USPS shared customer postal addresses with Meta, LinkedIn and Snap
techcrunch.com
techcrunch.com
Of course, it's terrible from a privacy point of view, but let's be honest and call things as they are.
2. those form field values are templated into a GET request to the Meta tracking pixel (or POST request to the /events endpoint, or ...)
3. profit
they've made it very easy https://developers.facebook.com/docs/meta-pixel/implementati...
("seen" meaning "I worked at a company where this happened and read the code with my own eyes" not just "I read it in the newspaper")
In that world, third party ‘tags’ that are included in a page are generally referred to as ‘pixels’. Sometimes they are single pixel img tags. Frequently they are scripts. But the industry calls them ‘pixels’ anyway.
It is, surprisingly, not a terribly honest industry.
https://chatgpt.com/share/3331fdec-c69c-46b0-9ffe-c48848fb29...
I did not, but now I know :)
(And although serverless doesn't mean 'no server', we know what the word means and it doesn't cause confusion.)
Doesn't the term confuse anyone hearing it for the first time? It sure did me.
I think about it every time I have to use it.
Maintaining a system takes people & resources. For 40+ years, there’s a push to not allow the government to actually hire and manage those itself, but use commercial entities, because “big government is bad”.
So it is easier to get the approval to pay x2 as much for a 3rd party than do it for half the budget internally. And as things need to be done, you end up saying f*k it and help ruin public service because it was mandated you’ll do so.
And then you end up with shitty services, which was the intent all along: it’s not about big government, it’s about outsourcing government contracts to you and yours.
The person that you’re replying to already called it negligent. It’s clear that it’s negligent.
That’s different from USPS not having some “legitimate” reason to use a Facebook tracking pixel somewhere.
I’m not even American, but I just spent 30 seconds on the USPS site and came across an online store where you can buy gifts, etc. This reasonably puts them well within the ballpark of an organisation that’d seek to use this sort of tech. As anyone that’s worked with anyone in ecommerce marketing will tell you, there’s always organisational pressure to shove these ‘tracking pixels’ onto your site.
Again, it’s negligent that they did it, from a privacy POV. But let’s not conflate that with ‘old man grumbling about social networks’.
> That’s different from USPS not having some “legitimate” reason to use a Facebook tracking pixel somewhere.
I don't think the USPS has any legitimate reason to be hosting tracking pixels from any entity outside the US government. USPS should have analytics on their website, but the USG has a hosted analytics package[0], and that's what they should be using -- which they are[1], so they should already be getting the data they need.
Or put it this way -- is there a data analytics platform that is suitable & easy to use for any US government agency? Not that I am aware of (but please let me know). Without such infrastructure, these government organizations understandably are looking for those commercial options.
That's definitely just a GeoIP database picking up AWS traffic.
* (in the last 30 minutes, as of now)
Well…
This is analytics data.
Or maybe you'd call that "mass surveillance".
I don't agree with them using known abusers of personal data for the tooling, but this is what I was talking about.
I don't like them using Facebook for analytics, I don't know what they were getting from it. But the basic premise of analytics, I think they should do.
I think it's fucked up that any agency is "marketing products" at all, but inasmuch as this is necessary in some way, surely they don't need the kind of surveillance marketing that's questionably even worth it for corporate advertisers to use. It literally reads like a google or facebook lawyer wrote it
I agree that they shouldn't be using tracking code from Facebook etc. for their analytics, but they do need analytics of at least some sort. I think that should hopefully be uncontroversial.
https://www.royalmail.com/privacy-notice and the cookie policy, 3.4.
I suppose it is nice that they tell you that they may send your name, contact information and purchase information to market research companies?
Matomo is pretty solid. And you can always use it just to ingest the data, then analyze it with something other than the default dashboards.
frankly I prefer when it's the government rather than companies selling it to foreign countries or scammers
> But being profitable is a non-goal; they exist to serve the people
Agree, but someone should probably tell Congress that.
The situation is trash (literally; 95% of my mail goes directly to the recycling bin), but conservatives want the USPS to behave more like a business, and its funding -- and need to do crappy things -- reflects that.
Their job isn't to stop junk mail. Their job is to reliably deliver whatever mail has my address on it to my mailbox.
How? The US government doesn’t fund the USPS.
There’s been some back and forth about the sudden mandate for USPS the pre funding retiree healthcare out 65 years, which nominally created a great deal of debt to the government as they failed to meet that sudden obligation. However, by removing the obligation that ‘debt’ disappeared as the government hadn’t actually spent any money on USPS retirees healthcare.
The second amendment doesn't define "arms" because (a) at the time there wasn't much ambiguity there and (b) "arms" isn't actually the most important concept there. The second amendment enshrines the right for citizens to be able to stand up militias and defend themselves. The US didn't have a standing army until WW2, despite Alexander Hamilton's opinions on the matter. The second amendment was put in place because colonists lived under the thumb of a monarch and at the end of an army's barrel with nothing guaranteeing the people a right to defend themselves, their neighbors, or their fellow colonists (eventually countrymen).
That aside, the concept of amendments exist for a reason. It's totally reasonable for Congress today to amend the Constitution if a definition of "arms" is now needed. It wouldn't be the first time a new amendment modified or entirely voided an earlier amendment.
What we don't need is court rulings, executive actions, or even new legislation short of an amendment trying to modify or redefine an existing amendment. If an amendment needs to be changed or clarified that needs to happen at the level of another amendment, anything less is short cutting the system and, in my opinion, not democratic.
I had to work on a feature like that, where individual client-companies wanted to sprinkle arbitrary pixel-trackers across different steps in our website's workflow for their users... Even today, I still worry I wasn't paranoid enough.
_______
For the curious/critiquing: When conditions are met, the main page JS creates a temporary <iframe src="..." sandbox="allow-scripts allow-same-origin">, and the destination URL (signed, time-limited) instructs a different subdomain to host up the icky arbitrary markup.
Yes, I know about the srcdoc attribute, and that would have been much easier except it breaks some tracker-code. In particular, Google Tag Manager silently stopped working, and it was because it contained some logic looking for "real site" aspects. This affected both `srcdoc` and also confused things when testing with `file://` URLs.
The platforms do an incredible job of selling their ad tech across a business. No matter what business you're in the expectation is that Google or Meta etc. SHOULD work, and if they don't your marketing team isn't doing it right.
So then the pressure comes from execs to do whatever is needed to make these platforms work well. The execs aren't close to the details of what that means, but they want results.
Marketing then gets told they need to push more data to the platforms to make things work. This lines up with the what the execs have been told as well, more data is a good thing right?
Since marketers are non-technical the platforms want to make passing data to the platforms AS SIMPLE AS POSSIBLE. Which leads to these all encompassing data trackers (which conveniently is good for the platforms as well). Marketers don't really understand the tradeoffs, they just know more data is a good thing, and they HAVE to get this platform working well or else they're out of a job.
Then the question of should we trust Google or Meta is just hand waved away. They're huge companies 'of course we should trust them, they're the best in the world' – is a pretty easy pitch for a personable account rep to make over an expensive lunch. Even if you don't trust them, what are you going to do, not work with them while you're competitors make money???
IMO it's clear market failure and govt intervention is the solution. Complaining about marketing departments not doing the right thing is never going solve the problem.
So we dodged some of those bullets just by a combination of training the marketing folks on how to use their own tools, and by just taking the bull by the horns and extracting the data for them.
We used to worry about trackers duplicating and profiling our player base back when we were running multi-billion dollar mobile games. F2P monetization being the long-tail beast it is, you really worry about ad platforms understanding your revenue dynamics. It was actually the managers who were worrying about trackers rather than the other way around.
I don’t know if you can find a similar argument in your industry, but losing the long tail to customer profiling can be a good string to pull.
(Their secondary purpose is to let you show ads to people who already came to your website, i.e.: focusing your ad dollars on people who might actually care about your products and services in the first place)
You needed to read through to the end of the article. TechCrunch did its own testing and confirmed that the mentioned sites were scraping data from the USPS, including but not limited to the postal addresses. The negligence that allowed USPS to leak such information in the name of analytics or whatever it is they were gaining from Facebook et al. is unconscionable, and USPS are very much responsible, just as they would be for a trivial hack with the same effect.
How come Meta can secretly scrape my web session, steal information, and that's not considered a massive violation of these same laws? These companies act like they're entitled to everything. Some CEOs and senior managers jailed for plotting these data theft tactics would be a welcome change... But it's never going to happen, and they know it.
I pointed out to him that advertising an unrelated company in his corporate emails was tacky, but even worse there was a tracking pixel in the email, clearly specific to him. So, any time someone opened one of his emails, WiseStamp would know.
He removed it immediately.
USPS customers have no recourse so arguably intent is irrelevent anyway.
Doesn’t really seem like clickbait to me.
"Everyone else does it" is not a palatable excuse.
These companies are known for having user-hostile, privacy-invasive reputations, so as developers we should by default be wary of them.
E.g. Including a Facebook "Like" snippet on your page lets them siphon all sorts of data from your visitors, particularly if the user hasn't logged out of their Facebook account. It's not how users expect the web to work, and it's an insidious technique (they're deliberately taking advantage of thousands of unwitting webmasters who don't understand the baggage that snippet comes with). More examples here: https://www.consumerreports.org/electronics-computers/privac...
Frankly, even if USPS was unaware, the data still ended up in those third party hands via their services so as far as I'm concerned, yes, they did facilitate the sharing of said data. At least they plugged the hole once it was pointed out to them.
Top post: Title is clickbait, driver didn't kill pedestrian on purpose.
Pedestrian: <is dead>
We don't actually know that. What we know is that they said they didn't share anything intentionally. But there is almost no penalty for lying about such things and the USPS is desperate for money, so I don't think it's impossible that some USPS person made an under-the-table deal with Meta or another company to add this stuff to its website in exchange for a kickback. Only a detailed audit would be able to find out the truth, and that seems unlikely to happen unless Congress gets upset about the issue.
>> We don't actually know that.
Hanlon's razor: "Never attribute to malice that which is adequately explained by stupidity."
This is the real reason why TikTok is a national security risk. Their ad platform, widely used by Shopify, Adobe, Segment, WooCommerce, etc., collects intimate data on non-TikTok users: prescriptions, medical appointments, loan applications, credit card details. Millions who'll never use TikTok, Facebook, etc. are still subject to this data collection in the name of "converting users to customers".
https://abs.codes/blog/2024/03/tiktoks-all-seeing-eye-survei...
At the policy level, we urgently need a national data privacy act to address these types of systemic issues. At the technology level, things like zero-knowledge advertising could mitigate a lot of the user privacy risk.
Seems pretty convenient to blame the people using the tool.
> Our system is designed to filter out potentially sensitive data it is able to detect.”
And just how much attention is spent making that work well? Or is that really just an afterthought with no ongoing improvements so that they can say they tried?
The head of the USPS (Postmaster General, currently Trump appointee Louis DeJoy) reports to the Board of Governors [1] (9 governors + PG + Deputy PG) who are nominated by the President; the PG can be removed by an absolute majority of the board. The USPS is overseen by the Office of Inspector General (USPS-OIG), current head Tammy Hull [2] and has a "hotline" (actually a web form) for reporting complaints [3] which fall under its focus areas, which includes fraud, computer crime and employee misconduct. Seems like one place to start.
For previous 2022 discussion of controversies involving Postmaster General DeJoy and what it would take to remove the PG, see [4].
The PG has no term limit but most recent PGs averaged ~5 years. Historically it wasn't seen as a partisan appointment and wasn't replaced when an incoming President changed to the other party.
[0]: https://en.wikipedia.org/wiki/United_States_Post_Office_Depa...
[1]: https://about.usps.com/who/leadership/board-governors/
[3]: https://www.uspsoig.gov/hotline
[4]: "Can Biden fire US Postmaster General Louis DeJoy?" https://www.federaltimes.com/federal-oversight/2022/08/24/ca...
We are going to start to see productivity drop at some point (now) from all of the corruption and inefficiencies that are stacking up to pay for said short-term profits.
We need to educate the Journeymen in the game to use try/catch and other methods so the hot-path don't die.
Not sure about the illegal part but, for sure a failure in test cases.
They sell that information. Or license it. Or whatever they call it when they are holding booths at advertising and marketing trade shows.
You want to fill out a temporary change of address, renew it the one allowable time and then ghost USPS.
By then you should have updated your personal and business contact info with any group you care about.
USPS is one of the largest distributors of spam in the United States.
https://www.govexec.com/management/2024/04/senators-call-pos...
https://fortune.com/2024/04/10/usps-dejoy-price-hikes-custom... | https://archive.is/b03We
Only individual's information must be kept private.
I have a friend who works at USGS in California, the folks who track (among other things) volcanic and tectonic activity on the west side of the US (that includes Yellowstone).
For their field trips, they have a daily stipend for food & lodging of ~$100 IIRC. If you know the cost of lodging, you can understand how that's a ridiculously small amount.
So yeah, they’re not staying at the Ritz on government business (and they shouldn’t be!) but it’s not like they’re living in a tent.
And if the government worker wants to travel for work like a consultant or a FAANG employee then they can of course pay out of pocket.
Completely impractical “yeah, but”-isms basically turn HN into an online political rally. This isn’t thoughtful conversation.
> The United States Postal Service shall be operated as a basic and fundamental service provided to the people by the Government of the United States, authorized by the Constitution, created by Act of Congress, and supported by the people.
This argument makes no sense at all to me (I did catch the part where you don't necessarily agree either btw).
There's no law which says that everything a government does has to be run at a pure loss on tax revenue. Many local utilities are owned by their respective governments, and are not infrequently run at a modest profit. That doesn't make them private, it makes them profitable.
> Some argue that because of this we have seen a significant degredation in the quality of mail, because the USPS explicitly and intentionally delivers the equivalent of spam mail to every address in the country.
This is quite possibly the case, but has no bearing on whether or not USPS is a government entity, which, it is.
> This ties into the current post as it seems plausible the reason USPS shares customer data with Meta is due to their requirement of self funding.
This, I do not consider plausible at all. I'm 99% sure that some youngster working on the digital side of USPS added some tracking pixels because it's all they knew how to do.
That you don't seem to like the USPS or its operations doesn't make it not a government service.
Some countries have no government postal service, and some have no postal service at all, but the US clearly has a government postal service.
For a work project, I recently had to visit about 200 government web sites from countries all over the world.
It's surprising how many of them not only load third-party content, but actually have banner and pop-over advertising on them, especially in Asia and Africa.
By comparison, even America's worst government web site¹ is better.
But then, yeah, it loads fast and does what it needs to do. I don’t think I’d want my taxpayer money getting some hip design studio to “modernize” it.
For a long time, .gov was for the federal government only.
In the days before search engines, people knew that their state's home page was state.xx.us. Lots of people memorized URLs back then, the way it was ordinary to know dozens of phone numbers off the top of your head.
I planned many a road trip by typing in travel.state.xx.us for the various states I planned to visit.
The problem was the Treasury obsoleted the second factor they issued in 2003 (a physical lookup card with numbers on it) and I had to reverify myself. They couldn't log me in with the information I used to log into Treasury Direct two decades ago.
Reverification required entering information like the Driver's Licence number I had in 2003 and the DL expiration date of my 2003 licence (I don't know! It was in another state and I no longer have it) and some other security questions I apparently answered when signing up and short-sightedly didn't write down ("Favorite Vacation Destination")
Good luck logging in to check your iBonds 30 years from now! The don't issue paper bonds anymore to anyone. Maybe they're hoping for "breakage" -- people will simply forget they own them!
The value of CDNs like this has diminished greatly with the advent of HTTP/2 and HTTP/3.
https://blog.qualys.com/vulnerabilities-threat-research/2024...
https://developer.mozilla.org/en-US/docs/Web/Security/Subres...
It would make the web faster and reduce tracking.
Now, is that really what Google Fonts or Cloudflare CDN wants ?
Maybe, but it will reduce the amount of data shared to the intelligence groups.
Sites don’t share that many resources byte-for-byte anyway. The current solution is fine.
This stuff isn’t easy. HN has way too big a head.
I don't know, it might be an intractable problem. It sucks how there's no way to tell the difference between the payloads of two different 3rd party scripts when they're executed in the browser, huh?
According to https://developers.google.com/fonts/faq/privacy#when_i_embed...,
"For clarity, Google does not use any information collected by Google Fonts to create profiles of end users or for targeted advertising."
Functional utility for the end user
AdTech companies don't pay you to install these on your websites. Their customers install them to help understand if the ads they're already paying for are leading to the outcomes they, the customers, care about. I posted a related comment here: https://news.ycombinator.com/item?id=41007679
<Customer> I want people to sign-up for my F2P game
<Google> We can show ads to people who may be interested in your F2P game
<Customer> How do I know if the ads I paid for actually led to installations?
<Google> Install this script on your "thanks for signing-up" page
<Customer> Cool thanksUSPS has an authenticated page where they know their customers. Why wouldn’t they just analyze THEIR OWN logs instead of relying on third-party advertising companies?
Was this really an accident?
The USPS wants to know which of their ad campaigns is successful, and want to be able to target advertising, so they embed their advertising platforms' Javascript in their site. That part seems reasonable for a government agency that's required to self-fund. The problem is either that the tracking was on pages that shouldn't have had it, or that it wasn't restricted in what it could send to the analytics platforms.
When you order, you enter their own address and name, so neither the delivery company, nor the web shop, have your details.
Shit like this is the only "uncertainty"
I didn’t do it once when I had a short stint and that addrsss isn’t leaked…
https://postalpro.usps.com/mailing-and-shipping-services/NCO...
Between delivering spam mail and selling my addresses, they provide net-negative value to my life.
I personally use the USPS quite a bit to ship things and I prefer to use them over FedEx or UPS any chance I get.
Please don't inflame the conversation with more combative language.
I don't think USPS is a net-bad though. I can only imagine how bad Fedex and UPS would become if they didn't have to compete with the USPS. And they're already pretty bad.
But yeah.. wish they only delivered mail.
Once I chose to send a package through them, and I watched the tracking as the package rerouted to their lost mail center in Atlanta ("Mail Recovery Center", a misnomer if there ever was one). How could it be lost if they were still updating the tracking information? (Naturally, it was never "found".)
I briefly forwarded my mail to a relative's address while I was out of the country for an extended period, and they sold that to numerous institutions without my permission, creating a headache to unwind. To this day knowledge-based authentication systems quiz me about an address I never lived at.
I don't get a warm and fuzzy patriotic feeling from having a national postal service. If anything it feels like an anachronism. Paper mail has been virtually irrelevant to me my entire life.
https://postalpro.usps.com/address-quality/AIS_Products_Pric...
None of which are delivery related.
It's just all the addresses they deliver to with things like building type, schedules, route ids, etc.
"We do not disclose your personal information to anyone, except in accordance with the Privacy Act.”
Exception: "if already in possession of your name and old mailing address"
Edit: spelling and such
Those images are part of their 'informed delivery' service which you can sign up for.
I've noticed on a number of occasions that the contents of the envelope were noticeable without enhancement and legible with simple contrast/level adjustment.
I've seen that as well, but I place the blame on the sender for using an envelope that isn't fully opaque.
Still it’s a major oversight on their part. I wonder if the tracking pixel is loaded as part of “social login” or “social media integration”.
Yet another reason I don’t use that shit, and heavily block them across all sites.
https://www.aclu.org/news/privacy-technology/warrantless-pol...
https://news.bloomberglaw.com/us-law-week/police-turn-on-hid...
>the court determined that no “search” had occurred prior to the entry in Tuggle’s home, so the Fourth Amendment did not apply. To reach this conclusion, the court had to set aside the dictionary and replace the normal meaning of “search” with a fuzzy definition that different courts interpret in different ways at different times.
That is quite literally on the dividing line between public and private space. I can easily imagine later courts ruling that the combination of specific intention on the part of the police, and the limitless nature of this surveillance, makes it different in kind from the classic stakeout (which does not require a warrant, and never has), and that therefore that in particular requires a warrant to be obtained. I don't think that will happen, but it's imaginable.
You're talking about a truck driving around with a camera, and sharing that data on request with law enforcement. That's a completely different thing, and it isn't an edge case at all. That is, and will be, not subject to 4th Amendment protection. On the contrary, Fields v. City of Philadelphia supports a 1st Amendment right to film in public, in that case, the conduct of the police. But the principle generalizes.
Furthermore, as an example, let's say that a repairman enters a home, and sees what he or she reasonably believes to be a brick of heroin on a desk. Later, the police, having staked out this home, ask that repairman if they happened to see something suspicious. The repairman tells the police about the brick, they get a warrant, and enter the home. All of this is completely legal.
So there's just no world in which a FedEx truck, or any truck, filming the public space in the ordinary course of doing what it does (delivering packages in this case), where the police later ask for and obtain that record, is going to be subject to 4th Amendment restrictions. It is simply, on many levels, not how things work.
I cannot even begin to fathom this logic
Please stop denying the fact that you could have disabled usps when they sent the sensitive data. But why would facebook/meta do it when they need so data.
And, why is USPS even using meta etc..