Live data from Hacker News

U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service

krebsonsecurity.com

31–40 of 135 posts

Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service

#31

Earlier quoted context omitted.

I signed up earlier this year and the validation required answering several multiple choice questions with data from my credit report such as mortgage, car loan, etc. I also received a postcard confirming that Informed Delivery had been activated for my postal address.

I see, so they do some kind of verification. Thanks for your reply! I guess asking about credit report info is inadequate if people are managing to abuse this. One problem with that kind of thing is it's essentially security by obscurity, it's not deliberately created secret knowledge that can be trusted, it's stuff which happens to not be public and which only you should know, but there's no guarantee and you can't…

The more I think about it I might be getting the validation mixed up with healthcare.gov.

I definitely received the postcard though.

Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service

#33

Earlier quoted context omitted.

> web of opaque "agencies" While I've got no love for credit-reporting agencies, and they have managed to mangle my file, they do act as a non-partisan 3rd party that can (when their records are accurate) verify that a person is credit-worthy -- Which is a highly valuable service. Banks can offer low rates and other economic incentives to credit-worthy people, and make decisions for hundreds of thousands of dollars (…

I pretty much have opted out entirely. I'm sure these agencies collect information on me regardless, there's not much I can do about that. I have no need for loans other than possibly a mortgage - I find it difficult to conceive of why one would even want a loan, outside of the first few years of adulthood. The mortgage is a stickler, but given that I have no desire to lock myself in to the traditional 25 years of wo…

In many cities, you can't even rent an apartment without a credit history.

Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service

#34

So I began reading and figured, huh, thieves must just stealing be the validation letter USPS would send, and thought, hey, that system which is used in many other places for similar things would be quite vulnerable to that attack, right? But then I got to this bit: > KrebsOnSecurity took the USPS to task last year in part for not using its own unique communications method — the U.S. Mail — to validate and notify res…

Yeah. It's essentially this bad almost everywhere. You think "surely X" but no. Almost never X. Almost always some lazy Y or nothing at all. After a couple consulting contracts / vuln disclosures I updated my priors of how competent the government was. I'm actually getting worried now that everything is going cyber-physical and corporations can pull the wool over their eyes. The government is great at offense, but de…

This is a great perspective but it's important to remember your sample bias -- you're only making judgments about the offender you've identified. Or more snarkily, you've only caught the people dumber than you.

When you're talking about basic attacks to steal some money, this is a substantial but not world-changing effect. On the other hand, a government or cartel willing to invest significant resources in cyber offense can really move the needle. What we've seen Russia, North Korea, Israel, and others achieve is probably only a fraction of what they've actually achieved.

Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service

#35

So I began reading and figured, huh, thieves must just stealing be the validation letter USPS would send, and thought, hey, that system which is used in many other places for similar things would be quite vulnerable to that attack, right? But then I got to this bit: > KrebsOnSecurity took the USPS to task last year in part for not using its own unique communications method — the U.S. Mail — to validate and notify res…

I signed up earlier this year and the validation required answering several multiple choice questions with data from my credit report such as mortgage, car loan, etc. I also received a postcard confirming that Informed Delivery had been activated for my postal address.

I signed up a few months ago and had this type of validation as well. I didn't get a postcard, presumably they hadn't started that practice yet.

Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service

#36
post #11

So I began reading and figured, huh, thieves must just stealing be the validation letter USPS would send, and thought, hey, that system which is used in many other places for similar things would be quite vulnerable to that attack, right? But then I got to this bit: > KrebsOnSecurity took the USPS to task last year in part for not using its own unique communications method — the U.S. Mail — to validate and notify res…

You can forward someone else's mail too. Just go to the post office, fill out the form, and drop it in the mailbox. There's no verification, though there is notification at both the old and the new address. Not to mention it's a crime to do that.

It struck me how easy it would be to get someone else's social security card this way: with the information from the Equifax breach, you have all the data you need to request a replacement card online, and by forwarding their mail you can get the card when it arrives.

Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service

#37
post #21

Earlier quoted context omitted.

Here in Sweden, everyone's address has to be registered with the Tax Agency. In their (securely authenticated by digital ID which can only be obtained using photo ID) online services you can choose to disallow changes of your registered address which are not made digitally to prevent this kind of thing. Personally I have this turned on, because I'm conscious that every piece of information you'd need to send a fake a…

That system would also allow us to completely get rid of our horrendous voter registration system, and make universal voting a reality.

[flagged]

Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service

#38
I've noticed after first signing up around April that whatever scanner they're using can see through the envelope and you can pretty clearly read at least part of the contents for a standard folded letter, but at some point later in the year the contrast of the images was changed and it wasn't as common to see it anymore. Most of my mail is junk, but I can only imagine the kinds of opportunity that capability at scale presents.

Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service

#39
I'm working on a honeypot service that lets people create canary credentials to detect eavesdropping. One of the fringe use cases is to see if someone has intercepted your mail or packages. I'm not sure if that's a use case anyone actually cares about though, but stories like this make me wonder.

curious if this is something anyone here would want to try, I'm happy to give some free invites if anyone wants - my email is in my profile.

Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service

#40

So I began reading and figured, huh, thieves must just stealing be the validation letter USPS would send, and thought, hey, that system which is used in many other places for similar things would be quite vulnerable to that attack, right? But then I got to this bit: > KrebsOnSecurity took the USPS to task last year in part for not using its own unique communications method — the U.S. Mail — to validate and notify res…

I signed up earlier this year and the validation required answering several multiple choice questions with data from my credit report such as mortgage, car loan, etc. I also received a postcard confirming that Informed Delivery had been activated for my postal address.

Same here. I signed up late last year and they used the same kind of credit bureau-based system that social security uses to verify your identity by asking questions about previous addresses, current mortgage or car loans, etc.

Maybe it would be good to also add in a postcard check where they send you a code to verify you have access to mail for the address anyway. Sure, a thief could too, but in that case there isn't much of an extra risk to informed delivery since you'd be compromised already.

Post reply on HN