As to whether or not something should be done, this is a sensitivity/specificity tradeoff. Too far in the other direction of distrusting customers and Amazon ends up like Paypal.
As to whether or not something should be done, this is a sensitivity/specificity tradeoff. Too far in the other direction of distrusting customers and Amazon ends up like Paypal.
In any case, some authentication aside from "Full Name" would be nice. When I was with Liquid Web, I had a pass phrase set up, which I could pass off as regular conversation even in a crowded room without anyone suspecting it was my authentication. That works best. Even a birth date and city of birth would be better than a name.
This is true. I got locked out of my Paypal account because I had the audacity to log in from a nearby country (Germany). Fair enough, though maybe a bit overzealous. To get control back they then had to charge a small, random amount of money to my account and phone my registered phone number to give me a code to input. Reasonable, perhaps, except that it didn't work! and to this day still hasn't. I can't count the number of times I entered in the code. So I just created a new account with an alternative email instead . . .
This was a few years ago admittedly, so maybe they're better now, but it's one thing to have overzealous policies and quite another to implement those policies poorly. And that's not even getting into the one time I actually needed PayPal buyer protection, because I'm sure we could all be sharing PayPal horror stories all day if we go down that road.
As the article points out, their web-based security seems pretty darn solid. Nearly any account change requires reauthenticating with your password, and only recently did they start to roll out support for a more persistent auth for viewing what most people would consider non-critical info (order history, etc). With the exception of a phone-based password reset - which should not cause a problem like the one described here - they could require even a web-based PIN (behind the login-wall, of course) for chat and phone support; live chat could skip this if the user already has a fresh auth.
I hope for everyone's sake that Amazon is able to prevent this kind of problem without harming their fantastic customer support. There's a reason I've averaged an order every 5.3 days this year (I can stop any time I want to, but thank you for your concern!)