6 ms·
Here's a working hypothesis: | Why is Amazon's security for replacement orders so lax? Amazon values customer satisfiction above their fraud write-off. | Why
by sdrinf 12y ago
Here's a working hypothesis:
| Why is Amazon's security for replacement orders so lax?
Amazon values customer satisfiction above their fraud write-off.
| Why would they send a replacement to an address that has never been associated with me, and is in a wholly different state than the one the original item was sent to?
Because the time between ordering an item, and defect can be sufficiently large to cover moves: people shift around all the time. It's entirely concievable you'd like to exercise replacement rights from Texas, even though you've ordered it from NY.
| How did the scammer know about my order in the first place to social engineer the replacement request?
Via: either buying order requests, using third-party honeypots to capture your info, using the domain registrar, or a combination of any of these.
| Why haven't Amazon black-listed the 13820 NE Airport Way; Portland, Oregon address as a destination for replacements? This package drop address shows up again and again when you Google around for people who have been hit by Amazon scams.
I suspect this might be http://reship.com/ http://reship.com/ (Alexa rank: 166K). This is entirely legit: if you're a UK customer who'd like to buy stuff that are exclusively US-only, reshippers are the cheapest way to do so. Based on their Alexa rank, I suspect Amazon makes quite a money on these customer segments. Blacklisting them also wouldn't help this case: reshipping companies can easily buy up a handful of different addresses in a range of cities, making this a game of whack-a-mole.
| Can I really trust this company to hold multiple credit card numbers of mine in their database, one click away from someone potentially ordering thousands of dollars of merchandise that they can apparently easily redirect to an address that should have been black-listed years ago, if there were any kind of sane security policy in place?
Note that no credit card, or password database has been compromised in executing this attack. This is social engineering corporate goodwill at it's vilest.
I suspect the root cause of this issue to be the friction-less execution of this engineering. A proper solution for this problem might be as simple as sending out an email with clickthrough-link-confirmation before replacement shipping; this would raise the bar from "knowing about an order" to "knowing about an order, and having an active compromise on the mark's inbox".
- jamespo 12y agoCertainly a confirmation email should be sent when the address is new
- georgemcbay 12y agoYeah this is what kills me; if I send something legitimately to an address it hasn't seen for me before it requires me to re-enter my full credit card number and other information to prove I am me; I don't understand why they don't do the same for replacement orders. It doesn't seem like that hard of a problem to solve when not solving it means they are out $1000 worth of product from my account alone times however many people this has happened to.
- SoftwareMaven 12y agoBut when you add a new address to your account, shipping to that new address could cost you money. When Amazon ships a replacement to a new address, it could cost them money. The risk profile is very different, so the implementation is different. For the record, I don't understand why Amazon keeps allowing this. It seems like it could be fixed without much of a hit on customer experience, and the fraud ultimately does cost all of us more, as they have to cover those costs through higher prices.
- largote 12y agoBecause someone can argue that they don't have access to their email right now (on a trip or something). Or that the associated email has "been hacked".
- enscr 12y ago> email has "been hacked". But that's probably a big reason to _not_ let the orders through.
- MichaelGG 12y agoAnd contribute further to the customer's unhappiness? "I got hacked near Christmas, and then Amazon wouldn't help me so some of my presents didn't get delivered right." I don't see why anyone cares if Amazon is liberal in replacements. So long they're not somehow hurting your account standing with Amazon, it's Amazon's choice.
- enscr 12y agoI wouldn't want my e-commerce store to fulfill orders for a compromised account without talking & confirming some key details with the customer. This HN post is testament to some funky ordering going on. My experience has been positive with Amazon and there has been situations where they've gone out of their way to make the customer happy. I'm fairly confident that a situation like yours can be resolved with Amazon over phone.
- Fuxy 12y agoYou can access email from just about anywhere with a internet connection. It's not Netflix you don't need to stream anything any crappy connection will do. I find it hard to believe you're unable to check your email for weeks. Unless you don't want to but then don't complain at that time.
- genericuser 12y agoLots of people still don't have smart phones, or computers they travel with. And so they do not use email when they travel. And believe it or not there are still people in this world that may only have an email address with their employer which they don't access regularly outside of work. And now back to the original article: We are only getting one of many parts of this story, for all we know the scammer perfectly told a sob story about ordering a gift for their grandson who they haven't seen in several years and will be visiting soon but it didn't arrive in time for their trip and now would like it sent directly to the grandson while they are visiting him so they can still see the joy their gift will bring him. My point is I don't assume that Amazon isn't trying pretty hard to prevent this fraud, and I don't assume scammers aren't putting in quite a bit of work to commit it.
- leorocky 12y ago> | How did the scammer know about my order in the first place to social engineer the replacement request? Via: either buying order requests Looks like you can buy order requests from people who social engineered order numbers out of amazon reps via chat. A rep from amazon provided someone who didn't authenticate themselves amazon order numbers [1]. > using third-party honeypots to capture your info, using the domain registrar, or a combination of any of these. But how does a "third-party honeypot" capture your activity on Amazon? What does a domain registrar have anything to do with placing orders on Amazon? [1] http://www.htmlist.com/rants/two-for-one-amazon-coms-socially-engineered-replacement-order-scam/ http://www.htmlist.com/rants/two-for-one-amazon-coms-sociall...
- cthalupa 12y ago>What does a domain registrar have anything to do with placing orders on Amazon? See someone make a blog post on their site about buying an Xbox from Amazon. Get WHOIS data from registrar. Have name and address of person who purchased Xbox. Use details to request replacement
- quackerhacker 12y agoI can't even imagine the justification in a board meeting that allows for shrinkage on their scale for such an easy resolution. To me, a simple resolution would be to escalate the "item not received," issue to a state side department (not in India, from what I'm understanding), track recent orders and customer interaction (super simple algorithm), and lastly and MOST importantly do not allow customer orders to be given out so freely with a verification of address and name (at least require an account pin or last 4 digits for the order in question). If Amazon implemented at least these barriers, then the security of an account would fall where it should...back on the owner...not so easily be phished through Whois data, or just knowing someone has an Amazon account. It's almost as if a black hat could use a phone book and tie names, with addresses and phone numbers and straight phish for data. This is just way too easy for fraud that the fact that it's Amazon is appalling.
- georgemcbay 12y ago> Amazon values customer satisfiction above their fraud write-off I do get this, and as an Amazon customer, I'm glad this is their stance overall, but on the other hand it seems like they could handle this situation more securely than they do. It seems to me that you could have some sane middle ground where you do no-questions asked replacements, but with some caveats like no ability to change the address the item is being sent to from the original order unless the person you are communicating with can prove they are the account owner. Maybe have a sort of two-factor system where the CSR can mark the order as "replacement approved" but you have to login to your Amazon account and take some action (just click a confirm button or whatever) to actually send the order out. At least in that case you wouldn't get cases like mine where someone managed to pull a replacement order without (seemingly) ever having actually had access to my Amazon account.
- gdh73 12y agoI'd think this could be prevented by a) stop giving out order numbers via chat and b) require customers to request replacements (or at least confirm them as you've suggested) by logging into their account.
- MichaelGG 12y agoAs someone that moves around a lot, I appreciate how willing Amazon is to take care every order-related issue, with zero fuss. I fail to see what the "security" issue is, other than Amazon choosing to lose some money on fraud. That's not a security issue to anyone outside of Amazon, and Amazon seems clear in their stance. Edit: A much bigger problem is Amazon's use of OnTrac, which repeatedly fails to make deliveries. Even in downtown SF.
- opendais 12y ago> Amazon values customer satisfiction above their fraud write-off. I doubt this is the case. I've had to place chargebacks against Amazon to get my money back for purchases that were not delivered due to Amazon screwing up and telling the vendor that the software key(s) were not purchased. For anything software related, they offer no refunds even when they and/or their vendor screw up to the point the product is unusable.
- hga 12y agoI thought they had an "ultimate" get your money back option, with the big limit of your only being able to invoke it 5 times in your life. I started to do it once, during which I noticed the limit and decided to reserve it for really big purchases. I have noticed that there doesn't seem to be any category of items sold by 3rd parties with more fraud than software, although this doesn't sound like such a case. What does Amazon do after you place a chargeback against them?
- opendais 12y agoSo far, nothing. I got my money back because they couldn't deliver the software during the entire dispute window. That being the case, the Credit Card company just handed me my money back. From what I can tell, Amazon failed to process the chargeback correctly on their end and the order doesn't show it was ever done on Amazon's end. I'm not really surprised. The last email I got from them on the subject was that the software was now available like 3-4 days after the dispute ended. I didn't even bother to download it since I just got it elsewhere with the refunded $$. However, I didn't do the chargeback until after 3 separate CSRs [including 1 from the vendor] all told me they wouldn't do a refund.
- deleted 12y ago[deleted]
- jdminhbg 12y ago> I doubt this is the case. I've had to place chargebacks against Amazon to get my money back for purchases that were not delivered due to Amazon screwing up and telling the vendor that the software key(s) were not purchased. There may be a difference between how they treat physical and digital purchases then, because my experience (and the experience of vast numbers of internet commenters) is that Amazon will refund or replace a physical order with basically zero investigation.
- panarky 12y agothe scammer just needed the name, email and billing address associated with their accounts Guess what, eBay just leaked 150 million names, emails and addresses. This will be a goldmine for scammers. http://www.businessinsider.com/amazon-replacement-fraud-2014-6 http://www.businessinsider.com/amazon-replacement-fraud-2014...
- yallarestupid 12y agoFirst of all you are a moron. The person had access to your account either by using a rat, key logger rat malware. Maybe you should first change your password and passwords to your email. Once someone logs into your amazon account they can see everything you ordered. Obviously changing your card which is on file is not that hard either along with your address. From there they hop onto live chat and well then your fucked. Why are you so bitchy about this, he logged into your amazon account and saw something to replace, he didnt miraculously find your order number.