Kindle and Amazon Shopping App security issues

Sam Vimes

Moderator
Sep 7, 2020
1,612
1,178
5,935
Visit site
Just a heads up on something I've discovered about the Kindle and Amazon Shopping App on my android tablet. If you don't have either of these then you don't have a problem.

On my tablet I have the Kindle App. Recently Amazon have stopped the ability to buy books via the App (siting Google charging too much as being the problem). Now you have to buy the books through the web site but can still download them to your devices.

Just out of interest I loaded the Amazon Shopping App onto the same tablet that Kindle is on. I wanted to see if you could buy the books through that - you can't.

The real security concern I have is that once the shopping app was installed and I ran it, it logged me in directly without asking for username, password or wanting the 2FA code I normally receive through the web page before I can get in.

This means that without any further checks I could see my account details, addresses, orders and even cards used for payments - although not the complete number. I could even create further delivery addresses or add new cards.

I've had a lengthy 'chat' with Amazon and we tried a few things. If I log out of the shopping app it also logs me out of the Kindle app - and I lose all my downloads and current positions in books. If I then log into the Kindle App it will also log me in to the shopping app. The two are linked.

I'm awaiting a call from Amazon to follow up on this and will let you know the outcome.

The concern is that if my tablet is stolen while unlocked then the Amazon Shopping App is open to all. My wife and daughters also have the Kindle App registered to my account. Should they install the Amazon Shopping App then they will be able to use my account for anything and should they have their tablets stolen, once again the app is open to all.

Not good in my opinion.
 
Jun 16, 2020
4,675
1,850
6,935
Visit site
Is this to do with your Andriod security settings? Do you have it set to auto log on? If so, the security is down to fingertip, face recognition or log on password. Whichever you have. Look at your Andriod security, you may be able to get it to ask for a password every time. This may be done on an app by app basis.

John
 

Sam Vimes

Moderator
Sep 7, 2020
1,612
1,178
5,935
Visit site
Thanks for the reply, John.

As far as I'm aware there is no security settings for individual apps. It has to be within the app itself.

After another session with Amazon customer support it would appear that this is done by design so that all Amazon apps and devices are linked. Not sure I understand the logic of that but they did seem to acknowledge that it wasn't quite right and that my feedback would be passed on .... To where?

I'm not convinced they'll ever fix this. I have no intention of using the shopping app since you can't buy Kindle books through it and now even less reason to install it because of the security concerns.

This is not the only app I've come across that has poor security IMO. The Scottish Power App remains logged in permanently even if you close it. You have to actually sign out rather than it logging you out when you close it. I gave up on that one as well.
 

TRENDING THREADS

Latest posts