Amazon have this lovely service: if you tell if you forgot your pw, they send you to: https://www.amazon.com/exec/obidos/self-service-forgot-password-get-email-done/104-2901457-0883904

where they ask you to confirm your identity... using 5 last digits of a credit card you used with them.

Nice oracle to find last 5 digits... making it quite easy to find the full number.

Not that anybody would bother. Still, I find it funny.
--
Best regards,

Amir Herzberg

Associate Professor
Department of Computer Science
Bar Ilan University
http://AmirHerzberg.com
Try TrustBar - improved browser security UI: http://AmirHerzberg.com/TrustBar Visit my Hall Of Shame of Unprotected Login pages: http://AmirHerzberg.com/shame

---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to [EMAIL PROTECTED]

Reply via email to