IRS Security Faults Leave Taxpayer Data At Risk
coondoggie writes "In this tax season, when billions of dollars and tons of personal information is relayed to and from the government, it's more than disconcerting to hear that the Internal Revenue Service is still struggling to keep private information secure. A report out Friday from watchdogs at the Government Accountability Office says about 69% of the tax agency's previously noted security flaws remain unfixed and continue to jeopardize the confidentiality, integrity, and availability of the IRS's systems (PDF). The problems put the IRS at increased risk of unauthorized disclosure, modification, or destruction of financial and taxpayer information, the GAO concluded."
Shameful that any company would fail at these basic tasks. It would take any competent admin very little time to compose policies that would effectively handle most of these. the others would require procedural changes but why would they continue to let the issue go if they know it's an audit exposure? (no pun intended)
From TFA:
For example, the GAO stated that the IRS continues to:
* use passwords that are not complex,
* ineffectively remove application accounts in a timely manner for separated employees,
* allow personnel excessive file and directory permissions,
* allow the unencrypted transmission of user and administrator login information,
* install security patches in an untimely manner
The IRS is concerned about not disclosing private data.
Private industry (including those companies you have not choice in using) has been selling as much of your information as possible for years. While of course encountering security breeches of their own.
The bottom line is that private companies have already sold all of this data, so relax.
Im not a fan of the IRS, but let's be real: 1. There are almost no government agencies or civilian organizations that don't have fairly terrible security...2. These checkbox requirements dont really tell a story. 2. These checkbox requirements dont tell a story of the actual level of security. You'd have to take a look at the whole architecture to figure out whether, for example, those UNIX passwords actually were important or not.
That's why I don't pay tax.
Fuck systemd. Fuck Redhat. Fuck Soylent, too. Wait, scratch the last one.
A long while back, someone came in on Slashdot and claimed to have consulted/worked with the IRS, and described a security culture and tolerance for hair-trigger detection measures that would make any security fascist drool. So these problems would most likely be on a purely bureaucratic level, then?
Emotions! In your brain!
It's good to know that those who deal with SOX compliance and don't come into compliance are slapped hard with penalties, yet the same rules don't apply to the branch of the FEDERAL GOVERNMENT that deals with more sensitive data than any SOX umbrella'd company.
I am Bennett Haselton! I am Bennett Haselton!
The only identity theft I've ever suffered is through the IRS. Supposedly four years ago someone else filed with my SSN. I haven't got my tax refund since. They won't talk to me about what is going on. I've done everything they've asked including filing a police report and verifying my identity with the social security office. If you call the customer support number they aren't able to help because my account is being handled by a secret agency within the IRS that not even they can talk to. They've twice sent me [different] dead phone numbers that are supposedly my point of contact for finding out what is going on. They've gone so far as to send me a bill and to threaten what will happen to me if they find out I'm doing something bad. Last year they finally sent me a letter confirming they recognize that I am me. They sent me a couple hundred dollar check (they owe me thousands) and said there might be more after further review. I've never heard from them again. This year my tax refund got flagged and lost in limbo again.
At what price learning? At what cost wisdom? The price is a man's peace of mind, and the cost is his life.