3 ms·
> With offline software you have no such exposure Generally I agree that it's a higher cost and therefore less valuable target, but there are ways to mass depl
by hackuser 10y ago
> With offline software you have no such exposure
Generally I agree that it's a higher cost and therefore less valuable target, but there are ways to mass deploy some exploits. For example, you could use a browser exploit to obtain access, and then use that to mass deploy an exploit on tax return software.
- problems 10y agoBrowser exploit? What? On software that runs completely locally - without a browser, then only connects over SSL to a single government-run server? How exactly do you propose that would work? Do you mean to suggest that malware unrelated entirely to the tax software has an impact on its security? I mean... you'd have the whole host machine compromised - no need to "exploit" the tax software at all, you can get that and a lot more than just taxes off there - but it's still hard to do in true bulk. Much worse than a simple database dump and would only affect people who browsed to your site during the time of the exploit. Much more limited than anyone who used a given service. Additionally, full browser exploits these days are very rare and extremely valuable though. I doubt you'd see one wasted on such a purpose - at least, one that still works if you keep reasonably up to date.