Turbotax Hacked?

February 11th, 2015 at 10:48:01 AM permalink
odiousgambit
Member since: Oct 28, 2012
Threads: 154
Posts: 5112
some stories make it seem likely

why is it so hard to prevent hacking past company computer security?
I'm Still Standing, Yeah, Yeah, Yeah [it's an old guy chant for me]
February 11th, 2015 at 11:30:20 AM permalink
DRich
Member since: Oct 24, 2012
Threads: 51
Posts: 4970
I did not read that TurboTax got hacked. I thought I read that they quit filing state returns because people were filing with false identities.
At my age a Life In Prison sentence is not much of a detrrent.
February 11th, 2015 at 11:41:57 AM permalink
AZDuffman
Member since: Oct 24, 2012
Threads: 135
Posts: 18215
Quote: odiousgambit

why is it so hard to prevent hacking past company computer security?


Not to comment on TT, but probably because we are still using 1980s ideas for security. It is as if you tried to drive a Model A on the interstates in the 1960s. Passwords are still the basic security. Why are we not using biometrics? Why not a thumb-rive with an impossible to copy "password" of a thousand characters including letters, numbers, and wingding-font symbols? Why not limit the IP that can log in?

If I knew how to do it all I could be on "Shark Tank" and get a date with Lori!
The President is a fink.
February 11th, 2015 at 12:49:29 PM permalink
odiousgambit
Member since: Oct 28, 2012
Threads: 154
Posts: 5112
Quote: DRich
I did not read that TurboTax got hacked. I thought I read that they quit filing state returns because people were filing with false identities.


some stories today have brought up the possibility that TT was hacked, of course if so this would be bad for them ... I mean, talk about trust being an issue with your clients!

Quote: AZDuffman
Passwords are still the basic security [etc]


not just home computers, but companies too?
I'm Still Standing, Yeah, Yeah, Yeah [it's an old guy chant for me]
February 11th, 2015 at 1:15:05 PM permalink
Face
Member since: Oct 24, 2012
Threads: 61
Posts: 3941
Quote: odiousgambit

why is it so hard to prevent hacking past company computer security?


Probably the same reason video games get released with bugs. You have a very small (relatively) window to test, and are limited to the trials conjured by the few testers you have. Once you release it, you have thousands doing things you never even considered one would attempt.
Be bold and risk defeat, or be cautious and encourage it.
February 11th, 2015 at 1:16:52 PM permalink
AZDuffman
Member since: Oct 24, 2012
Threads: 135
Posts: 18215
Quote: odiousgambit


not just home computers, but companies too?


Companies I worked for are not much beyond username and password. Sometimes when you try to work remote there was more security, but still a user and password as well as a cookie on your machine.

Now imagine if they had something like a thumb drive. It has multiple passwords of say 15 digits each and they are in an order. When one is used it gets "destroyed." And there are say 100 only and they expire. It also expires after 30 days or so. You forget it at work and you get to go home and get it.

Now imagine it has a basic biometric so if I find it then I cannot use it. Even more layers possible.

Surely someone smarter than me can come up with better ideas. Of course, the best is to go back to private networks not connected directly to the internet. That is one more layer.
The President is a fink.
February 11th, 2015 at 2:37:56 PM permalink
rxwine
Member since: Oct 24, 2012
Threads: 189
Posts: 18764
There was a story awhile back of someone taking a picture of Angela Merkel's fingers and was able to reproduce her prints from it, just to prove it could be done.
You believe in an invisible god, and dismiss people who say they are trans? Really?
February 11th, 2015 at 3:00:36 PM permalink
DRich
Member since: Oct 24, 2012
Threads: 51
Posts: 4970
My E-Trade account has a little FOB that they send a confirmation type code to. Even registering a cell phone where a code can be texted is a big improvement that some systems are using now.
At my age a Life In Prison sentence is not much of a detrrent.
February 11th, 2015 at 3:30:19 PM permalink
rxwine
Member since: Oct 24, 2012
Threads: 189
Posts: 18764
I don't know if anything has changed with credit cards, but I've always felt I should be able to designate the limits (below the card limits) as to what can be purchased.

The credit card companies want to leave your limit up to whatever the max rate is, and if someone gets hold of it they just absorb the loss, but I could set the lower limit myself because I know what I'm doing for the month.

I believe I was told, 'well I might inconvenience myself' if I try to use my card and forgot to raise the limit. Worse reason I can think of, if I do it, it's my own fault. I'm willing to accept it.

I think they do it the way they do because some purchases just might not get made. But there are weeks where I know I don't need single purchase limits above $100. Yet they leave it open to thousands of dollars. Pisses me off. I should be able to phone in a code, (touchtone) and control access myself.
You believe in an invisible god, and dismiss people who say they are trans? Really?