08 Dec 2018

USPS Informed Visibility weaknesses

USPS has a system called Informed Visibility (IV) which provides the visibility of mail and package delivery throughout its entire delivery stream.  IV was launched in November 2014 and completed in September 2017.  On October 12, 2018, the Office of Inspector General (OIG) released a Vulnerability Assessment  on IV which identifies both encryption and database weaknesses.  The three encryption and authentication vulnerabilities are related to its communication protocols.  Communication protocols apparently were not upgraded during a USPS web application configuration review.  Database account management also had failed to disable expired user accounts, employ enough password complexity, and maintain proper audit logs.
