Live data from Hacker News

Amazon admits it exposed customer email addresses, but refuses to give details

techcrunch.com

1–10 of 160 posts

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#3
post #2

This is one of the less appreciated clauses of the GDPR: That companies are required to disclose data breaches within a reasonable time-frame, and users have the right to know about any exposure of their data.

It sounds like they did that but TC wants more. I'm not really sure why HN allows techcrunch stories on the front page. TC is tabloid journalism at its finest.

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#4
based on spam email i have received, that i clearly should not have, i believe this was an exposure to marketplace sellers from whom you have bought a product.

I am very careful with my email. i’m not just guessing here. i actually reported it to amazon security. (no answer from them of course.)

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#5

based on spam email i have received, that i clearly should not have, i believe this was an exposure to marketplace sellers from whom you have bought a product. I am very careful with my email. i’m not just guessing here. i actually reported it to amazon security. (no answer from them of course.)

eBay are particularly careless in that regard.

There's no reason that a seller should ever see the customer's actual e-mail address on such a site but I'm up to ebay5@ on my mail server due to direct spam from sellers from whom I bought one item in the past.

No, sellers, I did not 'opt in' to your spam just because I bought something. But why does eBay ever give them the address?

Oddly I've never had a problem with random Chinese sellers, it's always Euro or US ones.

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#6

based on spam email i have received, that i clearly should not have, i believe this was an exposure to marketplace sellers from whom you have bought a product. I am very careful with my email. i’m not just guessing here. i actually reported it to amazon security. (no answer from them of course.)

They intentionally provide this information to marketplace sellers. It's arguably poor design but it's definitely not an unintentional security flaw. Marketplace/FBA sellers have talked about strategies for utilizing customer email address for years [1]

[1] https://sellercentral.amazon.com/forums/t/how-to-access-all-...

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#7
post #2

This is one of the less appreciated clauses of the GDPR: That companies are required to disclose data breaches within a reasonable time-frame, and users have the right to know about any exposure of their data.

It sounds like they did that but TC wants more. I'm not really sure why HN allows techcrunch stories on the front page. TC is tabloid journalism at its finest.

There's been now and then reasonable TC articles that produced good conversations here on HN though. They also make mention of a reasonable number of startups which is obviously something that sparks interest to many here on HN.

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#8

based on spam email i have received, that i clearly should not have, i believe this was an exposure to marketplace sellers from whom you have bought a product. I am very careful with my email. i’m not just guessing here. i actually reported it to amazon security. (no answer from them of course.)

eBay are particularly careless in that regard. There's no reason that a seller should ever see the customer's actual e-mail address on such a site but I'm up to ebay5@ on my mail server due to direct spam from sellers from whom I bought one item in the past. No, sellers, I did not 'opt in' to your spam just because I bought something. But why does eBay ever give them the address? Oddly I've never had a problem with r…

Chinese sellers have been very pleasant to deal with IME, including obviously hand-written niceties, handwritten thank you notes (maybe not in the best English but the sentiment is there) for a bunch of stuff. Occasionally small 'gift' items, have gotten Chinese fun-size snacks too.

There are US sellers that have resulted in 27+ emails _within one day of purchase_, one seller has managed to sign my ebay_a10f9@ alias up for five separate companies reselling third party warranties / affiliate spam for the above. What the fuck?

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#9
post #6

based on spam email i have received, that i clearly should not have, i believe this was an exposure to marketplace sellers from whom you have bought a product. I am very careful with my email. i’m not just guessing here. i actually reported it to amazon security. (no answer from them of course.)

They intentionally provide this information to marketplace sellers. It's arguably poor design but it's definitely not an unintentional security flaw. Marketplace/FBA sellers have talked about strategies for utilizing customer email address for years [1] [1] https://sellercentral.amazon.com/forums/t/how-to-access-all-...

Also, your Amazon profile is public by default, especially any wishlists.

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#10

based on spam email i have received, that i clearly should not have, i believe this was an exposure to marketplace sellers from whom you have bought a product. I am very careful with my email. i’m not just guessing here. i actually reported it to amazon security. (no answer from them of course.)

Great reason to setup wildcard e-mails so you can do something like amazon@yourdomain.com!
Post reply on HN