Hacking of Tax Returns More Extensive Than First Reported, I.R.S. Says
nytimes.com
nytimes.com
A guy I know worked for an IRS regional office in an enforcement/audit role for something like 40 years. He had something like 75 co-workers in that role in 1999 and retired with 8. Technology actually increased their workload, but with less people, they only targeted the most egregious violations.
He stuck around because he was really passionate & dedicated to his work. He was a guru on some very specific/arcane areas and wanted to transition it to somebody. That never panned out, so he gave up and left when his health declined.
But by implicitly ignoring the rules through inattention, except when you don't, it creates a perception of corruption and arbitrary behavior.
The IRS budget is $10 billion/year[0]. Is that enough money to expect decent security? If not, what is? Are we allowed to demand security from smaller organizations, or only from Google-sized or larger?
If we expect small businesses to protect our information, it's not too much to ask for the same from a $10b/year government department.
0. http://www.politico.com/story/2015/06/gop-irs-budget-118835....
The politicians love to hand wave about "big government" and "do something" about the evil IRS. But actual simplification of the tax code would cost their political patrons too much money, so they make it easier for folks to break the law.
Findings from a GAO report this year: http://www.accountingweb.com/tax/irs/gao-report-links-irs-pr...
The actual report: http://www.gao.gov/products/GAO-14-298
And Time's article backing it up: http://time.com/money/3819382/john-oliver-and-irs-tax-gap/
Something similar to using Google to logon to certain services rather then creating a user name and password. Then you can make a single point much more secure and difficult to log into.
The downside of this is that I think the US government would have have an in person verification system to get an account. I.E. you go into the DMV, get an account and then you are connected to the service. You can then implement 2 factor authentication, and you link that service to your bank accounts.
I have no clue if this would actually be more secure then what is already in place, but it seems more then likely that hackers already have my Social Security number and my previous residences because of the OPM hack.
They were never intended as anything more than a payroll identifier. This was known since its inception [that it was unsafe]. Its simply a question of the scale of exploitation is larger with computers.
The underlying problem is security is a cost center and no one wants to pay for it.
(It also means that if the system can be broken you can steal someone's identity very easily and thoroughly)
With perfect security hygiene, more things are attainable.
But an even more perfect crime is hedging both sides of an option with phony identities, with different amounts, different enough times, different brokerages, different IP addresses, etc.
Feel free to try it out and report back.
If the hackers had access to data outside the US, then it may have to be us the taxpayers, unfortunately.