Live data from Hacker News

Amazon's customer service backdoor

medium.com

161–170 of 366 posts

Re: Amazon's customer service backdoor

#161
post #93
post #40

Earlier quoted context omitted.

Agree. Your contact info in whois adds little to any number of other public records that will contain your name, address, phone number. It does make good sense to not use your primary "personal" email address in whois, nor your home address. PO Box rentals are fairly cheap and that's what I use for whois registrations.

Sadly, you can't even use PO boxes for all domains, some registries require a "full" address.

USPS now supports a feature called "street addressing". Basically, instead of writing "PO Box #" as the address, you may write the actual street address of the same facility followed by your box number, something like "123 Main St #456". Private mailbox providers also often accept addresses like "123 Main St Apt 456", where 456 is the number of your mailbox as well.

Re: Amazon's customer service backdoor

#162

This is exactly the same thing that let someone delete Mat Honan's (Wired author) accounts back in 2012: Apple tech support gave the hackers access to my iCloud account. Amazon tech support gave them the ability to see a piece of information — a partial credit card number — that Apple used to release information. http://www.wired.com/2012/08/apple-amazon-mat-honan-hacking/

No, customer service did not disclose the cc number in this instance -- they did disclose his address though, which stinks.

Re: Amazon's customer service backdoor

#163
post #17

Whois is great for social engineering attackers. You get a name, email, address, and the first service to attack. Meanwhile, the ICANN is working around the clock to make it illegal for us to protect our personal information, and whois protection is becoming an increasingly niche service for registrars. For example, gandi.net (and thus Amazon) doesn't hide your name when you have it turned on. By the time you find th…

A related word of warning: Namecheap updated their registration page last year. Now, when you register a domain it tells you free Whoisguard is included, but it doesn't make it clear that it's disabled by default." Previously it just worked. Now you have to check another box to turn it on. This change makes no sense to me. (If you want free Whoisguard, why would you not want it turned on?) I was white-hot furious* wh…

I found last week that Namecheap enabled auto-renew of both the domain and whoisguard by default:

http://imgur.com/hoGfojZ.png

If you click-through the checkout with the 'Confirm Order' button at the top right away you can miss that detail - as I have twice.

One of the reasons I switched to Namecheap in the first place is because they were a registrar that didn't rely on bundling tricks. I'm considering moving all of my domains away.

Re: Amazon's customer service backdoor

#164
post #17

Whois is great for social engineering attackers. You get a name, email, address, and the first service to attack. Meanwhile, the ICANN is working around the clock to make it illegal for us to protect our personal information, and whois protection is becoming an increasingly niche service for registrars. For example, gandi.net (and thus Amazon) doesn't hide your name when you have it turned on. By the time you find th…

If WHOIS is destroyed, your contact information will still be known by everybody you're in contact with, many you've only met, possibly many you haven't met but want to meet, and millions of employees of companies you've interacted with. There is no meaningful difference between that and public information.

It is Amazon's absurd assumption that your contact information is private that is at fault here. Trying to ameliorate this by contacting fewer people is self-destructive, and cannot achieve complete security unless you're willing to eliminate contact with everybody but those you trust with your accounts. Without a doubt it is Amazon's policy that needs to change.

Re: Amazon's customer service backdoor

#166
post #66

Earlier quoted context omitted.

Which only proves your comment's parent's point even more. {SWAT, pizza orders, etc} assume that the phone number that shows up on caller ID is authentication of the identity of the phone line on the other end. They could call back the number on caller ID to verify the original caller matched the person who picked up, but they don't. Having knowledge of a Social Security number was assumed to be authentication, but i…

Keep in mind too that Caller ID is trivially blockable (and blocked caller id isn't remarkable enough to be super suspicious), and it's also easily within the capability of many of the 4chan/gg griefers to spoof "correct" Caller ID numbers as well.

By "gg" you mean what? Gamer gate?

Re: Amazon's customer service backdoor

#167
post #44

Earlier quoted context omitted.

I created my catch-all on a subdomain. While it gives a problem with certain websites (don't consider it a valid e-mail address), I barely receive spam on it.

> While it gives a problem with certain websites (don't consider it a valid e-mail address) Are you saying that there are sites out there which don't accept mailbox@subdomain.example.com a valid email address? If so, that's beyond broken...

My school's student addresses ended in @u.northwestern.edu. You can imagine this was annoying sometimes when email addresses ending in .edu were used to verify student status.

Re: Amazon's customer service backdoor

#168
post #15

Damn, lucky they send out emails after a customer service interaction or you'd have never had any idea this even took place.

It makes me wonder, if the person is unsuccessful at authenticating, does the real owner get a follow up email? For instance, maybe he had to try 5 times to contact support before he found an agent who authenticated me using a fake address.

Re: Amazon's customer service backdoor

#169
post #86

Earlier quoted context omitted.

A happy NameCheap user for years, I have started switching away. Their horrid "modern" 40px padding everywhere bubbly redesign makes GoDaddy look good in comparison. A major pain to manage more than a couple of domains, and numerous user feedback seems to fall on deaf ears, e.g. [1][2][3][4] Example weird feature: all domains are shown, even ones that you've let expire/sold years ago, and there is no way to hide them…

Do you mind sharing where you switched to?

I've used joker.com for years. The website isn't pretty, but you can actually do many functions via pgp email.

Re: Amazon's customer service backdoor

#170
post #17

Whois is great for social engineering attackers. You get a name, email, address, and the first service to attack. Meanwhile, the ICANN is working around the clock to make it illegal for us to protect our personal information, and whois protection is becoming an increasingly niche service for registrars. For example, gandi.net (and thus Amazon) doesn't hide your name when you have it turned on. By the time you find th…

When we start using block chain to replace DNS and usernames to replace domains, and services to replace hosted servers, a lot of things will change. One is that there will be nobody to force us to verify who we are. These kinds of things serve no purpose other than to hand leverage up the chain.
Post reply on HN