Earlier quoted context omitted.
In all seriousness, email jeff@amazon.com. The most likely outcome is that some relevant managers will receive one of the infamous "?" emails from him. If so, that'll result in two things: 1) Your problem will be resolved ASAP, managers right up the chain will be tracking it extremely closely, as they'll have to justify every action to Jeff. Everyone goes scrambling when one of those emails goes out. 2) A post-mortem…
I think that's gone the way of the dodo. Last I remember, he didn't read those anymore, and they were automatically just shunted into the normal escalation flow. Too many people got wind of it and abused it.
Still locked out of my AWS account
121–130 of 283 posts
Re: Still locked out of my AWS account
#122Also having problem with AWS - can't access it and they keep billing me for something there I want to shut it down (EC2?) but I can't. I recently moved from Brazil to UK (new address) and changed phone + sim card (Authenticator after restore from backup lost all 2 factor auth entries). This is the moment when you realise that you're outside of predefined use cases of The Machine and you're fucked. Nobody is here to h…
This is why, when creating a new 2FA login, you MUST write down the one time use backup codes, and store them in a safe and secure place.
Re: Still locked out of my AWS account
#123Might sound obvious in hindsight, but _always_ create separate AWS accounts for your different projects.
Doesn't this require separate gmail addresses? If so, then that's an extremely bad idea. I already had one gmail account completely banned with no notice. I wasn't doing anything abusive -- I used it for some npm projects and a github account. Actually, is there a reasonable free gmail alternative for situations like this? I'd like to migrate. FastMail is worth paying for, but it's too expensive for one-off side proj…
FastMail will let you create multiple aliases, either at your own domain, or one of theirs, linked to your account.
Re: Still locked out of my AWS account
#124Protip for everyone on this site. Look at a companys stock price. If it's in the triple digits, avoid it, because they can and will screw you over.
Re: Still locked out of my AWS account
#125Earlier quoted context omitted.
> My point was, if you use a single account, it's far less likely to get banned Why do you think that? If anything, you have more activity you can be banned for... And also, why you say it like gmail is the only email provider? You need separate _email_ accounts, not gmail. It can be some other service or your own domain. Google can be service provider behind your own domain, but you will control address space etc. N…
It seems like Google uses some heuristics when deciding whether to ban an account. My theory is that if you stick with your personal gmail account, you have such a long history of activity that it's unlikely to be flagged by whatever "smart" algorithm they're using. I was quite surprised that my gmail account was banned without doing anything remotely malicious. (Certainly not anything listed in https://www.google.co…
I never saw/heard of evidence of such behavior.
> but you'll still lose your emails if they decide to suspend you
Emails are easily backupable, you can download them locally and/or forward everything to the "backup" email. One more service to host email on your own domain is Yandex.Mail, it's free and pretty good.
Re: Still locked out of my AWS account
#126Earlier quoted context omitted.
I had 2FA activated, changed phones and lost it. I couldn't log in to my account, so I contacted support. Within about 30 min they had put me back into my account. The dude who helped me was super chill and understanding as well.
What is the purpose of 2FA when social engineering the support team circumvents it? This should not be possible! Lost your phone? That’s what 2FA backup codes are for.
Re: Still locked out of my AWS account
#127Earlier quoted context omitted.
I don't follow your logic about the breach risk. If you're using unique passwords per service (and you really should) then I would expect any breach that involved passwords would have less of an effect. If there is a breach with a centralized single sign on service then every other dependent service is also affected.
There's a big difference between what people should do, and what people actually do. Research consistently shows that a large percentage of people reuse passwords across many sites. [1] http://www.jbonneau.com/doc/DBCBW14-NDSS-tangled_web.pdf
Re: Still locked out of my AWS account
#128Earlier quoted context omitted.
This is such a meaningless statement. What exactly are you trying to convey?
Don't ever use services provided by a third party. That's why I cut my own hair, make my own toothpaste, and create my own electricity from coal I mine myself!
Re: Still locked out of my AWS account
#129[Deleted]
Please delete your comment. I am incredibly happy that Digital Ocean made you go to those lengths to get your account back. The last thing we need is web services companies requiring less security. Social engineering attacks are typically the method of entry to hosting providers such as Digital Ocean. Frankly I would be totally fine if they required another form of ID (such as a passport) or another form of address/n…
Re: Still locked out of my AWS account
#130Protip for everyone on this site. Look at a companys stock price. If it's in the triple digits, avoid it, because they can and will screw you over.
Should your rule be written to use market cap?