Live data from Hacker News

IRS says thieves stole tax info from 100,000

washingtonpost.com

81–90 of 106 posts

Re: IRS says thieves stole tax info from 100,000

#81
post #52
post #51

If this were a company, the headline would have been "IRS hacked; tax information stolen from 100,000." Instead the IRS was able to spin it to The Washington Post. The headline is "thieves stole tax info." Thieves! The real headline is that the IRS is hackable.

> Instead the IRS was able to spin it to The Washington Post. The headline is "thieves stole tax info." Thieves! They spun it even better than that. The headline is "thieves stole tax info from 100,000 people" (i.e. not from the IRS, but from the people themselves)

why does the realization of this sneaky tactic make me so mad

Re: IRS says thieves stole tax info from 100,000

#82

Something is wrong with the wording here. Thieves stole the tax info of 100,000 but they stole it from the IRS. Make no mistake: IRS needs to be held responsible for this. It is their fault.

So when the victim is someone you don't like, it's somehow their fault?? The fault should be with the person/people that stole the tax information, not the IRS. Blaming the IRS would be like blaming a home owner for not installing a good enough security system when they get robbed instead of the criminals.

Since the IRS has custody of other people's sensitive data, they should be held to a different standard than the carefree homeowner in your example.

If I pay my bank for a safe deposit box, good security is part of what I am paying for. If it can be shown that they were lax/careless/negligent in the event of a theft, then I certainly would lay blame with both the bank and the thief for loss of my assets.

This is even more the case for a government with vast resources.

Re: IRS says thieves stole tax info from 100,000

#83
post #54

Earlier quoted context omitted.

You can look at it from the other side too, maybe Americans are putting too much weight on the SSN. I could practically post my Spanish ID number next to my name online and nothing would probably happen. As a matter of fact, a stupid regional government agency posted it next to my name in 2011 and it's been up ever since.

If you properly protect your security number, which requires some monthly commitment (such as $15 lifelock, or freecreditreport $5 per month), you can pretty much post your SSN online and really not much will happen. Any time someone uses it, you will get the alert and chance to act (stop the inquiry before it hit hard). It just that most people believe that not making their SSN public is enough for it to be safe.

1) There are free sites to monitor your credit such as Credit Karma. No need to pay hundreds a year. They even send out emails whenever you open up a new line of credit. Lifelock is a huge scam and has been fined by the FTC.

2) Just being alerted when someone else opens up credit in your name is hardly "protection." They still opened up credit in your name and you have to deal with that which is at the very very least inconvenient.

3) Posting you SSN online makes products more expensive for everyone because companies at the very least have to devote extra man hours every time someone else tries to take out credit in your name. Even if nothing happens to you they may have already issued a loan to the person and now has to write that off.

4) This is about fraudulent tax returns which credit monitoring companies wouldn't have info on.

I've had my identity stolen and I can tell you,it is truly awful.

Re: IRS says thieves stole tax info from 100,000

#84
post #28

Earlier quoted context omitted.

Someone fraudulently used my social security number. It is such a sick and terrible feeling knowing that your number is "out there" and can be used by anyone for a whole host of things. It feels horrible and really, really violating.

And worse, there's no way to rotate it that I know of, so it's like having your password leak and being unable to change it. It's out there forever.

You technically can get a new social security number under special circumstances but I think that is really an exception.

https://faq.ssa.gov/link/portal/34011/34019/Article/3789/Can...

Re: IRS says thieves stole tax info from 100,000

#85
post #28

Earlier quoted context omitted.

Someone fraudulently used my social security number. It is such a sick and terrible feeling knowing that your number is "out there" and can be used by anyone for a whole host of things. It feels horrible and really, really violating.

And worse, there's no way to rotate it that I know of, so it's like having your password leak and being unable to change it. It's out there forever.

https://faq.ssa.gov/link/portal/34011/34019/Article/3789/Can...

"We can assign a different number only if:

* Sequential numbers assigned to members of the same family are causing problems;

* More than one person is assigned or using the same number;

* A victim of identity theft continues to be disadvantaged by using the original number;

* There is a situation of harassment, abuse or life endangerment; or

* An individual has religious or cultural objections to certain numbers or digits in the original number. (We require written documentation in support of the objection from a religious group with which the number holder has an established relationship.)"

Re: IRS says thieves stole tax info from 100,000

#86
post #28

Earlier quoted context omitted.

Someone fraudulently used my social security number. It is such a sick and terrible feeling knowing that your number is "out there" and can be used by anyone for a whole host of things. It feels horrible and really, really violating.

I'm really sorry to hear that. Being a victim of an ill-designed system you're forced to be a part of is not a great feeling. :/

Thank you for the empathy.

The problem is it wasn't a designed system, it just came about by itself slowly over time. Social security numbers were never designed to be used in any way outside of social security.

Re: IRS says thieves stole tax info from 100,000

#87
post #54
post #21

I started "working" a few hours a week teaching programming at my kids' school. When they put me on the payroll I was astounded by the number of forms I had to fill out. I counted 15 forms requiring my signature, no less than 5 of which required my SSN. Lo and behold, there was a data breach of employee and volunteer records. Volunteers had to have background checks, which required the SSN. Thousands of people had th…

You can look at it from the other side too, maybe Americans are putting too much weight on the SSN. I could practically post my Spanish ID number next to my name online and nothing would probably happen. As a matter of fact, a stupid regional government agency posted it next to my name in 2011 and it's been up ever since.

Possible solution: require everyone to generate and register (in-person) public keys, which tax returns need to be signed with.

Re: IRS says thieves stole tax info from 100,000

#89

I believe that this actually happened to me -- which tells me the 100,000 number is way too low. To be more precise: when we went to electronically file our 2014 return, it was rejected because our return had already been filed (not by us, of course). I (like 80+ million others) am a victim of the Anthem breach, and I have assumed that my fraudulent return was part of that breach. (Regardless, I have opted into the i…

Unbelievable that the IRS would have this "Get Transcript" feature readily available via the web without any password, or better two-factor authentication. It's already been taken offline, but was up for a long time.

Will there be punitive lawsuits against the IRS as there were for Target and likely will be for Anthem?

Re: IRS says thieves stole tax info from 100,000

#90
I'M SO SICK OF BEING HACKED & MONEY STOLEN FROM ME AND THEN EXERTING A TON OF EFFORT (WEEKS) TO GET IT BACK. Something drastic needs to be done. It's been two times in the last five years and that's too many times for me!!!

Recently, a phantom Uber account of mine was hacked; phantom because I signed up years ago and must have connected my PayPal account & never used it. Needless to say, I was shocked that some worthless piece of shit/thief hacked into my Uber account and supposedly took a $800 ride in London on my bank(im in NYC).

What's even worse is Uber doesn't give one rats ass about it's customers/users (try to delete your Uber account yourself.. try to deactivate your Uber payment method - HA good luck). This hack has been going on for many months and those smug, greedy pigs at Uber haven't done a damn thing besides blame it's users/customers for choosing similar usernames/passwords used on other sites. Check out all the poor souls being hacked per this twitter search https://twitter.com/search?q=%40uber_support%20london&src=ty....

Hackers unite, let's please come up with better tools to secure ourselves from all this stress and insanity!!!

Post reply on HN