Live data from Hacker News

Amazon's customer service backdoor

medium.com

211–220 of 366 posts

Re: Amazon's customer service backdoor

#211

Earlier quoted context omitted.

Wouldn't that allow somebody who stole your phone to lock you out of your bank if they answered the call? Seems like that'd make a stressful situation potentially worse if thieves knew they could do that. Especially if they called from a number that's linked to the bank anywhere and something like Google's dialer surfaces who it is - your bank calling seems like a potential "maybe I can get more" for a thief so they…

I would prefer that my bank, if it detects fraudsters trying to pull some sort of trick involving my account, to freeze things until I show up and present ID. That's inconvenient, but clearly better than the alternative.

My bank did this. They had actually made a mistake on their end; one of their reps put a hold on my account (presumably a suspicious transaction), but didn't put it in right so it registered as being my request.

I called up, asking why there was a hold, they said I put it there, I said I didn't. There was a long pause, followed by "for security reasons, we won't be able to help you with anything related to your accounts until you come into a branch and present photo ID".

It was a bit inconvenient, but I have to say I was pretty impressed.

Re: Amazon's customer service backdoor

#212

Earlier quoted context omitted.

> While it gives a problem with certain websites (don't consider it a valid e-mail address) Are you saying that there are sites out there which don't accept mailbox@subdomain.example.com a valid email address? If so, that's beyond broken...

My school's student addresses ended in @u.northwestern.edu. You can imagine this was annoying sometimes when email addresses ending in .edu were used to verify student status.

>My school's student addresses ended in @u.northwestern.edu. You can imagine this was annoying sometimes when email addresses ending in .edu were used to verify student status.

Sorry, could you repeat that? yourname@u.northwestern.edu certainly matches \.edu$.

Unless you're worried about the false-positive for a non-student with a different subdomain?

Re: Amazon's customer service backdoor

#213
post #59

Earlier quoted context omitted.

Note, though, that catch-all emails will also catch a ridiculous amount of spam. Creating each account name individually avoids that problem, at the cost of some extra trouble when registering a new service. An intermediate step that may work if you don't expect people to target you individually: have one or more required substrings for the email local part, and catch all mail to addresses containing that substring.

One method that I've seen used (heard it described by a guest one of Leo Laporte's podcasts a looooong time ago) is to iterate account names by year. For example, this year the email address would be pyre2016@example.com, and next year it will be pyre2017@example.com. Not sure how well it works, but the idea is that by that every year you start over with a fresh address (that takes a while to get onto spam lists). I'…

I believe the real issue here is its not uncommon for spam services to try to locate valid email addresses. Generally, an email server won't accept email to an invalid users and will probably start flagging the incoming server/domain as those attempts start to cross a threshold of some sort. OP is talking about *@example.com as a catchall which means a spammers script will sit there and email a dictionary of usernames against your domain until it crosses it's own threshold. It's not too hard to add an alias for each name as you go along but it really depends whose list your domain gets on.

Re: Amazon's customer service backdoor

#214
post #17

Whois is great for social engineering attackers. You get a name, email, address, and the first service to attack. Meanwhile, the ICANN is working around the clock to make it illegal for us to protect our personal information, and whois protection is becoming an increasingly niche service for registrars. For example, gandi.net (and thus Amazon) doesn't hide your name when you have it turned on. By the time you find th…

When we start using block chain to replace DNS and usernames to replace domains, and services to replace hosted servers, a lot of things will change. One is that there will be nobody to force us to verify who we are. These kinds of things serve no purpose other than to hand leverage up the chain.

Did I miss an RFC?

Re: Amazon's customer service backdoor

#215
post #86

Earlier quoted context omitted.

A happy NameCheap user for years, I have started switching away. Their horrid "modern" 40px padding everywhere bubbly redesign makes GoDaddy look good in comparison. A major pain to manage more than a couple of domains, and numerous user feedback seems to fall on deaf ears, e.g. [1][2][3][4] Example weird feature: all domains are shown, even ones that you've let expire/sold years ago, and there is no way to hide them…

Do you mind sharing where you switched to?

I recommend Gandi. They support almost all the TLDs, their web UI is very decent, their support is excellent and they live up to their "No bullshit" motto. They are also overall good guys, donate to the EFF, took public stances against sopa and such...

They're a bit more expensive when it comes to domains but we're talking single dollars a year here.

Re: Amazon's customer service backdoor

#216
post #105
post #100

Earlier quoted context omitted.

I think there is already enough here to shame Amazon into action if it gets on a major newspaper. Something like "Hackers break into Amazon account and Amazon will not do anything" Perhaps the Washington Post would be a good newspaper with credibility.

Not sure if you were being sarcastic or not, but Jeff Bezos bought Washington Post...

oh, whoops...

Re: Amazon's customer service backdoor

#217
post #7

Any recommendation what one (as a customer of Amazon) can do today ? 2FA does not help here as someone goes through support channel which looks like bypasses 2FA Also concerned if the same trick can be applied to Amazon Cloud services, as there one can also run up a big bill pretty quickly.

Use an special email address. In India, you can use Netbanking for making payments where the bank handles the transaction and the merchant doesn't get any of your information like card details, etc.

Re: Amazon's customer service backdoor

#218
post #17

Whois is great for social engineering attackers. You get a name, email, address, and the first service to attack. Meanwhile, the ICANN is working around the clock to make it illegal for us to protect our personal information, and whois protection is becoming an increasingly niche service for registrars. For example, gandi.net (and thus Amazon) doesn't hide your name when you have it turned on. By the time you find th…

For me the solution has been to stick with my national ccTLD registry. If your country has strong private protection laws then your national registry will shield your information for your ccTLD domains from public whois. It's not exactly bulletproof, they still make that information available from their whois database but it's just another step someone has to make to get to your information. That much said, on a ccTLD you should be able to get away with only just a name, surname and a valid email address.

What are the alternatives? Those fishy private protection companies? Technically once you sign up there, they own your domain, simple as that.

OpenNIC? I wish that was the case.

Re: Amazon's customer service backdoor

#219
post #46
post #35

> services should allow me to easily create lots of aliases. Right now the best defense against social engineering seems to be my fastmail account which allows me to create 1 email address alias per service What you may want is a catch-all email - which lets you do @domain.com -> nmjohn@domain.com (where is everything besides already defined addresses) - that way you can make up emails on the fly without having to se…

Fastmail and Gmail support a local suffix of the form yourname+amazon@gmail.com. That's a plus character between the local name and local suffix. If you use a password manager, you can replace a predictable suffix like "amazon" with random hex value. Unfortunately, many sites borked their e-mail address validation and do not accept the plus character. (Amazon permits it.) Also, you'll ocassionally find a customer ser…

Gmail also allows yourname.amazon@gmail.com

Re: Amazon's customer service backdoor

#220
post #72

Earlier quoted context omitted.

Worse, they'll happily sell you Whoisguard for domains that don't support it. When you discover it's not usable, they'll give you a refund, then include it again in the next billing cycle. I switched to Namecheap based on recommendations here, and their previous stance on certain privacy issues, but I'm running out of alternatives.

I've been a happy user of Google Domains since closed beta. I'll never go anywhere else for domains again.

Still waiting for them to open to the rest of the world, beta is only for USA. Frankly , no idea what is taking them so long.
Post reply on HN