11 ms·
This seems like a cool idea, but I don't feel comfortable giving out my Amazon credentials with no guarantee of how they are used.
by bearbin 12y ago
This seems like a cool idea, but I don't feel comfortable giving out my Amazon credentials with no guarantee of how they are used.
- pdabbadabba 12y agoAgreed. My understanding is that having your password does not necessarily allow someone to see your CC number or order things on your behalf through Amazon, but it definitely does not seem like a best practice to go around handing out one's Amazon password. This sort of thing sounds like a good argument, though, for Amazon's implementing the sort of fine-grained permissions (in conjunction with a federated authentication system like oauth) one finds on twitter, FB, Google, and other services with a well-developed API and ecosystem. I would happily authorize a site like this to view my order history, even if I would not be willing to provide my password.
- ChristianKletzl 12y agoI wish Amazon would implement this. We see them visiting our site a lot. If you read this, dear Amazon employee, please implement :)
- mritun 12y agoIt's in progress: http://login.amazon.com http://login.amazon.com
- sliverstorm 12y agoAlso highly risky is AWS. Maybe an attacker can't order diamond rings for themselves, but they certainly could spin up a million EC2 instances to mine bitcoin. The cost efficiency is terrible of course, but what do they care.
- ChristianKletzl 12y agoWe haven't tested that, but I highly recommend (regardless of using ShelfFlip) to use "Multi-Factor Authentication" for AWS.
- Corrado 12y agoWhile MFA is a great idea and I highly recommend it, it doesn't do anything to prevent API access. :(
- schrodinger 12y agoHow could having your password not allow someone to order things on your behalf? All I need to get into my account is my password, and then I can order anything I want.
- cylinder 12y agoIf you want to ship to a new address (not in your address book), Amazon requires you to re-input your card number.
- pdabbadabba 12y agoFair point. They can order things on your behalf, but cannot easily order things for THEMSELVES on your behalf since they can't enter a new shipping address without reentering the card number. But that doesn't totally eliminate the risk. They could be prepared to swipe the stuff off your porch when it's delivered (since they could predict when this would be) or they could use their power to simply harass you.
- ChristianKletzl 12y agoIs there anything we could do to make you (and many more with the same sentiment) more comfortable? We are thinking of writing a blog post of what happens in the background would that help? Any other ideas?
- cleverjake 12y agoA giant "Why we are asking for this" would be a great start
- mileswu 12y agoJust an off-the-top-of-my-head idea: Could you give people a bookmarklet or an extension that they can run when they are on their order history page that exports all the Amazon product IDs?
- jaredsohn 12y agoI was going to write something similar to this. One issue, though, is that it doesn't necessarily track new purchases. To do that as well, it needs to be an extension and it should also monitor whenever you buy something. If there is a concern that purchases might happen when on another computer, you could allow the user to enter their password into the extension so that the extension can monitor things for you in the background. While users don't have a guarantee that the extension is using the password securely, at least it is possible for the source code to be inspected.
- J3ff0 12y agoYou can actually download your entire order history as a CSV (which is kind of fun -- on the account page, find "Download Order Reports"), which could then be uploaded into this service to get a report on everything you've purchased. The only sensitive information included in the report is name and address.
- pdabbadabba 12y agoI'm not sure, but Mint.com seems like a good place to look for ideas. They have somehow persuaded me and millions of others to hand over all our banking passwords. Gaining this trust, though, will probably not be easy. One advantage a site like Mint has is that they have so much content and so many partnerships that it is clear they are not a scam, have enough at stake to not misuse my information, and probably have the resources to keep it safe. A site like yours, however, could easily have been cobbled together in a number of hours by a scammer. (I don't mean this as a criticism -- I actually like your site. It just doesn't have anything on it to suggest that you are the sort of business I can trust with my passwords.)
- melvinmt 12y agoAmazon already has an OAuth solution: http://login.amazon.com http://login.amazon.com
- ChristianKletzl 12y agoUnfortunately, this only works as a login mechanism comparable to facebook, but doesn't give a site access to your past purchases.
- gnu8 12y agoWould it help you to know that Shelflip is secured by Norton secured and ex-Google Engineers?
- justinph 12y agoNo. You can put anything you want in text or graphics on the screen. You need to send people to a secure amazon.com login page and pass an OAuth token.
- sahaskatta 12y agoI agree. If my Amazon credentials are stolen, here's what I have at risk: - My credit card details (multiple) - Shipping / billing addresses - My private order history 5+ years - Access to all my AWS instances - Amazon Cloud Drive data - And I'm probably forgetting a few... With that being said, even services like Mint.com require handing over your bank's password to them even today. It's really not a good practice even if they are stored securely.
- toomuchtodo 12y agoTried Shelfflip, minutes later received this email from Amazon: "Your Amazon.com password has been changed" This is an important message from Amazon.com. As a precaution, we've reset your Amazon.com password because you may have been subject to a "phishing" scam. Here's how phishing works: A scam artist sends an e-mail, which is designed to look like it came from a reputable company such as a bank, financial institution, or retailer like Amazon.com, but is in fact a forgery. These e-mails direct you to a website that looks remarkably similar to the reputable company's website, where you are asked to provide account information such as your e-mail address and password. Since that web site is actually controlled by the phisher, they get the information you entered. Go to amazon.com/phish to read more about ways to protect yourself from phishing. To regain access to your Amazon customer account: 1. Go to Amazon.com and click the "Your Account" link at the top of our website. 2. Click the link that says "Forgot your password?" 3. Follow the instructions to set a new password for your account. Please choose a new password and do not use the same password you used with us previously. Thank you for your interest in Amazon.com.
- canvia 12y agoI wonder why more sites don't allow you to create a second read only set of credentials for your account. This would solve a lot of trust issues when using a service like this or say for online banking services like Mint. If you want to stream Netflix/Amazon from an insecure computer would be another use case.
- pnathan 12y agoWord. I am not giving my Amazon credentials to a site that just launched.