6 ms·
They don't mention Amazon specifically except in the title and the final sentence. I recall, when I signed up for my free year of AWS, that it required a valid
by euank 12y ago
They don't mention Amazon specifically except in the title and the final sentence.
I recall, when I signed up for my free year of AWS, that it required a valid credit card. They claimed to only target providers that need essentially only an email address.
I think that detail makes the title incredibly misleading.
- kordless 12y agoThe cards aren't charged. You could sign up for several accounts with the same card, and I would imagine it's trivial to buy credit cards with $25 on them each or buy up old ones with less. These cards could also be stolen - one possible reason the information doesn't align in the article. Imagine using stolen cards for authenticating an account that doesn't accrue charges. It's genius. This also illustrates the rules of efficiencies. If there exists a resource one makes available for a given purpose (signing up lots of developers for free accounts) then you can assume there exists others who will figure out how to get those resources and turn them into something else of value to them. There's no such thing as a free lunch. There's also no such thing as limiting fraud. It will always be a choice.
- rdrey 12y agoI believe that AWS account creation requires unique emails & card numbers, but I'm not sure. There is definitely a telephone call with voice PIN, so I highly doubt that they used AWS accounts directly. I think the "Amazon" spin in the title is from many other services running atop of EC2 and effectively reselling EC2 instances or access to VMs that run on EC2. They could more easily create accounts with these services and technically still run "within Amazon's cloud".
- newaccountfool 12y agoYou may not even need to use stolen cards or buy them, Amazon was susceptible to fraudulent purchases via kindle just because the card number supplied matched the luhn algorithm.
- NamTaf 12y agoWe can thank our lucky stars that those in organised cybercrime never have access to vast troves of credit card information... That's, after all, just an permutation of the 'use scraped email addresses to create realistic-looking fake email addresses'. I think anyone wanting to use this for damage wouldn't be stopped by some CC requirement, especially if it's not charged.