Showing posts with label USPS. Show all posts
Showing posts with label USPS. Show all posts

Thursday, November 22, 2018

60 Million USPS Users' Data Left Exposed Over A Year Despite The Notification By A Researcher.


U.S. Postal Service has addressed a gap security that allowed a person with an account at usps.com to not only view but in some cases to modify account details on behalf of more than 60 million users of a system called Informed Visibility.
An anonymous researcher who discovered the flow informed the #USPS a year ago but has not received any response nor a fix to the problem. Due to the danger that to security flow posed, the same researcher contacted KrebsOnSecurity but also informed the journalist that he/she wished continued to remain anonymous.
KrebsOnSecurity contacted the USPS after confirming his findings, and USPS promptly addressed the issue.

The problem stemmed from an authentication weakness in a USPS Web component known as an “application program interface,” or API tied to a Postal Service initiative called “Informed Visibility,” which according to the USPS is designed to let businesses, advertisers and other bulk mail senders “make better business decisions by providing them with access to near real-time tracking data” about mail campaigns and packages. You can get more information about the issues here.

Monday, November 10, 2014

USPS, Unites States Postal Service, Hacked, Possibly By Chinese.

USPS, Unites States Postal Service, Hacked, Possibly By Chinese.

Hackers originating from China are suspected of breaching the computer networks of the United States Postal Service, compromising the data of more than 800,000 employees. FBI is currently investigating the intrusion. The intrusion was initially discovered in mid-September and according to the officials, and is now secure.
The compromised data included names, dates of birth, Social Security numbers, addresses, dates of employment and other information, officials said. Every employee from the letter carrier to the postmaster general was exposed.
“It is an unfortunate fact of life these days that every organization connected to the Internet is a constant target for cyber intrusion activity, the United States Postal Service is no different. Fortunately, we have seen no evidence of malicious use of the compromised data and we are taking steps to help our employees protect against any potential misuse of their data.” Postmaster General Patrick Donahoe said in a statement.
Washington Post
USPS Press Release