Live data from Hacker News

U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service

krebsonsecurity.com

51–60 of 135 posts

Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service

#51
post #21

Earlier quoted context omitted.

Here in Sweden, everyone's address has to be registered with the Tax Agency. In their (securely authenticated by digital ID which can only be obtained using photo ID) online services you can choose to disallow changes of your registered address which are not made digitally to prevent this kind of thing. Personally I have this turned on, because I'm conscious that every piece of information you'd need to send a fake a…

That system would also allow us to completely get rid of our horrendous voter registration system, and make universal voting a reality.

Except in the USA, voting is constitutionally a state thing, not federal.

Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service

#53

So I began reading and figured, huh, thieves must just stealing be the validation letter USPS would send, and thought, hey, that system which is used in many other places for similar things would be quite vulnerable to that attack, right? But then I got to this bit: > KrebsOnSecurity took the USPS to task last year in part for not using its own unique communications method — the U.S. Mail — to validate and notify res…

I signed up earlier this year and the validation required answering several multiple choice questions with data from my credit report such as mortgage, car loan, etc. I also received a postcard confirming that Informed Delivery had been activated for my postal address.

I just signed up and 2 out of the 4 questions could easily have been looked up on Zillow and they're all multiple choice with 4 options. The 2 questions were the year my house was built and the original sale price.

So anyone would've had a 1/16 chance of just guessing it right.

Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service

#54

Earlier quoted context omitted.

I use this service, and when I signed up there was nothing to verify I was who I was. I just put in my address, created an account, and within a day or so could get scans of mail sent to my e-mail. This is pretty great too. I moved about two months ago, and switched addresses in Informed Delivery. I got a letter saying I switched, but I never put their code into Informed Delivery, and I still get scans of my mail at…

Note that tampering with the mail, even if there are little technical limitations, is a federal crime that carries pretty severe penalties.

People love repeating this for some reason, but mail crime is under-funded, rarely investigated, and even more rarely enforced.

Realistically if you tamper with mail nothing at all will happen to you, until your fraud raises to a headline figure and could get someone a promotion.

Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service

#55

So I began reading and figured, huh, thieves must just stealing be the validation letter USPS would send, and thought, hey, that system which is used in many other places for similar things would be quite vulnerable to that attack, right? But then I got to this bit: > KrebsOnSecurity took the USPS to task last year in part for not using its own unique communications method — the U.S. Mail — to validate and notify res…

> What the hell are USPS smoking?

They always been smoking something.

When they released their "forward your mail to your new home online" feature where they charge your credit card $1 to verify your new ZIP code, I read it somewhere on dark web that a gift card works as well. I was actually purchasing new house, so I figured I give it a try! I bought a $20 gift card Visa Vanilla (with cash) and registered it online (during my visit in Starbucks using their WiFi) with my new ZIP code (you can provide any ZIP code while you register your gift card - its only for further verification) and sure it worked out like a charm! I figure I am not the only one that succeed with this. Then I read few months later at the same forum someone answer that USPS is blocking gift and prepaid cards at the moment. But for few months at least a hell broke out loose when you could load $20 gift card and pretty much forward mail of 20 strangers to your desired location, at $1 per pop.

Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service

#56

So I began reading and figured, huh, thieves must just stealing be the validation letter USPS would send, and thought, hey, that system which is used in many other places for similar things would be quite vulnerable to that attack, right? But then I got to this bit: > KrebsOnSecurity took the USPS to task last year in part for not using its own unique communications method — the U.S. Mail — to validate and notify res…

We had Informed Delivery at our old house, and now we have it at our new house... except we don't know how to stop receiving emails from the old house, so we know what the homeowner of our old house gets every day.

Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service

#57
post #21

Earlier quoted context omitted.

Here in Sweden, everyone's address has to be registered with the Tax Agency. In their (securely authenticated by digital ID which can only be obtained using photo ID) online services you can choose to disallow changes of your registered address which are not made digitally to prevent this kind of thing. Personally I have this turned on, because I'm conscious that every piece of information you'd need to send a fake a…

That system would also allow us to completely get rid of our horrendous voter registration system, and make universal voting a reality.

The failures of the US voter registration system are deliberate, targeted disenfranchisement.

Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service

#58
post #11

So I began reading and figured, huh, thieves must just stealing be the validation letter USPS would send, and thought, hey, that system which is used in many other places for similar things would be quite vulnerable to that attack, right? But then I got to this bit: > KrebsOnSecurity took the USPS to task last year in part for not using its own unique communications method — the U.S. Mail — to validate and notify res…

You can forward someone else's mail too. Just go to the post office, fill out the form, and drop it in the mailbox. There's no verification, though there is notification at both the old and the new address. Not to mention it's a crime to do that.

People have been abusing this already https://www.chicagotribune.com/news/local/breaking/ct-met-up...

Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service

#59

So I began reading and figured, huh, thieves must just stealing be the validation letter USPS would send, and thought, hey, that system which is used in many other places for similar things would be quite vulnerable to that attack, right? But then I got to this bit: > KrebsOnSecurity took the USPS to task last year in part for not using its own unique communications method — the U.S. Mail — to validate and notify res…

> What the actual hell? You can sign up online to get mail scanned… without any physical verification you're at the address, with only a physical notification being sent after-the-fact?

I signed up for Informed Delivery a couple weeks ago, and it did ask for additional verification information. It was similar to questions asked by financial institutions when opening accounts online: "which of these 4 addresses have you lived at in the past?", "What was the name of your first pet?", etc. All presumably information that has been collected by companies such as Experian.

Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service

#60

So I began reading and figured, huh, thieves must just stealing be the validation letter USPS would send, and thought, hey, that system which is used in many other places for similar things would be quite vulnerable to that attack, right? But then I got to this bit: > KrebsOnSecurity took the USPS to task last year in part for not using its own unique communications method — the U.S. Mail — to validate and notify res…

I'm guessing they were going off the doctrine of "You have no expectation of privacy in the external packaging of your mail" .

Thus, they didn't see a need for tight security regarding who can get access to such images.

Post reply on HN