3 ms·
http://krebsonsecurity.com/2016/03/irs-suspends-insecure-get-ip-pin-feature/ http://krebsonsecurity.com/2016/03/irs-suspends-insecure-get... That isn't a passw
by fweespee_ch 10y ago
http://krebsonsecurity.com/2016/03/irs-suspends-insecure-get-ip-pin-feature/ http://krebsonsecurity.com/2016/03/irs-suspends-insecure-get...
That isn't a password and its basically available based on public information, just like a SSN.
The IRS created a system that is literally another username and called it a PIN.
- apaprocki 10y agoThe original PINs were sent in the mail and in order to retrieve it you had to fill in the AGI from the previous year's return, not those credit-bureau challenge/response questions. It seems they created some vulnerability there, but it wasn't always like that.
- fweespee_ch 10y ago> The original PINs were sent in the mail and in order to retrieve it you had to fill in the AGI from the previous year's return, not those credit-bureau challenge/response questions. It seems they created some vulnerability there, but it wasn't always like that. The same information many people hand out as part of loan applications when they are asked for their tax returns as well as the IRS and other places. Hell, I had to do it in March and my AGI for 2014 is in god knows how many people's hands. Once again, that is a username and not a password. 1) Passwords are secret credentials possessed by one trusted party, yourself. 2) The hashed representation of which is stored by the opposing party for verification. You keep listing publicly available authentication factors which are effectively usernames, just like a SSN. If you need me to clarify further, I can. I'm just genuinely horrified people treat these things as confidential because they are not. I feel this is alot like my conversation here: https://news.ycombinator.com/item?id=11447435 https://news.ycombinator.com/item?id=11447435 People, even IT professionals, seem genuinely ignorant of the fact this data is essentially public knowledge and it simply requires a small amount of [potentially illegal] effort to acquire. They then go and build authentication schemes based on this information on the assumption literally no one on the planet is a criminal. That isn't "security" for anything that involving real money.