Whois is great for social engineering attackers. You get a name, email, address, and the first service to attack. Meanwhile, the ICANN is working around the clock to make it illegal for us to protect our personal information, and whois protection is becoming an increasingly niche service for registrars. For example, gandi.net (and thus Amazon) doesn't hide your name when you have it turned on. By the time you find th…
> For example, gandi.net (and thus Amazon) Why do you say here and thus Amazon?
Amazon's customer service backdoor
61–70 of 366 posts
Re: Amazon's customer service backdoor
#62Whois is great for social engineering attackers. You get a name, email, address, and the first service to attack. Meanwhile, the ICANN is working around the clock to make it illegal for us to protect our personal information, and whois protection is becoming an increasingly niche service for registrars. For example, gandi.net (and thus Amazon) doesn't hide your name when you have it turned on. By the time you find th…
> By the time you find this out, it might occur to you to just type in a different name, but now you're violating ICANN policy. Why not just "sell"/transfer ownership of your domain to another entity (one that you own)?
a) A valid email address. (A gmail that forwards to your real email will do).
b) A valid postal address. By valid I mean "in the proper form".
As such the following would get flagged:
1 Main St. Anytown USA 10016
(because it doesn't exist..)
545 Jones St. New York NY 10016
(let's say that's a post office..)
is fine.
Re: Amazon's customer service backdoor
#63On your Amazon home page, go to: Your Account › Change Account Settings › Advanced Security Settings Turn on 2-step Verification. It won't completely solve social engineering, but it can't hurt.
If you had read the article you would know that they already had 2F turned on before the first intrusion and throughout the subsequent intrusions.
"As a security conscious user who follows the best practices like: using unique passwords, 2FA, only using a secure computer and being able to spot phishing attacks from a mile away, I would have thought my accounts and details would be be pretty safe? Wrong."
Are you sure the author enabled 2FA on his Amazon retail account, or was it only enabled on his AWS account? The two systems do not share the same 2FA.
FYI I enabled 2FA on my Amazon retail account and when I called customer support they verified it. Once the verification failed and they refused to give me support.
Anyone else confirm a similar story with 2FA and support? Anyone willing to explicitly test this out?
Re: Amazon's customer service backdoor
#64Earlier quoted context omitted.
I would prefer that my bank, if it detects fraudsters trying to pull some sort of trick involving my account, to freeze things until I show up and present ID. That's inconvenient, but clearly better than the alternative.
So... what about banks with no actual physical branches?
Re: Amazon's customer service backdoor
#65How to stop this: 1. Get a friend's permission to "hack" into his Amazon account (or "hack your own account"). 2. Contact Amazon's customer service, try the same social engineering techniques that the OP documented. 3. Once you obtain some sensitive information from the account, scare the CS rep by saying: "Haha! I am actually not the customer. I am a journalist/hacker/whatever and wanted to see how easy it was to so…
Bad idea.
Re: Amazon's customer service backdoor
#66Earlier quoted context omitted.
If someone has your public name and address you're already at significant risk if you ever say anything controversial that gets attention. You're liable to being swatted, getting fake pizza orders, having people show up at your house, harassing you and much more. See Zoe Quinn, Brian Krebs, lots of less well known individuals, etc.
Which only proves your comment's parent's point even more. {SWAT, pizza orders, etc} assume that the phone number that shows up on caller ID is authentication of the identity of the phone line on the other end. They could call back the number on caller ID to verify the original caller matched the person who picked up, but they don't. Having knowledge of a Social Security number was assumed to be authentication, but i…
Re: Amazon's customer service backdoor
#67Earlier quoted context omitted.
Note, though, that catch-all emails will also catch a ridiculous amount of spam. Creating each account name individually avoids that problem, at the cost of some extra trouble when registering a new service. An intermediate step that may work if you don't expect people to target you individually: have one or more required substrings for the email local part, and catch all mail to addresses containing that substring.
I receive all mails @ my domain and I get about 1 spam a day. Fastmail's spam filters are pretty good.
Re: Amazon's customer service backdoor
#68Earlier quoted context omitted.
While that's true, and perhaps even needs to be "the default", there really needs to be a way to say "Hey, I'm concerned, and am prepared to take responsibility for my own access credentials. I demand you categorically _do not_ disclose any of my personal information to anyone without a warrant or court order." And for that sort of demand to have appropriate legal teeth to ensure people collecting that data are suffi…
Unfortunately, far more people think they want that than can take full personal responsibility for it. See also: people who don't understand that full-disk encryption means they lose their data if they forget their passphrase. That doesn't make full-disk encryption in any way bad, but if you train people to think that all accounts have a "forgotten password" option, they might get a nasty surprise.
Re: Amazon's customer service backdoor
#69How to stop this: 1. Get a friend's permission to "hack" into his Amazon account (or "hack your own account"). 2. Contact Amazon's customer service, try the same social engineering techniques that the OP documented. 3. Once you obtain some sensitive information from the account, scare the CS rep by saying: "Haha! I am actually not the customer. I am a journalist/hacker/whatever and wanted to see how easy it was to so…
So, commit criminal fraud to prove a point? Bad idea.
Re: Amazon's customer service backdoor
#70If you own a home in the U.S., anybody already can get your address legally and easily from your county or district property appraiser's/assessor's website. Along with how much you paid for it, and when you bought it. So calling Amazon CS rep is a hard way to go about it. :)