Hacker Newsnew | past | comments | ask | show | jobs | submit | fron's commentslogin

Woke up to a billing alarm email. Thought I had leaked my AWS keys accidentally and somehow run up 437 billion dollars of charges. Joke's on them though, I don't have 437 billion dollars

Anyways I didn't need coffee. That produced an adrenaline release unlike any I've experienced before. Thanks AWS


If you owe AWS 437k bucks, that’s a big problem for you

If you owe AWS 437B bucks, that’s a big problem for AWS


Far less scary than a smaller amount


This number is obviously absurd but for other normal amount (say 2 million which can definitely happen with a mistake), can't they claim it in court that will bankrupt you even if your entire worth is just 100K for example?


I wonder how many people may have gotten an actual heart infarct because of that. There may be a person out there that may be dead as a result.

It's entirely irresponsible of Amazon to even display such values to the user.


Reminds me of the time a Robinhood user killed themselves after Robinhood erroneously showed their account balance at -$730k.

https://www.bbc.com/news/world-us-canada-55990461


In that case, they settled with Robinhood and FINRA fined Robinhood 70 million dollars.

https://edition.cnn.com/2021/07/01/business/robinhood-lawsui...


"They" being the family; Robinhood couldn't settle with the guy who was wronged because he, ya know, killed himself first


Ah, there'll be something in the TOS absolving them of responsibility.


Maybe AWS is also “for entertainment purposes only”

https://techcrunch.com/2026/04/05/copilot-is-for-entertainme...


Well... That depends on the country jurisdiction. And any ToS is bounded by law and can be questioned.


I legit had a small panic attack due to this.

I'm not a devops but we are running some s3 buckets. When I saw the number I couldn't even comprehend and thought we had been hacked.

I feel like this is such a bad mistake from AWS and we will never be compensated for it.

Put me off having anything on AWS from now on.


Worth a shot to give them a call and explain that. They can probably adjust it down to 100 billion.


What is this, US health care negotiations?



https://health.amazon.com/prime

Ugh. No. Never. Do not use Amazon Pharmacy.

I had it for three months, and each month it was unable to deliver pills before I ran out, so I cancelled and switched to the brick-and-mortar pharmacy down the street.

A year later, suddenly Amazon Pharmacy starts sending unauthorized prescription refill requests to my doctor.

I still have the account cancellation confirmation e-mail from Amazon Pharmacy, but Amazon won't close my account. Amazon's account rep says it cannot close accounts for "legal reasons." Bullshit. He can't say what the legal reasons are, or point me to a document stating these conditions.

Now my doctor's office just ignores all refill requests from Amazon Pharmacy.

Never trust your health to big tech.


It wasn't a recommendation, more of a sick joke that "Amazon has that, too".


I went through a two month long fight with AWS over a compromised account. I lost 20K even when my previous usage for the last 3 years was like $20/month, and I had more invoices coming worth tens of thousands of dollars. AWS refused to help until I stopped the breach myself, which required me to spend several all nighters after work learning how to script for AWS infra. They also refused to close my account after the breach was under control. They asked me to sign a shared responsibility agreement before they could look at my case, which I refused to do. I finally contacted the AG office in my state and they email AWS directly. In less than 24h I had a AWS manager calling me to fix my account and issue a refund for the 20K. Still, they refused to close my account after all this ordeal, apparently there’s no way for you to completely get out of AWS once you are in. It’s the shittiest business ever.


I had a similar situation where some dormant account was still charging my credit card.

The account was probably real, made for some purpose 15 years ago. I had ignored the charge for years because it was like $7 a month. Then it went to $300/month, making it worth the time. I could find no invoice email and none of my AWS accounts lined up with the bill.

I tried contacting support, but without the account number involved they had no way to help. I disputed the charge, the bank refunded that month and then went right back to charging the next month(my credit card helpfully accepted the charges despite the dispute).

I had to cancel the credit card entirely to make it stop.


Same story for $500 million. I was shaking so bad I couldn't type my password.


huge irl laugh at “i don’t have 437 billion dollars”


“Best I can do for you is $3.75 and a cup of coffee.”


Clearly the Agentic AI is running free on AWS. Matt does it again...what a success...


I was trying to go to sleep when I got mine. It was certainly above the $16 threshold I had set!


Why use light gray code highlighting on a light background? Most of the code blocks are unreadable due to this.


Hey, thanks for the feedback, sorry for that. Should be fixed now.


Many (most?) services offer a choice between SMS 2FA and no 2FA. It's not always so easy.


"Never attribute to incompetence that which can be attributed to malice" or something.

Clearly automatic beds have some degree of embedded software. The decision to put the controls in the cloud was certainly a conscious one.


> "Never attribute to incompetence that which can be attributed to malice" or something.

Isn't that the inverse of the Hanlon's razor? But I agree - the Occam's razor says that the inverse Hanlon's razor is most likely the case here.


Yeah SSO is down for me too


Come back if/when it gets announced. Until then, this is just clickbait nonsense


That's super cool! Is there a way to save the editor and diagram state into a URL hash so we can share tsdiagram links with others, similar to how the TypeScript Playground works?


Added now, thanks for the idea!


It's more than likely that they'll inject their own softball questions and focus on those instead of addressing everyone's concerns in any meaningful way.


When they removed the upvote/downvote count, it was clear reddit was fine with manipulation.

Anything I read on the website has been met with extreme skepticism since it very well could be an astroturfer.

It's money. Reddit wants astroturfers, it grows their platform and helps sell ads.


> Anything I read on the website has been met with extreme skepticism since it very well could be an astroturfer.

Good advice for any site. It's not like HN is immune to astroturfing.


You have more courage than me to say that here.


> When they removed the upvote/downvote count, it was clear reddit was fine with manipulation

I wasn't a big issue to me tbh. Vote fuzzing had always made those counts meaningless.


May not even need to be an astroturfer, it could be u/spez directly. Don’t forget that he went rogue and modified a user’s comment in the Reddit database!


Or that the Reddit founders used fake users to make the young site look busy:

https://arstechnica.com/information-technology/2012/06/reddi...


> it was clear reddit was fine with manipulation

talking about manipulation, reddit's current ceo edited users comments back when the bad guys were on business side of it.

https://www.theverge.com/2016/11/23/13739026/reddit-ceo-stev...


Let's talk about Rampart!


Love that game!


good test for the new AI bot accounts


How many times does this have to happen before people learn that cryptocurrency is not a good place to park money?


It's a great place but when you need to cash out you need fresh linux system with fresh wallet software connected to the internet only when you make the transaction. Not an app for your phone. Everybody will have malicious keylogger on their phone eventually if they install apps and sometimes even if they don't.


> a fresh linux system with fresh wallet software connected to the internet only when you make the transaction

wow, what a practical way to be able to store and use money!


It is rather safe and practical, for storing assets. It’s called a cold wallet.

If you want “practical” and unsafe, then store all your crypto in hot wallets like Atomic, that sure ended up well.


> Everybody will have malicious keylogger on their phone eventually

Are there actually any keyloggers for iOS and Android? Unlike on desktop OSes, there isn’t even an API for that, so you’d need an actual OS exploit.

> fresh linux system with fresh wallet software

And how do you make sure that that doesn’t come with a keylogger (in a world where a significant number of people were to actually do that)?


> you’d need an actual OS exploit

Not necessarily, for instance 3rd party keyboards like Grammarly are keyloggers by their very nature. They grab your input, process it, and give output in terms of grammar corrections. And a rogue app update can absolutely do the same.

> And how do you make sure that that doesn’t come with a keylogger

The same way you verify anything is what you want and stays that way, MD5/SHA256 hashes and airgaps.


It's possible to disable third party keyboards for sensitive data entry at least on iOS. Not sure if the same is possible on Android – worst case, a wallet could just provide their own keyboard/passphrase entry method.

> The same way you verify anything is what you want and stays that way, MD5/SHA256 hashes and airgaps.

How do you determine a given hash to be trustworthy? And how do you know you can trust your `sha256sum` implementation?

You're always trusting someone. Any security analysis pretending otherwise is worthless.


Of course you also need a clean version of linux and all software compiled with a clean compiler.

Thankfully we can be reasonably sure that some compilers at least predate cryptocurrency.


the level of technical savvy to store crypto safely makes it impractical for the general population


And god forbid if you accidentally transfer your crypto from one incomprehensible address to another.


AKA:too many crocodiles at the watering hole.



Who would park it there though? You receive money there and send it to your bank, or you send a little money to pay something. Who stores money there?


Why should anyone feel that they are unsafe with a heavily regulated payment industry?


If it's not a bank and not state backed/insured, it might as well be crypto. With crypto, at least in cold storage, there is a lot less chance of losing your money and no chance of getting a dreaded 'your account was indefinitely suspended' from the 'AI' at Paypal. And having no recourse whatsoever.

Still, personally, I distribute over all kinds of banks (where I get E100k per bank when they fall, so I make sure I'm under that amount per bank) and assets so the fallout is minimal if something falls. Well, unless it's a 1929 event of course; then it remains to be seen what is left after. But then crypto is wiped out too; people gotta live, so they will mass sell off.


> If it's not a bank and not state backed/insured, it might as well be crypto.

All I ever hear is how we need more regulation with crypto. Why aren't we demanding that with something as pervasive as Paypal/Venmo?


There are ways to park it safely and ways not to park it safely.


How are laypeople supposed to know which is which?


From my understanding, as what’s essentially a layperson in crypto, is hardware over any form of software. Same as with fiat in say PayPal, you don’t own it unless you can physically hold it. And physically holding it in this case is via FOSS hardware wallets such as Trezor.


That hardware will ultimately also be running software, and you need to be trusting the vendor/supply chain of both.

This is not at all to say that there is no point in hardened/secure execution environments like smartcards, Yubikeys, hardware wallets etc., but the important point is that the statement "hardware is more secure than software" by itself is dangerously misleading.

And there is no such thing as (fully) "FOSS hardware". Somebody needs to build a physical thing in the end, and you can't verify every single step of that process. Openness/transparency has its advantages and reduces the chance of nefarious things happening in your supply chain, but this is lightyears away from "trustlessness".


? It is literally uncountable how many times the big banks stole money from regular people. Crypto indeed is a good place to store money.


When this happens with big bank, you could try going to the court.

When this happens to crypto, you got nobody to blame but yourself.


> When this happens with big bank, you could try going to the court.

Great. So not only I lost my money but now I'm getting an assignment as well. Which will last many years and at best will result in recovering a fraction of what I lost and the most likely outcome us not getting anything back and possibly paying more.


Ah yes, big bank, bad. Government, very bad. Crypto good. Sure.


Huh? You literally mean a bank took your money from your account?

Which ones?


I had the California State Board of Equalization empty one of my bank accounts without warning because they thought I owned them back taxes. I had moved out of the country and wasn't filing California taxes, which was a mistake. You still have to file a 0 tax.

I still haven't gotten my money back.


Dude, there are whole countries where the Goverment just stopped everyone from getting their money out of the Bank. Greek for example, just a few years ago. It's not something very rare nor do you have to be in a third world country.


Fwiw I've heard many horror stories about Paypal


Paypal is not considered a bank, which is the root of many problems we are facing with paypal.


Can't you just call in and change it back then?


They said they couldn't change it back. They said they would have to delete the account. So far, it's been referred to the "Elite Support" team... waiting for info.


So you're saying they can't just do it?


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: