Man Allegedly Used Change of Address Form to Move UPS Headquarters
npr.org
npr.org
Come on, this guy is a genius. The fact he managed to pull it off by literally using cartoon-level forgery is nothing but remarkable.
I don't it takes a genius to recognize the fragile parts of a seemingly secure system we live in. I'm sure there are people in every industry that know things that can be easily exploited for profit.
This is about affecting businesses worth billions of dollars. Couldn't the same have happened to a Fortune 500 company?
Someone remotely close to being smart would instead route to someplace he doesn't live, for starters. And it doesn't say anything about credit card fraud, which would be much wiser rather than check fraud (in the context of breaking the law here) since there is much less recorded evidence.
if you want to learn the fundamentals of social engineering or educate a person who needs to be resistant to it, read mitnick's "art of deception" book.
I've tried to get it fixed online, but so far no results.
Imagine how terrible GMail's spam filters would be if spammers paid Google for delivery... Oh wait, Google literally has a dedicated tab for that! For those that find it useful (and I don't doubt it is), imagine what the alternative would be for the spammers, you'd be 100% ignoring it by unsubscribing or filtering it as spam. Now that it's corralled off, you can look at it at your leisure, and Google can keep advertisers happy by offering them a non-zero chance you'll look at their spam.
I mean, ok so USPS is getting $5/mo for my address from a dozen companies. Can I just pay them that $5? Not today.
I'd be happy to open the discussion on opting out of the junk mail without going to a costly service like earth-class mail.
I'll give you my two big complaints:
1) The time delay. My Traveling Mailbox address is in the western half of the US. Mail has to be delivered to that address, then shipped cross country to North Carolina where their headquarters and mail scanner is. You can count on an additional 3 to 14 days after USPS thinks the mail has been delivered before a scan of it shows up in my email inbox. A couple years ago, this was much worse and less consistent; occasionally letters were 3 weeks late. However in the past 2 years or so, I've noticed the time delay has been much more consistent, centering around 3-5 business days. They maintain addresses all over the country, and there's probably only the scale and margin to maintain one scanning facility, so I don't know what TM could realistically do to address this problem. If I didn't need an address where I have it, I would have already moved my address to Sanford, NC, where their headquarters is.
2) Some banks don't like the address. Due to KYC laws, banks and financial institutions need a residential address for their clients. I'm homeless and don't have such an address, so this is difficult for me. Traveling Mailbox is nice in that they give you a street address, not a P.O. Box. To a casual glance, it looks like a normal street address, but if one researches the address online, one will find that it's a business. When I changed my address over to use my TM address as my home address, about half the financial institutions I worked with rejected the address as not being my residence and said they couldn't do business with me anymore. Some asked for a driver's license as proof of the address. I said no problem and faxed my driver's license (which has my TM address), but the institutions still closed my account without further explanation. I'm still a little salty about the hubris of the politicians who enacted the KYC laws, assuming that everybody conforms and has a permanent residential address.
Edit: It should be obvious that you could do this with physical mail too.
The problem I see is that the processing and bandwidth used by advertising are currently "as much as advertisers can get away with" and I think it's leading to a tragedy of the commons.
But I see no need to eliminate ads and free services either. There just needs to be a cap enforced on the resources used.
Once it's in my mailbox, what can I do, drop it on the ground? That's littering and a crime. Leave it in my mailbox? I tried that and the mailman eventually stuck a Post-It note on my box saying I wasn't allowed to do that.
So I'm in some sort of weird uncontracted relationship wherein I must ferry a bunch of paper from my box to the recycling bin.
I used to do that until the mailman decided I didn't live here anymore...twice.
Now I apparently don't have a mailing address though the only bill I could never successfully get converted to all electronic (not from lack of trying) is the power company which messes them up every so often getting their bills returned every month.
I tried this with a twist, I wrote "return to sender" on it. Mail(wo)man also said "you cannot do this."
I'm curious if there's a list of things like this that the USPS explicitly does not allow..
1. Open the envelope and look for a pre-franked reply envelope. If there is one, stuff the junk into that and post it. Extra revenue for the postal service.
2. If it is a really persistent and annoying sender, mutilate my address and post it. This should result in it being routed back to the sender but does impose extra work on the postal service.
Sadly, I think the USPS now refuses to deliver those, after a rash of people taping return envelopes to cinder blocks a few decades back.
On one hand we have PCI-compliance, SSL encryption, and on the other hand we have a phone call (unecrypted, easily tappable anywhere along the thousands of miles of wire) where companies expect to call me and assume it's secure enough for me to 1) know that it's definitively them and 2) not have some support agent steal my credit card information/private information.
To which I reply “You called me. I don’t know that you are who you say you are. I’m not giving you anything.” And hang up. What moron thought this was a good idea?
One time my own bank scammed me into giving them my full seven digit SSN over the phone when they called me. And all they had to do was ask me for it!
The worst part was that I fell for it. Of course, no harm done, because it really was my bank, but what an idiot I was.
At least I knew better when the Windows Support people started calling me a year later!
You've seen off by one errors, this is twice as bad.
Apparently, every time I order medical supplies they call me to tell me that they've sent a Very Important Letter, but they can't say what it is. When it arrives the next day, it informs me that they've approved my request for the supplies, which by this point have already arrived a week and a half ago.
It's gotten to the point where the calls now go like this:
Them: Hi, this is [insurance company], can I have your date of birth please?
Me: Is this about the letter you've sent?
Them: ...Yes?
Me: OK, I'll keep an eye out.
Them: Erm... right. Have a nice day!
I have no idea what the moral of this story is.Even if it had been a fraudulent call, they weren't asking for anything (so I didn't have to bother verifying it was legitimate), and even if they got the wrong person there is limited damage they could do.
Also, at some point, it becomes infeasible enough (that someone would have redirected my mail, hijacked my phone number or managed to change it with the bank, triggered a call from my bank, and managed to line them all up so I hadn't noticed there was a problem) and more trouble than it's worth to be worried about it happening.
You’re the fraud prevention department for chrissakes. Act like you’re preventing fraud, not participating.
it is designed to be as convoluted as possible to
a) increase billable hours
b) create loops hole big enough to drive a truck through that the $$$$$ lawyers can exploit for their clients
But like you said, it's all about screwing the system and I'm sure a judge would not understand any of these concepts regardless of how simple someone would make them.
Now that I'm older it worries me that it is very possible to go to court and be on the right side and have a judge and jury who cannot comprehend these basic concepts. I've had bosses who work in software / hardware industry not understand concepts, God forbid I ever have to defend myself in a public forum.
It's actually incredibly annoying, my rental contract was sent via this method, so I have to go to the post office to pick it up, despite the fact that I actually live closer to the real estate agents office.
Why they couldn't just email it to me, I'm not entirely sure.
Restricted Delivery
Specify the person who can sign for and receive your item. Must be purchased in combination with another extra service as follows: Certified Mail, COD, Insured Mail (over $500), Registered Mail, or Signature Confirmation.
Edit: Per Stamps.com [0], the USPS “may” require ID on delivery, but again, in my experience, I’ve never been asked once.
[0] https://stamps.custhelp.com/app/answers/detail/a_id/157/~/re...
From another perspective though - while not "secure against manipulation", at least postal mail has federal laws with serious punitive remedies, and investigators who seem to genuinely be committed to enforcing those laws and chasing the penalties.
Most things in the real world are not "4096 bit cryptographically secured, guaranteed unbreakable before the heat death of the universe", instead they're "secured by people with guns, courts, and jails who are society's deterrence against smashing fragile windows, picking flimsy locks, and fraudulently filling out paperwork".
It _mostly_ works.
And in some ways, the "fiction of security backed by laws with teeth" works _better_. I locked myself out of my apartment recently, and my friend with my spare keys was on a trip ~800km away. So I called a locksmith, who got through the two locks on my front door in ~90 seconds. I'm _very_ glad he could, even though the tool he used is easily available on AliExpress for ~$25...
Most door locks and deadbolts in the US will fall to rakes in a minute or less. I've found the Southord L-rake and Pagoda to be pretty effective. These can be had in basic versions without much of a handle from southord.com for $1.65. (A tension tool is also required; it's pretty much just a bent piece of steel).
I kinda knew "ordinary domestic locks" weren't very secure agains skilled lockpickers, and I don't know if there's some hidden technique required to use those things - but I was astounded and dismayed at how quickly my two different locks fell to such an easily available tool...
In short, standard pins in locks only have one place they're likely to stick when manipulated under tension: the shear line that allows the lock to open. Security pins have additional grooves machined into them that will make the pin stick at points that do not result in the lock opening. It's still possible to pick locks that have them, but it often needs to be done one pin at a time, which is usually slower and tends to require more skill.
There are some pretty incredible stories about the USPIS.
https://en.wikipedia.org/wiki/United_States_Postal_Inspectio...
I was downloading Postal Service mp3s from Kazaa and ended up downloading some USPS disciplinary reports on accident. I shared them with a friend because I thought they were funny, and he posted excerpts on a message board. From there it somehow got to the USPSIS who tracked down my friend’s cell phone #. I eventually agreed to meet, so the inspector flew out from DC and met us at a diner in Santa Cruz. He showed us his badge and went over how I ended up with the files. The whole thing was sort of bizarre, but he was pretty friendly and seemed more interested in figuring out how the files got out than throwing the book at me or my friend.
ACH is also laughably insecure, the only thing standing between it and total chaos is federal prison.
If you have a merchant account, you can take direct debits from and account using those numbers. Getting a merchant account underwritten for yourself can take less than a day, and the verification process isn’t all that robust.
Account numbers are essentially more valuable than credit card numbers. Except credit card numbers are at least supposed to be protected by a rather decent security standard. With ACH there is no such standard, you can handle account numbers any way you please, and many merchants do so very poorly. Also, the account number is written on checks that you literally hand out to people, which is pretty much the worst thing you could do with a credit card number.
Your anecdote is meaningless. Any individual can easily commit fraud with an account number, and if they put a small amount of effort into it, they could do it on a very large scale. There is no security standard that protects ACH data, only a short set of regulations that describe how committing fraud will send you directly to prison.
And governments!
In my neighborhood I routinely get mail that is meant for my neighbors, and they get mine. I don't know if it's a sorting problem at the central office or driver incompetence but regular postal mail is absolutely not reliable.
Of course, the penalties are pretty harsh, so most people don't bother.
Well, yes, but it's insecure in the same way that the average bank branch is insecure:
- you're not going to get away with a lot (important stuff is sent using something more secure than first-class mail)
- you're automatically committing a felony
- your crime will automatically be investigated by federal law enforcement, not just the local donut patrol
Uh, I didn't get one of those a few years ago when I moved. After the move I mailed something to my old address to make sure it worked.
I think the best way of preventing abuse for such a system would be to include a lookup fee for it's use (part of normal postage for mailed items).
You can use for: government interaction, banks, utilities, health records, and lots of other things.
They also made a digital secure mailbox, where you can receive PDFs from government, banks, utilities, doctors, etc. You can also send replies.
It sucks that all of this is point-and-click web apps without a standardized API. I'm sure other countries have similar things, but most implementations are probably snowflakes.
Whereas email is universally integrated everywhere, it's not trusted for personal sensitive information.
I hope one day secure webauthn and secure email will replace all these snowflakes. But as much as I hate to admit it, the non-standard walked gardens does do a better job, with higher security than the old paper world ever did.
Does that mean one has to constantly monitor this mailbox and is liable if something is left unanswered?
Like I said, I hate these systems with passion, but as much as I hate to admit it they are more secure than paper ever was. Probably also more convenient, as things moving fast compared to snailmail.
Yes, it's absolutely a snowflake as well, but considering the low amount of messages, I'm not sure that's much of a problem.
There are downsides in my opinion, like that my address/date of birth/age/living status is /very/ public.
Googling my name brings you to: https://www.hitta.se/jan+martin+harris+harasym/malm%C3%B6/pe...
Let's just do what we do with DNS and let anyone register a globally unique identifier. When USPS or FedEx or whomever wants to deliver to that address, they just perform a lookup to find the physical address to deliver to. You could create different identifiers for the different sorts of things you want delivered, and if you start to get a lot of spam you could just delete it and create a new one.
The reason why it needs to be handled through national ID numbers is because ultimately, national governments are today's identity arbiters, and they do the best job of verifying identity. They're not perfect, but they're the best body for the task, and strong, verifiable identity is the foundation upon which all other security is built.
I'm genuinely curious how Americans think a national ID number would practically increase any surveillance?
To me it sounds like a win for consumers. You no longer give your home address out to every single website that requires an address, or every time you buy something online. You can update your address in 1 place when you move, and don't have to fuss around with redirects and missed mail/packages.
I'm very open to being shown what I'm missing though, as it's a hot debate lately and I just don't get it.
This is simply false. I choose not to carry a smartphone, I pay with cash for virtually everything, no "social media", I often use a VPN. There are many people who voluntarily give away all of their personal data to corporations - and there are many (though far fewer) of us who don't.
I am not sure when the above restriction went into effect. It appears the crime mentioned in the article was in 2016, so perhaps it is recent.
Was this actually a felony?
Now, if the return address on unstamped mail isn't within the local delivery area, it just goes to the dead letter pile.
> Henderson-Spruce now faces federal charges of mail theft, which carries a maximum sentence of five years, and mail fraud, which can be up to 20.
While a lot of current government processes aren't secure, they come with pretty hefty penalties that dissuade most people from messing around with them.
[1] https://torontolife.com/city/crime/name-johnson-chrome-hes-c...
If I had forwarded Company X's mail to my house, I might be able to argue that I thought it was just a prank, and planned to contact their legal team about it (and give them the (sealed) mail). That is still probably illegal, but it's believable that someone might not realize that.
If I start opening the mail and cashing the checks? WTF, I don't see how anyone could confuse that for ethical or legal behavior.
Do they actually investigate mail theft if it isn't at a huge scale like this? Someone got a hold of the USPS skeleton keys in our medium sized city (Oakland) and has raided the mail in our building multiple times, and we have them clearly on video for the multiple break ins, and the postal inspector in charge of the case just kind of shrugged it off as no big deal.
Would switching to a fob system that identifies who has access be the way to go?
I found this out on accident when I forwarded my mail somewhere else while I was traveling and they prompted me to sign up. I immediately started receiving emails with photos of all the mail going to this address.
Huge privacy fail. (And yes, the USPS knows about each individual apartment, delivering mail into a separate USPS box per apartment...)
If there is any verification, it occurs after the fact when someone complains that a payment got lost. Then the banks start looking to see what happened.
1) slow down every deposit by an order of magnitude or more in order to perform careful identity verification, when the vast majority are correct and honest
or
2) expend effort, afterward, cleaning up, the very few that are doing something illegal using the records they keep on what happened, and the fact that they can simply reverse the transactions when they do find something amiss.
For them, the cost of #2 is likely still lower than the costs of #1.
Now, the situation is different if you go in with a check and try to negotiate it for cash in hand right then and there. They will do the full identity verification at that time, massively slowing down your one-time action of converting a check into US Dollars in your pocket. This of course makes sense, there is no way to reverse a transaction that involves handing someone a stack of fifty dollar bills that they stick in their pocket. But in this case, just the one individual that did need to be triple checked before the action completed had their time extended by the verification process.
I once received a check to “The Estate Of <<my father>>”. I tried depositing it into a regular joint bank account that was under my name and my father’s name, and they rejected it and said I needed to open an account explicitly under my father’s estate, since you c can’t deposit a check to “The Estate Of...” to an account under the name of the deceased. I did the paperwork (my state allows you to file a Small Estate Affadavit in lieu of going through probate in some cases, mine included) and deposited the check.
Then I receive another check to “The Estate Of...” and take that to the bank, and they deposit it into the wrong account. Words cannot adequately express how I felt about this...
oh. hang on...
Thanks, Equifax data breach.
Good news: the SSA will only send your new card to your current address as reported in your credit report.
Thanks, USPS.
So, in summary, sounds like getting someone else’s social security card is pretty easy. Admittedly there’ll be a nifty paper trail, but I’m sure that’s solvable too.
Pretty funny way to go to jail.
apparently that is a service people offer on the dark net
Of course, depositing it into your own account creates a "paper trail" that will eventually lead to some law enforcement officer discussing your activities with you at some time in the future.
Then again, maybe the USPS is in fact, just that incompetent