PSA: The Amazon wishlist doxing threat is much greater and more immediate than folks might realize.
-
PSA: The Amazon wishlist doxing threat is much greater and more immediate than folks might realize. Attack works like this:
Stalker who wants your address opens an Amazon seller account and lists themselves as a third party seller for any item on your public wishlist. Then, they order the item from themselves as a gift for you. Bam, they have your address.
In particular, attack does not depend on an existing third party seller having poor PII handling hygiene, like the articles have implied.
@dalias every single engineer I've seen talking about this has immediately identified this attack, so it's guaranteed that this will be exploited right away if it goes ahead (and also that Amazon absolutely knows about it)
-
@dalias (and I also hate the tendency of everything from walmart to digikey to turn into a "marketplace" lately. At one point you could buy oscilloscope software options on walmart's website because TEquipment had a storefront there)
@dalias just make a store to sell your products, and let me know i'm buying from you, a company i presumably trust to some extent. that's it, do one thing, do it well
-
The only mitigations are refraining from using public wishlists entirely (set any wishlists you may have to private) or using a PO box or reshipping service to conceal your real physical/final address.
@dalias
Never make a "wishlist" public, or share it. -
@dalias every single engineer I've seen talking about this has immediately identified this attack, so it's guaranteed that this will be exploited right away if it goes ahead (and also that Amazon absolutely knows about it)
@alex They obviously knew about it since the beginning. That's why gifts were limited to fulfilled-by-Amazon. Then some piece of shit manager with no understanding of safety wanted to make the sketchy marketplace more lucrative to sellers to compete in race to bottom.
-
PSA: The Amazon wishlist doxing threat is much greater and more immediate than folks might realize. Attack works like this:
Stalker who wants your address opens an Amazon seller account and lists themselves as a third party seller for any item on your public wishlist. Then, they order the item from themselves as a gift for you. Bam, they have your address.
In particular, attack does not depend on an existing third party seller having poor PII handling hygiene, like the articles have implied.
@dalias I'm hoping we can use this opportunity to get people off of Amazon.
-
PSA: The Amazon wishlist doxing threat is much greater and more immediate than folks might realize. Attack works like this:
Stalker who wants your address opens an Amazon seller account and lists themselves as a third party seller for any item on your public wishlist. Then, they order the item from themselves as a gift for you. Bam, they have your address.
In particular, attack does not depend on an existing third party seller having poor PII handling hygiene, like the articles have implied.
@dalias A couple of guys I trained with in martial arts, are in a paramilitary group, and are now planning a para-doxing welcoming committee.
-
@dalias Or just mail you a tracker.
-
PSA: The Amazon wishlist doxing threat is much greater and more immediate than folks might realize. Attack works like this:
Stalker who wants your address opens an Amazon seller account and lists themselves as a third party seller for any item on your public wishlist. Then, they order the item from themselves as a gift for you. Bam, they have your address.
In particular, attack does not depend on an existing third party seller having poor PII handling hygiene, like the articles have implied.
@dalias holy shit, wow. I appreciate that heads up. Thank you.
-
@alex They obviously knew about it since the beginning. That's why gifts were limited to fulfilled-by-Amazon. Then some piece of shit manager with no understanding of safety wanted to make the sketchy marketplace more lucrative to sellers to compete in race to bottom.
@dalias exactly. They could also have trivially made wishlists with that setting private, which would at least limit the immediate harm, but that doesn't goose the wishlist metrics
-
@dalias
Never make a "wishlist" public, or share it.That would be nice, but a lot of people are using them as teachers for classroom supplies now or charities using them to get donations of supplies they need.
-
@dalias
Never make a "wishlist" public, or share it.@raymaccarthy @dalias true and even if this is how 'streamers' and 'content creators' grift, this is also used as a tool for mutual aid.
-
@raymaccarthy @dalias true and even if this is how 'streamers' and 'content creators' grift, this is also used as a tool for mutual aid.
@erikcats @raymaccarthy I'm not sure how accepting gifts from ppl who enjoy you entertaining them is "grift".
-
@erikcats @raymaccarthy I'm not sure how accepting gifts from ppl who enjoy you entertaining them is "grift".
@dalias @raymaccarthy i'm sorry, probably too jaded - milking parasocial relationships goes into the grift pigeonhole immediately. Your phrasing is a lot more generous, you're right
-
PSA: The Amazon wishlist doxing threat is much greater and more immediate than folks might realize. Attack works like this:
Stalker who wants your address opens an Amazon seller account and lists themselves as a third party seller for any item on your public wishlist. Then, they order the item from themselves as a gift for you. Bam, they have your address.
In particular, attack does not depend on an existing third party seller having poor PII handling hygiene, like the articles have implied.
@dalias With all of the current digital surveillance we are subjected to, that should not have been possible
-
PSA: The Amazon wishlist doxing threat is much greater and more immediate than folks might realize. Attack works like this:
Stalker who wants your address opens an Amazon seller account and lists themselves as a third party seller for any item on your public wishlist. Then, they order the item from themselves as a gift for you. Bam, they have your address.
In particular, attack does not depend on an existing third party seller having poor PII handling hygiene, like the articles have implied.
@dalias wait, does this coincide with the Mail I got from Amazon about third party sellers being allowed. Guess I'll delete my wishlist now. Haven't used it in years anyway 😬😬
-
PSA: The Amazon wishlist doxing threat is much greater and more immediate than folks might realize. Attack works like this:
Stalker who wants your address opens an Amazon seller account and lists themselves as a third party seller for any item on your public wishlist. Then, they order the item from themselves as a gift for you. Bam, they have your address.
In particular, attack does not depend on an existing third party seller having poor PII handling hygiene, like the articles have implied.
@dalias Again I Think logistic companies coming as intermediaries can serve to shield our Addresses since only their addresses will be given
-
Note that even PO boxes are not particularly safe against a dedicated stalker. They can stake out the PO for someone picking up a distinctive package once they know what PO it's at.
@dalias Thanks for the heads up on this. Deleted all my wishlists and set the default to private.
-
PSA: The Amazon wishlist doxing threat is much greater and more immediate than folks might realize. Attack works like this:
Stalker who wants your address opens an Amazon seller account and lists themselves as a third party seller for any item on your public wishlist. Then, they order the item from themselves as a gift for you. Bam, they have your address.
In particular, attack does not depend on an existing third party seller having poor PII handling hygiene, like the articles have implied.
@dalias I would have expected that wish listing something would mark that exact product from that exact seller as the thing you want. Like... I want this known authentic doodad from this known reputable seller.
Is that not the case?
-
That would be nice, but a lot of people are using them as teachers for classroom supplies now or charities using them to get donations of supplies they need.
@darwinwoodka @dalias
They can share what they need as an item that the donor buys? No need to share an account's "wishlist". -
PSA: The Amazon wishlist doxing threat is much greater and more immediate than folks might realize. Attack works like this:
Stalker who wants your address opens an Amazon seller account and lists themselves as a third party seller for any item on your public wishlist. Then, they order the item from themselves as a gift for you. Bam, they have your address.
In particular, attack does not depend on an existing third party seller having poor PII handling hygiene, like the articles have implied.
@dalias I did not understand this. Thank you for letting us know!