Live data from Hacker News

Request your personal information

amazon.com

71–80 of 89 posts

Re: Request your personal information

#71

Earlier quoted context omitted.

Even better fun fact: There’s some issuers that won’t validate your CVV at all, so any of the 999 options work for those cards.

As a Swede, with both my CC and direct debit I'm transfered to the Swedish "Bank ID" service to do mfa with my phone using a 6+ digit code before any online purchase goes through. Kinda privacy invasive, but it's also impossible to steal money from me without these things: my card, my cvv, my phone, my phone unlock code, my bank ID code.

> impossible

Absolute quantifiers shouldn't be used in the context of cybersecurity. Yes, it's more difficult and would most likely require a SIM swap. But there are some gullible people who willfully gave their one-time code to attackers identifying as their bank after some initial groundwork had been done (calling them previously from a number identifying as their bank and warning of a fraud, the victim verifying the number is correct, the attacker calling again and redirecting them to a form requiring a validation with the code).

Re: Request your personal information

#72

Earlier quoted context omitted.

As a Swede, with both my CC and direct debit I'm transfered to the Swedish "Bank ID" service to do mfa with my phone using a 6+ digit code before any online purchase goes through. Kinda privacy invasive, but it's also impossible to steal money from me without these things: my card, my cvv, my phone, my phone unlock code, my bank ID code.

> impossible Absolute quantifiers shouldn't be used in the context of cybersecurity. Yes, it's more difficult and would most likely require a SIM swap. But there are some gullible people who willfully gave their one-time code to attackers identifying as their bank after some initial groundwork had been done (calling them previously from a number identifying as their bank and warning of a fraud, the victim verifying t…

> impossible to steal money from me without these things

First of all, "stripe" pushes information to the BankID app asking for confirmation, there's no code to input to the site, the verification happens on my phone where I'm asked if i wanna authenticate X or Y to happen (logging in, or transferring money)

But yes, they actually saw an attack vector where people could be fake challenged at the same time they're logging in themselves if someone knows they're about to log in.

This was solved by putting a QR code on the Bank website (and others that have implemented this so far) to be scanned by the BankID app. So now to steal money you would have to pwn the HTTPS between the bank and "me" or pwn my browser, or pwn my entire machine.

Also if you get 2 BankID challenges at the same time they cancel both of them.

Anyways, point is that without my phone and my own personal code being entered after a challenge where I see who's challenging me it's impossible to get money out of my account. It's designed to be REALLY hard to be tricked into authenticating someone else.

This system doesn't care about SIM swaps because it doesn't use the carrier network for anything other than encrypted communications with the BankID service.

I don't think there's a more secure system deployed on this wide of a scale anywhere and I'm quite happy with it. It's a PITA if you lose your phone though since there's no fallback method other than getting a new smartphone.

Nitpicking on words seems a bit below the standard of discussion I want to have though, and it seems like you thought it was just SMS verification. We're not cavemen across the pond, we're people just like you.

A nice benefit of this system is that when I call my bank I'll input my social security number in the system and it'll challenge me with a BankID challenge meaning the bank person knows they're talking to me. It's useful for a lot of things and at the same time VERY privacy invasive. Also doesn't work without a connection on your phone, but we're quite connected here so it's usually fine.

CC purchases in person are not authenticated with this system, we rely on the NFC thingy or chip. Magstrip isn't used anywhere here anymore. The bank covers all fradulent NFC charges without pin entry (which is why they're limited to 40$).

If you're curious for more information about BankID they have a site: https://www.bankid.com/en/ I think it's owned as a collab between "all" Swedish banks.

We also have electronic mail via a system called "Kivra" that the government will send mail through to me so that i don't have to rely on someone not dropping my mail. Also privacy invasive of course, but quite convenient.

Re: Request your personal information

#73

It was requesting my personal information from Amazon that made me decide to dump all my Alexa smart devices. We had bought one for my in-laws and the Echo had picked up entire conversations between them even though the wake word had not been said. They were categorised under "Not intended for Alexa". My father in-law is at the end of his life, and I really hated the fact that deeply private and incredibly poignant c…

Wow, that's bad. It seems obvious that something like Alexa would transmit some amount of data not intended for it and that would be listened to by someone for training purposes. And probably enough data that someone remotely privacy conscious would not voluntarily install some 24/7 listening device into their inner sanctum.

But what on earth would posses Alexa to record entire conversations without either piping up ("sorry, I did not understand this request") or figuring out after a few seconds that this was probably a false alarm and turning itself off? How would this be remotely excusable?

How long was the longest recording not really intended for Alexa?

Re: Request your personal information

#74

Earlier quoted context omitted.

Some of us were in Kindergarten about then so we would have missed the original Show HN for that. Glad to have found it eventually though.

I know I'm not supposed to comment when it doesn't add to the conversation, buuuut, your reply made me literally laugh out loud. Thank you for this! I often forget being ~40 means I'm no longer ~20 and that there are people who are actually ~20 out on the internet...

Hey while we're here in this closet shhhh posting non-additive replies... I have a website that's still up from 1996. Older than so many Kids These Days. :P

Re: Request your personal information

#75
post #73

It was requesting my personal information from Amazon that made me decide to dump all my Alexa smart devices. We had bought one for my in-laws and the Echo had picked up entire conversations between them even though the wake word had not been said. They were categorised under "Not intended for Alexa". My father in-law is at the end of his life, and I really hated the fact that deeply private and incredibly poignant c…

Wow, that's bad. It seems obvious that something like Alexa would transmit some amount of data not intended for it and that would be listened to by someone for training purposes. And probably enough data that someone remotely privacy conscious would not voluntarily install some 24/7 listening device into their inner sanctum. But what on earth would posses Alexa to record entire conversations without either piping up…

I've switched off all voice-activated devices in my home.

I'm not sure how long the longest recording was...I'll go back over the data to have a look, but the one that really broke my heart was about 20 seconds during which my mother in-law was upset because my father in-law was not waking up.

Re: Request your personal information

#76

Earlier quoted context omitted.

> impossible Absolute quantifiers shouldn't be used in the context of cybersecurity. Yes, it's more difficult and would most likely require a SIM swap. But there are some gullible people who willfully gave their one-time code to attackers identifying as their bank after some initial groundwork had been done (calling them previously from a number identifying as their bank and warning of a fraud, the victim verifying t…

> impossible to steal money from me without these things First of all, "stripe" pushes information to the BankID app asking for confirmation, there's no code to input to the site, the verification happens on my phone where I'm asked if i wanna authenticate X or Y to happen (logging in, or transferring money) But yes, they actually saw an attack vector where people could be fake challenged at the same time they're log…

> If you're curious for more information about BankID they have a site: https://www.bankid.com/en/ I think it's owned as a collab between "all" Swedish banks.

I'm not sure if it's the same technology as in Norwegian banks:

https://link.springer.com/chapter/10.1007/978-3-540-85230-8_...

Re: Request your personal information

#77

I lost an AWS account many years ago to losing an MFA device during an adventure that I will avoid documenting here. What is really weird is that AWS account is tied to a very old (1998?) Amazon account. I wonder what this request will reveal.

Stories like this are what keep me using strong passwords (in Keepass) instead of MFA. I'd love to hear more details as I'm finding more and more services push the MFA aspect, and I don't use a smartphone. Thanks.

Most password managers can also store TOTP tokens. A few services support registering redundant Yubikeys. Failing that, they usually give you a recovery code with which you can restore access to an account you're locked out of.

Re: Request your personal information

#78

Earlier quoted context omitted.

> impossible to steal money from me without these things First of all, "stripe" pushes information to the BankID app asking for confirmation, there's no code to input to the site, the verification happens on my phone where I'm asked if i wanna authenticate X or Y to happen (logging in, or transferring money) But yes, they actually saw an attack vector where people could be fake challenged at the same time they're log…

> If you're curious for more information about BankID they have a site: https://www.bankid.com/en/ I think it's owned as a collab between "all" Swedish banks. I'm not sure if it's the same technology as in Norwegian banks: https://link.springer.com/chapter/10.1007/978-3-540-85230-8_...

Paywalled paper from 2008 or am I missing something?

Re: Request your personal information

#79
post #40
post #22

I can't do this because amazon does not have my personal information. Amazon has a pseudonym with a dedicated Twilio number that delivers to a private postal box. I burn the pseudonym every few years. Which reminds me ... This is simple because VISA/MC do not validate cardholder name. Everyone thinks they do and most merchants believe that they do but ... they do not. You can use your card with "Mickey Mouse" and it…

My mind is blown. Reflecting on a lifetime of getting declined filling web forms in with a wrong CC number, billing address, expiration or CCV, I...don’t think I’ve ever misspelled my name. Trying this out on my next purchase for sure.

From my own experience, the only required part of the address is the zip code as it's used for verification.

However, some services go out of their way to check if the address you entered exists and is valid, but that has nothing to do with Visa or MC.

Re: Request your personal information

#80
post #40

Earlier quoted context omitted.

My mind is blown. Reflecting on a lifetime of getting declined filling web forms in with a wrong CC number, billing address, expiration or CCV, I...don’t think I’ve ever misspelled my name. Trying this out on my next purchase for sure.

From my own experience, the only required part of the address is the zip code as it's used for verification. However, some services go out of their way to check if the address you entered exists and is valid, but that has nothing to do with Visa or MC.

This was a really frustrating experience moving into a new townhouse as the first-ever occupant. It took nearly three years for the city's property records to be correct and propagate everywhere. We couldn't even pay our property taxes at first, and the US Postal Service would not process my move request, insisting my address did not exist, in spite of me being physically in the house.
Post reply on HN