Results 1 to 2 of 2

Thread: ID thieves are exploiting USPS mail-scanning service, Secret Service warns

  1. #1

    ID thieves are exploiting USPS mail-scanning service, Secret Service warns

    The U.S. Postal Service’s Informed Delivery service is cool. The free service sends users an email every morning with photos of the mail they can expect in the day’s delivery. It’s a convenient option for anyone anxiously awaiting the arrival of their Orphan Annie Secret Society decoder pin (or just too lazy to trudge to the mailbox every day). More than 6 million people have signed up for Informed Delivery, but they may rethink the decision after a recent warning from the U.S. Secret Service.

    Tech watchdog Krebs on Security reports that the U.S. Secret Service sent an internal alert on November 6 warning that scammers are using the Informed Delivery feature “to identify and intercept mail, and to further their identity theft fraud schemes.” They also want to use the service to “surveil potential identity theft victims” on criminal forums, Krebs reports.
    The alert was sent in the wake of a Michigan bust, where seven people were arrested for allegedly stealing credit cards from mailboxes and racking up $400,000 in charges after signing up as those victims at the USPS website. Krebs on Security had warned this was possible a year ago, bluntly calling Informed Delivery “a stalker’s dream.”

    More at: https://www.fastcompany.com/90265536...-service-warns
    Never attempt to teach a pig to sing; it wastes your time and annoys the pig.

    Robert Heinlein

    Give a man an inch and right away he thinks he's a ruler

    Groucho Marx

    I love mankind…it’s people I can’t stand.

    Linus, from the Peanuts comic

    You cannot have liberty without morality and morality without faith

    Alexis de Torqueville

    Those who fail to learn from the past are condemned to repeat it.
    Those who learn from the past are condemned to watch everybody else repeat it

    A Zero Hedge comment



  2. Remove this section of ads by registering.
  3. #2
    A broken U.S. Postal Service API exposed more than 60 million users by allowing a researcher to pull millions of rows of data by sending wildcard requests to the server. The resulting security hole has been patched after repeated requests to the USPS.
    The USPS service, called InformedDelivery, allows you to view your mail before it arrives at your home and offered an API to allow users to connect their mail to specialized services like CRMs. We profiled the service in 2017.
    The anonymous researcher showed that the service accepted wildcards for many searches, allowing any user to see any other users on the site. Brian Krebs has a copy of the API’s code on his site.

    More at: https://techcrunch.com/2018/11/26/th...rs/?yptr=yahoo
    Never attempt to teach a pig to sing; it wastes your time and annoys the pig.

    Robert Heinlein

    Give a man an inch and right away he thinks he's a ruler

    Groucho Marx

    I love mankind…it’s people I can’t stand.

    Linus, from the Peanuts comic

    You cannot have liberty without morality and morality without faith

    Alexis de Torqueville

    Those who fail to learn from the past are condemned to repeat it.
    Those who learn from the past are condemned to watch everybody else repeat it

    A Zero Hedge comment



Similar Threads

  1. Postal Service photographs mail
    By Matt Collins in forum Individual Rights Violations: Case Studies
    Replies: 13
    Last Post: 09-17-2013, 07:21 PM
  2. Postal Service to Cut Saturday Mail
    By green73 in forum U.S. Political News
    Replies: 10
    Last Post: 02-06-2013, 10:30 AM
  3. The Next Bailout: The U.S. Postal Service (USPS)?
    By FrankRep in forum U.S. Political News
    Replies: 3
    Last Post: 05-18-2011, 05:27 PM
  4. Postal Service (USPS) to Close Thousands of Post Offices
    By FrankRep in forum Economy & Markets
    Replies: 22
    Last Post: 01-31-2011, 04:58 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •