8 ms·
Amazon Quietly Closes Security Hole After Journalist’s Devastating Hack
- stephengillie 14y agoI would like to see a customer service/tech support org where customers have to enter their 2-factor PIN at a phone menu before reaching a human support agent. You could possibly combine that with caller ID for better verification - basically use phone # like a username and the PIN as password. Or you could just use them alongside other verification steps.
- drewinglis 14y agoYou would also need to enter your username or email address, though, and that's hard to do over the phone... I guess voice-to-text is improving, so that might be an option.
- pavel_lishin 14y agoYou don't have to actually enter your email address, you just have to prove that you know it - and telephones have the full alphanumeric set of characters on the keypad. Use a * or # for special characters, and something like "pavel@lishin.org" could be entered as "72835#547446#674". Edit: I guess that may not be sufficient to identify you, but it could verify that you are the account holder for other services.
- taligent 14y agoSome people have 20+ character long email. You really think they are going to be happy about sitting around typing that in on their phone hoping they don't make a mistake ?
- djeikyb 14y agoMy cell phone (Pantech 5000) has a qwerty keypad. It doesn't have the old rotary phone style letter-number association. I know many people whose phones don't have this.
- einhverfr 14y agoOk, but you can't do dtmf with querty, so its use in a call center is somewhat less important. With standard numbers, you could use any touch tone phone.
- djeikyb 14y agoWhat I mean is the map of 2 to a,b,c is fading fast. I can't figure out how to dial 1-800-CALL-ATT by looking at my phone, much less my email address.
- ars 14y agoVoice to text works fine for limited input. So if all you needed was the letters of the alphabet (rather than words) it works pretty well.
- LoganCale 14y agoWhat if they've had their mobile phone stolen and can't do 2-factor auth and that's why they're calling?
- laconian 14y agoSecurity traded for convenience, back to square one.
- Wingman4l7 14y agoIsn't this scenario why Gmail's 2-factor authorization gives you a set of one-time passwords?
- ianferrel 14y agoWhat if you lose them? At some point, there has to be a way to get back into your account. Probably, going through slow and hard to hack methods like the postal system.
- Wingman4l7 14y agoWell, continuing to use Gmail as an example, there is an account recovery system, which IIRC asks for a bunch of details to try and determine if you are the account owner (account creation date, names of labels used, etc.) If Google or a third party would provide a list of these details, then you could collate that info as additional insurance against your posited scenario.
- LoganCale 14y agoThere's inevitably going to be someone who loses them or never prints them out in the first place.
- jrockway 14y agoBofA does this for teller transactions. To talk to a teller, you have to swipe your debit card and type your PIN. While not foolproof, I think it's a pretty nice security measure.
- Osiris 14y agoIf you don't have your card with you, however, you can provide photo ID and they'll look up your account number. I suppose it would be possible to provide a forged photo ID to gain access to someone's account.
- kellyhclay 14y agoGoDaddy essentially does this - but you have to give the human the PIN. Also, most banks do this as pointed out (fwiw, I bank with USAA and I have to call from a registered phone number and enter a pin before reaching a human.)
- brudgers 14y agoThis is the only possible response after the "exploit" was published. Amazon's process was appropriate for their business, and the problems the journalist experienced were due solely to the level is security Apple chose to implement and their decision to allow remote wiping of people's Macbooks. This is only a story because of Apple's of operational decisions. The information required to game their system could have come from a myriad of sources other than Amazon.
- Osiris 14y agoI disagree that Amazon's processes were 'appropriate'. Being able to gain access to someone's Amazon account with such basic information can be a big problem. I know a guy that's a huge amazon seller and he says there are Amazon sellers often with upwards of $100,000 in their accounts on Amazon before pulling the cash out. If someone were able to gain access to a seller account (I'm not sure if this 'exploit' would have worked for a seller account or not), that could have been quite financially painful for some people.
- Wingman4l7 14y agoWhy are they leaving so much in their accounts? Amazon is not a bank, and as such they're probably not subject to the same regulations. We've already seen this issue with people leaving too much money in winnings in online poker accounts, or PayPal accounts.
- deleted 14y ago[deleted]
- mattacular 14y agoLeaving that amount of money anywhere other than in an FDIC insured bank is incredibly irresponsible. Arguably as irresponsible as Apple's decision to require the last 4-digits of a credit card to gain access to iCloud, where a malicious intruder could arguably do way more damage, on average. I could walk up to an ATM behind someone and get the last 4 of their card all day long. It is printed on every single receipt you've ever gotten.
- larrys 14y agoFor those not aware whenever a journalist uses the term "quietly" it equates to "didn't issue a press release" or post publicly in an announcement.
- arrrg 14y agoYeah, and? What else would it equate to? Press releases and public announcements are how a company communicates. If a company changes something without communicating, they changed something quietly. I’m not really understanding what point you are trying to make. What is there to misunderstand about that “quietly”?
- jakeludington 14y agoWhile they have closed the loophole for adding credit cards, you can apparently still change your email or password via phone: http://www.forbes.com/sites/kellyclay/2012/08/07/amazon-tightens-security-after-high-profile-hacking-sort-of/ http://www.forbes.com/sites/kellyclay/2012/08/07/amazon-tigh...
- nohat 14y agoIf you can change the email or password by phone, then nothing is solved. Adding the credit card was, as I understand, simply because amazon required a credit card number on the account (possibly last four digits).
- davros 14y agoIs it possible to prevent a remote wipe by Apple? Or at least so it is only possible with knowledge of my password? If I lose both my MBA and my password, I am ok with not being able to remote wipe. EDIT: OK, I can disable remote wipe entirely by disabling 'find my mac'.
- X-Istence 14y agoIt is only possible if you know your iCloud username and password. Now the reason why the attacker was able to remote wipe is because he had the iCloud username and the newly generated password.