• Home
  • About
  • Contact Us
  • Privacy Policy

Technic News

The Latest in Technology

  • New Technology
  • Cool Gadgets
  • Latest Tech & Gadgets
  • Tech & Gadget Reviews
  • Tech & Gadget News
  • Gadgets Shop

Security flaw in Florida tax website exposed filers’ sensitive data

Some Florida residents may be keeping a close eye on their finances after a security incident. Researcher Kamran Mohsin tellsTechCrunch that Florida’s Department of Revenue website had a flaw that exposed hundreds of filers’ bank account and Social Security numbers. Anyone who logged in to the state business tax registration site could see, modify and even delete personal data just by modifying the web address pointing to a taxpayer’s application number — you just needed to change the digits in the link.

There were over 713,000 applications in the Department’s pipeline at the time of the discovery, Mohsin said. Mohsin warned the Department about the flaw on October 27th.

Department representative Bethany Wester said in a statement that the government fixed the flaw within four days of the report, and that two unnamed firms have deemed the site secure. She added there was “no sign” attackers abused the flaw, but didn’t say how officials might have spotted any misuse. The agency contacted every affected taxpayers by phone or writing within four days of learning about the issue, and has offered a year of free credit monitoring.

Bugs like these, known as insecure direct object references, are relatively easy to fix. The damage might also be limited compared to other tax-related breaches, such as a Healthcare.gov intrusion that compromised about 75,000 people in 2018. However, the incident underscores the potential harm from weak security — even a small-scale exposure like this could be used to commit tax fraud and steal refunds.

Brought to you by USA Today Read the rest of the article here.

  • Facebook
  • Twitter
  • Pinterest

Filed Under: Tech & Gadget News

  • Email
  • Facebook
  • YouTube

www.sicherversichert.de

www.service-hotel-24.com

www.virtutea.com

www.my-fly.club 

www.1-2-holiday.com

www.women-fashion-online.com

www.amer.de

www.cupado.de

Recent Posts

  • Magic, which is developing an AI-powered code-generating tool similar to GitHub’s Copilot, raised a $23M Series A led by Alphabet’s CapitalG (Kyle Wiggers/TechCrunch) February 7, 2023
  • Disney is bringing the first episode of ‘The Mandalorian’ to broadcast TV February 7, 2023
  • Filing: eBay plans to lay off ~500 employees, ~4% of its total workforce, to create space to invest in “new technologies, customer innovations, and key markets” (Reuters) February 7, 2023
  • Source: Microsoft plans to release software to help large companies create and customize their own chatbots using ChatGPT technology later this year (Jordan Novet/CNBC) February 7, 2023
  • The Samsung Galaxy S23 series has a Game Booster setting that lets a plugged-in phone bypass the battery to use power directly from the charger, reducing heat (Ben Schoon/9to5Google) February 7, 2023

Copyright © 2023 · Designed by Amaraq Websites

We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept”, you consent to the use of ALL the cookies.
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled

Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.

Non-necessary

Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.