Earlier quoted context omitted.
Here in Sweden, everyone's address has to be registered with the Tax Agency. In their (securely authenticated by digital ID which can only be obtained using photo ID) online services you can choose to disallow changes of your registered address which are not made digitally to prevent this kind of thing. Personally I have this turned on, because I'm conscious that every piece of information you'd need to send a fake a…
That system would also allow us to completely get rid of our horrendous voter registration system, and make universal voting a reality.
U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service
111–120 of 135 posts
Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service
#112So I began reading and figured, huh, thieves must just stealing be the validation letter USPS would send, and thought, hey, that system which is used in many other places for similar things would be quite vulnerable to that attack, right? But then I got to this bit: > KrebsOnSecurity took the USPS to task last year in part for not using its own unique communications method — the U.S. Mail — to validate and notify res…
You can forward someone else's mail too. Just go to the post office, fill out the form, and drop it in the mailbox. There's no verification, though there is notification at both the old and the new address. Not to mention it's a crime to do that.
Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service
#113Earlier quoted context omitted.
That system would also allow us to completely get rid of our horrendous voter registration system, and make universal voting a reality.
Except in the USA, voting is constitutionally a state thing, not federal.
Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service
#114Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service
#115So I began reading and figured, huh, thieves must just stealing be the validation letter USPS would send, and thought, hey, that system which is used in many other places for similar things would be quite vulnerable to that attack, right? But then I got to this bit: > KrebsOnSecurity took the USPS to task last year in part for not using its own unique communications method — the U.S. Mail — to validate and notify res…
I use this service, and when I signed up there was nothing to verify I was who I was. I just put in my address, created an account, and within a day or so could get scans of mail sent to my e-mail. This is pretty great too. I moved about two months ago, and switched addresses in Informed Delivery. I got a letter saying I switched, but I never put their code into Informed Delivery, and I still get scans of my mail at…
Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service
#116So I began reading and figured, huh, thieves must just stealing be the validation letter USPS would send, and thought, hey, that system which is used in many other places for similar things would be quite vulnerable to that attack, right? But then I got to this bit: > KrebsOnSecurity took the USPS to task last year in part for not using its own unique communications method — the U.S. Mail — to validate and notify res…
Yeah. It's essentially this bad almost everywhere. You think "surely X" but no. Almost never X. Almost always some lazy Y or nothing at all. After a couple consulting contracts / vuln disclosures I updated my priors of how competent the government was. I'm actually getting worried now that everything is going cyber-physical and corporations can pull the wool over their eyes. The government is great at offense, but de…
Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service
#117I'm working on a honeypot service that lets people create canary credentials to detect eavesdropping. One of the fringe use cases is to see if someone has intercepted your mail or packages. I'm not sure if that's a use case anyone actually cares about though, but stories like this make me wonder. curious if this is something anyone here would want to try, I'm happy to give some free invites if anyone wants - my email…
Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service
#118Earlier quoted context omitted.
> I sat with a whole table of them and watched them fall for a simple social engineering attack one minute after being told they were going to fall for the attack. Story time?
I mean it isn't that interesting of a story, really.[-1] And I want to stress I'm not a full time government contractor. I just did a couple short contracts for a department and it made me wtf so hard I signed up for one of those conferences where they set the ticket price so high it keeps out the curious[0], but it isn't classified or even protected. But I'll share anyway because you asked. I walk into the room titl…
Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service
#119I'm working on a honeypot service that lets people create canary credentials to detect eavesdropping. One of the fringe use cases is to see if someone has intercepted your mail or packages. I'm not sure if that's a use case anyone actually cares about though, but stories like this make me wonder. curious if this is something anyone here would want to try, I'm happy to give some free invites if anyone wants - my email…
would you mind expounding a bit on how this might work in application?
The users then hide these bait credentials in places that should be private (in this case, a letter or package to be mailed). If an eavesdropper intercepts the package, they'll also find the bait credentials (perhaps written on a post-it note). If they try to use the stolen bait credentials at the honeypot website, our users then get an alert, and the intrusion is logged.
The normal use case is to place bait credentials on your devices or servers, but in this case they would be used in a physical location (i.e. a letter in the mail).
Take a look at https://www.tamarin.us if you want - I'd appreciate any feedback, I'm still trying to validate the concept.
Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service
#120Earlier quoted context omitted.
Informed Delivery is just them offering a service based on infrastructure that was already there -- the mail scanning was put into place during the 90's anthrax in the mail scares, and that's really it's purpose.
" and that's really it's purpose." Not to get off topic but...Or so we were told. Today, __every__piece of USPS is scanned because of a handful of rogue letters 20+ yrs ago? No one unreasonable would find that reasonable.
Every package is also X-rayed for potential explosives because of a scare 20+ years ago -- and thankfully they continued to do so otherwise we'd have some dead due to pipe bombs.
People find it extremely reasonable. We have increased airport security now because of what happened 17 years ago and most people also find that reasonable.