sellercentral.amazon.com/gp/help/external/200386250 But yeah, it is going to be a hard one for Amazon to enforce unless a number of people complain about a seller.

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#157
post #12

When I started selling the first gadget I ever made on Amazon I was so excited and was only getting a couple sales a month. If you were one of my customers I looked at your house, judged your grass, found you on LinkedIn and Facebook, Instagram, mortgages, mugshots, everything lol. The sellers also get your full name and address even on fulfilled by Amazon. If you have been on the net long enough this will creep you…

For anyone who is curious why a seller gets this much information, you have to be able to confirm the shipping address is correct. Google Maps can quicken this process. Yes, this process is automated and usually works, however, the systems don't know everything, and you have to manually override the error to ship the product. With that said, I think it's grossly irresponsible to look people up on all their social med…

Its actually illegal for companies to contact me unless I already have business with them.

Why Americans don't value their privacy or enjoy being harassed by sales people is beyond me.

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#158
post #153

Earlier quoted context omitted.

Do a bit more research: you'll find that Troy (the guy who runs the service) has been working on this for several years before any involvement with 1password, and so far he's been very transparent about what he does with breach data and also about his relationship with 1password. Whenever he gets access to an unverified dump he first tries to verify its authenticity with the company or service that was pwned, then ge…

I'm aware, but my question is how can I verify it myself instead of taking his word for it.

You'd have to download each of the public hack dumps and check for your email in them.

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#159
post #130

Earlier quoted context omitted.

> saltysugar Can you elaborate? I've never heard this phrase before and google results aren't very helpful.

It's not a policy, it's the username of the parent's poster.

LOL, now I realize the wisdom of not referring to people by usernames... "saltysugar states" sounds completely plausible.

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#160

Earlier quoted context omitted.

People care because it begs more questions. Why is Amazon leaking email addresses? What part of their system is unsecure? Can we trust Amazon at all?

Presumably because nobody cares about the security of email addresses. The part of their system which handles credit cards hasn't been shown to be compromised, but maybe Gmail's spam filter needs to work a little harder. (I've already spent longer writing this than I spend going through my spam folder each year)

If a company's user email list is hacked, how much harder is it to attack other information? Financial information (e.g., credit cards) usually get extra security, but plenty of other information is typically stored right next to email addresses (e.g., user behavior history, IP addresses, signup dates, pricing info, password hashes, friend connections, etc etc etc).

So whenever a company says that only their user email addresses were compromised and nothing more, I'm pretty skeptical of the validity of their assertions.

Post reply on HN