The Register® — Biting the hand that feeds IT

Feeds

Going lo-tech to avoid NSA snooping? Unlucky - they read snailmail too

US Postal Service scoops metadata from your letters: report

Supercharge your infrastructure

Privacy-conscious US citizens looking to go retro in the wake of the ongoing controversy about PRISM-related snooping and the NSA harvesting metadata on an industrial scale will find little refuge in snail mail.

The New York Times reports that the United States Postal Service photographs the exterior of every piece of mail going through the system as part of the Mail Isolation Control and Tracking programme. The data is retained for use by law enforcement as part of a scheme set up in the wake of anthrax attacks in late 2001 that killed five people, including two postal workers.

The dataset creates a means to go back in time and trace mail correspondence and was used by the FBI in a case involving the transmission of ricin-laced letters to President Obama and New York Mayor Michael R Bloomberg, says the paper.

Contents of letters are not recorded as part of the Mail Isolation Control and Tracking programme, which operates in conjunction with a decades-old "mail covers" scheme, which involves physically keeping tabs on mail sent to individuals either suspected of criminal or subversive activity.

Leslie Pickering, the owner of a bookshop in Buffalo, and a former spokesman for the Earth Liberation Front, a radical environmentalist group, claims he was among those targeted as part of the mail-covers scheme. He says he learned he was under watch after a handwritten card instructing postal workers to pay special attention to the letters and packages sent to his home arrived in his letter box after apparently being delivered by mistake, according to the NY Times.

Pickering claimed postal officials subsequently admitted they were tracking his mail without explaining why, or for how long, he and his family might have been monitored. NYT said postal officials had declined to comment on his claims.

Law enforcement agencies submit a request for a mail cover direct to the Postal Service, which is able to grant or deny a request without judicial review. By contrast, judges need to sign off wiretap requests. Mail cover requests (granted for 30 days, with possible extensions up to 120 days) are rarely refused, law enforcement officials told the NYT. Requests may relate to either criminal investigation or national security matters.

Criminal activity requests average 15,000 to 20,000 per year, according to unnamed law enforcement officials who spoke to the NYT on the condition of anonymity. The volume of anti-terrorism mail cover requests is unknown.

Law enforcement officials need warrants to actually open mail, but a surprising amount of information can be gleaned from the metadata on the outside of a letter or parcel.

"Court challenges to mail covers have generally failed because judges have ruled that there is no reasonable expectation of privacy for information contained on the outside of a letter," the NYT reports.

"Officials in both the Bush and Obama administrations, in fact, have used the mail-cover court rulings to justify the NSA's surveillance programs, saying the electronic monitoring amounts to the same thing as a mail cover. Congress briefly conducted hearings on mail cover programs in 1976, but has not revisited the issue."

Postal mail volumes are dropping but there were still more than 160 billion pieces of mail sent in the US last year. ®

5 ways to prepare your advertising infrastructure for disaster

Whitepapers

5 ways to prepare your advertising infrastructure for disaster
Being prepared allows your brand to greatly improve your advertising infrastructure performance and reliability that, in the end, will boost confidence in your brand.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Email delivery: Hate phishing emails? You'll love DMARC
DMARC has been created as a standard to help properly authenticate your sends and monitor and report phishers that are trying to send from your name..
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Email delivery: 4 steps to get more email to the inbox
This whitepaper lists some steps and information that will give you the best opportunity to achieve an amazing sender reputation.

More from The Register

next story
Chaos Computer Club: iPhone 5S finger-sniffer COMPROMISED
Anyone can touch your phone and make it give up its all
Hundreds of hackers sought for new £500m UK cyber-bomber strike force
Britain must rm -rf its enemies or be rm -rf'ed, declares defence secretary
NSA in new SHOCK 'can see public data' SCANDAL!
What you say on Twitter doesn't stay on Twitter
UK's Get Safe Online? 'No one cares' - run the blockbuster ads instead
Something like Jack Bauer's 24 ... whatever it'll take to teach kids how to bat away hackers
Would you hire a hacker to run your security? 'Yes' say Brit IT bosses
We don't have enough securo bods in the industry either, reckon gloomy BOFHs
Sweet murmuring Siri opens stalker vulnerability hole in iOS 7
'Siri, hand over my contacts and history now…'
Facebook allows full personal data ransack with Graph Search
Posts, updates, the lot. Our ad sales will boom. Mwu-ha-haaaa ... bitch
London schoolboy cuffed for BIGGEST DDOS ATTACK IN HISTORY
Bet his parents wish he'd been playing computer games
prev story