Wednesday, April 11, 2007
Doing your taxes online?
As simple as anything involving taxes, and you can be sure you're using the most up-to-date tax software if you do your taxes on the Turbotax web site. And of course, they wouldn't put up the web site without checking carefully to make sure your information was protected, right?
Not carefully enough. A customer found out by accident that she could see other Turbo Tax customers's bank routing information.
Intuit did two things right. They accepted the good-faith bug report and didn't blame her. Then they fixed the problem. So you're safe now, if no bad guys stumbled across it first, and if Intuit fixed it correctly.
But we don't know whether they did, since they chose not to explain what happened. With the problem already fixed, most security people would like to see an accident report so that other web sites could check whether they made the same mistake.
|
Not carefully enough. A customer found out by accident that she could see other Turbo Tax customers's bank routing information.
Intuit did two things right. They accepted the good-faith bug report and didn't blame her. Then they fixed the problem. So you're safe now, if no bad guys stumbled across it first, and if Intuit fixed it correctly.
But we don't know whether they did, since they chose not to explain what happened. With the problem already fixed, most security people would like to see an accident report so that other web sites could check whether they made the same mistake.