TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Amazon admits it exposed customer email addresses, but refuses to give details

521 pointsby Ours90over 6 years ago

17 comments

edooover 6 years ago
When I started selling the first gadget I ever made on Amazon I was so excited and was only getting a couple sales a month. If you were one of my customers I looked at your house, judged your grass, found you on LinkedIn and Facebook, Instagram, mortgages, mugshots, everything lol. The sellers also get your full name and address even on fulfilled by Amazon.<p>If you have been on the net long enough this will creep you out: <a href="https:&#x2F;&#x2F;haveibeenpwned.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;haveibeenpwned.com&#x2F;</a>
评论 #18505171 未加载
评论 #18505530 未加载
评论 #18507799 未加载
评论 #18504551 未加载
评论 #18508735 未加载
评论 #18504872 未加载
评论 #18506670 未加载
评论 #18509445 未加载
评论 #18505992 未加载
评论 #18510168 未加载
评论 #18510182 未加载
评论 #18510185 未加载
评论 #18508298 未加载
评论 #18508636 未加载
kullover 6 years ago
This is how it looked for me: I few days ago I was shopping on Amazon and they showed me a message, you already purchased this product. See order details. I was surprised since I did not buy it before. After clicking the link, I was shown details of not my order, including name, address and email where a product was shipped to.
评论 #18506674 未加载
评论 #18507805 未加载
评论 #18507809 未加载
评论 #18511884 未加载
评论 #18507828 未加载
评论 #18507668 未加载
fredleyover 6 years ago
This is one of the less appreciated clauses of the GDPR: That companies are <i>required</i> to disclose data breaches within a reasonable time-frame, and users <i>have the right</i> to know about any exposure of their data.
评论 #18505300 未加载
评论 #18504162 未加载
ben509over 6 years ago
&quot;Besides the brevity, what&#x27;s giving people pause is they sign the email <a href="http:&#x2F;&#x2F;Amazon.com" rel="nofollow">http:&#x2F;&#x2F;Amazon.com</a> Why cap the &quot;a&quot; and why no <a href="https:&#x2F;&#x2F;" rel="nofollow">https:&#x2F;&#x2F;</a>? Strange&quot;<p>This one is easy to answer: the customer support people aren&#x27;t particularly technical. In many ways, Amazon is a weird mashup of a traditional retailer and a tech company.
评论 #18507894 未加载
评论 #18506839 未加载
jiveturkeyover 6 years ago
based on spam email i have received, that i clearly should not have, i believe this was an exposure to marketplace sellers from whom you have bought a product.<p>I am <i>very</i> careful with my email. i’m not just guessing here. i actually reported it to amazon security. (no answer from them of course.)
评论 #18504254 未加载
评论 #18504264 未加载
评论 #18504481 未加载
评论 #18504851 未加载
评论 #18507117 未加载
sharkweekover 6 years ago
Amazon is being so strangely cagey about this - I followed up on the email asking who saw my email, and they sent back the exact same response.
rhizomeover 6 years ago
Aren&#x27;t all programming mistakes and bugs &quot;technical errors?&quot;
hef19898over 6 years ago
One comment further down stated that it might have affected marketplace sellers. Amazon doesn&#x27;t really put the same amount of thought and resources on marketplace than Amazon retail even if they should IMHO.<p>Regardless, that&#x27;s AFAIK the first time that ever happened to Amazon. Bad enough if it was third party sellers. A catastrophe if it was Amazon customers. With all the controversy regarding counterfeits in some countries an incident that bears the risk of impacting customer trust is the last thing Amazon needs. Maybe I should have sold my stock 4 months ago... But maybe Q4 will be stellar and stock goes up again in January. I should think about a stop order, just in case Q4 disappoints that year.
rdiddlyover 6 years ago
An email address isn&#x27;t secret, is it? It&#x27;s sent back and forth in clear text through any number of relay servers. I consider my name and email address to be basically public information. Along with (unfortunately) my Social Security number.<p>If Amazon exposed any data fields <i>more</i> sensitive than email address, I would call that stonewalling&#x2F;covering up as TC seems to be implying. But otherwise it kind of just sounds like TC being all petulant that Amazon wouldn&#x27;t tell it everything it wanted to know. And the motivation there is likely to be the generation of clicks, not the protection of customers.<p>Take the &quot;number of users affected&quot; for example. Knowing that info doesn&#x27;t help any individual customer. But it does help journalists drum up pageviews, or at least I feel like <i>they believe</i> it does. Having a big number in there is like this (dubious) Holy Grail of page-irresistability. I&#x27;m just judging from how, for example, the reporters on the TV news always bug their eyes out and raise their voice and talk really slowly and emphatically any time they come to a number. &quot;The pool was reported to be FOURTEEN FEET DEEP...&quot; &quot;The petition has THIRTY THOUSAND signatures...&quot; Wow! A number! I&#x27;m supposed to be all impressed I guess! <i>ZOMG let me throw all my money at you right now!!!!</i>
评论 #18505213 未加载
评论 #18506615 未加载
评论 #18506427 未加载
评论 #18505517 未加载
评论 #18505493 未加载
moneil971over 6 years ago
Every major tech company has had this problem, yet people still keep sharing their personal info (even home address, phone numbers, social security numbers) online. Don&#x27;t share anything you wouldn&#x27;t yell out on a crowded street to strangers.
jumpinalakeover 6 years ago
The video advertisement on the linked webpage crashed Safari on my iPhone.
danielorover 6 years ago
Hmm... it seems this drip of bad news in big tech is setting up for some heated debates on regulation. It will be interesting how proactive the Europeans are with GDPR.
评论 #18505252 未加载
gnulinuxover 6 years ago
I don&#x27;t understand this. In the American startup I&#x27;m working we&#x27;re extremely careful with respectful data practices due to ethics and GDPR (we have a lot European customers). Why doesn&#x27;t Amazon give a shit about GDPR? Do they have a leverage?
评论 #18505223 未加载
评论 #18506064 未加载
erbiumover 6 years ago
Would explain the billions of new spam emails I&#x27;ve been receiving.
Tsubasachanover 6 years ago
Amazon and my spam filter have a long and intimate relationship.
garysahota93over 6 years ago
Wasn&#x27;t there another post on HN of this?
评论 #18504780 未加载
isarangover 6 years ago
Watch this space <a href="https:&#x2F;&#x2F;amazon.com&#x2F;profile" rel="nofollow">https:&#x2F;&#x2F;amazon.com&#x2F;profile</a>