Live data from Hacker News

Amazon's customer service backdoor

medium.com

221–230 of 366 posts

Re: Amazon's customer service backdoor

#221
post #72

Earlier quoted context omitted.

A related word of warning: Namecheap updated their registration page last year. Now, when you register a domain it tells you free Whoisguard is included, but it doesn't make it clear that it's disabled by default." Previously it just worked. Now you have to check another box to turn it on. This change makes no sense to me. (If you want free Whoisguard, why would you not want it turned on?) I was white-hot furious* wh…

Worse, they'll happily sell you Whoisguard for domains that don't support it. When you discover it's not usable, they'll give you a refund, then include it again in the next billing cycle. I switched to Namecheap based on recommendations here, and their previous stance on certain privacy issues, but I'm running out of alternatives.

Maybe check out gandi.net? Very happy with them so far.

Re: Amazon's customer service backdoor

#222

"The problem is, 9999 times out of 10000 support requests are legitimate, agents get trained to assume they’re legitimate. But in the 1 case they’re not, you can completely fuck someone over." That's why nothing will change if these estimates are even in the right universe. Nobody wants to inconvenience the vast majority of customers to prevent a minuscule number of issues.

Minuscule number of issues that can lead to identity theft. I'm fairly sure that most countries have laws stating companies must prevent this to a reasonable extend, even if it means being inconvient to 99.99% users calling. This is after all a simple way to teorists to get a new identity. At the very least they should be able to flag accounts are high risk, and special procedures and senior staff handling such cases.

That said, the author have a very good point. If you cannot log into your account, they should not assist you. MS Support/Store does something similar. They send an email with a code to the address they have on record. If you cannot tell them the code they send, they will not help you. So if you cannot log into your account, they can assist you in password recovery, and take it from there.

Re: Amazon's customer service backdoor

#223
post #89
post #33

Earlier quoted context omitted.

They don't hide the name because you cannot hide the name while legally owning the domain yourself. Services that hide the name actually result in a company (e.g. "Domains by Proxy LLC") purchasing and holding domain ownership for you, which is a very different legal arrangement with different risks.

Treat a domain like money: if you want it held pseudonymously, you put it in the ownership of a shell corporation you control (through power of attorney to the board of directors), but don't own any equity in.

I've thought of checking that... Instead of Domains By Proxy LLC or whatever legally holding your account, setup an offshore shell corporation and use that to register my domains, becoming my own whoisguard in the process. It's going to be more expensive than these services, but the domains stay under your full control and you can keep your personal info private.

Re: Amazon's customer service backdoor

#224
post #27

"The problem is, 9999 times out of 10000 support requests are legitimate, agents get trained to assume they’re legitimate. But in the 1 case they’re not, you can completely fuck someone over." That's why nothing will change if these estimates are even in the right universe. Nobody wants to inconvenience the vast majority of customers to prevent a minuscule number of issues.

Until/unless we can find and implement a workable way to make this a problem Amazon is financially on-the-hook for, instead of Amazon (et al) customers. I wonder what the PCI implications are if it's true that Amazon gave away his last four cc digits over the phone? I wonder if there are applicable PII laws in his jurisdiction that'd have Amazon able to be held liable for disclosing his address? (I think there are he…

In the US, the relation Legal Name ~ Home Phone Number ~ Address is emphatically not private. It's in the phone book, it's in directories published by local school districts, it's on public property ownership records, in some cases voter registrations are subject to FOIA, it's on corporate registrations, amateur radio licenses, FAA pilot licensing (including small drones), all kinds of professional certifications and business licensing which is published on the internet, etc.

So no, very unlikely.

Re: Amazon's customer service backdoor

#225

Earlier quoted context omitted.

A related word of warning: Namecheap updated their registration page last year. Now, when you register a domain it tells you free Whoisguard is included, but it doesn't make it clear that it's disabled by default." Previously it just worked. Now you have to check another box to turn it on. This change makes no sense to me. (If you want free Whoisguard, why would you not want it turned on?) I was white-hot furious* wh…

Hiding your contact information is like security through obscurity. I'm not saying it's not a good extra step to decrease the frequency of attacks (much like changing an SSH port to 3857 or something), but it doesn't add any real security. This is the crux of the problem; our addressees and birthdays are treated like passwords by these companies.

[deleted]

Re: Amazon's customer service backdoor

#226
post #17

Whois is great for social engineering attackers. You get a name, email, address, and the first service to attack. Meanwhile, the ICANN is working around the clock to make it illegal for us to protect our personal information, and whois protection is becoming an increasingly niche service for registrars. For example, gandi.net (and thus Amazon) doesn't hide your name when you have it turned on. By the time you find th…

In Germany you have to publish a full address on your website, so even if you don't own the domain, anybody can get you IRL.

http://www.gesetze-im-internet.de/tmg/__5.html

Re: Amazon's customer service backdoor

#227
post #185

Earlier quoted context omitted.

Passwords are also security by obscurity.

Ssh ports are brute forceable, passwords have a much much larger search space.

Changed SSH port is not security measure. It's needed to keep your log files clear from random network scanning.

When your SSH port is something like 53148 and you see password brute-force activity in logs it's almost always mean that somebody intentionally scanning your server.

Re: Amazon's customer service backdoor

#228
post #17

Whois is great for social engineering attackers. You get a name, email, address, and the first service to attack. Meanwhile, the ICANN is working around the clock to make it illegal for us to protect our personal information, and whois protection is becoming an increasingly niche service for registrars. For example, gandi.net (and thus Amazon) doesn't hide your name when you have it turned on. By the time you find th…

How does one go about having their details removed from whois?

Re: Amazon's customer service backdoor

#229
post #17

Whois is great for social engineering attackers. You get a name, email, address, and the first service to attack. Meanwhile, the ICANN is working around the clock to make it illegal for us to protect our personal information, and whois protection is becoming an increasingly niche service for registrars. For example, gandi.net (and thus Amazon) doesn't hide your name when you have it turned on. By the time you find th…

In Germany you have to publish a full address on your website, so even if you don't own the domain, anybody can get you IRL. http://www.gesetze-im-internet.de/tmg/__5.html

Only if you have a commercial site.
Post reply on HN