Live data from Hacker News

Amazon admits it exposed customer email addresses, but refuses to give details

techcrunch.com

71–80 of 160 posts

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#71
post #43

An email address isn't secret, is it? It's sent back and forth in clear text through any number of relay servers. I consider my name and email address to be basically public information. Along with (unfortunately) my Social Security number. If Amazon exposed any data fields more sensitive than email address, I would call that stonewalling/covering up as TC seems to be implying. But otherwise it kind of just sounds li…

What's your email address?

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#72
post #43

An email address isn't secret, is it? It's sent back and forth in clear text through any number of relay servers. I consider my name and email address to be basically public information. Along with (unfortunately) my Social Security number. If Amazon exposed any data fields more sensitive than email address, I would call that stonewalling/covering up as TC seems to be implying. But otherwise it kind of just sounds li…

What's your email address?

..and name and Social Security number?

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#73
post #43

An email address isn't secret, is it? It's sent back and forth in clear text through any number of relay servers. I consider my name and email address to be basically public information. Along with (unfortunately) my Social Security number. If Amazon exposed any data fields more sensitive than email address, I would call that stonewalling/covering up as TC seems to be implying. But otherwise it kind of just sounds li…

Amazon employee here, but the statement I'm making is of my own. Internally we treat customer names and email addresses as the second highest data classification. The highest one is credit card/financial/password data. What does it mean? It means that there are a bunch of requirements that a software team must fulfill and pass (reviewed by an SDE trained in the process outside the team). This makes accessing this sor…

I can confirm that names and email addresses are classified as saltysugar states, and the security reviews. So they do have to pass all those requirements for secure storage and transmission, but then names and emails are made visible by default through mechanisms like reviews, profile, wishlists, and that passes the review because it is the user's choice.

I don't even think this is anything nefarious by Amazon. It's more that teams dedicated to security issues consider it out of their lane to deal with conflicts between the designed UX and actual user expectations; especially for privacy issues where even asking the person isn't a reliable way to understand what they want.

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#74
post #70

Earlier quoted context omitted.

This is irrelevant as long as they have customers whose rights are protected by GDPR.

i am mistaken. But the idea is , if they were not based in europe , which country's DPA is going to go after them? Where will the money be paid?

But they have european entities (AWS, fulfilment centres, etc).

If they don't choose to put themselves somewhere, everyone may go after them separately.

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#75

based on spam email i have received, that i clearly should not have, i believe this was an exposure to marketplace sellers from whom you have bought a product. I am very careful with my email. i’m not just guessing here. i actually reported it to amazon security. (no answer from them of course.)

eBay are particularly careless in that regard. There's no reason that a seller should ever see the customer's actual e-mail address on such a site but I'm up to ebay5@ on my mail server due to direct spam from sellers from whom I bought one item in the past. No, sellers, I did not 'opt in' to your spam just because I bought something. But why does eBay ever give them the address? Oddly I've never had a problem with r…

I have a different point of view as a longtime eBay user on both the buying and selling side. The more the company acted to "re-intermediate" buyer-seller interaction by doing things like restricting auction content, channeling communication through their own messaging system, concealing identities in feedback to prevent buyers and sellers from doing reasonable due diligence on each other, prohibiting various payment methods in order to shove PayPal down everyone's throats, and so on, the less interested I became in using eBay in general.

There was a strong sense of community on eBay in the company's early years that gradually went away over the years, and I still miss it. eBay is now dominated by medium-to-high volume corporate sellers, and that was not how it was originally supposed to work.

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#76
post #43

An email address isn't secret, is it? It's sent back and forth in clear text through any number of relay servers. I consider my name and email address to be basically public information. Along with (unfortunately) my Social Security number. If Amazon exposed any data fields more sensitive than email address, I would call that stonewalling/covering up as TC seems to be implying. But otherwise it kind of just sounds li…

I notice you don't have your email address in your HN profile.

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#77
post #12

When I started selling the first gadget I ever made on Amazon I was so excited and was only getting a couple sales a month. If you were one of my customers I looked at your house, judged your grass, found you on LinkedIn and Facebook, Instagram, mortgages, mugshots, everything lol. The sellers also get your full name and address even on fulfilled by Amazon. If you have been on the net long enough this will creep you…

You only get shipping address, not billing address, right? I have always got my Amazon stuff shipped to a work office address, so hopefully have kept the residential (billing) address from sketchy sellers! heh

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#78
post #62

This is how it looked for me: I few days ago I was shopping on Amazon and they showed me a message, you already purchased this product. See order details. I was surprised since I did not buy it before. After clicking the link, I was shown details of not my order, including name, address and email where a product was shipped to.

Maybe someone released a pretty aggressive page cache to help handle "Black Friday" shopping.

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#79

Earlier quoted context omitted.

Any particular reason? Seems like a reasonable thing for the GDPR to have.

Same reason you might do a gradual refractor instead of a large software rewrite. The more narrowly scoped a piece of legislation, the more feedback and implementation/enforcement can be tailored to the satisfaction of all before increasing scope (or not if ineffective). In the GDPR's case, it superseded existing data protection legislation because of a somewhat opposite mindset: the scope/consequences/enforcement we…

Writing laws is like writing software in every way except:

1. You have hundreds of code reviewers, many of whom will have their own motivations

2. The code base is hundreds of years old, poorly maintained and often contradictory in its goals.

3. You have hundreds of millions users.

Re: Amazon admits it exposed customer email addresses, but refuses to give details

#80
post #74
post #70

Earlier quoted context omitted.

i am mistaken. But the idea is , if they were not based in europe , which country's DPA is going to go after them? Where will the money be paid?

But they have european entities (AWS, fulfilment centres, etc). If they don't choose to put themselves somewhere, everyone may go after them separately.

... and then they can negotiate with the country that gives them the smallest punishment. (under gdpr only one will go after them at a time).
Post reply on HN