Amazon's customer service backdoor
medium.com
medium.com
Meanwhile, the ICANN is working around the clock to make it illegal for us to protect our personal information, and whois protection is becoming an increasingly niche service for registrars.
For example, gandi.net (and thus Amazon) doesn't hide your name when you have it turned on. By the time you find this out, it might occur to you to just type in a different name, but now you're violating ICANN policy. And it's already been scraped by any of those whois history websites.
{SWAT, pizza orders, etc} assume that the phone number that shows up on caller ID is authentication of the identity of the phone line on the other end. They could call back the number on caller ID to verify the original caller matched the person who picked up, but they don't.
Having knowledge of a Social Security number was assumed to be authentication, but it's increasingly obvious that such an authentication scheme is antiquated and was destined to fail from the beginning. When an identity thief can get a mortgage under my name with little more than credit bureau data on me, it costs only a little more than $15 to destroy my credit, my time, and my future because transactions don't have sufficient authentication.
These awfully designed authentication schemes will only magnify the problems as more companies (especially credit bureaus and data marketers) pass around data on me and make it easier for someone to buy it on demand.
I'm pretty much a hair away from blocking all calls without caller ID at my house so I can reliably lock out the remaining spam callers.
No the people that designed and implemented Social Security knew it was not secure for identification purposes, the first few decades of the program even had "Not to be used for Identification" on the card.
Then the government, and financial industry got lazy and said "well since the majority of people already have these numbers assigned to them lets just use them for Identification as well" and made it a defacto National ID. Something it was never designed for, nor secure enough to be,
This is getting to the point of paranoia at this point. You're already at significant risk if you ever say anything that gets attention by virtue of living in a society. But it comes with benefits, too...
It does make good sense to not use your primary "personal" email address in whois, nor your home address. PO Box rentals are fairly cheap and that's what I use for whois registrations.
Where I am (Australia) theres a whole bunch of places that'll provide "non Post Office PO boxes" who're perfectly happy for you to address things to "Suite 306" or "Apartment 306" as well as "PO Box 306" at whatever address the box is located. Fools _most_ of the "must be a real address, not a PO Box" restrictions.
(Interestingly StartSSL failed me on that once when I gave one of those as a personal address - they mailed me saying "that looks like a business address, we need a personal home address for personal identity validation") - I dunno of they Google Street-viewed it or of they've got some automated system that flagged it...)
1) it's free, and
2) they will also accept UPS/FedEx/DHL/etc shipments on your behalf for no charge! (they will sign for packages, but if "Direct" signature (the named recipient) is required, they can't accept those.)
If you just try using "UNIT #" or "APT #" or whatever, or you don't have this additional agreement signed, they can and will return to sender.
Keep in mind that street addressing doesn't work at all USPS locations, although it does work at most of them. You have to fill out a form with USPS or any mail addressed to that location will be returned as undeliverable.
I wish this was an industry with a bit more visibility. When you think about renting a "PO Box", there's a good chance that you'd be better off with a box rental from a private mail service.
His daughter was also attacked...
Now, when you register a domain it tells you free Whoisguard is included, but it doesn't make it clear that it's disabled by default."
Previously it just worked. Now you have to check another box to turn it on.
This change makes no sense to me. (If you want free Whoisguard, why would you not want it turned on?)
I was white-hot furious* when I discovered that a handful of new domain regs had leaked my contact details, and I began getting the inevitable spam calls and texts.
I switched to Namecheap based on recommendations here, and their previous stance on certain privacy issues, but I'm running out of alternatives.
I have used them since they opened (2002) and never used anybody else after that, because I have never been dissatisfied. (I don't remember if the box is checked by default, but they definitely offer whois privacy, along with services like custom/dynamic DNS and some other stuff, at no extra charge).
Their site is kinda barebones and old-school, but there are real humans in the rare case you actually need one, and they've never done me wrong.
So for whatever that's worth: another recommendation on HN.
Example weird feature: all domains are shown, even ones that you've let expire/sold years ago, and there is no way to hide them.
[1] https://community.namecheap.com/forums/viewtopic.php?f=10&t=...
[2] https://community.namecheap.com/forums/viewtopic.php?f=10&t=...
[3] https://community.namecheap.com/forums/viewtopic.php?f=10&t=...
[4] https://community.namecheap.com/forums/viewtopic.php?f=10&t=...
Many pluses: predictable, can be administered using the AWS CLI, consolidated billing with other AWS services. Heck, can even register domains from the CLI.
Only downside as others have pointed out is that Gandi doesn't make it at all easy to hide your name or company contact information.
So you are recommending someone switch over privacy concerns from namecheap to Amazon in story about how Amazon is leaking private Customer data.....
Really...
They're a bit more expensive when it comes to domains but we're talking single dollars a year here.
I must say that I have never verified this myself, mostly because I've never needed it that bad. At least something worth looking into if that problem arises.
(Can actually confirm that from this month's experience, so it's even freshly verified :)
(Full disclosure: I work at Namecheap)
But their "redesign" and presumably the backend changes tied to it (or lack of them, whatever the real case is) resulted in the worst experience I've ever had with this kind of service in years, culminating in what was the last straw - one of my domains getting shut down five times in a single month due to bogus "domain contacts verification" procedures, which their support wasn't able to solve from early December to when I finally decided to move away in mid-January (from a short exchange after I moved away I assume it's still broken today as they were apparently "investigating it" even after I was gone. That after having it in some or some other way "fixed" for about three times during the previous support exchanges.) Honestly though during that time my tickets mostly kept bouncing back and forth through customer reps that insisted on politely suggesting things like "to check my spam folder", even though I specifically explained every time that I was in full control of my mail servers and that it is them who don't deliver any kind of verification emails to those servers, so there was really nothing that could even end up in "a spam folder" and that yes, I actually thoroughly checked that, several times over. Yet my requests for them to check their own mail logs because I'm here actually losing access to my domains without being able to do anything about it were each time politely swept under the rug with generic assurances like "they're working on it and will keep me informed"... Then quickly closed the ticket as fixed. Every time after the one particular domain went dark (and with another domain randomly flipping into bogus unverified states in the frontend interface, clearly lingering on the edge of the same fate), the domain was reactivated either by me or the customer support, was either set to have its contacts covered by WhoisGuard (which doesn't even use the contacts verification process at all), or at a later point even manually set back to fully verified by their techs (and one time completely having all my zone data wiped without explanation or apparently without whoever caused it having a backup at hand to restore it from) - only to again and again end up suspended as "unverified" several days later, losing me access to its emails, websites, everything...
Now I could still go on and on about how clunky the entire new interface compared to the old one is (yes, the original was lackluster, but not even remotely this level bad and in fact I've never had a single technical issue with it, other than being somewhat hard to navigate) and that ever since the redesign the new frontend frequently displays outdated or plain wrong information, crashes with cryptic errors, sometimes just decides to log you out five times in five minutes for no reason, but I think this is getting too long as it is anyway, so enough.
When I finally grew tired of running through their customer support in a neverending circle (to their credit, they were always very polite and nice, but it felt like that's all that Namecheap support was really trained for. And that clearly doesn't make my domains magically work there), I moved to Gandi just basing on their overall popularity and good reputation with a few people. Already in a week time I had two great support experiences with them and got my issues resolved each time in literally a single step of exchange. In the first case I've received about a page-length of actual technical reply from their support rep that not only bothered to carefully read through several issues that I ran into when trying to run a Python app on their web hosting platform that I ordered for the domains moved there, they even included a how-to custom tailored to my specific use case that was way beyond what I originally asked for and that ended up saving me quite some time discovering it on my own, and also acknowledged that they had a major issue in their documentation system and that they had it quickly fixed in meantime. Now second time was less technical, as I accidentally burned a discount code while customizing and re-customizing some orders in what was probably an unexpected way for their interface, that ended in the code never being applied to any order but still ended up as used and lost... I wrote down the problem in a few sentences, customer support quickly verified it and issued me a new replacement code right with the initial reply in what had to be less than an hour. Can't really say I'll be missing Namecheap any time soon.
TL;DR: Credit card was stolen, Namecheap penalized me for that and then blackmailed by locking all domains.
Please write a blog post about this.
Also, $240 because of one chargeback, and doing the above while the customer is trying to sort out a fraud issue? Neither of those sounds like normal practice for a responsible domain registrar either.
Obviously there are two sides to every story and we're only seeing one here, but that one does look pretty bad for Namecheap.
This isn't about blackmail as jewsin writes in the comments, it's about the reputation a business suffers with a chargeback. All you would need to do is reverse the chargeback and the full charge would go away.
Disclosure: I work for Namecheap.
Still, I think my original points stand. I find Namecheap locking out unrelated domains and redirecting traffic unethical and in bad faith of the service provider / customer relationship. Not to mention that the domains continued to point to parking pages even after I paid up.
I'm sorry as well for the parking page situation - my guess is it didn't immediately propagate, but I'd have to investigate further as to why that happened. Usually, it's not about redirecting traffic but just not letting you get into your account. This does not sound like it should have happened at all. I sincerely apologize that this is what you encountered.
p.s. I love how trying to genuinely be helpful has resulted in an onslaught of downvotes. I'm going to assume you helped balance that out with an upvote. So thanks :)
Sent my ticket number via the contact form on the website from your profile. I see that you spearheaded the SOPA membership surge - it's what got me to join in the first place.
I wish people wouldn't do that. It does appear that Namecheap has behaved very poorly in this case, intentionally or otherwise. Sadly, downvoting a person who works for an organisation has become a proxy for downvoting the organisation itself on HN recently, which doesn't seem constructive, particularly if that person is trying to share relevant information and/or improve the situation.
Also, the issue with all domains being shown is a bug. If you have a ticket number regarding this, please let me know and I'll investigate this further because it should be resolved.
They have a very strong privacy stance and take security seriously
I registered a new domain with Namecheap just last Thursday and it had whoisguard automatically turned on.
If you click-through the checkout with the 'Confirm Order' button at the top right away you can miss that detail - as I have twice.
One of the reasons I switched to Namecheap in the first place is because they were a registrar that didn't rely on bundling tricks. I'm considering moving all of my domains away.
Do you actually have untrusted users on the box?
Why would you not secure the custom port to root-only?
When your SSH port is something like 53148 and you see password brute-force activity in logs it's almost always mean that somebody intentionally scanning your server.
https://www.shodan.io/report/uMZDnWfT
This is a long-running problem and one with various popular solutions: restrict the source networks which you accept traffic for, disable password authentication entirely, and add some sort of rate limiting (e.g. 2004's fail2ban) for failures. Trying to reduce log volume by obscurity is futile - you really need to address the root problem and use tools which allow you to filter and aggregate effectively.
And relying on what looks like secret data (changing the SSH port) where the number of bits of entropy is low enough that it's plausible to try them all (16) probably still counts as security by obscurity -- it might hide you from many attackers, but it's not enough to make you secure.
Relying on data that's not actually secret, just hard to find, is just insecure.
That's not why you change the ssh port at all.
You change the ssh port to filter out false positives, if someone is attacking you on your weirdo ssh port, it's likely an actual attack that you need to pay attention to. You still need to do the rest of the security stuff.
I've recently purchased a domain from namecheap, with whoisguard, and if I recall correctly I didn't have to turn it on. I whois'd myself and found that it didn't leak anything. It didn't occur to me that scrapers can get at the info before you protect it.
Perhaps this has changed since your experience? Please could anybody else verify one way or another?
Cheers
Services that hide the name actually result in a company (e.g. "Domains by Proxy LLC") purchasing and holding domain ownership for you, which is a very different legal arrangement with different risks.
Not only ICANN but the whole financial world. Shell corporations provide no real use other than hiding money and ownership.
Besides, my primary domain is my full name dot com, so anyone who has any interest in the domain already knows my name.
Why not just "sell"/transfer ownership of your domain to another entity (one that you own)?
a) A valid email address. (A gmail that forwards to your real email will do).
b) A valid postal address. By valid I mean "in the proper form".
As such the following would get flagged:
1 Main St. Anytown USA 10016
(because it doesn't exist..)
545 Jones St. New York NY 10016
(let's say that's a post office..)
is fine.
Why do you say here and thus Amazon?
(I think this is true...I can't remember now actually).
It is Amazon's absurd assumption that your contact information is private that is at fault here. Trying to ameliorate this by contacting fewer people is self-destructive, and cannot achieve complete security unless you're willing to eliminate contact with everybody but those you trust with your accounts. Without a doubt it is Amazon's policy that needs to change.
Well, yeah, I've been with Gandi for years, that's their published policy: https://www.gandi.net/domain/whois/
> By the time you find this out
You realize you should have done your homework and read your registrar's policies beforehand? I understand your overall point, but don't make it sound like Gandi did anything wrong here, just because you don't like it.
Gandi is very up-front about every aspect of their services. I found out that Gandi's whois privacy doesn't hide the name you provide as the registrant long before I entered my credit card details to provide payment information.
Their whois privacy is structured in this way because for many (all?) TLDs ICANN requires that the entity listed as the registrant be the actual owner of the registered domain.
What are the alternatives? Those fishy private protection companies? Technically once you sign up there, they own your domain, simple as that.
OpenNIC? I wish that was the case.
„Die Anbieterkennzeichnungspflicht muss praktisch von jedem, der ein Online-Angebot bereithält, erfüllt werden. Etwas anderes gilt nur bei Angeboten, die ausschließlich privaten oder familiären Zwecken dienen und die keine Auswirkung auf den Markt haben. Im Zweifel sollten Sie davon ausgehen, dass die Anbieterkennzeichnungspflicht besteht.“
Which roughly translates to: everyone has to do it, unless its a purely private service. So I guess you don't need it for you web-enabled password protected security cam, but you definitely need it for your blog.
- The year I was born
- The district I was born (not the exact town, although that wouldn't be hard to guess)
- My mother's maiden name (which is what most banks et al ask as a security question...)
- The areas I've lived (based upon the electoral register, which you can opt out of but supposedly this impacts your credit rating)
- That I am a director of a company
This is just what is available for free - you can get the full records this is extracted from by paying a small fee.
If you know the name of my company (which isn't hard to find out), you can also find for free:
- My full name
- My address
- My date of birth
- Roughly how much I make a year
TL;DR; If you rely on this to 'identify' someone, you are doing it wrong.
It is a requirement to register if requested, the fine for failing to do so is £80. However, it is always an option to not appear on the open register. The open register is publicly accessible, and being absent from it will not be detrimental to your credit rating.
But it will make identity checks with banks a little more complicated, normally they use the electoral register to confirm your address
Seems like your details can still be used for credit checks and fraud prevention (which I imagine covers confirming identities and addresses) even when you opt out[1].
[1] http://www.electoralcommission.org.uk/faq/voting-and-registr...
Although they planned to change this if you ran ads on your site:
http://www.theguardian.com/technology/2014/jun/11/nominet-ne...
Which is why the system is set up so that if I go to the bank with this information and take money as you, I have stolen your identity and thus you are the victim and are responsible for the losses unless you fight back. Identity theft was created so financial institutions could be lax with their verification process thanks to the blame being shifted.
In reality, identify theft doesn't exist. In my example I stole from the bank, no you, and you shouldn't at all be involved in the process.
It definitely wasn't just "created" either. Pretending to be someone else to gain the benefits of their identity/reputation/privilege has always been around.
I will never again register a domain with my real info. Sorry ICANN, I don't give a about you or your policy.
.dk-domains are owned by persons, not the registrars, and therefore the whois-information for .dk-domains follow the same procedure as addresses. So if you have 'address protection' as it is called, your personal information is immediately removed from your whois information.
https://medium.com/@amaz/thank-you-for-sharing-this-but-i-co...
(contains pretty great screencaptures)
1. Get a friend's permission to "hack" into his Amazon account (or "hack your own account").
2. Contact Amazon's customer service, try the same social engineering techniques that the OP documented.
3. Once you obtain some sensitive information from the account, scare the CS rep by saying: "Haha! I am actually not the customer. I am a journalist/hacker/whatever and wanted to see how easy it was to social engineer information out of your customer service department, and you failed. I would like to talk to your manager please."
Hopefully if enough people do this, it will get some internal attention at Amazon.
Bad idea.
It looks like both Amazon and Apple have fixed _some_ issues since then - Amazon is no longer leaking last 4 digits, but instead they're still leaking other info. Apple now requires more information to reset accounts and to wipe devices.
The option is only (at the moment) available for Amazon.com accounts, but if you enable it there is will also be turned on for other domains Amazon.co.uk etc.
This is very smart, why has no one thought of this before? When people post it on Medium and share it on HN/Reddit it will not get enough internal attention at Amazon for sure. So let's do something totally stupid which could easily get us in trouble with the law enforcement to make a shitty point to Amazon so that they can notice something is wrong on their end.
The fraudster did this at least 3 times with increasing amounts of money. Amazon did not care. Only when we went to the police did this stop.
Amazon sold me a phone, the box arrived empty (I wonder why they do not check the weight when it leaves their warehouse, DHL printed a weight on the box that was less than the phone alone). It took Amazon support months to solve this, especially they could or would not cancel the attached mobile phone contract for months.
I verified with just name and address to a customer service rep and asked for the steps I'd have to do to unlock it again, and they told me that (a) the transaction failed, (b) they told me my IBAN. In plaintext. The full IBAN. (c) and then they told me the steps to fix it (wire them the money that I was owing them, plus 6 EUR. Standard procedure in Germany).
In the end, everything worked again, but, the fact that they gave out by IBAN — enough info for anyone to go and pull money from my account — is making me so angry.
Maybe you're thinking of credit card number? The CC's I had had different CC number and IBAN account.
Specifics vary from country to country. Some require active approval from the customer (IIRC France, probably more), others "just work".
Fraud is not as common, since bank accounts that are allowed to debit money this way are generally only available to companies who have to sign paperwork ensuring that they have written permission from each debitor. Additionally, although this might be country-specific as well, chargebacks can be initiated without providing any reason for at least 8 weeks, and in case of a fraudulent transaction, up to 13 months.
I can’t pull money from your account, even if you tell me your IBAN.
But I can use your IBAN to order from amazon, and then amazon can just pull however much they want from your account.
Luckily chargeback with direct debit works just as fast as with credit cards.
You can go to amazon, give them your IBAN, and buy things, and they’ll use direct debit to get the money from the account specified by the IBAN, no further authentication necessary.
Obviously, you can do chargebacks, but this is still something they shouldn’t publish.
What you may want is a catch-all email - which lets you do @domain.com -> nmjohn@domain.com (where is everything besides already defined addresses) - that way you can make up emails on the fly without having to setup the alias beforehand.
I've had that setup for 5 or 6 years now, and it works extremely well. A handy side-effect of this is it makes it easy to see which companies sell your email address to spammers when you included the name of the original company in the email you register with
An intermediate step that may work if you don't expect people to target you individually: have one or more required substrings for the email local part, and catch all mail to addresses containing that substring.
Are you saying that there are sites out there which don't accept mailbox@subdomain.example.com a valid email address? If so, that's beyond broken...
Sorry, could you repeat that? yourname@u.northwestern.edu certainly matches \.edu$.
Unless you're worried about the false-positive for a non-student with a different subdomain?
Only one university in Germany has a .edu, and their students obviously manage to get far more benefits than those of us with an @informatik.uni-kiel.de email.
In Brazil, universities can use .edu.br, but we have few universities providing email addresses to students and also, the majority of grad schools in Brazil are not universities but a small college called 'University Center'
I'll note that I don't use this method as it seems too high maintenance and the effectiveness is unclear.
I haven't found this to be true, or at least Google's spam filters have gotten sufficiently good to prevent it.
I have a catch-all address @morgante.net and rarely ever see spam—maybe once a week.
Hasn't been a problem for me.
It's ignored for delivery, but gmail's filters can match on it in the to: address.
Unfortunately, many sites borked their e-mail address validation and do not accept the plus character. (Amazon permits it.) Also, you'll ocassionally find a customer service ticketing system that expects replies to come "From" your account's e-mail address. (Many mail clients can alter that header, but it's a pain.)
Not that I trust the "security questions", but if Amazon lets you use freeform questions as well as answers, it might help to make your first security question "Have you noticed this account has two factor authentication turned on?" with an answer like "Yes, so Amazon Customer Service will take additional care when being asked to reveal account information, right?"
Even if you can't do freeform questions, perhaps the answer to "What's your mother's maiden name?" could be something like "Have you noticed this account has two factor authentication turned on? Please take extra care before disclosing account details to anyone, Thanks."
Remember it's a human verifying this. The attacker just needs to answer: "oh, yeah i just spammed the keyboard with some jibberish" and he's in.
The other thing I noticed by the attacker going after me, sometimes he'd call/contact the service multiple times in a row. All he needs to do is find out from 1 support rep that the reset password is randomly generated. Then tell another support rep that its "some jibberish" and he's in.
What's your favourite football team? -> Genghis Khan 2nd XI What was your first school called? -> Little Horrors School for Hackers
etc. Easier to say, you won't lose the customer service rep's attention either :)
(Satisfied Panix customer.)
Twice now I was only able to register after removing the +[something] part of the email.
Is + actually an invalid email character (according to RFCs etc?). I couldn't find any reference to that when I looked.
RFC 821 is the original and 2821 summarizes it plus the few that came after to add and clarify.
The only true "RFC email validity check" is to send an email to whatever address they provide.
I used to do this too and it was great, but then when I started trying to recover accounts that were a few years old, I had a heck of a time remembering what email address I had actually given them in the first place!
aws vs amazon-web-services vs amazon.web.services
facebook vs fb vs fbook
Or for example I've used Rally the project management tool but my health insurance uses a (terrible) "rewards" program called "werally" but it's ALWAYS referred to "rally". It can get unmanageable.
Now I use 1Password to track all of this stuff which works well so I think there are solution but I do understand the grand-OPs point.
Perhaps I could have saved even more than 15% if I'd just gone with it. :D
That's why nothing will change if these estimates are even in the right universe. Nobody wants to inconvenience the vast majority of customers to prevent a minuscule number of issues.
It's why banks still use laughably short and simple PIN codes.
I wonder how long it'll be before (or how long ago it became) sensible to register a shell company as the holder of any public record you're legally required to make public? It's probably much easier to roll your shell companies "registered address" if you discover it's been compromised than it is to move house every time Amazon's customer service goes "above and beyond" on your behalf to your attackers...
You'd need to take care to avoid getting people locked out of their accounts, but otherwise that sounds like a useful service for the small fraction of people who have a high enough profile that others may actively target them. I don't know if that represents a large enough target market for a sustainable business, but it might.
> I wonder how long it'll be before (or how long ago it became) sensible to register a shell company as the holder of any public record you're legally required to make public? It's probably much easier to roll your shell companies "registered address" if you discover it's been compromised than it is to move house every time Amazon's customer service goes "above and beyond" on your behalf to your attackers...
Depends on how easily you can register a shell company that doesn't itself have easily traceable public records of ownership. Little point in the indirection if you can then look up the shell company and its official owners and legal contacts.
See also: people who don't understand that full-disk encryption means they lose their data if they forget their passphrase. That doesn't make full-disk encryption in any way bad, but if you train people to think that all accounts have a "forgotten password" option, they might get a nasty surprise.
One time I had my carefully encrypted secrets thoughtfully spread across my laptop drive, my iPod as backup #1, and an external hard drive as backup #2. All of which I had in my backpack one night - which I proceeded to leave at a restaurant where I'd been sitting outside on the sidewalk tables, and I didn't notice until _way_ after they'd closed for the night. (I used up a _great_ deal of luck that night - we went to that restaurant enough to be "regulars", and the waitstaff found it and knew it was one of ours, and it was waiting for me when they opened the next day...)
Most of "us" already deal with these things though - there's no "forgot password" for my ssh keys or my ssl keys or my topt seeds - there's no "forgot password: for my 1Password and Keypass safes. We occasionally get to laugh at out less diligent colleagues and peers who belatedly reveal the time they "lost" the ssl private key or the production webserver ssh key, but it's not like we see critical infrastructure falling apart regularly because of forgotten-but-unretrievable passphrases.
But I suspect you're right, there'd probably be a whole lot of "Hold my beer and watch me turn on full personal responsibility here! Oh, hang on - shit. Oooops..." if Ama-Face-Goo-Yah-stagram allowed this...
It can't be a simple checkbox, or an Agree button. Make someone type, exactly:
I accept all responsibility for this
Even then, the majority of the general public (as opposed to computer nerds) would be awfully upset at being locked out.You're exactly right: there'd probably be a whole lot of "Hold my beer and watch me turn on full personal responsibility here! Oh, hang on - shit. Oooops..."
I wonder what the PCI implications are if it's true that Amazon gave away his last four cc digits over the phone?
I wonder if there are applicable PII laws in his jurisdiction that'd have Amazon able to be held liable for disclosing his address? (I think there are here in Australia(1), but that doesn't mean regular Amazon customers have any chance of prevailing in court against Amazon's in-house legal team...)
(1) 6.67 of this says your address is "individually identifying data": http://www.alrc.gov.au/publications/6.%20The%20Privacy%20Act...
Absolutely none, unfortunately. Merchants are specifically allowed to store the first six and last four digits of a credit card number in any form they like.
So no, very unlikely.
Except if they became reliable for the damage caused by the infromation they released of course. They would then have a financial incencitive to have better security checks.
Then Trump will even use this incident to say "I will force Amazon to become great again, after I'm president."
So a "small issue" could help Donald Trump get that much closer to becoming the most powerful man in the world. So, thanks Amazon?!
Obviously, it's all tongue-in-cheek, but I think you see my point. If it can be done, eventually we'll hear about a celebrity being hacked like this.
That said, the author have a very good point. If you cannot log into your account, they should not assist you. MS Support/Store does something similar. They send an email with a code to the address they have on record. If you cannot tell them the code they send, they will not help you. So if you cannot log into your account, they can assist you in password recovery, and take it from there.
I had my identity stolen once, and it sure was annoying... if also a little fun. A credit was opened in my name, that I had to fight to close, and I was even interrogated by police because false me was associated with shady characters (surprise!) but in the end it wasn't the end of the world.
Security "features" however, are usually so annoying they destroy the will to live. They would be tolerable once, but they're constant, and constantly remind you that you are, in fact, a suspect. They pretend to "protect" you but actually dehumanize you and every interaction you have with other humans (not to mention security theater, where the features don't increase security in any way but are simply there to make you "feel" safe).
Being alive is to be at risk, and at the mercy of bad guys. We should accept it and enjoy life before we all die in the end anyway.
PGP/GPG comes to mind. Yes, technically superior but good god is it arduous.
Apple tech support gave the hackers access to my iCloud account. Amazon tech support gave them the ability to see a piece of information — a partial credit card number — that Apple used to release information.
http://www.wired.com/2012/08/apple-amazon-mat-honan-hacking/
Everyone knew that I had this access, and everyone knew that it was against Amazon's own policy to give me access. But to them, that was easier than fixing the service so that it was more useful.
Perhaps I'm just clueless, but something tells me that any relevant competitor to Amazon - say, I don't know, Google - would choose to fix the service instead.
Why? The attitude you describe (do what's easy, not what's right) is endemic to any organization over a certain size in my experience.
Like domain names, privacy when you have a company is hard.
No, not all of the time, but very often enough to make it useful for social engineering.
You MIGHT still be able to search by name in the old fashioned way, by going into the office, but I am uncertain about that.
Call or visit the Swedish Tax Agency if you want further info, such as personal identity number ("personnummer" - think Social Security Number but used for absolutely everything), taxed income, identity and full info of parents (including mother's maiden name - so much for that), etc. You don't have to tell them who you are or why you want this information.
Enter a street address on a site like ratsit.se and you'll find all the people registered on that particular address. I could go on. When I talk about this with friends in countries like Germany and France they're often flabbergasted; in Sweden we're so used to it that we think it's natural. We're basically doxxed by our own government by default. A stalker or identity thief's paradise. It's messed up.
Many Swedish online shops will happily send you goods along with an invoice that you pay later. The invoice option is often only available if you provide your personnummer - which as I mentioned is public information, a phone call away - and have the goods sent to the address tied to that number. If you live in a house with a mailbox outdoors, a thief could order stuff to your address and empty the mailbox before you. "Stuff" could also be things like mobile phone subscriptions and whatnot.
Or, having your personnummer, someone could send a form to the tax agency to have your official address changed! I believe they do send a letter to the old address saying the address has been changed to <new address>. But there's time to do bad stuff in between the time of the change and your discovery of it. (If, indeed, you do discover it. You might be traveling somewhere, a fact that might've been gleaned from your social media activity.)
And, as breakingcups points out above, even if it were the case that sound security procedures were implemented in Sweden, that wouldn't matter much for the numerous non-Swedish services most Swedes use every day.
Anyway -- people being able to do stuff in your name is just one thing. I don't want the whole world to know my address, or marital status, or date of birth, etc - period. It's about privacy.
Not saying all customer support people are like this. However, majority of people are. They rely on pre-written scripts. When a question is asked, they search for the template question with the answer.
Most companies would do well to invest in "Customer Support Engineer" type roles, putting people who understand systems and are informed problem solvers on the front lines, people who can identify technical solutions to customer problems. Customer Support Representatives problem solving seems to begin and end with what they've learned from the latest ZenDesk Webinar. Most companies seem to believe that fast and friendly messages are what customers want, through twitter and Facebook, when the reality is they want their problem solved and the business most benefits when the cause is identified and solved for all customers, not the symptoms for one customer.
Most companies could slice their customer support costs in half and increase their customer satisfaction substantially if they invested in building out roles for problem solvers instead of ticket solvers. 1 ticket solved is 1 ticket solved. A problem solved can be hundreds or thousands of future tickets prevented and an improved customer experience.
(This comment isn't a slight against customer service representatives, they serve an important purpose at many companies and often provide great value. This comment is a slight against the companies that choose to hire a dozen more customer support representatives instead of addressing the core issues that are driving people to their support.)
An additional thing I'm doing is reviewing what accounts have my credit card. One of the things I like about my Bank of America credit card is that I can use their ShopSafe feature to generate a card number for specific accounts.
So if I'm buying transit pass on a website probably made by incompetent people, I generate a new credit card number and use it one time. Same thing with doctors that want me to write my credit card info on a piece of paper and mail it back to them.
2FA does not help here as someone goes through support channel which looks like bypasses 2FA
Also concerned if the same trick can be applied to Amazon Cloud services, as there one can also run up a big bill pretty quickly.
Using a unique email address.
Using a unique physical address (both for my account details and for my delivery addresses).
Use a unique credit card (I'd probably get a refillable prepaid gift card, and set up some auto topup to ensure it's got my expected monthly Amazon bill available as "credit", but not much more).
I'd probably move any AWS billing to a different Amazon account.
If I were more paranoid (or being actively targeted), I'd probably also try to go unique on _everything_ I tell Amazon; phone numbers, different city/state/zipcode (as well as street address), company name, website url, alternate contacts - then I'd set up "Security questions" with unguessable questions/answers (perhaps diceware/xkcd style "correct horse battery staple" type ones, that a CS rep could easily read out and verify - rather than a base64 GUID...).
Not that I trust the "security questions", but if Amazon lets you use freeform questions as well as answers, it might help to make your first security question "Have you noticed this account has two factor authentication turned on?" with an answer like "Yes, so Amazon Customer Service will take additional care when being asked to reveal account information, right?"
Think about how many people actually use Amazon services
Through sheer competition, Amazon is forcing Walmart to close over 100 stores. We only know that because Walmart is big enough to get noticed.
Remember when Walmart was the company putting local mom and pop shops out of business?
Cycle of life I suppose...
I've had credit cards get compromised in the past, and it was actually quite painless to have my bank (Chase) shut the card down and issue a new one.
Your information can be stolen from SO MANY sources and not just Amazon customer service. It's impossible to guarantee who sees any of your personal information once you share it with ANYONE on the internet (Amazon, Google, some random retailer, domain registrar, etc.).
The server at your local Applebees could steal your CC info.
Be sensible with where you share personal information, but don't be unreasonable. It's safe to use Amazon.
Just watch your credit report (regardless of whether you feel you're at high risk) and bank statements.
If/when a problem arises, then deal with it.
What we need is a global security standard for support staff, with a template as to what information is accessible by staff and what isn't. And what is available to better trained 2nd-level support, etc.
And then each company can say they are certified for this particular security standard, and then you can't get social engineering attacks where you attack one large corporation, get partial information, and then feed that into another large organization to get other information. This was done previously using Amazon, again, to get enough information to take someone's Twitter account, if i remember correctly.
The bottom line really is that so far these kinds of social engineering attacks haven't been enough of a problem for companies to have the slightest economic incentive to improve the situation.
I also use different cards for the major online retailers / tech giants so knowing the last four digits from my Amazon account is useless to validate anything else (though this does require having several credit cards or debit cards).
Whois privacy is absolutely required.
Unfortunately if someone is determined enough, almost all ISPs, cell companies, retailers, etc will happily give them control of your entire digital life. You can only minimize the risk somewhat.
Because they don't have customer support?
Taking back the DNS took time. Meanwhile the hijackers were logged in, and could not be logged out by Amazon. This took more than a day. It took us two full days to get all back to normal.
The good thing is that they could not login to our servers. What they wanted is still not clear, and who did this - we saw some suspicious traffic from Russia, but that's all.
I use blur from Abine.com, gives me a new email that forwards to my main, as many as I want, integrated with a browser plugin that barely adds time to signup.
For example, you can turn on 2FA for sending money via Bank of America's webpanel. As in, you log in with username/password and need 2FA for some restricted actions.
Well, phone up customer support and they'll remove your 2FA if you can provide them some secret details... all of which are displayed on the webpanel to anyone that was already able to log in.
It's a joke.
But most companies aren't anywhere near that careful.
"Hi I'm from bank xxxx calling to warn about some potentially fraudulent transactions we've detected on your credit card before we can continue please answer a few security questions to verify your identity."
I suspect some people would fall for that and tell the 'bank' their personal details.
In the past I've also sent letters to bank security teams not to cold call and ask for personal details.
One of my banks actually switched to a standard recorded message that ends in a "Please call our 1-800 number at your earliest convenience." Better.
Just saying "Your account has been flagged for a lost/stolen phone which you use as your 2FA. Please contact support if this is not correct."
And even if you make sure your bank has a local branches (which really, I've not gone to one in years, why would I need one?), what happens when you are on a trip, and your accounts are frozen? I've had my CCs frozen because the bank considered my expenses during a trip to be potentially fraudulent, but I could clear it up over the phone. Do we have to devolve back to carrying thousands in cash, like in the old days?
Security is always a tradeoff between avoiding fraud and being usable, and the tradeoffs that are great for some people in some situations are unacceptable for others.
I called up, asking why there was a hold, they said I put it there, I said I didn't. There was a long pause, followed by "for security reasons, we won't be able to help you with anything related to your accounts until you come into a branch and present photo ID".
It was a bit inconvenient, but I have to say I was pretty impressed.
"I lost my phone" (or "my phone stopped working") does need some solution, though.
The right way to handle "I lost my phone" seems like one of two possibilities: either come into a branch and provide legal identification matching what you used to open the account (and get "yourself" on camera doing so), or have a token mailed to your physical address on file (which you cannot change at the same time as a lost phone claim).
This is the worst for the customer point of view. Takes a long time.
You provide a scanned copy of a government-issued photo ID.
You provide a scanned copy of a statement showing both the most recent deposit and a name and address matching one of your accounts.
You complete SMS verification. (SMS must be previously configured.)
You complete 2-factor verification. (2-factor auth must be previously configured.)
You correctly answer your security question. (Security question and answer must be previously configured, below.)
You use an ssh key to create a file with a specific name on one of your sites hosted here. (Must be previously configured, won’t work if account is empty.)
We try and fail to contact you via your currently configured email address. (This one may take a long time.)
You can then pick how many of these you want to require to get your account back (and which you want to configure), including an option not to help at all in the case you lose your account.So yeah, bad idea.
Two years ago I found out that Amazon allows multiple accounts to be set up using the same email address with different passwords (!!!) - which means that the potential attack vector is larger for no good reason.
I don't recall how this happened but I can only assume at the time I signed up to AWS and I might have reset/changed the password somehow that resulted in the system creating another copy of my account.
So all the information (credit cards, addresses, etc) of the "old" account still existed until I deleted them. But let's say if someone who has no idea that they have more than one accounts with Amazon, they could easily leave their information intact in their "old" accounts, which if they have weak passwords can easily be compromised.
Unfortunately Amazon did not take this report seriously, and to this very day this issue still persists.
This is really bad. The security implications are different between the two.
While you can certainly register two accounts and start all over, it's clear I meant an intentional support by the system to allow one to separate the two.
When I trained Apple techs the clear communication was that people use pretexting for not just mundane things like credit card theft, but to commit violence against other people (especially in the case of domestic violence where they have some personal details and can try to get more).
Anything but the strategy of verify only is putting people's lives in danger.
Interestingly, last night I did get an SMS: "Message from Amazon Customer Service: xxxxx is your Amazon security code" even though my 2FA is not an SMS (it's using authenticator).
I don't have access to the recording, so I have no idea what actually happened. But based on the email ("here's the details" on your order) I'm almost certain they were successful. Probably just told them that they lost the phone, or something. At this point, they've now been able to get almost everything possible about me.
Also interestingly, not once did Amazon recommend that I use 2FA to avoid social engineering. I was told by two different support reps to change my password though.
On that note, I order alot from Amazon and throw out their boxes in the trash outside all the time. Sometimes I notice that neighbors (presumably) take those boxes for their own use before trash pickup comes along. All of them have my name and mailing address on them...
Ideally, the suffix would be some non obvious function of the service name, which I can remember easily. Like taking the second letter of the service name and relating it to an object I encounter a lot in my life.
e.g. email+ifidontknowthisthisisnotme@youremail.com
Not sure how an agent would react to someone having part of the correct email though.
- you agreed to arbitration
- you agreed to disallow class action lawsuits
I.e. thanks to the Supremes[1]:
As a result, businesses that include arbitration
agreements with class action waivers can require
consumers to bring claims only in individual
arbitrations, rather than in court as part of a
class action.
[1] https://en.wikipedia.org/wiki/AT%26T_Mobility_LLC_v._Concepc...(IANAL and I'm only familiar with English law, but I'd be very surprised if there was anywhere where that isn't true, it's pretty fundamental)
I think I need to make a script that can do that for me. A simple mail server to forward emails both ways.
Your Account › Change Account Settings › Advanced Security Settings
Turn on 2-step Verification.
It won't completely solve social engineering, but it can't hurt.
In any case, I will leave my comment so that folks who come across this thread have a handy reference for turning on 2FA on their Amazon accounts.
"As a security conscious user who follows the best practices like: using unique passwords, 2FA, only using a secure computer and being able to spot phishing attacks from a mile away, I would have thought my accounts and details would be be pretty safe? Wrong."
Are you sure the author enabled 2FA on his Amazon retail account, or was it only enabled on his AWS account? The two systems do not share the same 2FA.
FYI I enabled 2FA on my Amazon retail account and when I called customer support they verified it. Once the verification failed and they refused to give me support.
Anyone else confirm a similar story with 2FA and support? Anyone willing to explicitly test this out?
As you can see here, they are not doing a good job even in that department. Taking huge profits for basically failing.
I have called this a lose-lose in the past.
So -- be good and stop using amazon!