Live data from Hacker News

Still locked out of my AWS account

docs.google.com

81–90 of 283 posts

Re: Still locked out of my AWS account

#81

Also having problem with AWS - can't access it and they keep billing me for something there I want to shut it down (EC2?) but I can't. I recently moved from Brazil to UK (new address) and changed phone + sim card (Authenticator after restore from backup lost all 2 factor auth entries). This is the moment when you realise that you're outside of predefined use cases of The Machine and you're fucked. Nobody is here to h…

I had 2FA activated, changed phones and lost it. I couldn't log in to my account, so I contacted support. Within about 30 min they had put me back into my account.

The dude who helped me was super chill and understanding as well.

Re: Still locked out of my AWS account

#82

Earlier quoted context omitted.

I look forward to your blog post on how to run a datacenter without power, internet connections, etc.

Companies used to have their own servers all the time before "cloud computing" became a thing.

GP's point is that those places still relied on power and networking from other places.

It's a counter to the broader point of not relying on others. You simply can't. Are there better ways to rely on others (e.g. specific contracts)? yes. Are there ways of not relying on single providers? yes. Are there ways of relying on no one? No.

Re: Still locked out of my AWS account

#84

Earlier quoted context omitted.

Because if you lose that single sign-on account, you lose everything attached to it as well.

Amazon offers many services, of course they are going to want users to have one set of credentials to access all those services. There are trade-offs to every security approach, but storing passwords at every web service is 100x worse.

What have passwords anything to do with this?

Re: Still locked out of my AWS account

#85
Expected from the earths most customer centric company. Here in India, my first order at Amazon was a fraud done by Amazon with its JV firm CloudTail. tl dr: Amazon Fulfilled product sold at fake discount and MRP mentioned on site was higher than printed MRP.

https://medium.com/@snaushads/my-first-order-at-amazon-in-5c...

Re: Still locked out of my AWS account

#86
post #56

Earlier quoted context omitted.

Doesn't this require separate gmail addresses? If so, then that's an extremely bad idea. I already had one gmail account completely banned with no notice. I wasn't doing anything abusive -- I used it for some npm projects and a github account. Actually, is there a reasonable free gmail alternative for situations like this? I'd like to migrate. FastMail is worth paying for, but it's too expensive for one-off side proj…

One trick I like is that you can use `account+ @example.com` and a lot of services will consider it a separate e-mail address, even though MTAs will transfer it to the same account; this has the added benefit of being easy to filter for on your e-mail client. I also use this tactic when signing up for web services that I anticipate will spam me. (I import a lot of merch from China/Japan; their unsubscribe systems ten…

I used this trick for years. However, there are downsides.

For example, sometimes a service will let you sign up with this just fine, but later when you need to do something else (such as password reset) or a phone agent has to enter it... it chokes.

Not to mention after some time passes you may forget what the special bit was and have to fall back to searching your email. Being regimented about the naming system helps, but it's not foolproof.

I'm using this trick less and less nowadays and just entering my plain email to avoid these hassles... especially for things like real life accounts. For possibly shady characters and account email consolidation, still a great trick!

Re: Still locked out of my AWS account

#87

8 days ago I tried to log in to my Amazon retail account, and received a password invalid error. As it turned out my account had been closed, as it appeared to Amazon that it had received a suspicious log in. This is the same account that I use for AWS - hosting websites critical to my business. Today it appears I am no closer to gaining access back to my AWS account than I was on day 1, even though I have been bille…

> This should serve as a warning to anybody else who has an Amazon account that is shared between retail and AWS.

So much this.

I had such an account and neglected the retail side (it was linked to amazon.com as well as AWS) as I was using a different account for retail (linked to amazon.co.uk from the days that these were separate systems).

Logging on to amazon.com one day I noticed LastPass suggest I log in, so I did. To see that I hadn't ordered anything retail for 5+ years. So I requested deletion of the amazon.com account (good hygiene, delete unused accounts).

Retail happily obliged... and a week later when payment failed and dunning started I realised what I had done. The account did not exist any more, I could not login to resolve this.

This was entirely my mistake (and quite funny as well as terrifying), but the risk is real.

Should anything happen to your retail account then your AWS account can and will suffer.

I managed to resolve this, I was only using S3 and I wrote a migration tool to remotely move S3 items from one account to another, using only the auth keys that were still active. But woah... if I'd been using EC2 or anything else I would have been in a lot of trouble.

Keep accounts single purpose and obvious. Use an account that only handles your AWS purchases.

Re: Still locked out of my AWS account

#88
post #9

Might sound obvious in hindsight, but _always_ create separate AWS accounts for your different projects.

Doesn't this require separate gmail addresses? If so, then that's an extremely bad idea. I already had one gmail account completely banned with no notice. I wasn't doing anything abusive -- I used it for some npm projects and a github account. Actually, is there a reasonable free gmail alternative for situations like this? I'd like to migrate. FastMail is worth paying for, but it's too expensive for one-off side proj…

> My point was, if you use a single account, it's far less likely to get banned

Why do you think that? If anything, you have more activity you can be banned for...

And also, why you say it like gmail is the only email provider? You need separate _email_ accounts, not gmail. It can be some other service or your own domain. Google can be service provider behind your own domain, but you will control address space etc. Nobody will ban you out of your own email address (except domain registrar, but that's unlikely).

Re: Still locked out of my AWS account

#89

Earlier quoted context omitted.

Doesn't this require separate gmail addresses? If so, then that's an extremely bad idea. I already had one gmail account completely banned with no notice. I wasn't doing anything abusive -- I used it for some npm projects and a github account. Actually, is there a reasonable free gmail alternative for situations like this? I'd like to migrate. FastMail is worth paying for, but it's too expensive for one-off side proj…

> Doesn't this require separate gmail addresses? It probably should, but I somehow ended up with two Amazon accounts (retail, not AWS) with the same email address. Changing the password I use changes which account I log in to. Presumably it's a bug, but it's certainly confusing.

I recently managed to do that as well. This becomes very interesting if you try to recover a password, because apparently the password recovery only recovers the last account.

Eventually I got out of that by changing the mail of whatever account I could log into, using gmails feature of ignoring everything between the first + and an @ in the address. But most annoying, now my aws login is something silly like me+awsConsole42@gmai1.com.

Maybe I could change that back, but I'm too scared to touch that.

Re: Still locked out of my AWS account

#90
post #9

Might sound obvious in hindsight, but _always_ create separate AWS accounts for your different projects.

Doesn't this require separate gmail addresses? If so, then that's an extremely bad idea. I already had one gmail account completely banned with no notice. I wasn't doing anything abusive -- I used it for some npm projects and a github account. Actually, is there a reasonable free gmail alternative for situations like this? I'd like to migrate. FastMail is worth paying for, but it's too expensive for one-off side proj…

Use aliases. It possible even in gmail. Or host your mailing and use aliases.
Post reply on HN