Live data from Hacker News

Amazon's customer service backdoor

medium.com

331–340 of 366 posts

Re: Amazon's customer service backdoor

#331
post #173
post #112

Earlier quoted context omitted.

Last I checked pairNIC was > $15/year for .com etc. That adds up when you have many domains. Therefore I use pairNIC for the domains I really care about, and Namecheap for the rest.

it seems they are down to $9.99/year: https://www.pairnic.com/prices.html

Wow! No excuses now. With pairNIC you can call up and talk to a technical person during business hours in Pittsburgh, PA.

Re: Amazon's customer service backdoor

#332
post #66

Earlier quoted context omitted.

Keep in mind too that Caller ID is trivially blockable (and blocked caller id isn't remarkable enough to be super suspicious), and it's also easily within the capability of many of the 4chan/gg griefers to spoof "correct" Caller ID numbers as well.

By "gg" you mean what? Gamer gate?

I assume so. The "gamergate are women-hating harassers" misconception is still alive and well.

Re: Amazon's customer service backdoor

#333

Earlier quoted context omitted.

In the UK this and a lot more is public information. As an example of what is available about me online (without paying a penny) just by searching for my name: - The year I was born - The district I was born (not the exact town, although that wouldn't be hard to guess) - My mother's maiden name (which is what most banks et al ask as a security question...) - The areas I've lived (based upon the electoral register, wh…

>TL;DR; If you rely on this to 'identify' someone, you are doing it wrong. Which is why the system is set up so that if I go to the bank with this information and take money as you, I have stolen your identity and thus you are the victim and are responsible for the losses unless you fight back. Identity theft was created so financial institutions could be lax with their verification process thanks to the blame being…

...that's not what identify theft is. It doesn't have to involve stealing from banks, it just happens to be a popular use of it.

It definitely wasn't just "created" either. Pretending to be someone else to gain the benefits of their identity/reputation/privilege has always been around.

Re: Amazon's customer service backdoor

#334
post #303

Earlier quoted context omitted.

Could you tell how knowing IBAN enables someone to take money from your account? As far as I understand, the only think that can happen with IBAN is to receive money. Maybe you're thinking of credit card number? The CC's I had had different CC number and IBAN account.

SEPA direct debit allows you to pull money via IBAN (+ BIC, depending on the countries involved in the transaction). Specifics vary from country to country. Some require active approval from the customer (IIRC France, probably more), others "just work". Fraud is not as common, since bank accounts that are allowed to debit money this way are generally only available to companies who have to sign paperwork ensuring tha…

Germany just works.

Re: Amazon's customer service backdoor

#335

As someone who has trained customer support agents, I can attest to the fact that most agents have to be taught every scenario. If it slightly deviates from the one they have been trained on, they are clueless. Not saying all customer support people are like this. However, majority of people are. They rely on pre-written scripts. When a question is asked, they search for the template question with the answer.

You're absolutely right about the majority. If someone is capable enough to understand customer needs and resolve issues outside of predefined scripts they are capable enough to be working beyond customer support. Customer support representatives are largely people who exist as an interface between a customer who doesn't understand a system and a system that doesn't understand the customer needs. Most companies would…

I think you substantially over-estimate the number of tickets which can actually be 'solved' like this, and dramatically under-estimate the cost it would take to solve the problem. I'd have a hard time believing that the large number of companies who all operate this model are getting the cost-benefit analysis wrong by such a large margin as you seem to suggest.

Re: Amazon's customer service backdoor

#336

Same sh#t happens with Apple Support all the time, for few years in a row. Someone was after my last 4 digits, requesting password resets to Apple ID, like 14 times a day, and then impersonating me, talking to support.

Did you activate 2FA?

After that I did. And I was so much surprised, Apple delays 2FA activation for a week! 'to be sure that you are you'

Re: Amazon's customer service backdoor

#337
post #322
post #83

Earlier quoted context omitted.

Also a lot of systems strip anything after the + now, especially spam systems.

I've even started seeing registration systems that tell me that I've entered an invalid address if I do the [email]+[something]@gmail.com trick. Twice now I was only able to register after removing the +[something] part of the email. Is + actually an invalid email character (according to RFCs etc?). I couldn't find any reference to that when I looked.

I'll try to avoid ranting here, but anything is a legal email address per the RFC (even an @ sign in a username, or an email address without any @ sign).

RFC 821 is the original and 2821 summarizes it plus the few that came after to add and clarify.

The only true "RFC email validity check" is to send an email to whatever address they provide.

Re: Amazon's customer service backdoor

#338
post #292

Earlier quoted context omitted.

Another ex-happy Namecheap customer here. Was going through credit card fraud issues back in July. In September out of nowhere get an email from Namecheap support that my July payment for one of the domains did not go through and I owe them $240 for the chargeback. No amount of reasoning got through to them - this is after several years of owning multiple domains with them. Dropped the penalty by $100, but that didn'…

Hey romanhn - did you contact support and try to make it right by reversing the chargeback? This isn't about blackmail as jewsin writes in the comments, it's about the reputation a business suffers with a chargeback. All you would need to do is reverse the chargeback and the full charge would go away. Disclosure: I work for Namecheap.

Hi tamar - thanks for reaching out! I was in contact with multiple members of the support team throughout this ordeal. Supposedly they consulted with senior management as well. Business reputation was never mentioned - it was always about paying a fee to the payment processor. At no point was chargeback reversal brought up. To be perfectly honest, I know nothing about chargebacks (this wasn't something I initiated, it was fraud-related) and the idea of a reversal never popped into my head. I may try to bring this up with them again, but I'm not sure how much I can do half a year after the fraud occurrence.

Still, I think my original points stand. I find Namecheap locking out unrelated domains and redirecting traffic unethical and in bad faith of the service provider / customer relationship. Not to mention that the domains continued to point to parking pages even after I paid up.

Re: Amazon's customer service backdoor

#339

Earlier quoted context omitted.

Do you mind sharing where you switched to?

Name.com has been legit for me for about 10 years. Use code PRIVACYPLEASE for free whois privacy (this code has worked for the past ~5 years). I've also used IWantMyName for some TLDs that name.com didn't have and I liked that they had 2FA, but overall it was much less polished.

[deleted]

Re: Amazon's customer service backdoor

#340

Earlier quoted context omitted.

Ah... if you're a resident of Sweden, anybody can get your full name, address, date of birth, civil status, list of company engagements (e.g., board member, owner of a firm, etc.) and the make and year of any cars registered by going to one of several websites - http://www.ratsit.se/ being one of the most popular ones. No login needed. This information is public data straight from the government. (Exceptions: people…

I believe that such openness from the govnerment is actually helping you implement a more sound security procedure. If all of that information is well known to be publicly available, there is much more awareness that it is unless as authorisation.

Having someone's personal identity nummer (personnummer) is in itself enough to do a lot of damage.

Many Swedish online shops will happily send you goods along with an invoice that you pay later. The invoice option is often only available if you provide your personnummer - which as I mentioned is public information, a phone call away - and have the goods sent to the address tied to that number. If you live in a house with a mailbox outdoors, a thief could order stuff to your address and empty the mailbox before you. "Stuff" could also be things like mobile phone subscriptions and whatnot.

Or, having your personnummer, someone could send a form to the tax agency to have your official address changed! I believe they do send a letter to the old address saying the address has been changed to . But there's time to do bad stuff in between the time of the change and your discovery of it. (If, indeed, you do discover it. You might be traveling somewhere, a fact that might've been gleaned from your social media activity.)

And, as breakingcups points out above, even if it were the case that sound security procedures were implemented in Sweden, that wouldn't matter much for the numerous non-Swedish services most Swedes use every day.

Anyway -- people being able to do stuff in your name is just one thing. I don't want the whole world to know my address, or marital status, or date of birth, etc - period. It's about privacy.

Post reply on HN