Live data from Hacker News

U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service

krebsonsecurity.com

101–110 of 135 posts

Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service

#101
post #10

Security Concerns aside. The informed delivery service is great. I've been using it for a little over a year now. They began inserting ads into the Informed Delivery Email. Senders must place some sort of barcode that is then read by the USPS scanner. It's nice to see our postal service trying to close the gap on their (net) loss.

Just looked this up--it's apparently called "Informed Delivery Interactive Campaigns". They use the example of a mailer advertising an online sale: recipients with Informed Delivery can click on the link right from the USPS dashboard to the sale website. They have a bunch of analytics you can get and the whole thing looks pretty sophisticated.

As far as I can tell, this is all free to mailers, at least for the moment. Maybe they're planning on charging for it later.

USPS docs here: https://www.usps.com/business/informed-delivery.htm

Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service

#102
I signed up the USPS mail scanning because I thought that it would be cool. However, I live in a small apartment building, and apparently USPS doesn't recognize it as an apartment building, so I would get everyone's mail. There was no verification either. I found it kind of scary the amount of info I was getting. Had to cancel because there was a lot of noise and it ultimately wasn't useful for me.

Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service

#103

So I began reading and figured, huh, thieves must just stealing be the validation letter USPS would send, and thought, hey, that system which is used in many other places for similar things would be quite vulnerable to that attack, right? But then I got to this bit: > KrebsOnSecurity took the USPS to task last year in part for not using its own unique communications method — the U.S. Mail — to validate and notify res…

You still need to go to the actual mailbox to steal the credit cards, so you could presumably steal the verification as well. I don't actually see what this buys a person beyond I guess knowing when the credit card will show up so he can intercept it, but really you could just figure 3 days to receive a new card and be right most of the time.

Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service

#104

So I began reading and figured, huh, thieves must just stealing be the validation letter USPS would send, and thought, hey, that system which is used in many other places for similar things would be quite vulnerable to that attack, right? But then I got to this bit: > KrebsOnSecurity took the USPS to task last year in part for not using its own unique communications method — the U.S. Mail — to validate and notify res…

[deleted]

Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service

#105
post #92

Earlier quoted context omitted.

People love repeating this for some reason, but mail crime is under-funded, rarely investigated, and even more rarely enforced. Realistically if you tamper with mail nothing at all will happen to you, until your fraud raises to a headline figure and could get someone a promotion.

People love stating this fact because it's likely most people are surprised the law allows for such severe serious penalties for what might seem like a petty infraction. What you've said about underfunded enforcement and rare investigations could be said about almost every other type of non-violent crime.

Uh kyc banking laws used to fund terrorism (eg hawalas) have been extensively ramped up over the past 20 yrs. Theres certain non violent crimes that law enforcement has carte blanche to investigate.

Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service

#106

Exploits aside, this service however convenient, just reeks of Big Brother to me. Not that I get that much info via USPS anymore but the idea that __everything__ is being logged (for future reference?) makes me uncomfortable.

This scanning of your mail is happening whether you sign up or not. It's simply part of the process of moving items from A to B. The fact USPS found a way to add value for their customers should be commended.

Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service

#107
post #84

Exploits aside, this service however convenient, just reeks of Big Brother to me. Not that I get that much info via USPS anymore but the idea that __everything__ is being logged (for future reference?) makes me uncomfortable.

Informed Delivery is just them offering a service based on infrastructure that was already there -- the mail scanning was put into place during the 90's anthrax in the mail scares, and that's really it's purpose.

" and that's really it's purpose."

Not to get off topic but...Or so we were told.

Today, __every__piece of USPS is scanned because of a handful of rogue letters 20+ yrs ago? No one unreasonable would find that reasonable.

Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service

#108

I wonder if more than one party can sign up for the same address? Am I safe because I've already signed up or are they happy to let someone else monitor my mail too?

Send me your address and I'll tell you. ;)

The article mentions that you really need to register every person at your address to avoid being monitored by an unknown. Even so, there is no clear indication whether USPS even verifies that a registered name receives mail at a given address.

Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service

#109
post #87

Earlier quoted context omitted.

It struck me how easy it would be to get someone else's social security card this way: with the information from the Equifax breach, you have all the data you need to request a replacement card online, and by forwarding their mail you can get the card when it arrives.

Last time I got social security cards, they were printed on cardstock with absolutely no security features. They would be trivial to counterfeit, if you had the number to begin with. It's amazing that they are accepted as a form of ID to get e.g. a passport.

They may be one form of ID required. (And I'm not sure that's even the case.) They are certainly not sufficient. You need proof of citizenship. You need some form of government-issued ID.

I haven't personally had a social security card in many decades. For the first time in I don't know how long, I do need to provide some form of proof of SSN to get a RealID drivers license renewal but last year's W2 is sufficient for that.

Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service

#110
post #94

Earlier quoted context omitted.

Yes, but they don't put their crack team on most stuff. Have you read the Snowden leaks? The actual raw content? It's pretty tame shit. My main takeaway was ahh, yes the world is as insecure as I thought it was not oh, these guys are using space laser technology hacks . They've got crack teams to break into some harder gear, and they've got some crazy awesome cryptanalyses going on, but for most of it it's just what…

> I sat with a whole table of them and watched them fall for a simple social engineering attack one minute after being told they were going to fall for the attack. Story time?

I mean it isn't that interesting of a story, really.[-1]

And I want to stress I'm not a full time government contractor. I just did a couple short contracts for a department and it made me wtf so hard I signed up for one of those conferences where they set the ticket price so high it keeps out the curious[0], but it isn't classified or even protected.

But I'll share anyway because you asked.

I walk into the room titled "something something Social Engineering Attacks" because the other one was on something I couldn't care less about. Fiddling with AWS settings probably.

Look around. Mostly tired, overworked looking sysadmins from different government departments and the occasional consulting company or bank.

Walk further into the room and there it is, a table full of my people. Dungeons and dragons (D&D) looking types of both genders that looked like they were born in or around 1984.

Sit down. "Hi." They're friendly; I forget what we talk about, but they all have sigint department name tags. Most were slated to give talks later in the conference.

Talk starts. Guy on stage.

Guy: "Within one minute of explaining what I'm going to socially engineer you to do you will do it."

Me: Internal monologue; The fuck you will.

D&D: Look kinda intrigued, kinda befuddled.

Guy: "Ok so first thing we need to do is to get you to stand up. Don't worry the clock hasn't started yet. We're just standing."

Me: Squints skeptically. Stands. Internal monologue: Where the hell is this going?

D&D: Stands up like the rest of the room, faces guy.

Guy: "Ok here is the game I'm going to get you to flip your hands like this."

Guy: Flips hands from palms down to palms up.

Me: Internal monologue: The fuck you are.

Me: Crosses arms.

D&D & Room: Chuckle.

Guy: "Ok, you ready? Go. Oh; one last thing..."

Me: Internal monologue: Ha! Good fucking luck buddy you already said "go" and I'm already crossed.

Guy: "...otherwise there is no game at all you'll just cross your arms and stand there. So you have to put your arms in front of you like this..."

Guy: Begins to slowly raise his arms.

D&D & Room: Begin to raise their arms so their palms are face down to the ground.

Guy: "... like this."

Guy: Shows arms out in-front of him with the palms face up.

Me (Quietly, to my table of future elf and dwarven partisans.): "Nooo. Don't do it."

D&D & Room: Flip their hands over to match guy.[2]

D&D: Look away from guy to me.

Guy: Does the TA-DA gesture.

Room: Laughs.

D&D: "How did you know?"

Me: "I know how these people think."

Rest of the conference people were convinced I was a Canadian spy or something. It's ok though. I got too drunk and made a fool of myself because a convo I had with a cyberwarfare guy (essentially) confirmed my fears that self-driving cars were WMDs due to class-attack (bad server update ala notPetya, say).

Gunna be feeling the burning shame on that one for at least another year.

Whatever.

At least all that foolishness is over. I thought I was losing my mind. Now that Schneier's book is out and it's been almost a year I'm back to being able to trust my own mind again. The cybersec scene is kinda stressful, but it's nothing compared to the kind of stress where you can't trust your own mind.

[-1] Well it wasn't going to be, so I spiced it up a bit by expanding into my failings as a human.

[0] Well most of the time, anyway. Can't stop me from lolsing into a conference to get a better read on where things are at.

[1] Memory isn't perfect, but you get the idea.

[2] Room of 100 people and I'm almost certain I was the only one that didn't get tricked.

Post reply on HN