Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Actually, I do have 2FA enabled on my account. But I don't think I had it enabled at the time for the very first attack.

Interestingly, last night I did get an SMS: "Message from Amazon Customer Service: xxxxx is your Amazon security code" even though my 2FA is not an SMS (it's using authenticator).

I don't have access to the recording, so I have no idea what actually happened. But based on the email ("here's the details" on your order) I'm almost certain they were successful. Probably just told them that they lost the phone, or something. At this point, they've now been able to get almost everything possible about me.

Also interestingly, not once did Amazon recommend that I use 2FA to avoid social engineering. I was told by two different support reps to change my password though.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: