IRS Security Faults Leave Taxpayer Data At Risk 42
coondoggie writes "In this tax season, when billions of dollars and tons of personal information is relayed to and from the government, it's more than disconcerting to hear that the Internal Revenue Service is still struggling to keep private information secure. A report out Friday from watchdogs at the Government Accountability Office says about 69% of the tax agency's previously noted security flaws remain unfixed and continue to jeopardize the confidentiality, integrity, and availability of the IRS's systems (PDF). The problems put the IRS at increased risk of unauthorized disclosure, modification, or destruction of financial and taxpayer information, the GAO concluded."
These are basic best practices. (Score:4, Informative)
Shameful that any company would fail at these basic tasks. It would take any competent admin very little time to compose policies that would effectively handle most of these. the others would require procedural changes but why would they continue to let the issue go if they know it's an audit exposure? (no pun intended)
From TFA:
For example, the GAO stated that the IRS continues to:
* use passwords that are not complex,
* ineffectively remove application accounts in a timely manner for separated employees,
* allow personnel excessive file and directory permissions,
* allow the unencrypted transmission of user and administrator login information,
* install security patches in an untimely manner
Re: (Score:2)
These are not basic best practices, but basic rules of economy. If it is not punishable and if it is an expense, it will not happen. Simple as that.
Re: (Score:2)
Re:These are basic best practices. (Score:4, Interesting)
* use passwords that are not complex,
* ineffectively remove application accounts in a timely manner for separated employees,
* allow personnel excessive file and directory permissions,
* allow the unencrypted transmission of user and administrator login information,
* install security patches in an untimely manner
I've seen most of those items every place I've worked. None of them are particularly "red alert" type problems on their own. For instance, are the passwords that aren't complex on publicly accessible systems? Someone logging into IRS.gov with "irs", "password" is a MAJOR MAJOR problem. Someone logging into a system only available in an IRS office with "s.johnson", "skipper2" is far less so.
The report is long and focuses on stuff auditors with no real IT experience sit around and worry about. I'm sure not going to read through the whole thing, but the parts I read are relatively yawn-worthy. An example would be how passwords were set to expire after 118 days on a certain system instead of 58 days. This despite the fact there's wide scale disagreement as to whether requiring people to change passwords has any real effect on security. Another example would be they didn't perfectly segregate important duties properly. (The example given was someone was both a database administrator and a system administrator).
The report is littered with statements like this:
(excuse me if this isn't something I'm going to write my congressman about)
If this is really the worst the GAO can come up with, I'd say we're all pretty safe. How many controls do you think your local H&R Block has?
Re: (Score:1)
The IRS is not a company. It doesn't have to please customers. It doesn't have to make a profit via voluntary exchange. Why should it care about protecting its payers' data?
Re: (Score:3, Insightful)
It doesn't have an inventory of products either, so there's no way to tell how much they're supposed to collect. If they don't keep thing secure, you could have multiple people using a single person's set of credentials to do business, but only paying the "fair share" of a single one of those people. IRS has an economic incentive to avoid that outcome at least.
IRS vs Private Industry (Score:2, Insightful)
The IRS is concerned about not disclosing private data.
Private industry (including those companies you have not choice in using) has been selling as much of your information as possible for years. While of course encountering security breeches of their own.
The bottom line is that private companies have already sold all of this data, so relax.
Re: (Score:2)
> The IRS is concerned about not disclosing private data.
Why do you believe this to be true?
The IRS is totally unaccountable for data security.
They could dump a billion private records into the public space and there would be no recourse for us and no punishment for them. Tried to sue the IRS lately?
The IRS is, by definition, exempt from accountability.
I agree with the other stuff you write and I have a hunch that you simply left out the word "not" from the first sentence.
Different how? (Score:3, Interesting)
Re: (Score:2)
Re: (Score:1, Funny)
How do you keep a grip on your scythe with one of those on?
Re: (Score:2)
I don't think he's a fan of taxes either, what with paying a fortune in tolls to that ferryman twice a day.
Re: (Score:1)
I'm a fan of the IRS, I have a t-shirt, mug and one of those giant over-sized nerf hands with the pointed index finger.
I'm not a fan of the IRS. I have a t-shirt, mug and one of those giant over-sized nerf hands with the pointed middle finger.
See?! (Score:2, Funny)
Re: (Score:3, Insightful)
Are you an Indian software engineer by chance? Because then you don't have to fill out the census either.
"Representatives and direct Taxes shall be apportioned among the several States which may be included within this Union, according to their respective Numbers... and excluding Indians not taxed"
Re: (Score:1)
*cough*Post Anonymously checkbox*cough*
Re: (Score:1)
Hey! We're the effin' IRS! (Score:2)
First they get coverage because they send 2 agents after a person who did not pay 4 cents.
I think someone at the IRS is under the impression that they're so badass they don't need security.
This goes contrary to what I've heard. (Score:2, Interesting)
Re: (Score:2)
So what you are saying is that some anonymous person posted on an internet forum claiming something that couldn't be verified (and then repeated by another anonymous person) and that this information could qui
Good to know (Score:4, Insightful)
Re:Good to know (Score:5, Insightful)
It's good to know that those who deal with SOX compliance and don't come into compliance are slapped hard with penalties,
Anyone who's ever been audited knows that the audit is all about the auditor, not about the rules. In the case of SOX, it's the company being audited who hires the auditor. The company DOING the audit isn't even liable if the the company being audited is fraudulent, and the auditor doesn't catch it. This adds up a huge conflict of interest along the lines of the bond rating companies. Who's going to hire an auditing firm that's a known bunch of sticklers?
the same rules don't apply to the branch of the FEDERAL GOVERNMENT that deals with more sensitive data than any SOX umbrella'd company.
Access to data is a very small part of what SOX is supposed to be about, and about zero reason why it was created in the first place. SOX was a reaction the the Enron scandal where they essentially had extraordinarily deceptive accounting practices that claimed they were worth billions of dollars when in fact they weren't worth much of anything. They did other tricks like create dummy corporations that traded assets back and forth to inflate worth. Citigroup was recently reported as selling their crappy worthless mortgage bonds the day before the end of a quarter for cash in exchange for buying them back the next quarter (this was actually recently). THAT is the real scam, though obviously the SOX rules didn't do much of anything to stop anyone.
If you want to get all pedantic about "the rules", go ahead. I think you miss the larger picture though.
Re: (Score:2)
$publish_whistleblower = "false";
echo "We're good! They'll never figure it out!";
} else {
$publish_whistleblower = "true";
}
if ($publish_whistleblower == "false") {
$internal_correction = "never";
$external_oversight = 0;
} else {
echo "Holy shit, the emperor really isn't wearing any clothes!";
$external_oversight = $external oversight ++;
$internal_correction = 1;
}
They fscked me. (Score:4, Insightful)
Re: (Score:3, Informative)
The only identity theft I've ever suffered is through the IRS. Supposedly four years ago someone else filed with my SSN.
It sounds to me like the identity theft itself wasn't through the IRS, but through some individual picking your SSN. It's not uncommon for an illegal alien to pick someone else's SSN when applying for a job. It happened to a friend of mine about 10 years ago and he only found out about it when he had a landlord or employer did a background check on him and found a referenced employer th
Re: (Score:2)
It's disturbing that the women's abuse center didn't itself do a background check...
Re: (Score:2)
Re: (Score:2)
I'm pretty sure you can request another SSN or taxpayer ID in circumstances like that. Also, if I were in your position, I'd try to reduce my withholding so that I'd always owe a little at the end. That way they can't refuse to send a refund.
That doesn't help you get back what you're owed, but just staunching the bleed seems like it would be an improvement.
Re: (Score:2)
I reduced my withholding. They sent me a bill and threatened me.
Re: (Score:2)
Gah. I wish I had a good idea then. Not having shared your plight, I remain optimistic that there's gotta be away to free yourself from the unyielding gears of bureaucracy somehow.
I mean, "Brazil" wasn't supposed to be a documentary.
--
way-side-comment: you're not really fscked. fscking is how one fixes corruption, and what happened to you is the opposite of fixing corruption.
How do you all not get this? (Score:2)
It’s the law of reactive efficiency.
They will only change something, if they lost something before, that was big enough to seriously get them at risk of losing their job.
Otherwise, what would be the point? (From their p.o.v.)
Seriously.
I mean you got a job. And your job is to obey rules. So you switch to passive mode.
You get good money. So you get the most profit from it, if you do the least possible amount of work in return.
It’s how nature works, and there is nothing weird about it.
The problem i
Transparency ??? (Score:1)
FairTax (Score:1)
At times like this, I wish we'd use something else [fairtax.org]