Worst case scenario they are looking into streams of suspicious behavior, like Russian IPs attempting to validate the SINs somewhere else, like at a bank.
Worst case scenario they are looking into streams of suspicious behavior, like Russian IPs attempting to validate the SINs somewhere else, like at a bank.
Anyway, I call, and it was the closest thing to magic I've ever seen. I give reception my SIN, and ask for the woman that signed the letter I received. I'm on hold for only 10 or 20 seconds, the woman answers, and greets me with my name. I didn't say more than a couple of sentences explaining the issue, and she says she'll check her computer, taps a button and poof she knows everything. Literally a few more seconds, and everything is sorted, and a cheque is being mailed.
I was almost speechless, I was expecting a 30 minute call between departments, explaining numbers, CRA scratching their heads since this was taking place across multiple provinces, and then me having to physically mail in a variety of personal information. Instead, it was a 1 or 2 minute call with an incredibly friendly woman, and she was so organized, it's like she spent the day preparing for me to call in advance. And, to reiterate, this was the woman that signed the original letter I received, not someone from support or customer service.
Now, the CRA website is a nightmare, but talking to them on the phone was the most impressive service I've ever encountered.
Every single interaction with them and every single person I know that has to deal with them has been nothing but mindblowingly professional. Even on the phone, they are exceptionally good at getting to the point IMMEDIATELY but without the normal "this isn't the right department" BS that every other Canadian government agency has.
It's hard to even think of a number two. The Supreme Court maybe? Elections Canada? Ellis Don?
So I called them up, waited on hold for 5 minutes. I spoke with a CRA rep who said "Yup, we screwed up. Fixed". And it was fixed. Total time to fix an $11K screw up? 15 minutes. Try that with any other organization.
"It is irrelevant whether your system can even support some of the cipher suites in the list, because the Heartbeat request that triggers the vulnerability is sent before any encryption takes place."
http://www.hut3.net/blog/cns---networks-security/2014/04/14/...
I was specifically wondering if a) the heartbeat messages which leak data (keys or whatever) are encrypted or not, and b) if they are, and PFS was used, is it even possible for someone to audit a full packet capture for heartbeat attacks.