![[personal profile]](https://www.dreamwidth.org/img/silk/identity/user.png)
A hacker has discovered -- and, happily, disclosed -- a "blind spot" between Apple and Amazon's identity and account verification procedures:
Details are here and here.
I have to say this had never occurred to me as a way to game the system, but it's scary easy because so much information is available online (names, addresses, phone numbers, email addresses) and I'll bet can be done with other paired accounts as well. I know how many places use the last 4 digits of your credit card as verification.
Amazon claims this has since been fixed, but I have my doubts. My wallet was stolen last year and within four hours I had closed all my credit and debit cards, but the thief got my debit card turned back on via the simple route of calling my bank, pretending to be me, and telling them the card had only been lost and was now found. Wow.
It's almost enough to make you leave ze interwebz entirely. Almost, because otherwise where would I go for beta readers??
Details are here and here.
I have to say this had never occurred to me as a way to game the system, but it's scary easy because so much information is available online (names, addresses, phone numbers, email addresses) and I'll bet can be done with other paired accounts as well. I know how many places use the last 4 digits of your credit card as verification.
Amazon claims this has since been fixed, but I have my doubts. My wallet was stolen last year and within four hours I had closed all my credit and debit cards, but the thief got my debit card turned back on via the simple route of calling my bank, pretending to be me, and telling them the card had only been lost and was now found. Wow.
It's almost enough to make you leave ze interwebz entirely. Almost, because otherwise where would I go for beta readers??
no subject
Date: 2012-08-08 01:50 am (UTC)Thanks for sharing!
Adding now that Apple is just as vulernable, if not more so, than windows.
Sooo glad I dont use iCloud.
no subject
Date: 2012-08-09 03:30 am (UTC)no subject
Date: 2012-08-08 03:46 am (UTC)no subject
Date: 2012-08-09 03:33 am (UTC)no subject
Date: 2012-08-08 07:17 am (UTC)Fortunately I don't have an apple account, and I'd hope they've learned from this lesson!
no subject
Date: 2012-08-09 03:34 am (UTC)no subject
Date: 2012-08-08 02:13 pm (UTC)no subject
Date: 2012-08-09 03:35 am (UTC)no subject
Date: 2012-08-15 02:16 pm (UTC)Sorry about your wallet, though! This is probably a silly question, but did the thief ever get caught?
no subject
Date: 2012-08-15 11:47 pm (UTC)