6 ms·
This is how it looked for me: I few days ago I was shopping on Amazon and they showed me a message, you already purchased this product. See order details. I was
by kull 8y ago
This is how it looked for me: I few days ago I was shopping on Amazon and they showed me a message, you already purchased this product. See order details. I was surprised since I did not buy it before. After clicking the link, I was shown details of not my order, including name, address and email where a product was shipped to.
- tyingq 8y agoMaybe someone released a pretty aggressive page cache to help handle "Black Friday" shopping.
- andrewflnr 8y agoUh, that just sounds completely unrelated. You didn't get your "email" "exposed", your account got pwned.
- kull 8y agoWhy so? This is how somebody's data was exposed to me, and how my data was exposed to somebody else.
- andrewflnr 8y agoAh, I see what you mean, at least about the other person's data being exposed to you. I interpreted your story as someone making unauthorized purchases on your account. Do you think they accidentally merged your account or order history with this other person's? That's much worse than what they're currently admitting to, to say the least. My other question is where you saw the email address on the order record. I'm looking at my order history and can't even find my own email.
- emptybits 8y agoI'll share a similar experience with Asics (the running shoe company) a couple of weeks ago. Out of nowhere, I received an email from Asics that contained another customer's name, their email address, phone number, and that customer's private message (apparently part of a customer service case). Bizarre. I informed the other customer, who was equally surprised but somewhat grateful for the notification. And I spent an hour or so reporting the incident to various levels of Asics worldwide (I'm in Canada, this customer was in the USA, and their privacy office apparently resides in the EU), partly out of curiosity to see how a small but concerning issue might be handled. Summary: Asics' privacy office got a customer service manager to contact me for details of the incident. They said "sorry" and "it won't happen again". Okay. ?
- tremon 8y agoThis is already a better response than I would expect from most multinationals. Thanks for sharing.
- beager 8y agoThis sounds like a possible reason why they can’t disclose the full extent of it. Cloudbleed was pretty tough to ascertain the extent of. Not a lot of caches I’ve had experience with have deep tools for introspection and auditing. I don’t believe they’re developed that way.
- kull 8y agoOne thing I wanted to add is that I wanted to report this issue to Amazon right away, it was very concerning to me. So, I clicked Ctrl+F to search for "contact" then "support", I went quickly through a few drop downs on the navbar, and I found nowhere any indication I can easily contact Amazon support to report it. I moved on and forgotten about this. So many companies make it super hard to contact their support.
- PuffinBlue 8y agoThere's no big blaring 'contact us' button but it's not that hard to find. In the footer is a link to 'help'. On the help page you just click 'need more help' and there's the contact us link.
- UncleEntity 8y agoEven more fun I recently had someone outfitting their brand new restaurant in New Jersey using my email address on a bunch of different sites like Amazon and Walmart. It was getting annoying so I was going to send them a text message telling them to get their own damn gmail account but they seemed to have stopped. Just imagining the damage I could have caused using the 'forgot password' link and their stored CC info...