Hacker News new | ask | show | jobs
by walrus01 6 days ago
Are you sure it was actually via whatsapp, and not just a six digit code sent via regular SMS to the phone number on record for her account? It's possible whatsapp on her phone has simply hijacked the SMS client functionality and set itself as the default.
6 comments

I know it was 3 days ago, but I just got an additional data point.

In the Amazon app, the same I normally use, on my normal account, I used Switch Accounts option, and proceeded to create a separate, additional Amazon account.

I entered a different, new email address and my real name.

Amazon happily sent me a verification email, I entered the code. I was then prompted to enter a phone number, I did so (it's a number I never used with Amazon (to my second phone)).

Amazon then requested me to enter the code it sent over on *WhatsApp*. I tried to take a screenshot but it came out all black.

I don't have WhatsApp account with this number.

There was an option to resend it through a normal text message but first it sent out a code on WhatsApp. That should never be a default.

No, my Microsoft Azure 2FA sends codes to WhatsApp, not SMS.

UK, where WhatsApp is absolutely mandatory.

WhatsApp is not in any way mandatory in the UK. I say this as someone who lived in the UK and does not use and has never installed WhatsApp.
> "WhatsApp on her phone"

GP clearly said she doesn't have WhatsApp.

If I had a dollar for every time I've seen an older person that doesn't even know what application they're running, or can't tell the difference between the content of a website inside a browser window and an application that runs natively on their computer. I read what the GP wrote, I'm saying there's a non zero possibility she's misunderstanding something.

It seems like something you have to specifically choose, on the amazon account side.

https://www.amazon.co.uk/gp/help/customer/display.html?nodeI...

I choose to not call a GP a liar or too thick for being unable to differentiate between apps :)

I also chose their presumed first hand statement than your unrelated experience with unrelated third parties.

Your point re: having to subscribe to WhatsApp notifications, if we're staying in the realm of "what ifs" and looking for the awkward but possible ways to discredit the claims, I can believe that she was enrolled without being asked. I've seen at least one person complaining about that exact scenario.

Cheers!

> I choose to not call a GP a liar or too thick

GP of the post or actual GP.....

It's not about being thick. I had a old person ranting at me once because all these Ukrainian girls were emailing him wanting dates, and didn't they realise he was too old for them.

> GP

The one recalling an event with their mother.

Your experience with a old person is not their experience with their mother.

Can you not project your own experiences on someone's else's?

You claim someone's else's reasoning is wrong based on *your* opinion and past, without anything that would support the relevance in *their* case.

Your experience is valid but irrelevant in that case. Don't project.

We generalise about non technical users all the time. Why is it unfair to generalise a subset of those users? What you term 'projecting' is my own experience, where I am supporting backing the experience of someone else. Yes we may be wrong, the op hasn't clarified as far as I'm aware, but I don't think that invalidates the greater point.

How should I engage with young children? Should I talk to a 2 year old like an adult? Or should I use my experience other 2 year old to inform how I should engage with other 2 year olds?

Older people can be surprisingly tech illiterate to a degree many would be surprised by. That is my experience, that is others experience. Yes there will be exceptions. But I don't think that invalidates the generalisation.

Personally I would hope that people would make an extra effort to educate those needing extra help in spotting potential fraud, rather than doing nothing to avoid 'projecting'.

If I forget to pause my VPN before going to Amazon's website, I can't log in with just username and password, I get a page telling me they've sent a code to WhatsApp (which I don't have) with a button to click if I want an SMS instead. Clicking that button never works (error message that I've 'requested too many OTPs') but opening the Amazon app on my phone shows a modal saying 'someone who knows your password is trying to log in... etc' and asking me to approve. They're definitely trying to use WhatsApp by default for sending verification codes.
but then amazon would not tell her that she should find the code in whatsapp, because amazon would still be sending send an sms. it should not have any awareness of whatsapp hijacking the sms function, and therefore the amazon message should reference the SMS. if it references whatsapp then it means amazon wants to send to whatsapp directly.
“which she doesn’t have and doesn’t want”