If you have been on the net long enough this will creep you out: https://haveibeenpwned.com/
If you have been on the net long enough this will creep you out: https://haveibeenpwned.com/
I realized an attack method where:
1. Find an unusual but generic product used by niche group such as a particilar adult toy.
2. Order product and sell in using existing amazon SKU (very common) at below market price point.
3. You now have difficult to procure personal data on a very specific customer segment, paid for in lost margins on the product.
Reminds me somewhat of the old days of Facebooks demographic targeting to get page likes. You could build interesting lists indirectly on the cheap.
It's super against Amazon's TOS for resellers to contact customers outside of Amazon controlled channels, but I never lost a lot of sleep over it, and dont think people were buying much 3PAR storage off amazon anyway.
I recently started making up random names when buying from Amazon Marketplace, to see if I can spot a pattern of who's buying and who's selling databases. I'll know better in a few months...
Could also be bad quality, liquidating goods on failed launches, etc
Yes, this process is automated and usually works, however, the systems don't know everything, and you have to manually override the error to ship the product.
With that said, I think it's grossly irresponsible to look people up on all their social media. This is part of considering customer trust.
I've yet to hear about sellers stalking customers in the real world, but IMO, there isn't any difference between doing this stuff online and the real world. Please don't do this if you are planning to be a seller.
While I agree with you in one sense, this wouldn't even be an issue if people didn't willingly post their entire lives to social media. I don't understand how one can be too upset about someone looking at data that they themselves decided to make public.
Back when I started using Facebook, it was obvious that you're building a profile to be publicly accessible, i.e. viewable by random strangers, and everything you posted publicly you did with the intent of it being a part of that public profile. It was kind of like blog, but with guaranteed active audience.
The intent has changed vastly over time.
By the time I was a senior, one of my parties got busted before it started because I forgot to lock down the invite.
Probably won't happen anytime soon, but eventually I think a service like this will exist.
Why Americans don't value their privacy or enjoy being harassed by sales people is beyond me.
Well that is down right crazy. Most sellers are people in their garages drop shipping 3PL. I'd trust them if they were background checked....maybe
There is nothing stopping anyone that has an e-commerce website from recording a clear version of your passwords along with all of your billing address and credit card informations.
There's no audits or anything.
Credit Card companies are very good at identifying the source of the leak from only a handful of fraud complaints you’ll be surprised how few places would be shared across even a small batch of cards say <50.
If the retailer is large enough to make an impact they’ll get caught and dealt with very quickly and the value of credit cards and matching PII/CHD today is very low a few million cards might be worth only a few 1000’s of dollars depending on their age, source and estimated credit limit.
Maybe that's why we need to move towards blockchain-based networks since trust is not required on blockchain, only proof.
We were routinely getting emails saying "I'm not comfortable sharing my CC info with you" (even though it goes through a processor), so ended up adding PP as an alternative. Guess what - now we get to see their full name and physical address, neither of which we need, because we sell software licenses. I'm guessing that people are more concerned with needing to deal with compromised cards than they are worried about over-sharing of sensitive personal details.
So whenever a company says that only their user email addresses were compromised and nothing more, I'm pretty skeptical of the validity of their assertions.
Go on then... post your e-mail address.
Since a lot of people re-use passwords, if your email is also contained in one of the countless breaches that we've seen cropping out in the last few years, there's a good chance that your Amazon account is using one of the pwned passwords: therefore Amazon's statement that people should not change their Amazon password is potentially harmful advice.
It's for the same reason that you don't post your name, address, and email address in a signature of your posts on HN.
One time Jimmy Kimmel ordered some gimmicky yoga thing and wanted it overnighted to his house along with a gift card. I checked and it was his girlfriend's birthday the next day. I called up offering to gift wrap it at no charge just hoping to talk to him but I ended up getting his assistant. Still offered the gift wrapping which they appreciated.
There are some rules around it listed here: https://sellercentral.amazon.com/gp/help/external/200386250 But yeah, it is going to be a hard one for Amazon to enforce unless a number of people complain about a seller.
Thankfully I'm in the habit of using throwaway passwords for sites I consider throwaway.
I have noticed recently that I've been getting a lot of extortion spam, demanding bitcoin and saying that they know my passwords have compromising footage of me, having pwned all my devices. For proof they include a password I used on something like pandora, to the service-specific email address I set up for pandora. It's quite funny but I bet it's caught quite a few people with a guilty conscience out.
Checked with lol@gmail.com, you have to add 14 other 'l's (lolllllllllllllll@gmail.com) in order to result in a green good news. How can I validate the claims? I'm a bit skeptical seeing it doubles as a sales front for 1password.com.