5 ms·
> Until the IRS stops using social security numbers to file, it's insecure. If it treated SSNs as a username and required everyone to generate some unique pass
by fweespee_ch 10y ago
> Until the IRS stops using social security numbers to file, it's insecure.
If it treated SSNs as a username and required everyone to generate some unique passwords...it would work.
- apaprocki 10y ago... like it already does? Since 2008 the IRS has required a security PIN code to e-file. It's not the most secure system in the world, but everyone needs to understand you can't just e-file someone's taxes by knowing their SSN.
- fweespee_ch 10y agohttp://krebsonsecurity.com/2016/03/irs-suspends-insecure-get-ip-pin-feature/ http://krebsonsecurity.com/2016/03/irs-suspends-insecure-get... That isn't a password and its basically available based on public information, just like a SSN. The IRS created a system that is literally another username and called it a PIN.
- apaprocki 10y agoThe original PINs were sent in the mail and in order to retrieve it you had to fill in the AGI from the previous year's return, not those credit-bureau challenge/response questions. It seems they created some vulnerability there, but it wasn't always like that.
- fweespee_ch 10y ago> The original PINs were sent in the mail and in order to retrieve it you had to fill in the AGI from the previous year's return, not those credit-bureau challenge/response questions. It seems they created some vulnerability there, but it wasn't always like that. The same information many people hand out as part of loan applications when they are asked for their tax returns as well as the IRS and other places. Hell, I had to do it in March and my AGI for 2014 is in god knows how many people's hands. Once again, that is a username and not a password. 1) Passwords are secret credentials possessed by one trusted party, yourself. 2) The hashed representation of which is stored by the opposing party for verification. You keep listing publicly available authentication factors which are effectively usernames, just like a SSN. If you need me to clarify further, I can. I'm just genuinely horrified people treat these things as confidential because they are not. I feel this is alot like my conversation here: https://news.ycombinator.com/item?id=11447435 https://news.ycombinator.com/item?id=11447435 People, even IT professionals, seem genuinely ignorant of the fact this data is essentially public knowledge and it simply requires a small amount of [potentially illegal] effort to acquire. They then go and build authentication schemes based on this information on the assumption literally no one on the planet is a criminal. That isn't "security" for anything that involving real money.