FacebookInstagramTwitterContact

 

Mayo Clinic Study Reveals Disturbing Impact Of Puberty Blockers On Testicular Development           >>           Why Freeze-Drying Is The Best Food Preservation Method           >>           10 Compelling Reasons To Steer Clear Of Gluten           >>           Only One Royal Has Ever Run The London Marathon           >>           Man Glassed In The Face After Telling Woman She Looked Like She Was 43           >>           You Have To See Travis Kelce's Reaction To Kardashian-Jenner Family Comparison           >>           Buried In The Cat's Paw Nebula Lies One Of The Largest Space Molecules Ever Seen           >>           Apple is launching new iPads May 7: Here's what to expect from the 'Let Loose' event           >>           FCC votes to restore net neutrality protections           >>           WhatsApp is enabling passkey support on iOS           >>          

 

SHARE THIS ARTICLE




REACH US


GENERAL INQUIRY

[email protected]

 

ADVERTISING

[email protected]

 

PRESS RELEASE

[email protected]

 

HOTLINE

+673 222-0178 [Office Hour]

+673 223-6740 [Fax]

 



Upcoming Events





Prayer Times


The prayer times for Brunei-Muara and Temburong districts. For Tutong add 1 minute and for Belait add 3 minutes.


Imsak

: 05:01 AM

Subuh

: 05:11 AM

Syuruk

: 06:29 AM

Doha

: 06:51 AM

Zohor

: 12:32 PM

Asar

: 03:44 PM

Maghrib

: 06:32 PM

Isyak

: 07:42 PM

 



The Business Directory


 

 



Security & Privacy


  Home > Security & Privacy


Security Flaw In Florida Tax Website Exposed Filers' Sensitive Data


Joe Raedle/Getty Image

 


 December 3rd, 2022  |  11:56 AM  |   786 views

ENGADGET

 

The state fixed the bug, which even revealed Social Security numbers.

 

Some Florida residents may be keeping a close eye on their finances after a security incident. Researcher Kamran Mohsin tells TechCrunch that Florida's Department of Revenue website had a flaw that exposed hundreds of filers' bank account and Social Security numbers. Anyone who logged in to the state business tax registration site could see, modify and even delete personal data just by modifying the web address pointing to a taxpayer's application number — you just needed to change the digits in the link.

 

There were over 713,000 applications in the Department's pipeline at the time of the discovery, Mohsin said. Mohsin warned the Department about the flaw on October 27th.

 

Department representative Bethany Wester said in a statement that the government fixed the flaw within four days of the report, and that two unnamed firms have deemed the site secure. She added there was "no sign" attackers abused the flaw, but didn't say how officials might have spotted any misuse. The agency contacted every affected taxpayers by phone or writing within four days of learning about the issue, and has offered a year of free credit monitoring.

 

Bugs like these, known as insecure direct object references, are relatively easy to fix. The damage might also be limited compared to other tax-related breaches, such as a Healthcare.gov intrusion that compromised about 75,000 people in 2018. However, the incident underscores the potential harm from weak security — even a small-scale exposure like this could be used to commit tax fraud and steal refunds.

 


 

Source:
courtesy of ENGADGET

by Jon Fingas

 

If you have any stories or news that you would like to share with the global online community, please feel free to share it with us by contacting us directly at [email protected]

 

Related News


Lahad Datu Murder: Remand Of 13 Students Extende

 2024-03-30 07:57:54

Searing Heat Shuts Schools For 33 Million Children

 2024-04-26 01:35:07

US Economic Growth Slows But Inflation Grows

 2024-04-26 07:36:54