Live data from Hacker News

Amazon's customer service backdoor

medium.com

131–140 of 366 posts

Re: Amazon's customer service backdoor

#131

The OP says he is "a security conscious user who follows the best practices like: using unique passwords, 2FA, only using a secure computer and being able to spot phishing attacks from a mile away..." yet I do not think he enabled 2FA on Amazon.com. If he did customer service would not have helped the hacker pretending to be him. As their help page says, "If you need help from Customer Service after enabling Two-Step…

Actually, I do have 2FA enabled on my account. But I don't think I had it enabled at the time for the very first attack.

Interestingly, last night I did get an SMS: "Message from Amazon Customer Service: xxxxx is your Amazon security code" even though my 2FA is not an SMS (it's using authenticator).

I don't have access to the recording, so I have no idea what actually happened. But based on the email ("here's the details" on your order) I'm almost certain they were successful. Probably just told them that they lost the phone, or something. At this point, they've now been able to get almost everything possible about me.

Also interestingly, not once did Amazon recommend that I use 2FA to avoid social engineering. I was told by two different support reps to change my password though.

Re: Amazon's customer service backdoor

#132

The problem is Amazon has thousands of poorly trained first-level support staff with far too much power and information. What we need is a global security standard for support staff, with a template as to what information is accessible by staff and what isn't. And what is available to better trained 2nd-level support, etc. And then each company can say they are certified for this particular security standard, and the…

Not Amazon. Essentially every company. Your typical first tier support rep is paid perhaps $9-10 an hour, utterly hates their job, and has access to scary amounts of account information. It doesn't help that call center turnover rates are often so high that it isn't unusual for the median experience of reps to be 6 months, or less.

The bottom line really is that so far these kinds of social engineering attacks haven't been enough of a problem for companies to have the slightest economic incentive to improve the situation.

Re: Amazon's customer service backdoor

#133
post #37

If you own a home in the U.S., anybody already can get your address legally and easily from your county or district property appraiser's/assessor's website. Along with how much you paid for it, and when you bought it. So calling Amazon CS rep is a hard way to go about it. :)

Buying the property through a Revocable Living Trust can make this harder (providing the name of your living trust doesn't contain your name, like most do!). Can cost only a couple of dollars to record the living trust, plus it helps with estate planning. Make sure the utilities are in the name of the trust as well, so they don't share your name+address.

Re: Amazon's customer service backdoor

#134
post #86
post #72

Earlier quoted context omitted.

Worse, they'll happily sell you Whoisguard for domains that don't support it. When you discover it's not usable, they'll give you a refund, then include it again in the next billing cycle. I switched to Namecheap based on recommendations here, and their previous stance on certain privacy issues, but I'm running out of alternatives.

A happy NameCheap user for years, I have started switching away. Their horrid "modern" 40px padding everywhere bubbly redesign makes GoDaddy look good in comparison. A major pain to manage more than a couple of domains, and numerous user feedback seems to fall on deaf ears, e.g. [1][2][3][4] Example weird feature: all domains are shown, even ones that you've let expire/sold years ago, and there is no way to hide them…

Do you mind sharing where you switched to?

Re: Amazon's customer service backdoor

#135
post #124

Earlier quoted context omitted.

I might be being pedantic, but the only mention of 2FA in the OP is: "As a security conscious user who follows the best practices like: using unique passwords, 2FA, only using a secure computer and being able to spot phishing attacks from a mile away, I would have thought my accounts and details would be be pretty safe? Wrong." Are you sure the author enabled 2FA on his Amazon retail account, or was it only enabled o…

There's no reason to assume he wasn't using 2FA. The title says "backdoor" and that's the point: they didn't verify identity... they asked for name, email and a nearby address.

> Actually, I do have 2FA enabled on my account. But I don't think I had it enabled at the time for the very first attack.

https://news.ycombinator.com/item?id=10965111

Re: Amazon's customer service backdoor

#136
post #89

Earlier quoted context omitted.

Treat a domain like money: if you want it held pseudonymously, you put it in the ownership of a shell corporation you control (through power of attorney to the board of directors), but don't own any equity in.

While I would love to do that it just isn't feasible for me and probably most others. ICANN really needs to provide better controls to avoid resorting to such workarounds.

> ICANN really needs to provide better controls to avoid resorting to such workarounds.

Not only ICANN but the whole financial world. Shell corporations provide no real use other than hiding money and ownership.

Re: Amazon's customer service backdoor

#137
post #70
post #37

If you own a home in the U.S., anybody already can get your address legally and easily from your county or district property appraiser's/assessor's website. Along with how much you paid for it, and when you bought it. So calling Amazon CS rep is a hard way to go about it. :)

If you are the officer of a company you own in the U.S., anybody can get your address from the annual corp. report.

It's the same in most countries. Opencorporates.com is the first place to look. Some countries, like New Zealand, have images of corporate documents online for free, which gives you a copy of the signature as well.

Like domain names, privacy when you have a company is hard.

Re: Amazon's customer service backdoor

#138
post #35

> services should allow me to easily create lots of aliases. Right now the best defense against social engineering seems to be my fastmail account which allows me to create 1 email address alias per service What you may want is a catch-all email - which lets you do @domain.com -> nmjohn@domain.com (where is everything besides already defined addresses) - that way you can make up emails on the fly without having to se…

but then the spammers use BCC and you don't know what email they used?

Re: Amazon's customer service backdoor

#139

Earlier quoted context omitted.

I fear that customer support might still accept emails without the suffix from the "customer". These are people, not robots, so if the address is close or in the vicinity of being correct, they might accept it. Same goes for the dot characters allowed in gmail addresses.

I strongly second this concern. I generate random strings as answers to my recovery questions. When I recently got asked one of the questions the support rep let out a sigh when asking (presumably because he saw the "crazy" answer) and then said "yeah yeah, alright" when I was about half way through the answer. That any company even suggests these insane security questions that anyone can trivially research is comple…

I would recommend strongly against that. You'd be far better off picking something plausible, so if someone does impersonate you it's obvious.

Remember it's a human verifying this. The attacker just needs to answer: "oh, yeah i just spammed the keyboard with some jibberish" and he's in.

The other thing I noticed by the attacker going after me, sometimes he'd call/contact the service multiple times in a row. All he needs to do is find out from 1 support rep that the reset password is randomly generated. Then tell another support rep that its "some jibberish" and he's in.

Re: Amazon's customer service backdoor

#140
post #93

Earlier quoted context omitted.

Sadly, you can't even use PO boxes for all domains, some registries require a "full" address.

"The street finds its own uses for things." Where I am (Australia) theres a whole bunch of places that'll provide "non Post Office PO boxes" who're perfectly happy for you to address things to "Suite 306" or "Apartment 306" as well as "PO Box 306" at whatever address the box is located. Fools _most_ of the "must be a real address, not a PO Box" restrictions. (Interestingly StartSSL failed me on that once when I gave…

Most likely more than x accounts used the same address.
Post reply on HN