openstreetmap / tile-attribution

This repository is used for reporting and tracking sites which are using tile.openstreetmap.org tiles but without attributing OpenStreetMap. The sites are tracked in the issue tracker.
35 stars 3 forks source link

tools.usps.com #49

Closed louwers closed 5 months ago

louwers commented 6 months ago

Is it maybe reported already?

Before you submit this form, please ensure the following criteria are met:

Date and time of the message (has it happened more than a week ago?):

10th of May 16:24 CEST

Where did you send it?

To their support https://www.usps.com/help/contact-us.htm

Please paste the content of the Love Letter you sent to the map user here.

image

The infringement is a:

Please drag and drop or attach the screenshot showing the map without proper attribution here.

Screenshot 2024-05-17 at 00 38 17

Where it is happening?

https://tools.usps.com/locations/home.htm

You need to enter a ZIP code (e.g. 10001).

Previous Reports:

No response

louwers commented 6 months ago

I have sent another follow-up with a reminder.

matkoniecz commented 5 months ago

Thanks for reporting!

I am trying to reach out to them as serious government organization seems more likely to be persuaded than some fly-by-night company, and there may be some proper official way of contacting them more likely to result in some fix.

(from my experience with government in another country - they typically have some contact channels where contact will result in prompt response while "contact us" forms at their websites often go straight into trash.

So I will not apply block right now, but I will do this if new efforts will fail.

louwers commented 5 months ago

Maybe we can abuse their vulnerability disclosure programme: https://hackerone.com/usps

Seems like a very effective way to get in touch with an actual developer, and 'bugs' can be reported too.

Edit: I have made a bug report via Hacker One. Their bug bountry programme is managed by Hacker One, so it may not make it past triage.

louwers commented 5 months ago

HackerOne (representing USPS) got back to me:

After review, there doesn’t seem to be any significant security risk and/or security impact as a result of the behavior you are describing. There is no impact to this.

matkoniecz commented 5 months ago

I attempted to contact them via their website (refuses to work without US address) and through https://www.facebook.com/USPS (refused to work outside US working hours, will retry)

matkoniecz commented 5 months ago

After review, there doesn’t seem to be any significant security risk and/or security impact as a result of the behavior you are describing.

Well, it was longshot. I guess that degradation of features (blocking map tiles) is not exactly a security risk.

louwers commented 5 months ago

I will give a call to their technical support today during US business hours.

If that doesn't work out, we should probably give up, block them, and hope someone finally gets notified.

matkoniecz commented 5 months ago

I may try writing on US forum whether anyone has idea how to contact them (or maybe we will be lucky and get USPS employee).

matkoniecz commented 5 months ago

Found their email and posted it there.

Melaskia commented 5 months ago

Hello,

I asked a friend of mine at USPS about that. The website is its own entity different from the day to day operation of USPS. Even him had no clear idea on how to reach the website people.

On Mon, May 20, 2024 at 9:20 AM Mateusz Konieczny @.***> wrote:

Found their email and posted it there.

— Reply to this email directly, view it on GitHub https://github.com/openstreetmap/tile-attribution/issues/49#issuecomment-2120779381, or unsubscribe https://github.com/notifications/unsubscribe-auth/AAMRCE777463QJJTUZBSJ5DZDIPGTAVCNFSM6AAAAABH3CL57KVHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHMZDCMRQG43TSMZYGE . You are receiving this because you are subscribed to this thread.Message ID: @.***>

louwers commented 5 months ago

The technical support phone number also does not cover USPS Tools.

matkoniecz commented 5 months ago

I reported it yesterday via mail, got automatic mail back with promise of response within 48 hours.

Tracking number: ref:!00Dj00GyYH.!500BY02LFVT:ref

louwers commented 5 months ago

I never got a reply, maybe you will have more luck.

gregorywaynepower commented 5 months ago

Perhaps you could reach out to the folks at Medallia that build this application?

Edit: Scratch, that--it's just the USPS's vendor for filing service tickets.

louwers commented 5 months ago

It's been 14 days since I sent my message, and 7 days since I sent a reminder. No replies.

b1tw153 commented 5 months ago

@watmildon and I would like to take a pass at making the right connections with USPS. You know how generic tech support e-mail can be. We'll try to get in touch with them starting on Tuesday because of the US holiday on Monday.

If you can afford more time before cutting them off from the tile server, that would be great. However, I understand if their usage is too much of a burden to allow it to continue. If we need to cut them off, I'd just like to know so we can include that in our communication.

grischard commented 5 months ago

Reasonable attempts have been made at contacting the USPS. Marking this one as accepted.

grischard commented 5 months ago

If anyone has a better contact at USPS, that would be very welcome.

louwers commented 5 months ago

@grischard @Firefishy They added attribution!

image
louwers commented 5 months ago

I closed the issue, so it shouldn't be picked up.

Thanks everyone! 👍

issues = client.issues(repo, state: 'open', labels: 'accepted')
grischard commented 5 months ago

Yes, only issues that are open create an active block. You did the right thing!

louwers commented 5 months ago

Good thing the accepted label is removed though, otherwise I would have too much power.

grischard commented 5 months ago

Ah, the 'accepted' label can stay, this was a valid issue, although the point is moot now.

The code filters for issues that are both open and 'accepted'.

louwers commented 5 months ago

I think I could block them by re-opening the issue then.