Live data from Hacker News

Amazon's customer service backdoor

medium.com

361–366 of 366 posts

Re: Amazon's customer service backdoor

#361
post #67

Earlier quoted context omitted.

I receive all mails @ my domain and I get about 1 spam a day. Fastmail's spam filters are pretty good.

Do you have a good idea of the rate of false positives?

No, I don't check my spam folder. Never had any reason to do so in the last couple of years.

Re: Amazon's customer service backdoor

#362
post #20
post #17

Whois is great for social engineering attackers. You get a name, email, address, and the first service to attack. Meanwhile, the ICANN is working around the clock to make it illegal for us to protect our personal information, and whois protection is becoming an increasingly niche service for registrars. For example, gandi.net (and thus Amazon) doesn't hide your name when you have it turned on. By the time you find th…

I think the bigger problem is that public information like your name and address is sufficient for proving your identity. If we make whois information private, what about phone books, property records, direct mail databases, etc. etc.

It's not just about proving who is who, it can also be about wanting to distance yourself from random people and their nonsense problems.

Re: Amazon's customer service backdoor

#363

Earlier quoted context omitted.

While I would love to do that it just isn't feasible for me and probably most others. ICANN really needs to provide better controls to avoid resorting to such workarounds.

> ICANN really needs to provide better controls to avoid resorting to such workarounds. Not only ICANN but the whole financial world. Shell corporations provide no real use other than hiding money and ownership.

They also sell gasoline.

Re: Amazon's customer service backdoor

#364
post #94
post #7

Any recommendation what one (as a customer of Amazon) can do today ? 2FA does not help here as someone goes through support channel which looks like bypasses 2FA Also concerned if the same trick can be applied to Amazon Cloud services, as there one can also run up a big bill pretty quickly.

If I were the OP or someone equally sure I was likely to be targeted via my Amazon account, I'd consider: Using a unique email address. Using a unique physical address (both for my account details and for my delivery addresses). Use a unique credit card (I'd probably get a refillable prepaid gift card, and set up some auto topup to ensure it's got my expected monthly Amazon bill available as "credit", but not much mo…

It seems to me that ANYONE who buys ANYTHING is equally likely to be targeted via their Amazon account -

Think about how many people actually use Amazon services

Through sheer competition, Amazon is forcing Walmart to close over 100 stores. We only know that because Walmart is big enough to get noticed.

Remember when Walmart was the company putting local mom and pop shops out of business?

Cycle of life I suppose...

Re: Amazon's customer service backdoor

#365
post #17

Whois is great for social engineering attackers. You get a name, email, address, and the first service to attack. Meanwhile, the ICANN is working around the clock to make it illegal for us to protect our personal information, and whois protection is becoming an increasingly niche service for registrars. For example, gandi.net (and thus Amazon) doesn't hide your name when you have it turned on. By the time you find th…

It's not just whois. Our personal info is out there everywhere. Say, you're a developer who signs his OSS software tool with a certificate that comes with your home address...

Re: Amazon's customer service backdoor

#366
post #46

Earlier quoted context omitted.

Fastmail and Gmail support a local suffix of the form yourname+amazon@gmail.com. That's a plus character between the local name and local suffix. If you use a password manager, you can replace a predictable suffix like "amazon" with random hex value. Unfortunately, many sites borked their e-mail address validation and do not accept the plus character. (Amazon permits it.) Also, you'll ocassionally find a customer ser…

Gmail also allows yourname.amazon@gmail.com

It ceartainly does not allow yourname.amazon@gmail.com if you don't own yournameamazon@gmail.com. You can do suffix with + and random . but not suffix with .
Post reply on HN