Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yeah, regarding amazon: http://imgur.com/a/yaI4B

That took 2 calls.



What am I looking at here?


Internal Amazon stuff, including the customer service tools that can be used to access anyones account, change their passwords etc...


Some top-notch social engineering there.


You'd think Amazon could afford to run a more competent show. When did this happen? Did you do this or you just had screens lying around? :) Can you recommend any cloud provider that is half sane? I was browsing around lately because I might want to start a project on the side, was disappointed that OVH was hacked recently, now Amazon.


> When did this happen?

Some of the screenshots have dates in them

>Did you do this or you just had screens lying around?

:)

>Can you recommend any cloud provider that is half sane?

Cloud providers suck. But I suppose google, softlayer and rackspace might suck a little less. But why not run on metal? It's cheaper and more secure.


Are you just bragging? I don't know what to get out of this other than that but maybe there's a point I'm missing.


My point was that this isn't just something that happens "on occasion", but a far more serious problem.

Trust me, your local FBI field office wouldn't fare any better.


That is fair. There is no system administered by humans that is free of human frailty.


I am very curious. Can you briefly explain what do you mean by "that took 2 calls"?


There's screenshots demonstrating access to two different Amazon support terminals (IRC screenshots are from a different terminal), access to both was gained during two successive calls to the main Amazon US number.

This did not require multiple attempts. The employees believed everything they were told and both remained on the calls for as long as they were asked to, demonstrating utter lack of training.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: