Live data from Hacker News

Amazon admits it exposed customer email addresses, but refuses to give details

techcrunch.com

41–50 of 160 posts

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#41
post #9
post #6

Earlier quoted context omitted.

They intentionally provide this information to marketplace sellers. It's arguably poor design but it's definitely not an unintentional security flaw. Marketplace/FBA sellers have talked about strategies for utilizing customer email address for years [1] [1] https://sellercentral.amazon.com/forums/t/how-to-access-all-...

Also, your Amazon profile is public by default, especially any wishlists.

This is incredibly creepy. A few months ago I realized this and was able to find some friend's profiles and see their reviews. I hate implicit sharing/suggested friends/etc in services especially non-social services. For instance, my friend is following me on a tech shopping site I use... something I have 0 interest in. I've started attaching pseudo anonymous sites to a backup email address for this reason. If I want to friend someone I'll find them.

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#42
post #28

Earlier quoted context omitted.

> any online retailer has to be trusted Well that is down right crazy. Most sellers are people in their garages drop shipping 3PL. I'd trust them if they were background checked....maybe

The internet is based on trust. There is nothing stopping anyone that has an e-commerce website from recording a clear version of your passwords along with all of your billing address and credit card informations. There's no audits or anything.

I agree, the scale of amazon makes it nearly impossible for any type of remediation or penalty if its abused. It would hurt the consumers life far worse than anything Amazon would be interested in looking into. Identify theft for someone shopping to save the most money to help make ends meet might ruin their life, whereas the loss of business/revenue/profit by either the seller or buyer to Amazon is laughable.

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#43
An email address isn't secret, is it? It's sent back and forth in clear text through any number of relay servers. I consider my name and email address to be basically public information. Along with (unfortunately) my Social Security number.

If Amazon exposed any data fields more sensitive than email address, I would call that stonewalling/covering up as TC seems to be implying. But otherwise it kind of just sounds like TC being all petulant that Amazon wouldn't tell it everything it wanted to know. And the motivation there is likely to be the generation of clicks, not the protection of customers.

Take the "number of users affected" for example. Knowing that info doesn't help any individual customer. But it does help journalists drum up pageviews, or at least I feel like they believe it does. Having a big number in there is like this (dubious) Holy Grail of page-irresistability. I'm just judging from how, for example, the reporters on the TV news always bug their eyes out and raise their voice and talk really slowly and emphatically any time they come to a number. "The pool was reported to be FOURTEEN FEET DEEP..." "The petition has THIRTY THOUSAND signatures..." Wow! A number! I'm supposed to be all impressed I guess! ZOMG let me throw all my money at you right now!!!!

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#44
post #12

When I started selling the first gadget I ever made on Amazon I was so excited and was only getting a couple sales a month. If you were one of my customers I looked at your house, judged your grass, found you on LinkedIn and Facebook, Instagram, mortgages, mugshots, everything lol. The sellers also get your full name and address even on fulfilled by Amazon. If you have been on the net long enough this will creep you…

I also noticed complete customer data access selling a bike part I had CAMd in China last year.

I realized an attack method where:

1. Find an unusual but generic product used by niche group such as a particilar adult toy.

2. Order product and sell in using existing amazon SKU (very common) at below market price point.

3. You now have difficult to procure personal data on a very specific customer segment, paid for in lost margins on the product.

Reminds me somewhat of the old days of Facebooks demographic targeting to get page likes. You could build interesting lists indirectly on the cheap.

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#45
post #43

An email address isn't secret, is it? It's sent back and forth in clear text through any number of relay servers. I consider my name and email address to be basically public information. Along with (unfortunately) my Social Security number. If Amazon exposed any data fields more sensitive than email address, I would call that stonewalling/covering up as TC seems to be implying. But otherwise it kind of just sounds li…

Amazon employee here, but the statement I'm making is of my own.

Internally we treat customer names and email addresses as the second highest data classification. The highest one is credit card/financial/password data.

What does it mean? It means that there are a bunch of requirements that a software team must fulfill and pass (reviewed by an SDE trained in the process outside the team). This makes accessing this sort of data a PITA for a lot of people, and I can see why they why they would send out notifications when a breach like this happen. Amazon takes security very seriously, and it in fact creates quite a bit of friction to many engineers. However, I'd rather than than the break things and ask for forgiveness model like some other companies (not going to name names here)

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#46

I don't understand this. In the American startup I'm working we're extremely careful with respectful data practices due to ethics and GDPR (we have a lot European customers). Why doesn't Amazon give a shit about GDPR? Do they have a leverage?

> Why doesn't Amazon give a shit about GDPR?

I would assume perceived toothlessness. A better question is why should they? Or else what? Is that "what" absorbable by them to not eagerly spend a bunch of money and be shown to kowtow to governments making very large internet laws? Can they just pay it some lip service for now like their peers?

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#48

Hmm... it seems this drip of bad news in big tech is setting up for some heated debates on regulation. It will be interesting how proactive the Europeans are with GDPR.

"Goal accomplished"

- traditional media and anti-big-web-tech

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#49
post #16

Earlier quoted context omitted.

It sounds like they did that but TC wants more. I'm not really sure why HN allows techcrunch stories on the front page. TC is tabloid journalism at its finest.

They did not disclose any of the following as specified by the data breach notification requirements of the GDPR: The name and contact details of the data protection officer or other contact point where more information can be obtained The likely consequences of the personal data breach The measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, meas…

They probably aren't obliged to speak to TechCrunh or any of the media about it, though.

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#50
post #2

This is one of the less appreciated clauses of the GDPR: That companies are required to disclose data breaches within a reasonable time-frame, and users have the right to know about any exposure of their data.

> This is one of the less appreciated clauses of the GDPR

One wonders if this clause should have instead been its own, separate, narrowly focused legislation and enforced specifically as such.

Post reply on HN