Live data from Hacker News

Amazon's customer service backdoor

medium.com

321–330 of 366 posts

Re: Amazon's customer service backdoor

#321
post #17

Whois is great for social engineering attackers. You get a name, email, address, and the first service to attack. Meanwhile, the ICANN is working around the clock to make it illegal for us to protect our personal information, and whois protection is becoming an increasingly niche service for registrars. For example, gandi.net (and thus Amazon) doesn't hide your name when you have it turned on. By the time you find th…

In the UK this and a lot more is public information. As an example of what is available about me online (without paying a penny) just by searching for my name: - The year I was born - The district I was born (not the exact town, although that wouldn't be hard to guess) - My mother's maiden name (which is what most banks et al ask as a security question...) - The areas I've lived (based upon the electoral register, wh…

>TL;DR; If you rely on this to 'identify' someone, you are doing it wrong.

Which is why the system is set up so that if I go to the bank with this information and take money as you, I have stolen your identity and thus you are the victim and are responsible for the losses unless you fight back. Identity theft was created so financial institutions could be lax with their verification process thanks to the blame being shifted.

In reality, identify theft doesn't exist. In my example I stole from the bank, no you, and you shouldn't at all be involved in the process.

Re: Amazon's customer service backdoor

#322
post #83
post #46

Earlier quoted context omitted.

Fastmail and Gmail support a local suffix of the form yourname+amazon@gmail.com. That's a plus character between the local name and local suffix. If you use a password manager, you can replace a predictable suffix like "amazon" with random hex value. Unfortunately, many sites borked their e-mail address validation and do not accept the plus character. (Amazon permits it.) Also, you'll ocassionally find a customer ser…

Also a lot of systems strip anything after the + now, especially spam systems.

I've even started seeing registration systems that tell me that I've entered an invalid address if I do the [email]+[something]@gmail.com trick.

Twice now I was only able to register after removing the +[something] part of the email.

Is + actually an invalid email character (according to RFCs etc?). I couldn't find any reference to that when I looked.

Re: Amazon's customer service backdoor

#323
post #52

How to stop this: 1. Get a friend's permission to "hack" into his Amazon account (or "hack your own account"). 2. Contact Amazon's customer service, try the same social engineering techniques that the OP documented. 3. Once you obtain some sensitive information from the account, scare the CS rep by saying: "Haha! I am actually not the customer. I am a journalist/hacker/whatever and wanted to see how easy it was to so…

There is no point in getting a friend involved. Just see how much sensitive data Amazon will give you without giving them any of your login credentials.

Re: Amazon's customer service backdoor

#324

Earlier quoted context omitted.

> ICANN really needs to provide better controls to avoid resorting to such workarounds. Not only ICANN but the whole financial world. Shell corporations provide no real use other than hiding money and ownership.

That's not true at all. Corporations have tons of legitimate uses, including reducing liability.

>Shell corporations provide no real use

Re: Amazon's customer service backdoor

#325
I worked for Amazon for four years. For nearly the entire time I worked there, I, as an engineer, had access to every customer's purchase history, contact information, email addresses, etc. The reason? On occasion, I'd need to get a user's email address to reach out to them if they reported bugs. The one service that offers employees this access is all or nothing. Either you get to see a customer's email, credit card number, and purchase history - or you get to see nothing at all.

Everyone knew that I had this access, and everyone knew that it was against Amazon's own policy to give me access. But to them, that was easier than fixing the service so that it was more useful.

Perhaps I'm just clueless, but something tells me that any relevant competitor to Amazon - say, I don't know, Google - would choose to fix the service instead.

Re: Amazon's customer service backdoor

#326
post #129
post #98

Earlier quoted context omitted.

I was doing that but some companies think you are "hacking" if you put the company name in. Like I don't think you can do facebook@mydomain.com on Facebook.

fb@mydomain.com is perfectly usable though.

So I think that was grand-OPs point to a degree. If you can't always do companyname@mydomain.com there is a change you will forget what you used: Example:

aws vs amazon-web-services vs amazon.web.services

facebook vs fb vs fbook

Or for example I've used Rally the project management tool but my health insurance uses a (terrible) "rewards" program called "werally" but it's ALWAYS referred to "rally". It can get unmanageable.

Now I use 1Password to track all of this stuff which works well so I think there are solution but I do understand the grand-OPs point.

Re: Amazon's customer service backdoor

#327
I think the best solution, for now, is to just regularly check your full credit report for anything you don't recognize and watch your credit card, debit card statements for any purchases you don't recognize.

I've had credit cards get compromised in the past, and it was actually quite painless to have my bank (Chase) shut the card down and issue a new one.

Your information can be stolen from SO MANY sources and not just Amazon customer service. It's impossible to guarantee who sees any of your personal information once you share it with ANYONE on the internet (Amazon, Google, some random retailer, domain registrar, etc.).

The server at your local Applebees could steal your CC info.

Be sensible with where you share personal information, but don't be unreasonable. It's safe to use Amazon.

Just watch your credit report (regardless of whether you feel you're at high risk) and bank statements.

If/when a problem arises, then deal with it.

Re: Amazon's customer service backdoor

#328
post #66

Earlier quoted context omitted.

Which only proves your comment's parent's point even more. {SWAT, pizza orders, etc} assume that the phone number that shows up on caller ID is authentication of the identity of the phone line on the other end. They could call back the number on caller ID to verify the original caller matched the person who picked up, but they don't. Having knowledge of a Social Security number was assumed to be authentication, but i…

Keep in mind too that Caller ID is trivially blockable (and blocked caller id isn't remarkable enough to be super suspicious), and it's also easily within the capability of many of the 4chan/gg griefers to spoof "correct" Caller ID numbers as well.

Caller ID shouldn't be blockable, these days. It's a big ridiculous problem that we've defaulted to "you can intrude with communications anonymously" - and phone calls are definitely intrusive.

I'm pretty much a hair away from blocking all calls without caller ID at my house so I can reliably lock out the remaining spam callers.

Post reply on HN