Opinion

OPINION: To Fix Cyber Mess, The U.S. Postal Service Must Get Its Priorities Straight

Joe Raedle/Getty Images

Ross Marchand Director of Policy, Taxpayers Protection Alliance
Font Size:

When mailing letters and packages to loved ones this holiday season, consumers have to place an awful lot of trust in their mailers.

This trust isn’t just about the safety of the paper-clipped check or expensive new gadget that passes through the hands of U.S. Postal Service (USPS) employees. Often, consumers give phone-numbers, e-mail addresses, and multiple addresses to the Postal Service with the understanding that their information will be protected.

Unfortunately, this has simply not been happening.

According to KrebsonSecurity, broken code in a USPS mail tracker called “Informed Delivery” allowed users to see any other user’s details — exposing the records of roughly 60 million individuals.

Normally, websites require that in order for users to retrieve sensitive information (ie. phone numbers listed on an account), they go through multiple access points (or hurdles) in order to retrieve said information. Due to a lack of multiple access points, malicious individuals were able to gain and change personal user information through merely logging onto the victim’s online portal.

This finding is bad enough in and of itself, but it was further revealed that USPS knew this information for a year and chose to ignore it.

The USPS’ lackluster cybersecurity effort, coupled with ignoring key vulnerabilities, show just how skewed the priorities are at one of the federal government’s most beleaguered agencies.

This is just the latest in a long string of scandals, mismanagement and abysmal finances at USPS. Congress must step in to demand urgent reform and much-needed accountability for the Americans who don’t just use USPS but whose taxes subsidize it by billions of dollars a year.

Just a few weeks ago, USPS reported a staggering $3.9 billion net loss in the 2018 fiscal year (FY), up from $2.7 billion in FY 2017. Worse yet, losses subject to management’s control (“controllable losses”) surged to $2 billion, more than double last year’s total.

This incredible sum, which seems to increase every single year, now comprises the majority of USPS losses and undercuts the carrier union’s claims that retiree health-benefit “pre-funding” beyond its control deserves the lion’s share for twelve straight years of net losses.

Given the magnitude of these losses, it may be difficult for the USPS to pay for a much-needed cybersecurity program.  But, the real problem is not money, it’s management.

The Office of the Inspector General (IG) lambasted USPS for not considering cybersecurity items to “be investments per Postal Service policy,” and “the Postal Service has not performed financial long-range planning and administering the cybersecurity program.”

Rather than correcting these and other issues, USPS management seeks to pay for new investments by increasing postage rates beyond inflation.  To be sure, this is a risky move considering the increasing amount of e-commerce and e-communication.

Far greater savings can come by implementing reforms already suggested by the IG. The USPS, for instance, is supposed to use a modeling tool to sort out job assignments based on mail processing volume, but regular deviations result in increased overtime and lower employee productivity.

The IG estimates that a more thorough use of its own modeling tools would save the USPS $420 million in labor costs alone.

The USPS can also save itself from gargantuan future expenses by making sensible fleet acquisition decisions.  Starting in FY2019, the USPS plans to spend an annual average of $821 million on new vehicles purchases. The USPS is considering two cost-effective foreign-origin bids (from Indian and Turkish manufacturers), but will likely be steered toward domestic bids due to the sway of “Buy America” provisions.

While the USPS isn’t subject to the Buy American Act, it does have an acquisition provision for considering domestic suppliers first. Therefore, the USPS (really, taxpayers) may pay an unnecessarily-high price for its fleet over the next decade. Additional considerations, such as preference for “alternative fuel capabilities,” may further inflate the price of vehicle operation, paving the way for further unnecessary costs for the beleaguered organization.

With an open mind toward foreign vehicle bids and a variety of fuel systems, the Postal Service could save over a billion dollars in the coming decades, a fraction of which should go toward shoring up cybersecurity.

USPS needn’t break the bank to beef up protections for users. International Computer Science Institute researcher Nicholas Weaver explains that recently fixed vulnerabilities “is not even Information Security 101, this is Information Security 1, which is to implement access control.”

With its spending priorities in order, the USPS can have a better-trained cybersecurity staff that maintains the trust between citizen and agency.

Until USPS reduces the risk posed by cyber vulnerabilities, Santa Claus may not be the only one snooping around to find out who’s been naughty or nice.

Ross Marchand is the director of policy for the Taxpayers Protection Alliance.


The views and opinions expressed in this commentary are those of the author and do not reflect the official position of The Daily Caller.

PREMIUM ARTICLE: Subscribe To Keep Reading

Sign up

By subscribing you agree to our Terms of Use

You're signed up!

Sign up

By subscribing you agree to our Terms of Use

You're signed up!
Sign up

By subscribing you agree to our Terms of Use

You're signed up!

Sign up

By subscribing you agree to our Terms of Use

You're signed up!
Sign up

By subscribing you agree to our Terms of Use

You're signed up!

Sign Up

By subscribing you agree to our Terms of Use

You're signed up!
Sign up

By subscribing you agree to our Terms of Use

You're signed up!
Sign up

By subscribing you agree to our Terms of Use

You're signed up!
BENEFITS READERS PASS PATRIOTS FOUNDERS
Daily and Breaking Newsletters
Daily Caller Shows
Ad Free Experience
Exclusive Articles
Custom Newsletters
Editor Daily Rundown
Behind The Scenes Coverage
Award Winning Documentaries
Patriot War Room
Patriot Live Chat
Exclusive Events
Gold Membership Card
Tucker Mug

What does Founders Club include?

Tucker Mug and Membership Card
Founders

Readers,

Instead of sucking up to the political and corporate powers that dominate America, The Daily Caller is fighting for you — our readers. We humbly ask you to consider joining us in this fight.

Now that millions of readers are rejecting the increasingly biased and even corrupt corporate media and joining us daily, there are powerful forces lined up to stop us: the old guard of the news media hopes to marginalize us; the big corporate ad agencies want to deprive us of revenue and put us out of business; senators threaten to have our reporters arrested for asking simple questions; the big tech platforms want to limit our ability to communicate with you; and the political party establishments feel threatened by our independence.

We don't complain -- we can't stand complainers -- but we do call it how we see it. We have a fight on our hands, and it's intense. We need your help to smash through the big tech, big media and big government blockade.

We're the insurgent outsiders for a reason: our deep-dive investigations hold the powerful to account. Our original videos undermine their narratives on a daily basis. Even our insistence on having fun infuriates them -- because we won’t bend the knee to political correctness.

One reason we stand apart is because we are not afraid to say we love America. We love her with every fiber of our being, and we think she's worth saving from today’s craziness.

Help us save her.

A second reason we stand out is the sheer number of honest responsible reporters we have helped train. We have trained so many solid reporters that they now hold prominent positions at publications across the political spectrum. Hear a rare reasonable voice at a place like CNN? There’s a good chance they were trained at Daily Caller. Same goes for the numerous Daily Caller alumni dominating the news coverage at outlets such as Fox News, Newsmax, Daily Wire and many others.

Simply put, America needs solid reporters fighting to tell the truth or we will never have honest elections or a fair system. We are working tirelessly to make that happen and we are making a difference.

Since 2010, The Daily Caller has grown immensely. We're in the halls of Congress. We're in the Oval Office. And we're in up to 20 million homes every single month. That's 20 million Americans like you who are impossible to ignore.

We can overcome the forces lined up against all of us. This is an important mission but we can’t do it unless you — the everyday Americans forgotten by the establishment — have our back.

Please consider becoming a Daily Caller Patriot today, and help us keep doing work that holds politicians, corporations and other leaders accountable. Help us thumb our noses at political correctness. Help us train a new generation of news reporters who will actually tell the truth. And help us remind Americans everywhere that there are millions of us who remain clear-eyed about our country's greatness.

In return for membership, Daily Caller Patriots will be able to read The Daily Caller without any of the ads that we have long used to support our mission. We know the ads drive you crazy. They drive us crazy too. But we need revenue to keep the fight going. If you join us, we will cut out the ads for you and put every Lincoln-headed cent we earn into amplifying our voice, training even more solid reporters, and giving you the ad-free experience and lightning fast website you deserve.

Patriots will also be eligible for Patriots Only content, newsletters, chats and live events with our reporters and editors. It's simple: welcome us into your lives, and we'll welcome you into ours.

We can save America together.

Become a Daily Caller Patriot today.

Signature

Neil Patel