Live data from Hacker News

U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service

krebsonsecurity.com

111–120 of 135 posts

Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service

#111
post #21

Earlier quoted context omitted.

Here in Sweden, everyone's address has to be registered with the Tax Agency. In their (securely authenticated by digital ID which can only be obtained using photo ID) online services you can choose to disallow changes of your registered address which are not made digitally to prevent this kind of thing. Personally I have this turned on, because I'm conscious that every piece of information you'd need to send a fake a…

That system would also allow us to completely get rid of our horrendous voter registration system, and make universal voting a reality.

Lots of countries use the tax system to automatically sign up voters. Obviously this doesn't catch all potential voters - the people who don't file taxes because they have no income are likely a lot of the most disenfranchised individuals - but it gets you 90% of the way there. In Canada, whenever you file your taxes you have a box to tick 'automatically share my information with federal and provincial elections authorities'.

Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service

#112
post #11

So I began reading and figured, huh, thieves must just stealing be the validation letter USPS would send, and thought, hey, that system which is used in many other places for similar things would be quite vulnerable to that attack, right? But then I got to this bit: > KrebsOnSecurity took the USPS to task last year in part for not using its own unique communications method — the U.S. Mail — to validate and notify res…

You can forward someone else's mail too. Just go to the post office, fill out the form, and drop it in the mailbox. There's no verification, though there is notification at both the old and the new address. Not to mention it's a crime to do that.

The thing that stunned me about mail forwarding in the US is that it's free. There's as little verification here in Canada as in the US, but it's a pretty pricey service (minimum ~$60 depending on length of time) which naturally rate-limits fraud attempts.

Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service

#113
post #51
post #21

Earlier quoted context omitted.

That system would also allow us to completely get rid of our horrendous voter registration system, and make universal voting a reality.

Except in the USA, voting is constitutionally a state thing, not federal.

Even if that were entirely true, which it isn't, the Constitution is not fixed (except maybe the part about equal representation in the Senate, and there's a two-step trick to change that, too.)

Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service

#115

So I began reading and figured, huh, thieves must just stealing be the validation letter USPS would send, and thought, hey, that system which is used in many other places for similar things would be quite vulnerable to that attack, right? But then I got to this bit: > KrebsOnSecurity took the USPS to task last year in part for not using its own unique communications method — the U.S. Mail — to validate and notify res…

I use this service, and when I signed up there was nothing to verify I was who I was. I just put in my address, created an account, and within a day or so could get scans of mail sent to my e-mail. This is pretty great too. I moved about two months ago, and switched addresses in Informed Delivery. I got a letter saying I switched, but I never put their code into Informed Delivery, and I still get scans of my mail at…

This is correct in my experience. The letter says you have to confirm with the code, but either without doing that you keep getting the emails with scanned images.

Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service

#116

So I began reading and figured, huh, thieves must just stealing be the validation letter USPS would send, and thought, hey, that system which is used in many other places for similar things would be quite vulnerable to that attack, right? But then I got to this bit: > KrebsOnSecurity took the USPS to task last year in part for not using its own unique communications method — the U.S. Mail — to validate and notify res…

Yeah. It's essentially this bad almost everywhere. You think "surely X" but no. Almost never X. Almost always some lazy Y or nothing at all. After a couple consulting contracts / vuln disclosures I updated my priors of how competent the government was. I'm actually getting worried now that everything is going cyber-physical and corporations can pull the wool over their eyes. The government is great at offense, but de…

VPN?

Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service

#117

I'm working on a honeypot service that lets people create canary credentials to detect eavesdropping. One of the fringe use cases is to see if someone has intercepted your mail or packages. I'm not sure if that's a use case anyone actually cares about though, but stories like this make me wonder. curious if this is something anyone here would want to try, I'm happy to give some free invites if anyone wants - my email…

would you mind expounding a bit on how this might work in application?

Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service

#118
post #94

Earlier quoted context omitted.

> I sat with a whole table of them and watched them fall for a simple social engineering attack one minute after being told they were going to fall for the attack. Story time?

I mean it isn't that interesting of a story, really.[-1] And I want to stress I'm not a full time government contractor. I just did a couple short contracts for a department and it made me wtf so hard I signed up for one of those conferences where they set the ticket price so high it keeps out the curious[0], but it isn't classified or even protected. But I'll share anyway because you asked. I walk into the room titl…

There are some interesting social pressure group dynamics at play (e.g. go out in public and start staring at the sky and a people will start trying to see what you are looking at and glance at the sky-- literally monkey see monkey do?)

Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service

#119

I'm working on a honeypot service that lets people create canary credentials to detect eavesdropping. One of the fringe use cases is to see if someone has intercepted your mail or packages. I'm not sure if that's a use case anyone actually cares about though, but stories like this make me wonder. curious if this is something anyone here would want to try, I'm happy to give some free invites if anyone wants - my email…

would you mind expounding a bit on how this might work in application?

Basically, we host a collection of honeypot websites, which resemble login pages for a normal website. Our users create 'bait credentials' (username/password) for these honeypot websites.

The users then hide these bait credentials in places that should be private (in this case, a letter or package to be mailed). If an eavesdropper intercepts the package, they'll also find the bait credentials (perhaps written on a post-it note). If they try to use the stolen bait credentials at the honeypot website, our users then get an alert, and the intrusion is logged.

The normal use case is to place bait credentials on your devices or servers, but in this case they would be used in a physical location (i.e. a letter in the mail).

Take a look at https://www.tamarin.us if you want - I'd appreciate any feedback, I'm still trying to validate the concept.

Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service

#120
post #84

Earlier quoted context omitted.

Informed Delivery is just them offering a service based on infrastructure that was already there -- the mail scanning was put into place during the 90's anthrax in the mail scares, and that's really it's purpose.

" and that's really it's purpose." Not to get off topic but...Or so we were told. Today, __every__piece of USPS is scanned because of a handful of rogue letters 20+ yrs ago? No one unreasonable would find that reasonable.

It wasn't 20+ years ago, that was my bad (there were some anthrax cases in the 90s, but the high profile cases were in the 00's). There are cases of the USPS finding traces of anthrax in mail every 5 years, on average, probably more that we don't hear about. Most recent high profile case was in 2008.

Every package is also X-rayed for potential explosives because of a scare 20+ years ago -- and thankfully they continued to do so otherwise we'd have some dead due to pipe bombs.

People find it extremely reasonable. We have increased airport security now because of what happened 17 years ago and most people also find that reasonable.

Post reply on HN