Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

How did this Chris Cardinal guy find out about the original camera order, if he didn't have access to htmlist@gmail.com?


Further down in the article I mention that a possible vector was that I tweeted from my personal Twitter that I was considering buying a T4i and that someone searching for that might consider me a target and try.

It's definitely an interesting question, but it's clear he was just hunting and pecking, which is why he wanted all the order numbers from November and December... not sure if he initiated a few other chat sessions to figure out what was in each order and found a high-ticket item to pursue, or what, but it's a good question... I don't know what made me an initial target at all.

Interestingly enough, Amazon offers a "Tweet this purchase" option which I did NOT avail myself of, but which would definitely exacerbate this problem.

(Also, my name is Chris Cardinal. I don't know the scammer's name, but of course he couldn't request Amazon to change the shipping address AND the name for the replacement order. That would be a bridge too far.)


Ah, didn't realize he used the same name. So potentially

1) first chat session with Amazon support to claim that he lost access to his email and needs order #s (which is what you've tested out, and it works)

2) subsequent sessions from different accounts with various dot placements to inquire about the status of specific order #s

3) when a high-value item is found, sticking to the original dotted address, and asking for replacement

Is your mailing address available from public sources?


Yep, it was on the whois for several of my domains. I've since privatized them, but the caches will remain. Oh, how they'll remain.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: