Woke up to a billing alarm email. Thought I had leaked my AWS keys accidentally and somehow run up 437 billion dollars of charges. Joke's on them though, I don't have 437 billion dollars
Anyways I didn't need coffee. That produced an adrenaline release unlike any I've experienced before. Thanks AWS
This number is obviously absurd but for other normal amount (say 2 million which can definitely happen with a mistake), can't they claim it in court that will bankrupt you even if your entire worth is just 100K for example?
I had it for three months, and each month it was unable to deliver pills before I ran out, so I cancelled and switched to the brick-and-mortar pharmacy down the street.
A year later, suddenly Amazon Pharmacy starts sending unauthorized prescription refill requests to my doctor.
I still have the account cancellation confirmation e-mail from Amazon Pharmacy, but Amazon won't close my account. Amazon's account rep says it cannot close accounts for "legal reasons." Bullshit. He can't say what the legal reasons are, or point me to a document stating these conditions.
Now my doctor's office just ignores all refill requests from Amazon Pharmacy.
I went through a two month long fight with AWS over a compromised account. I lost 20K even when my previous usage for the last 3 years was like $20/month, and I had more invoices coming worth tens of thousands of dollars. AWS refused to help until I stopped the breach myself, which required me to spend several all nighters after work learning how to script for AWS infra. They also refused to close my account after the breach was under control. They asked me to sign a shared responsibility agreement before they could look at my case, which I refused to do. I finally contacted the AG office in my state and they email AWS directly. In less than 24h I had a AWS manager calling me to fix my account and issue a refund for the 20K. Still, they refused to close my account after all this ordeal, apparently there’s no way for you to completely get out of AWS once you are in. It’s the shittiest business ever.
I had a similar situation where some dormant account was still charging my credit card.
The account was probably real, made for some purpose 15 years ago. I had ignored the charge for years because it was like $7 a month. Then it went to $300/month, making it worth the time. I could find no invoice email and none of my AWS accounts lined up with the bill.
I tried contacting support, but without the account number involved they had no way to help. I disputed the charge, the bank refunded that month and then went right back to charging the next month(my credit card helpfully accepted the charges despite the dispute).
I had to cancel the credit card entirely to make it stop.
That's super cool! Is there a way to save the editor and diagram state into a URL hash so we can share tsdiagram links with others, similar to how the TypeScript Playground works?
It's more than likely that they'll inject their own softball questions and focus on those instead of addressing everyone's concerns in any meaningful way.
May not even need to be an astroturfer, it could be u/spez directly. Don’t forget that he went rogue and modified a user’s comment in the Reddit database!
It's a great place but when you need to cash out you need fresh linux system with fresh wallet software connected to the internet only when you make the transaction. Not an app for your phone. Everybody will have malicious keylogger on their phone eventually if they install apps and sometimes even if they don't.
Not necessarily, for instance 3rd party keyboards like Grammarly are keyloggers by their very nature. They grab your input, process it, and give output in terms of grammar corrections. And a rogue app update can absolutely do the same.
> And how do you make sure that that doesn’t come with a keylogger
The same way you verify anything is what you want and stays that way, MD5/SHA256 hashes and airgaps.
It's possible to disable third party keyboards for sensitive data entry at least on iOS. Not sure if the same is possible on Android – worst case, a wallet could just provide their own keyboard/passphrase entry method.
> The same way you verify anything is what you want and stays that way, MD5/SHA256 hashes and airgaps.
How do you determine a given hash to be trustworthy? And how do you know you can trust your `sha256sum` implementation?
You're always trusting someone. Any security analysis pretending otherwise is worthless.
If it's not a bank and not state backed/insured, it might as well be crypto. With crypto, at least in cold storage, there is a lot less chance of losing your money and no chance of getting a dreaded 'your account was indefinitely suspended' from the 'AI' at Paypal. And having no recourse whatsoever.
Still, personally, I distribute over all kinds of banks (where I get E100k per bank when they fall, so I make sure I'm under that amount per bank) and assets so the fallout is minimal if something falls. Well, unless it's a 1929 event of course; then it remains to be seen what is left after. But then crypto is wiped out too; people gotta live, so they will mass sell off.
From my understanding, as what’s essentially a layperson in crypto, is hardware over any form of software. Same as with fiat in say PayPal, you don’t own it unless you can physically hold it. And physically holding it in this case is via FOSS hardware wallets such as Trezor.
That hardware will ultimately also be running software, and you need to be trusting the vendor/supply chain of both.
This is not at all to say that there is no point in hardened/secure execution environments like smartcards, Yubikeys, hardware wallets etc., but the important point is that the statement "hardware is more secure than software" by itself is dangerously misleading.
And there is no such thing as (fully) "FOSS hardware". Somebody needs to build a physical thing in the end, and you can't verify every single step of that process. Openness/transparency has its advantages and reduces the chance of nefarious things happening in your supply chain, but this is lightyears away from "trustlessness".
> When this happens with big bank, you could try going to the court.
Great. So not only I lost my money but now I'm getting an assignment as well. Which will last many years and at best will result in recovering a fraction of what I lost and the most likely outcome us not getting anything back and possibly paying more.
I had the California State Board of Equalization empty one of my bank accounts without warning because they thought I owned them back taxes. I had moved out of the country and wasn't filing California taxes, which was a mistake. You still have to file a 0 tax.
Dude, there are whole countries where the Goverment just stopped everyone from getting their money out of the Bank. Greek for example, just a few years ago. It's not something very rare nor do you have to be in a third world country.
They said they couldn't change it back. They said they would have to delete the account. So far, it's been referred to the "Elite Support" team... waiting for info.
Anyways I didn't need coffee. That produced an adrenaline release unlike any I've experienced before. Thanks AWS