Community
Wiki Posts
Search

Kindle security

Thread Tools
 
Search this Thread
 
Old Jan 23, 2011 | 8:14 am
  #1  
Original Poster
 
Join Date: May 2007
Location: LAS
Programs: none
Posts: 30
Kindle security

The two times I have bought e-books on my kindle over the 3g connection I have also had an unauthorized charge to my credit card. Once from netflix and once from a website c28.com. I find it odd that this only happens when I bought e-books with the kindle. Where is the security hole the Kindle, whispernet, Amazon, or did my number get skimmed elsewhere and this is all a coincidence?
pwrdwnsys_*immed is offline  
Old Jan 23, 2011 | 9:24 am
  #2  
 
Join Date: Mar 2004
Location: Wenatchee, WA
Programs: Lifetime AA Gold-1MM
Posts: 4,909
Did you use a stored credit card on Amazon and use the one-click ordering, or did you enter a credit card number? (I thought you had to use one-click ordering, but I may be wrong.) Using a stored card should prevent this from happening since you're never transmitting your credit card information.
BLI-Flyer is offline  
Old Jan 23, 2011 | 10:49 am
  #3  
Original Poster
 
Join Date: May 2007
Location: LAS
Programs: none
Posts: 30
Originally Posted by BLI-Flyer
Did you use a stored credit card on Amazon and use the one-click ordering.
Yes I used one click ordering on the kindle with a credit card that was already stored at amazon
pwrdwnsys_*immed is offline  
Old Jan 23, 2011 | 11:09 am
  #4  
20 Years on Site
 
Join Date: Nov 2000
Location: Portland
Programs: UA 1K, AK Gold 75K, etc. etc.
Posts: 1,660
Its never happened to me (knock on wood).
mikel51 is offline  
Old Jan 23, 2011 | 11:47 am
  #5  
A FlyerTalk Posting Legend
10 Countries Visited20 Countries Visited30 Countries Visited20 Years on Site
 
Join Date: Apr 2001
Location: PSM
Posts: 69,232
I'm guessing coincidence.
sbm12 is offline  
Old Jan 23, 2011 | 2:49 pm
  #6  
20 Countries Visited
30 Countries Visited
40 Countries Visited
15 Years on Site
 
Join Date: Jul 2006
Location: California
Programs: AA EXP, lowly UA 1K; Hyatt Diamond, SPG Gold, Hilton Gold; National EC, Hertz PC
Posts: 2,227
Originally Posted by sbm12
I'm guessing coincidence.
Yea that is my thinking too. Was it the same CC both times? It might be time get a new number issued.
adambadam is offline  
Old Jan 24, 2011 | 11:35 am
  #7  
 
Join Date: Sep 2007
Location: SNA, LAX
Posts: 425
When you buy a book from the Kindle device, you aren't transmitting your credit card over the air -- just the order to Amazon, which already has your credit card info stored. Coincidence seems the most likely explanation.
whitearrow is offline  
Old Jan 24, 2011 | 6:47 pm
  #8  
10 Countries Visited
20 Countries Visited
30 Countries Visited
20 Years on Site
 
Join Date: Apr 2004
Location: EWR, PHL
Programs: UA1k 3MM, AA Plt, peasant on everybody else, elite something or other at a bunch of hotels.
Posts: 4,648
Originally Posted by whitearrow
When you buy a book from the Kindle device, you aren't transmitting your credit card over the air -- just the order to Amazon, which already has your credit card info stored. Coincidence seems the most likely explanation.
Along with Amazon account info?
1kBill is offline  
Old Jan 24, 2011 | 6:57 pm
  #9  
15 Years on Site
 
Join Date: Aug 2006
Location: San Jose CA
Posts: 1,100
Originally Posted by 1kBill
Along with Amazon account info?
Amazon's been in the business long enough to know the importance of data security. But for argument's sake, let's say that your Amazon account name and password are transmitted over the air in cleartext by the Kindle. Now what? You're a bad guy, you used Aircrack-ng, and now you've got access to an Amazon account. But you can't get the credit card number out of the Amazon account, just the last four digits. So you can't buy stuff on Netflix, or from the random web site mentioned by the OP.
boberonicus is offline  
Old Jan 25, 2011 | 11:09 am
  #10  
 
Join Date: Sep 2007
Location: SNA, LAX
Posts: 425
Originally Posted by 1kBill
Along with Amazon account info?
Maybe your account name, but why would it transmit a password? It knows that it's receiving the order from a Kindle device you have physical access to. Why would it transmit a password, especially in the clear? Doesn't make sense. And even if it did, all the bad guy would get access to is the Amazon account, which never shows full credit card numbers once they're entered anyway.

ETA: I see boberonicus posted essentially the same thing. Sorry
whitearrow is offline  
Old Feb 15, 2011 | 12:17 am
  #11  
 
Join Date: Jan 2006
Location: SZX/HKG/BWI
Programs: UA 1K 1.1MM, CX Diam 1.0MM, Bonvoy LT Titanium, Hertz PC, MGM Pearl
Posts: 2,637
Would it make a difference if the books were purchased through a set Wi-Fi network? (In terms of security)

It's just my habit, but when I purchase books on Amazon, I make it a point to transfer through some of the Wi-Fi networks I've set on my Kindle. I only use 3G if I absolutely need to.
mjcewl1284 is offline  
Old Feb 15, 2011 | 2:24 am
  #12  
All eyes on you!
15 Years on Site
 
Join Date: May 2009
Posts: 538
Originally Posted by mjcewl1284
Would it make a difference if the books were purchased through a set Wi-Fi network? (In terms of security)

It's just my habit, but when I purchase books on Amazon, I make it a point to transfer through some of the Wi-Fi networks I've set on my Kindle. I only use 3G if I absolutely need to.
Can't see it making a difference.
ukflyer1 is offline  
Old Feb 15, 2011 | 2:09 pm
  #13  
All eyes on you!
15 Years on Site
 
Join Date: Jun 2008
Location: YVR
Programs: Aeroplan, AAdvantage
Posts: 2,107
Huh, eavesdropping on 3G is not exactly the most trivial thing in this world. (Esp compared to a weakly or not at all secured wifi.)

Also, those charges, i dunno, do you have a rogue family member maybe ?
chx1975 is offline  
Old Feb 15, 2011 | 5:23 pm
  #14  
 
Join Date: Sep 2007
Location: SNA, LAX
Posts: 425
Originally Posted by ukflyer1
Can't see it making a difference.
Me either.
whitearrow is offline  
Old Jun 15, 2011 | 6:34 pm
  #15  
 
Join Date: Jun 2011
Posts: 1
Originally Posted by pwrdwnsys_*immed
The two times I have bought e-books on my kindle over the 3g connection I have also had an unauthorized charge to my credit card. Once from netflix and once from a website c28.com. I find it odd that this only happens when I bought e-books with the kindle. Where is the security hole the Kindle, whispernet, Amazon, or did my number get skimmed elsewhere and this is all a coincidence?
pwrdwnsys_*immed, I happened across your forum post by accident. I am one of the website developers for c28.com.

I do believe that the charges were a coincidence - though you should change your card asap. Most frauds that we deal with are fraudsters who have gotten credit card numbers some how and are trying to verify whether the cards are valid. They will make small purchases with websites like netflix, us, and others. If they receive validation of the card, they will usually resell the card number.

There are a few ways of getting credit card numbers. One way common way is to get a number from a particular bank and then, using a script and an algorythm, try other combinations. Once you have one card number from a bank, you can use an algorythm to calculate each successive valid card number, and using website shopping carts, you can then try expiration dates with each number until you get one that processes.

We do try to do what we can to reduce these issues and our customer service department will cancel orders as soon as we find out about them.

I'm sorry it took so long to answer your question and if you have any questions, feel free to contact me.
rgc6789 is offline  


Contact Us - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service -

This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2026 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.