Intuit Notice of Unauthorized Access to Tax Returns [pdf]
ago.vermont.gov
ago.vermont.gov
[edit]: Here is a source with more info - https://www.scmagazine.com/home/security-news/intuit-the-com...
Claiming that usernames cannot be a source of entropy/security needs foundation.
Back when the whole concept of authentication was new (UNIX) that was true because usernames were quite literally public information, you could see them via a directory listing. With early email (SMTP) that remained true but worse via public directories listings across-computer.
However in this context there's nothing inherent about a username that allows us to ignore its security characteristics. Unless the argument is "over the shoulder" leakage? Which I'd argue itself doesn't have a strong foundation.
Both obscure usernames and obscure passwords can contribute to the overall strength of a system. A system that allows the user to set their own password may gain particularly from pre-selected randomized usernames, as users have proved untrustworthy in the past when picking passwords (e.g. reuse, patterns, common words, etc).
As an aside, scrapping usernames and only having a password isn't inherently problematic, except two users with the same password may clash, and a password recovery scheme may be more difficult to develop. That's essentially what authentication tokens are.
> Generate a random unique password for your user and don’t have a username at all.
Because having an unknown username with an unknown password increases the difficulty of compromise via improved entropy.
> Because having an unknown username with an unknown password increases the difficulty of compromise via improved entropy.
Not necessary. It depends on the characteristics of each. If the username is truely random, sure, but then you are back in the same boat as using one random string.
I don't see how relying on haveibeenpwnd can be considered secure. Many people use the same password for different sites. If your site's login credentials are just email+password you are relying on the security and honesty of all other sites that use the email+password combination.
I don't believe this is grounded in evidence. You are basically saying that given two hard to remember strings, most people will write down one hard to remember string and not the other hard to remember string. Why?
> I don't see how relying on haveibeenpwnd can be considered secure. Many people use the same password for different sites. If your site's login credentials are just email+password you are relying on the security and honesty of all other sites that use the email+password combination.
I think you are missing the point of the haveibeenpwnd service. The point is to block people from using ANY password that is listed in the haveibeenpwnd database, thus denying attackers from using that dictionary of known passwords.
Yes, using the haveibeenpwnd service offers some level of protection. But it still allows an attacker to breach a random website like funnycatpictures.com and find the email/password combinations that are not on haveibeenpwnd. Boom, that attacker has access to all those users' tax information.
Further, do some automatic challenge-response thing between the server and yourself so you are authenticated to the server, and the server is authenticated to you. Which the current username/password scheme doesn't do at all.
Our current default state (username/password where both are human-rememberable) is failing us massively. Its arbitrary, historical and currently pointless.
[1] https://ttlc.intuit.com/questions/2902682-what-is-two-step-v...
Confused whether this is just precautionary and given out to governments each tax season, or if something has occurred. The "Insert Date" makes it appear like the former.
Edit: According to another comment linking to "scmagazine," this is not precautionary!
But, one quirk many may not be aware of, even with 'desktop' versions, is if one e-files, the data follows this path:
Desktop -> Intuit (or other software) servers -> IRS
So to avoid a copy of one's tax data being stored on the servers of the software prep. company, one has to print and file via. paper forms.
[1] I realize this does not mean it is not silently uploading the data in the background somewhere to their servers anyway, but the 'web' version is guaranteed to be storing the data on their servers. But I do hope with the number of users using these packages that if this were to happen, someone would notice and sound the alarm.
I have used it for 5 odd years, but it's really starting to annoy me now. I'm seriously considering trying to find a professional that can handle everything for, say $500/year.
Taking the standard deduction (all your work, charitable donations, and other itemizable items still don't cross this threshold).
It's really annoying that taxes are even the way they are, it's all just a huge, convoluted mess. For something like 95%+ of the US the government already knows your earnings (W2/etc), banking (INT-whatever), and any brokerage/etc stuff. The only reason the IRS doesn't send a pre-filled out form that says "this is what we believe is owed to whom, - please pay / cash the check, or fill out taxes manually to report where you think we missed data" is PRECISELY because HR Block and Intuit (Turbo Tax) lobby for complicated taxes and no government automation.
Maybe you already know this, but the "prefilled form form the IRS" is similar to how a lot of countries do their taxes. From what I've heard the US uses tax writeoffs to influence people's behavior more than other countries do, so I wonder if that approach would lead to fewer people taking certain deductions.
It is a nice idea but in practice it would just overcomplicate things. Changing up the Internal Revenue Code is a better way forward.
I have:
* A job with a W-2
* 2x brokerage accounts with 1099-INT + 1099-DIVs
* An HSA with a 1099-SA / 5489-SA forms
* A housing coop with a 1098 mortgage interest form, and property taxes to deduct
* A mortgage with a 1098 mortgage interest form
Some pain points:
* TurboTax wants to know if I paid Alternative Minimum Tax in the past, but doesn't seem to check its own records (I have only ever used TurboTax), or give me an easy way to check that (i.e., go look at line / box #xx on your previous 1040s). My memory is that I did end up doing AMT one year, and I think that somehow influences future years?
* I ended up doing estimated tax payments one year (TurboTax gave me the forms and details for this), but then the next year I didn't understand that I needed to deduct those payments (or rather, I had imagined TurboTax would know / ask me about that, but it didn't in any clear fashion). I got a letter from the IRS about the discrepancy, I had to send them the estimated tax payment data, they sent me an adjusted form, it was all fine in the end but it took some extra time + hassle to work through.
* The brokerage accounts lead to capitals gains and losses which can need carrying over across years, and the dividend income seems to be enough to cause the estimated taxes in some years but not others.
* TurboTax is just way more annoying than it needs to be with its upselling, animations, sometimes vaugely worded questions, and apparent reluctance to use last year's records.
* Overall, my assets / income aren't massive or anything, but it wouldn't suprise me if someone being paid $500 / year or thereabouts could pay for themselves in saved time + mistakes or optimization suggestions.
The first time around, it's a little bit of a pain to figure out what forms you need to attach and such, but it's really not that hard if you read the instructions for the forms and just follow the directions. If you're doing something complex like running a business and dealing with depreciable property or calculating AMT, it gets a little hairy, but even then I've generally been able to figure things out by just reading through the free publications that the IRS puts up on the web. I also like the sense of deeper understanding that I get from seeing how everything is being calculated, instead of just answering a bunch of questions and then having an algorithm spit out a number for my refund.
whois freefilefillableforms.com Domain Name: FREEFILEFILLABLEFORMS.COM Registry Domain ID: 1532523225_DOMAIN_COM-VRSN Registrar WHOIS Server: whois.godaddy.com Registrar URL: http://www.godaddy.com Updated Date: 2017-12-12T17:27:56Z Creation Date: 2008-12-11T19:53:30Z Registry Expiry Date: 2019-12-11T19:53:30Z Registrar: GoDaddy.com, LLC Registrar IANA ID: 146 Registrar Abuse Contact Email: abuse@godaddy.com Registrar Abuse Contact Phone: 480-624-2505 Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited Domain Status: clientRenewProhibited https://icann.org/epp#clientRenewProhibited Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited Domain Status: clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited Name Server: DNS1.QUICKEN.COM Name Server: DNS2.QUICKEN.COM Name Server: DNS3.INTUIT.COM Name Server: DNS4.INTUIT.COM DNSSEC: unsigned URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
You are sending your data to Intuit.
Personally, I am a bit pissed that the IRS, a government organization with the sole purpose of collecting taxes, has no method for me to submit my tax return to them via the internet.
Maybe it's time to just switch back to downloading the PDF forms, filling them in on my local computer, printing them out, and just mailing them in. Ugh.
At some point, it's possible that one or more IRS databases themselves will be breached. This may (?) cause a re-evaluation of the risks the US government is subjecting its citizens to by collecting and storing such large volumes of financial data.
Anyway, isn’t it much easier for criminals to pick a target by simply going into a wealthy neighborhood? The American rich are much more segregated than their Scandinavian counterparts. That’s a more obvious target on their back than having tax data available on request.
[edit]
For some data, you can look at primary school districts (which are almost always geographically assigned in the US, and are usually much smaller than secondary school districts). They tend to have statistics on percentage of students that qualify for government subsidized meal programs, which is a good proxy for poverty. I'm well above this line, but have lived in districts where the numbers were as high as 91% and as low as 5%.
And no way in hell am I giving the information to Intuit first, so that they can mine and sell it (and probably leak it unintentionally as well)