Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Something is wrong with the wording here. Thieves stole the tax info of 100,000 but they stole it from the IRS.

Make no mistake: IRS needs to be held responsible for this. It is their fault.



Why is it necessarily their fault?

I'd suspect the information needed to access the tax returns was obtained via phishing or a data breach elsewhere like a tax preparation service.


It's their fault because the information needed is widely available.


It's the fault of Congress that they need that information.

http://en.wikipedia.org/wiki/Tax_Reform_Act_of_1986


It's the people's fault because they elected the Congress.


Yes! Clearly the only appropriate action is to cut their budget another 20%. Maybe then they'll learn their lesson and fix the problem!

The budget cuts will continue until security improves!


So when the victim is someone you don't like, it's somehow their fault??

The fault should be with the person/people that stole the tax information, not the IRS.

Blaming the IRS would be like blaming a home owner for not installing a good enough security system when they get robbed instead of the criminals.


Since the IRS has custody of other people's sensitive data, they should be held to a different standard than the carefree homeowner in your example.

If I pay my bank for a safe deposit box, good security is part of what I am paying for. If it can be shown that they were lax/careless/negligent in the event of a theft, then I certainly would lay blame with both the bank and the thief for loss of my assets.

This is even more the case for a government with vast resources.


Perhaps, but what I can blame them for is for having very poor monitoring (50% failure rate and nobody noticed??) and poor security, culminating in this data breach.

People need to be held accountable for the security of their systems when they are storing personally identifiable information on customers or the public at large.

Edit: Perhaps they shouldn't be blamed when someone leverages a zero-day to break in, but if this is due to their failure to patch their systems, IMO their 100% liable for everything that follows.


50% failure rate is probably pretty normal for a form asking for SSN, name, address, and birth date - I fail my bank's security questions at least 1/3 of the time because things like "Anywhere Street" and "Anywhere St" are not the same.


Shouldn't that work with companies as well, not just IRS?

Take for example some large corporations. I.e. if Amazon or Google stores their customer information carelessly, and someone steals it - then Amazon would be victim, and if you say that they should have protected the information, you are blaming the victim because you don't like them?

The American revenue service has even larger resources and also a larger responsibility than even the largest of multinational corporations. They should be held accountable for what they do (like the tax officials in any country).


"and if you say that they should have protected the information, you are blaming the victim because you don't like them?"

If we only blamed Amazon in your example, then yes, we would only be blaming the victim.

How do we know they were "careless"?? They could have been using all of the correct security precautions and still got the data stolen.

It could have been an employee that installed malware because they fell for a phishing attack. Should they also be brought up on charges?

If my HN account gets compromised, should PG get brought up on charges? After all, he was supposed to protect my data, right?

Why aren't we even discussing the hackers that stole the data? Is it because they are supported here on HN?


There is a fundamental difference between HN and the IRS (for Americans, and corresponding agencies of the government for people in other countries): using HN is completely voluntary. Giving your personal information in a tax return is mandatory and not complying is punished severely.

In my opinion, this sets the required standard to a completely different class. The tax services have an important responsibility to process their information in a secure way. The information needs to be protected against leaks.

And from the outcome we can see that the protections are not adequate.


"In my opinion, this sets the required standard to a completely different class. The tax services have an important responsibility to process their information in a secure way. The information needs to be protected against leaks."

There is no way to protect leaks 100%. So you have unrealistic expectations.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: