Skip to content
0
  • Home
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
  • Home
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Sketchy)
  • No Skin
Collapse

Wandering Adventure Party

  1. Home
  2. Uncategorized
  3. PSA: The Amazon wishlist doxing threat is much greater and more immediate than folks might realize.

PSA: The Amazon wishlist doxing threat is much greater and more immediate than folks might realize.

Scheduled Pinned Locked Moved Uncategorized
45 Posts 28 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • CassandrichD Cassandrich

    PSA: The Amazon wishlist doxing threat is much greater and more immediate than folks might realize. Attack works like this:

    Stalker who wants your address opens an Amazon seller account and lists themselves as a third party seller for any item on your public wishlist. Then, they order the item from themselves as a gift for you. Bam, they have your address.

    In particular, attack does not depend on an existing third party seller having poor PII handling hygiene, like the articles have implied.

    CassandrichD This user is from outside of this forum
    CassandrichD This user is from outside of this forum
    Cassandrich
    wrote last edited by
    #3

    The only mitigations are refraining from using public wishlists entirely (set any wishlists you may have to private) or using a PO box or reshipping service to conceal your real physical/final address.

    CassandrichD Ray McCarthyR axolotl solidarioA draNgNonD 4 Replies Last reply
    0
    • CassandrichD Cassandrich

      The only mitigations are refraining from using public wishlists entirely (set any wishlists you may have to private) or using a PO box or reshipping service to conceal your real physical/final address.

      CassandrichD This user is from outside of this forum
      CassandrichD This user is from outside of this forum
      Cassandrich
      wrote last edited by
      #4

      Note that even PO boxes are not particularly safe against a dedicated stalker. They can stake out the PO for someone picking up a distinctive package once they know what PO it's at.

      Kat the LeopardessC toerrorT Erik JohnsonD Piggo :verified_horse:P 4 Replies Last reply
      0
      • CassandrichD Cassandrich

        PSA: The Amazon wishlist doxing threat is much greater and more immediate than folks might realize. Attack works like this:

        Stalker who wants your address opens an Amazon seller account and lists themselves as a third party seller for any item on your public wishlist. Then, they order the item from themselves as a gift for you. Bam, they have your address.

        In particular, attack does not depend on an existing third party seller having poor PII handling hygiene, like the articles have implied.

        Mx. Eddie RS This user is from outside of this forum
        Mx. Eddie RS This user is from outside of this forum
        Mx. Eddie R
        wrote last edited by
        #5

        @dalias
        It appears the change will roll out in Canada in March.
        I've deleted all my public wishlists.

        1 Reply Last reply
        0
        • CassandrichD Cassandrich

          PSA: The Amazon wishlist doxing threat is much greater and more immediate than folks might realize. Attack works like this:

          Stalker who wants your address opens an Amazon seller account and lists themselves as a third party seller for any item on your public wishlist. Then, they order the item from themselves as a gift for you. Bam, they have your address.

          In particular, attack does not depend on an existing third party seller having poor PII handling hygiene, like the articles have implied.

          Andrew ZonenbergA This user is from outside of this forum
          Andrew ZonenbergA This user is from outside of this forum
          Andrew Zonenberg
          wrote last edited by
          #6

          @dalias was this not already possible? like i'm not sure how wishlists would work if the seller didn't know how to ship the product?

          CassandrichD 1 Reply Last reply
          0
          • CassandrichD Cassandrich

            Note that even PO boxes are not particularly safe against a dedicated stalker. They can stake out the PO for someone picking up a distinctive package once they know what PO it's at.

            Kat the LeopardessC This user is from outside of this forum
            Kat the LeopardessC This user is from outside of this forum
            Kat the Leopardess
            wrote last edited by
            #7

            @dalias I live in a rural area of my state. This means that everyone living here has to get a USPS PO Box

            We get the double edged sword of

            ...dealing with entities and online vendors that do not accept our PO Box address as valid.

            ...but also that we are still suceptible to the privacy issues despote that our mail doesnt come to our physical location.

            1 Reply Last reply
            0
            • Andrew ZonenbergA Andrew Zonenberg

              @dalias was this not already possible? like i'm not sure how wishlists would work if the seller didn't know how to ship the product?

              CassandrichD This user is from outside of this forum
              CassandrichD This user is from outside of this forum
              Cassandrich
              wrote last edited by
              #8

              @azonenberg Previously you could select that you only accept gifts fulfilled by Amazon. They just took away that ability.

              Andrew ZonenbergA 1 Reply Last reply
              0
              • CassandrichD Cassandrich

                Note that even PO boxes are not particularly safe against a dedicated stalker. They can stake out the PO for someone picking up a distinctive package once they know what PO it's at.

                toerrorT This user is from outside of this forum
                toerrorT This user is from outside of this forum
                toerror
                wrote last edited by
                #9

                @dalias Or just mail you a tracker.

                ✧✦Catherine✦✧W 1 Reply Last reply
                0
                • CassandrichD Cassandrich

                  @azonenberg Previously you could select that you only accept gifts fulfilled by Amazon. They just took away that ability.

                  Andrew ZonenbergA This user is from outside of this forum
                  Andrew ZonenbergA This user is from outside of this forum
                  Andrew Zonenberg
                  wrote last edited by
                  #10

                  @dalias aha, ok.

                  I miss when amazon was a way to buy books directly from them and that was it...

                  Andrew ZonenbergA 1 Reply Last reply
                  0
                  • Andrew ZonenbergA Andrew Zonenberg

                    @dalias aha, ok.

                    I miss when amazon was a way to buy books directly from them and that was it...

                    Andrew ZonenbergA This user is from outside of this forum
                    Andrew ZonenbergA This user is from outside of this forum
                    Andrew Zonenberg
                    wrote last edited by
                    #11

                    @dalias (and I also hate the tendency of everything from walmart to digikey to turn into a "marketplace" lately. At one point you could buy oscilloscope software options on walmart's website because TEquipment had a storefront there)

                    Andrew ZonenbergA 1 Reply Last reply
                    0
                    • CassandrichD Cassandrich

                      PSA: The Amazon wishlist doxing threat is much greater and more immediate than folks might realize. Attack works like this:

                      Stalker who wants your address opens an Amazon seller account and lists themselves as a third party seller for any item on your public wishlist. Then, they order the item from themselves as a gift for you. Bam, they have your address.

                      In particular, attack does not depend on an existing third party seller having poor PII handling hygiene, like the articles have implied.

                      Alex RA This user is from outside of this forum
                      Alex RA This user is from outside of this forum
                      Alex R
                      wrote last edited by
                      #12

                      @dalias every single engineer I've seen talking about this has immediately identified this attack, so it's guaranteed that this will be exploited right away if it goes ahead (and also that Amazon absolutely knows about it)

                      CassandrichD 1 Reply Last reply
                      0
                      • Andrew ZonenbergA Andrew Zonenberg

                        @dalias (and I also hate the tendency of everything from walmart to digikey to turn into a "marketplace" lately. At one point you could buy oscilloscope software options on walmart's website because TEquipment had a storefront there)

                        Andrew ZonenbergA This user is from outside of this forum
                        Andrew ZonenbergA This user is from outside of this forum
                        Andrew Zonenberg
                        wrote last edited by
                        #13

                        @dalias just make a store to sell your products, and let me know i'm buying from you, a company i presumably trust to some extent. that's it, do one thing, do it well

                        1 Reply Last reply
                        0
                        • CassandrichD Cassandrich

                          The only mitigations are refraining from using public wishlists entirely (set any wishlists you may have to private) or using a PO box or reshipping service to conceal your real physical/final address.

                          Ray McCarthyR This user is from outside of this forum
                          Ray McCarthyR This user is from outside of this forum
                          Ray McCarthy
                          wrote last edited by
                          #14

                          @dalias
                          Never make a "wishlist" public, or share it.

                          Darwin WoodkaD ErikE 2 Replies Last reply
                          0
                          • Alex RA Alex R

                            @dalias every single engineer I've seen talking about this has immediately identified this attack, so it's guaranteed that this will be exploited right away if it goes ahead (and also that Amazon absolutely knows about it)

                            CassandrichD This user is from outside of this forum
                            CassandrichD This user is from outside of this forum
                            Cassandrich
                            wrote last edited by
                            #15

                            @alex They obviously knew about it since the beginning. That's why gifts were limited to fulfilled-by-Amazon. Then some piece of shit manager with no understanding of safety wanted to make the sketchy marketplace more lucrative to sellers to compete in race to bottom.

                            Alex RA 1 Reply Last reply
                            0
                            • CassandrichD Cassandrich

                              PSA: The Amazon wishlist doxing threat is much greater and more immediate than folks might realize. Attack works like this:

                              Stalker who wants your address opens an Amazon seller account and lists themselves as a third party seller for any item on your public wishlist. Then, they order the item from themselves as a gift for you. Bam, they have your address.

                              In particular, attack does not depend on an existing third party seller having poor PII handling hygiene, like the articles have implied.

                              Mason Loring BlissM This user is from outside of this forum
                              Mason Loring BlissM This user is from outside of this forum
                              Mason Loring Bliss
                              wrote last edited by
                              #16

                              @dalias I'm hoping we can use this opportunity to get people off of Amazon.

                              Mason Loring Bliss (@mason@partychickens.net)

                              Public service announcement: Amazon hurts people. If you use Amazon, you're okay hurting people. Here are some references. There are many, many more. 2024: Why Amazon Is Bad for Society: Examining the Hidden Costs of Convenience https://www.historytools.org/consumer/why-is-amazon-bad-for-society 2023: Exclusive: ‘I Feel Like I’m Drowning.’ Survey Reveals the Toll of Working For Amazon https://time.com/6248340/amazon-injuries-survey-labor-osha/ 2023: 41 Percent of Amazon Workers Have Been Injured On the Job, New Report Finds https://cued.uic.edu/pain-points/ 2024: Amazon’s Biggest Delivery: Millions of Pounds of Plastic Pollution https://www.foodandwaterwatch.org/2024/07/03/amazon-plastic-pollution/ 2019: 10 Ways Amazon Violates Human Rights https://greenamerica.org/blog/10-ways-amazon-violates-human-rights 2025: Why So Many People Are Boycotting Amazon: 11 Major Complaints Explained https://www.marketingscoop.com/consumer/why-do-people-hate-amazon/ 2023: The Local Harms of Amazon and What State Lawmakers Can Do About Them https://www.economicliberties.us/our-work/the-local-harms-of-amazon/# 2025: Amazon's Environmental Impact: Unpacking The Harmful Effects On Our Planet https://shunwaste.com/article/why-is-amazon-bad-for-the-environment 2024: Amazon workers struggle with injuries and low pay despite company’s profits https://prismreports.org/2024/06/05/amazon-workers-struggle-injuries-low-pay/ #amazon #boycott

                              favicon

                              PartyChickens (partychickens.net)

                              1 Reply Last reply
                              0
                              • CassandrichD Cassandrich

                                PSA: The Amazon wishlist doxing threat is much greater and more immediate than folks might realize. Attack works like this:

                                Stalker who wants your address opens an Amazon seller account and lists themselves as a third party seller for any item on your public wishlist. Then, they order the item from themselves as a gift for you. Bam, they have your address.

                                In particular, attack does not depend on an existing third party seller having poor PII handling hygiene, like the articles have implied.

                                Nu ModularN This user is from outside of this forum
                                Nu ModularN This user is from outside of this forum
                                Nu Modular
                                wrote last edited by
                                #17

                                @dalias A couple of guys I trained with in martial arts, are in a paramilitary group, and are now planning a para-doxing welcoming committee.

                                1 Reply Last reply
                                0
                                • toerrorT toerror

                                  @dalias Or just mail you a tracker.

                                  ✧✦Catherine✦✧W This user is from outside of this forum
                                  ✧✦Catherine✦✧W This user is from outside of this forum
                                  ✧✦Catherine✦✧
                                  wrote last edited by
                                  #18

                                  @toerror @dalias this. even my stalkers are not dedicated enough for potentially multi-week stakeout, but an apple tag is super easy

                                  1 Reply Last reply
                                  0
                                  • CassandrichD Cassandrich

                                    PSA: The Amazon wishlist doxing threat is much greater and more immediate than folks might realize. Attack works like this:

                                    Stalker who wants your address opens an Amazon seller account and lists themselves as a third party seller for any item on your public wishlist. Then, they order the item from themselves as a gift for you. Bam, they have your address.

                                    In particular, attack does not depend on an existing third party seller having poor PII handling hygiene, like the articles have implied.

                                    The Shaking EarthE This user is from outside of this forum
                                    The Shaking EarthE This user is from outside of this forum
                                    The Shaking Earth
                                    wrote last edited by
                                    #19

                                    @dalias holy shit, wow. I appreciate that heads up. Thank you.

                                    1 Reply Last reply
                                    0
                                    • CassandrichD Cassandrich

                                      @alex They obviously knew about it since the beginning. That's why gifts were limited to fulfilled-by-Amazon. Then some piece of shit manager with no understanding of safety wanted to make the sketchy marketplace more lucrative to sellers to compete in race to bottom.

                                      Alex RA This user is from outside of this forum
                                      Alex RA This user is from outside of this forum
                                      Alex R
                                      wrote last edited by
                                      #20

                                      @dalias exactly. They could also have trivially made wishlists with that setting private, which would at least limit the immediate harm, but that doesn't goose the wishlist metrics

                                      1 Reply Last reply
                                      0
                                      • Ray McCarthyR Ray McCarthy

                                        @dalias
                                        Never make a "wishlist" public, or share it.

                                        Darwin WoodkaD This user is from outside of this forum
                                        Darwin WoodkaD This user is from outside of this forum
                                        Darwin Woodka
                                        wrote last edited by
                                        #21

                                        @raymaccarthy @dalias

                                        That would be nice, but a lot of people are using them as teachers for classroom supplies now or charities using them to get donations of supplies they need.

                                        Ray McCarthyR 1 Reply Last reply
                                        0
                                        • Ray McCarthyR Ray McCarthy

                                          @dalias
                                          Never make a "wishlist" public, or share it.

                                          ErikE This user is from outside of this forum
                                          ErikE This user is from outside of this forum
                                          Erik
                                          wrote last edited by
                                          #22

                                          @raymaccarthy @dalias true and even if this is how 'streamers' and 'content creators' grift, this is also used as a tool for mutual aid.

                                          CassandrichD 1 Reply Last reply
                                          0

                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          • First post
                                            Last post