Live data from Hacker News

Request your personal information

amazon.com

81–89 of 89 posts

Re: Request your personal information

#81
post #22

I can't do this because amazon does not have my personal information. Amazon has a pseudonym with a dedicated Twilio number that delivers to a private postal box. I burn the pseudonym every few years. Which reminds me ... This is simple because VISA/MC do not validate cardholder name. Everyone thinks they do and most merchants believe that they do but ... they do not. You can use your card with "Mickey Mouse" and it…

Many do validate the address or at least postal code, however, although American Express doesn’t appear to in my experience. I assume it also depends on the issuer for Visa/Mastercard considering many have their own two-factor verification portal.

Note - AMEX does verify cardholder name. In my original comment I am referring only to VISA/MC. They do not verify cardholder name. They do, however, verify other things related to address, etc.

Re: Request your personal information

#82

Earlier quoted context omitted.

> If you're curious for more information about BankID they have a site: https://www.bankid.com/en/ I think it's owned as a collab between "all" Swedish banks. I'm not sure if it's the same technology as in Norwegian banks: https://link.springer.com/chapter/10.1007/978-3-540-85230-8_...

Paywalled paper from 2008 or am I missing something?

It turns out they are not the same thing[0], they just share the same name. The one you use in Sweden is different from the one in Norway that was cracked already in 2008 (and fixed somehow since then). I'm sure the one in Sweden will show its weaknesses sooner or later, all these systems do.

Actually, it looks like some scammers have already exploited it using a variant of the method I've already described above[1].

[0] https://en.wikipedia.org/wiki/Talk:BankID

[1] https://www.thelocal.se/20220117/foreign-citizens-in-sweden-...

Re: Request your personal information

#83
post #41

Earlier quoted context omitted.

Fun fact (from 2012): some credit cards had more than one CCV. You could find out by simply trying all 1000 combinations on some web shops. Back then, I did security consulting and we knew a shop or two where it was possible to enumerate the CCVs without submitting an order and without being blocked. Not sure if this is still valid nowadays, but it blew my mind as well.

Even better fun fact: There’s some issuers that won’t validate your CVV at all, so any of the 999 options work for those cards.

Wouldn't there be 1000 options?

Re: Request your personal information

#84
post #73

Earlier quoted context omitted.

Wow, that's bad. It seems obvious that something like Alexa would transmit some amount of data not intended for it and that would be listened to by someone for training purposes. And probably enough data that someone remotely privacy conscious would not voluntarily install some 24/7 listening device into their inner sanctum. But what on earth would posses Alexa to record entire conversations without either piping up…

I've switched off all voice-activated devices in my home. I'm not sure how long the longest recording was...I'll go back over the data to have a look, but the one that really broke my heart was about 20 seconds during which my mother in-law was upset because my father in-law was not waking up.

I'm sorry that you went through this. I think even a really short recording (under 20s), of a distraught, close person at some critical junction would feel very unsettling to me especially with the knowledge that it shouldn't really exist, I shouldn't be able to listen to it, and it probably was listened to by some complete strangers as well as part of some routine megacorp work.

Re: Request your personal information

#85

Earlier quoted context omitted.

Paywalled paper from 2008 or am I missing something?

It turns out they are not the same thing[0], they just share the same name. The one you use in Sweden is different from the one in Norway that was cracked already in 2008 (and fixed somehow since then). I'm sure the one in Sweden will show its weaknesses sooner or later, all these systems do. Actually, it looks like some scammers have already exploited it using a variant of the method I've already described above[1].…

Sorry, wrong link in [1]:

https://www.thelocal.se/20180813/millions-of-kronor-stolen-i...

Re: Request your personal information

#86

Earlier quoted context omitted.

Yes, but "having a human in the system" isn't answering the original question: what does Amazon benefit from introducing excess cost into this equation? Surely there should be nothing clandestine in your own usage data, search queries etc.

> Yes, but "having a human in the system" isn't answering the original question It does. There is a human manually running queries to copy your data into an Excel spreadsheet (or equivalent) then passing that onto the next part in the chain. This is done quite a few times and stalls the process. > what does Amazon benefit from introducing excess cost into this equation? It's cheaper to have the already existing emplo…

Thanks. I still find it surprising a company of Amazon's stature wouldn't have figured out how to fully automate something relatively trivial like this.

Re: Request your personal information

#87

Earlier quoted context omitted.

It turns out they are not the same thing[0], they just share the same name. The one you use in Sweden is different from the one in Norway that was cracked already in 2008 (and fixed somehow since then). I'm sure the one in Sweden will show its weaknesses sooner or later, all these systems do. Actually, it looks like some scammers have already exploited it using a variant of the method I've already described above[1].…

Sorry, wrong link in [1]: https://www.thelocal.se/20180813/millions-of-kronor-stolen-i...

Since then banks (at least my bank) has changed so that the Bank presents a QR code which I scan with the BankID app, meaning there's no "prewriting my social security number for a challenge".

Also, even if I authenticate someone to my bank account they're unable to transfer money out of my own accounts without me approving a transaction, where the BankID app will show me the amount and the destination for the money.

So this issue is mostly solved as we move towards the QR code thing and people stop giving their money away. It's impossible to fix layer 8, if someone "willfully" gives their money away it's their fault when the UX is as good at preventing this as it actually is.

Someone could be tricked into giving their money away in person or by other means, look at Theranos, Nikola (I would argue anything Elon Musk touches too) and the likes. They're also scammers. I didn't invest in Theranos or Nikola because i called bullshit directly, same same but different. My colleague tried to get me in on "Onecoin", he walked away with a loss and I didn't because I called the bluff straight away.

What I'm trying to say is, the system isn't insecure at all. There are many failsafes people have to ignore to get scammed.

Re: Request your personal information

#88
post #8

interesting how the request takes about a month to process.. it's almost... almost like... they dont really wanna do it but have to

I built a system just like this at another company whose products or services you likely use often or everyday. This pessimistic view assumes the worst about people like me who build these kinds of systems, as if we’re evil or corrupt or somehow doing this to take something from you. In reality, data is stored in disparate systems, under the custodianship of different organizations. Once you can find everything and a…

For some reason this is not an issue when it's about personalizing ads...

Re: Request your personal information

#89
post #81

Earlier quoted context omitted.

Many do validate the address or at least postal code, however, although American Express doesn’t appear to in my experience. I assume it also depends on the issuer for Visa/Mastercard considering many have their own two-factor verification portal.

Note - AMEX does verify cardholder name. In my original comment I am referring only to VISA/MC. They do not verify cardholder name. They do, however, verify other things related to address, etc.

Even for Visa/Mastercard, this seems to depend on the issuer to some extent. Issuing banks often handle two-factor fraud portals (Verified by Visa, etc.) differently, and these portals are increasingly common especially in much of Europe and other regions. As you noted, American Express typically seems to depend on the name but not the address.
Post reply on HN