you are viewing a single comment's thread
view the rest of the comments
[–] 4 points 2 years ago (1 child)

Hmm, interesting.

And yeah, that is my understanding, too. If an attacker knows that a certain e-mail address has an account associated, they might try to bruteforce the password or send a phishing mail to that e-mail address, which looks like an official mail from Amazon.

I'm guessing, Amazon requires 2FA, which would protect from this to some degree, but still seems unnecessary to hand out information like that.

  • source
  • parent
  • hideshow 2 child comments