Identity Thieves Obtain 100,000 Electronic Filing PINs From IRS System (csoonline.com)
itwbennett writes: In January attackers targeted an IRS Web application in an attempt to obtain E-file PINs corresponding to 464,000 previously stolen social security numbers (SSNs) and other taxpayer data. The automated bot was blocked by the IRS after obtaining 100,000 PINs. The IRS said in a statement Tuesday that the SSNs were not stolen from the agency and that the agency would be notifying affected taxpayers.
with ten-thousand 4-digit PINs. Interested?
NB: The message above might reflect my opinion right now, but not necessarily tomorrow or next year.
I'm pretty sure I forgot my e-file pin, it would be ever so helpful if the hackers would offer to sell it to me for a reasonable fee so I wouldn't have to go through the bother of a reset.
"There is more worth loving than we have strength to love." - Brian Jay Stanley
Would love to be hacked and have someone pay my back taxes for me!
love is just extroverted narcissism
Since when do systems allow brute-force attacks on PIN numbers? Many systems have been locking out (or slowing down) logins after a certain number of failed attempts for a long time now. While this allows for denial-of-service attacks, it seems better than allowing a bot to try 1000 passwords per second until it succeeds.
Have you read my blog lately?
What else is new?
That's probably why the IRS sent me a letter with my 2014 IP PIN and a follow-up letter that I should use my 2014 IP PIN for filing my taxes. Filed my taxes through H&R Block and my return got accepted yesterday.
The IRS really should assign everyone PINs or, preferably, better security. There's no good reason that additional security is restricted to people in Georgia, Florida, or those who have suffered tax-related identity theft. Also, why not simply maintain a registry of public keys for individuals? Require tax returns to be filed electronically and digitally sign them using the private key of individuals. As long as people don't allow anyone access to their private keys, this could prevent a lot of the problem. Why we're still using SSNs for identity information in the 21st century is beyond me. They were supposed to serve one purpose and one purpose only -- an identifier to track people's contributions to social security.
I hate all anonymous shitbags. Log in, you filthy bastards.
I've been doing electronic tax filing since the days of yore, even back when the tax software was generating a special machine-readable "1040PC" form with all your data on one page. If I remember correctly, the PIN was supposed to be a replacement for your physical signature on the return, since the rules say you need to certify that you are submitting a true return and acknowledge the penalties for not doing so. So, I'm not sure it was a secret PIN in that sense.
BUT -- these e-filing services shouldn't be so insecure that someone can just sniff traffic and collect the PINs. I always assumed that it worked something like this -- IRS hands out TLS certificate to "authorized e-file providers" who operate the tax payment gateways and communicate the return data from the program, to the gateway, to the IRS. Hopefully they're not just FTPing the data around :)
...and the government wants to move to e-records for your healthcare. So far I've been compromised with the Target breach, the Home Depot breach, the TMobile Experian breach. The government has been breached many times including this one to the tune of millions of people. You have to assume that your information is out there already. I'm not keen on moving to those electronic health records...
Seeing this makes me wonder if this was the real reason for the IRS stopping to accept electronically filed returns last week. No mention of it in TFA, but the Christian Science Monitor was a bit cynical when reporting Tax filing halted by IRS computer outage. Will refunds be delayed? by putting quotes around the "hardware failure".
A "hardware failure" forced the shutdown of several tax processing systems, including the e-file system, the IRS said in a statement.
whereas the actual IRS statement was (in the same article)
The IRS experienced a hardware failure this afternoon affecting a number of tax processing systems, which are currently unavailable. Several of our systems are not currently operating, including our modernized e-file system and a number of other related systems. The IRS is currently in the process of making repairs and working to restore normal operations as soon as possible. We anticipate some of the systems will remain unavailable until tomorrow.
I am Slashdot. Are you Slashdot as well?
The app requires taxpayer information such as name, Social Security number, date of birth and full address.
It was not brute force. They had a lot more information about the person to get the PIN.
Am I missing something here? What is the risk in someone having my SSN and e-file PIN? Are they going to file my taxes for me? Even if they file a fraudulent return and the IRS cuts a check to the bad guy, I'm not seeing any liability for me.
I had my SSN stolen and used once for illegal employment. I only found out when the IRS contacted me and asked why I hadn't filed my "other" W-2. It was pretty clear that I wasn't simultaneously working two full time jobs, and they quickly marked the other W-2 as fraudulent and moved on.
Wrong. The Affordable Care Act (some call it Obamacare) is administered by the Health and Human Services Department.
Okay, I find it funny that the IRS reassuring people that SSN's were not stolen from them. Not sure it matters, the SSN' s were already stolen. All they wanted was the PINs and, Hey, 25% isn't bad. Still worth a fortune. Wonder if data would be safer being send by pigeon carrier. All these data breaches recently. FBI, CIA and the IRS.
"Imagination is more important than knowledge" - Einstein
"Not stolen from the agency."
Thieves' Computer: Is this a valid pin?
IRS' Computer: Nope
Thieves' Computer: Is this a valid pin?
IRS' Computer: Nope
Thieves' Computer: Is this a valid pin?
IRS' Computer: (Smirks and looks away) Nope!
(-1: Post disagrees with my already-settled worldview) is not a valid mod option.
Yeah, the IRS only charges you a fee if you don't have approved insurance, hardly the same thing as managing our health insurance, or even health care.
APK likes to ask for responses to the same things over and over. Maybe he just likes the responses?
All a PIN does is act as a proxy for a ink signature, an issue that the government hasn't been able to figure out yet.
love is just extroverted narcissism
Yeah, the IRS only charges you a fee if you don't have approved insurance, hardly the same thing as managing our health insurance, or even health care.
God forbid that you ever owe for being a member of society.
In case you're curious, this is how APK spent his day yesterday. I see about 7 waking hours throughout the day when he was not trolling Slashdot, although I may have missed a few posts. All times are correct at least for my timezone. The vast majority of these are replies to you (that's how it's easy to find them - just go through your post history and he's there like stink on shit), some of the ones late at night were trolling replies to me. This is who we're dealing with. Something tells me that this is not a one-off thing for him, I think this is his normal day. He goes online and trolls all day, and spends a few hours to eat, shit, masturbate, play games, etc.
Note this is only for yesterday. He's back today continuing his crap flood and I haven't even included any of those posts, these are just for the 9th (my time).
8:56 http://slashdot.org/comments.p...
9:14 http://slashdot.org/comments.p...
9:16 http://slashdot.org/comments.p...
10:02 http://slashdot.org/comments.p...
10:06 http://slashdot.org/comments.p...
10:20 http://slashdot.org/comments.p...
10:29 http://slashdot.org/comments.p...
10:52 http://slashdot.org/comments.p...
10:56 http://slashdot.org/comments.p...
11:02 http://slashdot.org/comments.p...
11:12 http://slashdot.org/comments.p...
11:15 http://slashdot.org/comments.p...
11:25 http://slashdot.org/comments.p...
11:39 http://slashdot.org/comments.p...
11:51 http://slashdot.org/comments.p...
11:53 http://slashdot.org/comments.p...
12:08 http://slashdot.org/comments.p...
12:15 http://slashdot.org/comments.p...
12:20 http://slashdot.org/comments.p...
12:35 http://slashdot.org/comments.p...
12:52 http://slashdot.org/comments.p...
13:02 http://slashdot.org/comments.p...
15:08 http://slashdot.org/comments.p...
15:19 http://slashdot.org/comments.p...
15:22 http://slashdot.org/comments.p...
15:27 http://slashdot.org/comments.p...
15:29 http://slashdot.org/comments.p...
"Our two-party system is like a bowl of shit looking at itself in a mirror." - Lewis Black
Everyone who gets a letter from the IRS saying their SSN was compromised needs to sue the government.
That's interesting, I saw him posting in the article about Sourceforge. I didn't see him mention APK though. It's probably worth linking him to this list.
"Our two-party system is like a bowl of shit looking at itself in a mirror." - Lewis Black
I'm ready for a system where I don't have to bother filing taxes........either a flat tax that is taken out of each paycheck or a national sales tax where it's taken at the register or whatever. I know taxes are needed to pay for stuff for the greater good, but holy cow, taxes are a pain. I'll pay my fair share (emphasis on fair), just make it easier for me.
I've been claiming 0 on my taxes so that I get a big refund. The logic is that it's easier for me to put away $3k on day then $115.0684931506849 every two weeks. I'm also quick to file my taxes because I want my money. For years this has worked well but now I think I should rethink my strategy.
I'm not sure that you are arguing against something I said. I merely pointed out that the IRS does not administer the ACA, but only charges the fee if you choose to go without insurance. I was pointing out that Archangel Michael was mischaracterizing how much the IRS is involved with the ACA.
APK likes to ask for responses to the same things over and over. Maybe he just likes the responses?
Yeah, he does so enjoy doing that. I think he has a script, because it seems like he replies to every one of my replies within a short amount of time. I try to keep the conversation to a single thread though. This time it is at least only 2 posts to each one. Last time he got a bug up his rear it was 5 posts to every post I made, which of course pisses everyone off.
APK likes to ask for responses to the same things over and over. Maybe he just likes the responses?
I missed it as well, perhaps it was in the Slashdot improvements article.
APK likes to ask for responses to the same things over and over. Maybe he just likes the responses?
I'm not sure that you are arguing against something I said.
I'm not sure either. Today has been one catastrophic brain fart after another on Slashdot. I guess my skinny vanilla latte haven't kicked in this morning.
Here it is. I kind of appreciate the vagueness of it. Hopefully they aren't just outright stopping the AC tradition though, that would probably be overkill, even for APK.
"Our two-party system is like a bowl of shit looking at itself in a mirror." - Lewis Black
Owe a fucking corrupt corporation!?! Are you fucking shitting me? I pay taxes for things like roads, cops and soldiers. But Why the Fuck do I have to pay the rich bastards who own Humana? And as far as HHS administering it? What the hell do they do besides rubber-stamping rate increases?
That whole string is awesome, I had to chip in a bit. I think it is hilarious AmiMoJo is posting against APK being silenced, but would gladly silence people who disagree with women...
APK likes to ask for responses to the same things over and over. Maybe he just likes the responses?
Owe a fucking corrupt corporation!?! Are you fucking shitting me?
Private citizens pay the government first before spending their money. Corporate citizens pay the government last after spending their money. The tax laws are in favor of the corporations and not individuals.
God forbid that you ever owe for being a member of society.
Being a member of society is not the same as involuntary servitude (13th Amendment). Got it. YOU MUST PAY to belong! So much for free association (1st Amendment).
This is why socialists suck. They have no clue how they enslave a society.
Agent K: A *person* is smart. People are dumb, stupid, panicky animals, and you know it.
Tax laws are in favor of those that can pay off the politicians the most. All taxes are regressive.
Agent K: A *person* is smart. People are dumb, stupid, panicky animals, and you know it.
And you think that is any better? Or you just missing the point that the government agencies that need to protect our information the most, can't?
Not sure you made your case any better. ;-)
Agent K: A *person* is smart. People are dumb, stupid, panicky animals, and you know it.
Tax laws are in favor of those that can pay off the politicians the most. All taxes are regressive.
Corporations are doing a fine in paying less in regressive taxes. Why not join them?
I realize you have the "Government bad" mind set but accuracy is important. You may as well blame the right department.
I wouldn't worry too much about it, he probably just wants your cock; that or he's using you as an excuse to spam his HOSTS engine garbage
How is it that these people don't get tracked?
Require refunds to go to a domestic bank with an account name matching the name on the return. Better yet, require refunds to be processed through the employer who collected the taxes in the first place if the taxpayer is still employed there.
And those don't even count the recent replies to me. Since he brought it up, and it was on-topic (claim that all ads are served from a different domain to the main site), I had to mention that a HOSTS file can't even block his OWN abuse ads on Slashdot.
Course I went into an amusing look into his history with CA, where his legal "threats" resulted in him "winning" because he filled out their 21 question form to be removed as a false positive for malware. You know, what you would do if you don't hire a lawyer.
He'll probably reply to this and still link to my previous comment and claim again that he "won" and that I must accept that he's right.
He'll probably reply to this and still link to my previous comment and claim again that he "won" and that I must accept that he's right.
Of course he will, that's all he does. After all, your comment failed to prove him "technically and validly wrong", right? Therefore, obviously he won. It doesn't matter that you're not trying to prove him wrong in the first place and that he's the only one playing that game, he still wins. That's the game, it's called "I win", and he's the only one who ever plays it. Then he'll follow up that post with 4 other anonymous posts where he refers to himself in the third person but still uses phrases like "you fail vs. apk" which only he ever uses (how many times have you used "vs." in normal conversation over the last month?), and he'll assume that no one knows that he's the one making those posts in support of himself. Then he'll come along again and post a reply to his anonymous self thanking himself for the support. And, just for good measure, he'll also accuse you of everything that you've accused him of doing, because he learned the "I know you are but what am I?" strategy in grade school and doesn't want to let that one go. This is the APK "debate" strategy in a nutshell. He concludes it all by stating (repeatedly; very, very repeatedly) that you have "eaten your words" and claims some sort of grand victory. He'll probably also manage to call you effete or something, he calls people effete a lot. I'm not sure what that says about his self-confidence or sense of masculinity, but he definitely calls everyone else effete.
"Our two-party system is like a bowl of shit looking at itself in a mirror." - Lewis Black
All from public information he's posted himself, in case you were curious.
Alexander Peter Kowalski AKA alecstaar
903 East Division Street Syracuse, N.Y
apk4776239@hotmail.com
I can't even imagine...
http://www.esciudad.com/casas/...
I haven't had the good fortune to read through that thread responding to John Carmack, that's awful. That's one of those things that makes you cringe for the person who doesn't get it. He posts a question to Carmack, and then the next day some AC replies kind of trolling him. 4 days after that the crapflood hits. He posts at (my times) 11:47am, 11:55, 11:58, 12:04, 12:10, 12:25, 12:39, all anonymous replies appearing to come from a third person (not APK), all saying the same crap as if all of a sudden 4 days later a bunch of people reading that at the same time all decided to post responses within an hour of each other, and he's going to assume that people don't know that it's him. It seriously makes me cringe. He feels the need to repeatedly defend his overclocking skills apparently. He follows that flood up with another 3 posts over the next 2 days still saying the same crap just for good measure. And here we are, nearly 14 years later, and his behavior hasn't changed at all. Think about that, zero personal growth over 14 years. I'd love to know what had to happen in childhood to damage a person like that, Im genuinely curious about what makes him tick. It's like encountering some bizarre animal that shouldn't be able to survive for more than a few years, but here's one 50 years later and you just want to know how that happened.
"Our two-party system is like a bowl of shit looking at itself in a mirror." - Lewis Black
The birth of a troll. Not that he hadn't been kicked out of several other online forums for the same behavior. I've had some fun googling the alecstaar username and seeing his banned self being talked about as a sort of trolling legend, while most are unaware of his Slashdot antics.
Or weirder, making coherent positive contributions on other web sites.
Im genuinely curious about what makes him tick
It looks like severe bipolar disorder, with Persecutory delusions - http://psycheducation.org/diag...
Well, I'm not going to be sorry to see him go. He's been trolling me for months after I called him out to stop with all of the spam he posts. I've emailed Slashdot about it asking if they can add some more filters specifically to block his post content (which it sounds like they're going to do), I've been emailing the people he cites as those who recommend his software to let them know how he's using their reputations in his spam, etc. He's been taunting me non-stop about how no one can affect him, etc. I don't know if my specific efforts influenced anything, but I'm glad that he's being treated the way he deserves. If he's going to gloat about defeating the various systems that Slashdot uses to protect against spam, about defeating the moderation system, etc, then he deserves to have additional roadblocks put up in front of him to try and step his crap-flood. Now he's whining about possibly being banned, as if blocking his spam is in any way unjust. He should have thought about that before gloating about defeating the anti-spam and moderation system.
"Our two-party system is like a bowl of shit looking at itself in a mirror." - Lewis Black
Entirely ironic that he spams an ad-blocking program. And then will complain when his ads....get blocked.
APK, the things that you do or say to me (or, for that matter, what any bipolar sociopath has to say) don't affect me, other than as a source of entertainment and possibly pity. Go ahead, let's hear again how nothing that I can do will affect you, because from what I hear you're about to see the effects. Slashdot is about to speak in a loud voice that your trollish shit is not welcome. It's a long time coming, and I will have zero sympathy for you when you're gone. You contribute nothing of value to this site, regardless of what you want to believe. In the past you had the opportunity to actually form some sort of small following here, but you completely squandered that opportunity by shitting all over the site at every available opportunity. There's no one who constantly says that you're a bad programmer, your ideas are wrong, etc, everyone always talks shit about your ridiculous behavior. Trying to bitch and moan about people wanting to silence your ideas is complete bullshit, the only thing that needs silencing is your constant flood of crap that contributes nothing. You're not being persecuted like some martyr, you're being blocked for being an abuser. That's what you are, an abuser. You're not some sympathetic persecuted martyr figure, you're just a troll, and you're about to add Slashdot to the long list of technical discussion sites where you are persona non grata. Think about what that says, is it more likely that there are all of these websites out there that have it wrong, or is it more likely that you're just an asshole? What's the simplest explanation for the fact that you are banned from so many discussion sites? You had an opportunity to gain a following with the substance of your posts, but that ship has sailed. At this point you are nothing but a minor nuisance just waiting to get squished by the inevitable shoe. Good riddance, I'll admit that I'll miss the entertainment value of the absurdity of some of your insults and claims, but I'm really not going to miss you. I'll be happy to continue to contact the site owners to let them know how I believe they can improve their service by way of removing you from it. You are determined to be a pain in the ass, so don't be surprised when you're treated like one. And don't try to pull the victim card either like a little bitch, you made your bed and now you get to lie in it. And I know you understand what it means to lie. What's the first rule when dealing with a spammer?
Adios, trollchacho.
"Our two-party system is like a bowl of shit looking at itself in a mirror." - Lewis Black
I like how you talk about the "risk of putting yourself out there", and then immediately follow that up 6 minutes later with a post where you act like you're someone else. Posts # 51500355 and 51500369 - 14 posts on Slashdot on Saturday morning and one of them just happened to be an anonymous supporter of yourself, and you still think that no one knows it's you. You're either a world-class hypocrite, or you are actually so bipolar that you really do think you're someone else. Maybe that's another personality shining through, I don't know. Either way, I'm done with you.
"Our two-party system is like a bowl of shit looking at itself in a mirror." - Lewis Black
You don't even need to look at the post history to see that, just check out my homepage APK :)