Skip to content
0
  • Home
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
  • Home
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Sketchy)
  • No Skin
Collapse

Wandering Adventure Party

  1. Home
  2. Uncategorized
  3. PSA: The Amazon wishlist doxing threat is much greater and more immediate than folks might realize.

PSA: The Amazon wishlist doxing threat is much greater and more immediate than folks might realize.

Scheduled Pinned Locked Moved Uncategorized
45 Posts 28 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • CassandrichD Cassandrich

    PSA: The Amazon wishlist doxing threat is much greater and more immediate than folks might realize. Attack works like this:

    Stalker who wants your address opens an Amazon seller account and lists themselves as a third party seller for any item on your public wishlist. Then, they order the item from themselves as a gift for you. Bam, they have your address.

    In particular, attack does not depend on an existing third party seller having poor PII handling hygiene, like the articles have implied.

    Johan Pelck OlsenJ This user is from outside of this forum
    Johan Pelck OlsenJ This user is from outside of this forum
    Johan Pelck Olsen
    wrote last edited by
    #41

    @dalias I don’t understand why anyone would ever want a public wishlist, even disregarding stalkers and the like. Seriously, how is it of public interest that you’d like a new bathrobe?

    CassandrichD 1 Reply Last reply
    0
    • CassandrichD Cassandrich

      Note that even PO boxes are not particularly safe against a dedicated stalker. They can stake out the PO for someone picking up a distinctive package once they know what PO it's at.

      Piggo :verified_horse:P This user is from outside of this forum
      Piggo :verified_horse:P This user is from outside of this forum
      Piggo :verified_horse:
      wrote last edited by
      #42
      @dalias must be missing decision log or something, like they fired the guy making the original assessment of the security issue and the information was lost
      1 Reply Last reply
      0
      • CassandrichD Cassandrich

        PSA: The Amazon wishlist doxing threat is much greater and more immediate than folks might realize. Attack works like this:

        Stalker who wants your address opens an Amazon seller account and lists themselves as a third party seller for any item on your public wishlist. Then, they order the item from themselves as a gift for you. Bam, they have your address.

        In particular, attack does not depend on an existing third party seller having poor PII handling hygiene, like the articles have implied.

        RootbrianR This user is from outside of this forum
        RootbrianR This user is from outside of this forum
        Rootbrian
        wrote last edited by
        #43

        @dalias Thankfully I have no wishlist. I just add items to the cart and leave 'em there indefinitely until I decide to purchase at a later date, or remove them if I don't. I rarely order anything at all online since most stores have what is commonly available.

        1 Reply Last reply
        0
        • draNgNonD draNgNon

          @dalias so to be clear, just setting the lists private is an immediate mitigation?

          I haven't touched this feature since... apparently 2020 (and have only ordered one thing from Amazon since WaPo declined to endorse Harris and I dropped Prime like a hot potato). if I can take it private now and reconsider the existence of these lists entirely when I have more time to do so, that is better for me.

          CassandrichD This user is from outside of this forum
          CassandrichD This user is from outside of this forum
          Cassandrich
          wrote last edited by
          #44

          @draNgNon That's my understanding.

          1 Reply Last reply
          0
          • Johan Pelck OlsenJ Johan Pelck Olsen

            @dalias I don’t understand why anyone would ever want a public wishlist, even disregarding stalkers and the like. Seriously, how is it of public interest that you’d like a new bathrobe?

            CassandrichD This user is from outside of this forum
            CassandrichD This user is from outside of this forum
            Cassandrich
            wrote last edited by
            #45

            @jpkolsen It's a way for fans to compensate people whose work they appreciate who can't easily take payment. AIUI one big place this comes up, and where doxing is a huge threat, is sex work. But really for anyone doing things where there's a parasocial relationship with an audience the same applies.

            1 Reply Last reply
            0
            • AngelaA Angela shared this topic

            Reply
            • Reply as topic
            Log in to reply
            • Oldest to Newest
            • Newest to Oldest
            • Most Votes


            • Login

            • Login or register to search.
            Powered by NodeBB Contributors
            • First post
              Last post