I use blur from Abine.com, gives me a new email that forwards to my main, as many as I want, integrated with a browser plugin that barely adds time to signup.
Amazon's customer service backdoor
21–30 of 366 posts
Re: Amazon's customer service backdoor
#22Earlier quoted context omitted.
If they were following a script and the script were careful, saying "I lost my phone" would cause them to try to contact your phone, and when you answered and said you still had it, would put a fraud alert on the account and stop all further attempts to social engineer customer service. But most companies aren't anywhere near that careful.
Many people (including me) don't answer from unknown numbers, so that wouldn't work.
Re: Amazon's customer service backdoor
#23On your Amazon home page, go to: Your Account › Change Account Settings › Advanced Security Settings Turn on 2-step Verification. It won't completely solve social engineering, but it can't hurt.
If you had read the article you would know that they already had 2F turned on before the first intrusion and throughout the subsequent intrusions.
In any case, I will leave my comment so that folks who come across this thread have a handy reference for turning on 2FA on their Amazon accounts.
Re: Amazon's customer service backdoor
#24Whois is great for social engineering attackers. You get a name, email, address, and the first service to attack. Meanwhile, the ICANN is working around the clock to make it illegal for us to protect our personal information, and whois protection is becoming an increasingly niche service for registrars. For example, gandi.net (and thus Amazon) doesn't hide your name when you have it turned on. By the time you find th…
Re: Amazon's customer service backdoor
#25On your Amazon home page, go to: Your Account › Change Account Settings › Advanced Security Settings Turn on 2-step Verification. It won't completely solve social engineering, but it can't hurt.
Re: Amazon's customer service backdoor
#26"The problem is, 9999 times out of 10000 support requests are legitimate, agents get trained to assume they’re legitimate. But in the 1 case they’re not, you can completely fuck someone over." That's why nothing will change if these estimates are even in the right universe. Nobody wants to inconvenience the vast majority of customers to prevent a minuscule number of issues.
It's why banks still use laughably short and simple PIN codes.
Re: Amazon's customer service backdoor
#27"The problem is, 9999 times out of 10000 support requests are legitimate, agents get trained to assume they’re legitimate. But in the 1 case they’re not, you can completely fuck someone over." That's why nothing will change if these estimates are even in the right universe. Nobody wants to inconvenience the vast majority of customers to prevent a minuscule number of issues.
I wonder what the PCI implications are if it's true that Amazon gave away his last four cc digits over the phone?
I wonder if there are applicable PII laws in his jurisdiction that'd have Amazon able to be held liable for disclosing his address? (I think there are here in Australia(1), but that doesn't mean regular Amazon customers have any chance of prevailing in court against Amazon's in-house legal team...)
(1) 6.67 of this says your address is "individually identifying data": http://www.alrc.gov.au/publications/6.%20The%20Privacy%20Act...
Re: Amazon's customer service backdoor
#28Whois is great for social engineering attackers. You get a name, email, address, and the first service to attack. Meanwhile, the ICANN is working around the clock to make it illegal for us to protect our personal information, and whois protection is becoming an increasingly niche service for registrars. For example, gandi.net (and thus Amazon) doesn't hide your name when you have it turned on. By the time you find th…
I think the bigger problem is that public information like your name and address is sufficient for proving your identity. If we make whois information private, what about phone books, property records, direct mail databases, etc. etc.
Re: Amazon's customer service backdoor
#29"The problem is, 9999 times out of 10000 support requests are legitimate, agents get trained to assume they’re legitimate. But in the 1 case they’re not, you can completely fuck someone over." That's why nothing will change if these estimates are even in the right universe. Nobody wants to inconvenience the vast majority of customers to prevent a minuscule number of issues.
Came here to say just that. I did general customer support for a telco for a few months a while back, and most of the general public can't really deal with high security for personal information. If you were as strict with security as you should be, you'd be locking half of your subscribers out of their accounts eventually. This would create a phenomenal amount of follow-up paperwork for your company, meaning higher…
Re: Amazon's customer service backdoor
#30Whois is great for social engineering attackers. You get a name, email, address, and the first service to attack. Meanwhile, the ICANN is working around the clock to make it illegal for us to protect our personal information, and whois protection is becoming an increasingly niche service for registrars. For example, gandi.net (and thus Amazon) doesn't hide your name when you have it turned on. By the time you find th…
Now, when you register a domain it tells you free Whoisguard is included, but it doesn't make it clear that it's disabled by default."
Previously it just worked. Now you have to check another box to turn it on.
This change makes no sense to me. (If you want free Whoisguard, why would you not want it turned on?)
I was white-hot furious* when I discovered that a handful of new domain regs had leaked my contact details, and I began getting the inevitable spam calls and texts.