3 ms·
The local software doesn't really carry the same security concern. With cloud-based or in-person tax preparation, there's a risk that a single breach could com
by problems 10y ago
The local software doesn't really carry the same security concern.
With cloud-based or in-person tax preparation, there's a risk that a single breach could compromise many, many tax returns. With offline software you have no such exposure, it's not like it's exposing open ports to the internet.
At least in Canada there's a whole slew of free tax preparation software available, offline desktop and cloud-based. The government even lists the various free and paid options: http://www.cra-arc.gc.ca/esrvc-srvce/tx/ndvdls/netfile-impotnet/crtfdsftwr/menu-eng.html http://www.cra-arc.gc.ca/esrvc-srvce/tx/ndvdls/netfile-impot...
- hackuser 10y ago> With offline software you have no such exposure Generally I agree that it's a higher cost and therefore less valuable target, but there are ways to mass deploy some exploits. For example, you could use a browser exploit to obtain access, and then use that to mass deploy an exploit on tax return software.
- problems 10y agoBrowser exploit? What? On software that runs completely locally - without a browser, then only connects over SSL to a single government-run server? How exactly do you propose that would work? Do you mean to suggest that malware unrelated entirely to the tax software has an impact on its security? I mean... you'd have the whole host machine compromised - no need to "exploit" the tax software at all, you can get that and a lot more than just taxes off there - but it's still hard to do in true bulk. Much worse than a simple database dump and would only affect people who browsed to your site during the time of the exploit. Much more limited than anyone who used a given service. Additionally, full browser exploits these days are very rare and extremely valuable though. I doubt you'd see one wasted on such a purpose - at least, one that still works if you keep reasonably up to date.