Listen Live!
join BAW
forgot password
LIFE
WORK
PLAY


blAck americaweb.com

Report Finds IRS Computer Security Flaws

Date: Wednesday, April 23, 2008
By: JIM ABRAMS -- Associated Press Writer, Associated Press

WASHINGTON (AP) One more tax-season dread: A week before the filing deadline, Treasury watchdogs said Monday that poor controls over IRS computers could allow a disgruntled employee, agency contractor or outside hacker to steal taxpayers' confidential information.

Indeed, a hacker might even "gain full control of the IRS network," said a report Monday from the office of the Treasury Inspector General for Tax Administration.

Investigators did not cite any specific cases of wrongdoing within the IRS, which processes some 137 million tax returns. But they suggested a lack of review means someone could get sensitive information and no one would ever know.

The report comes amid increasing scrutiny of the IRS and the problems posed both by security concerns within the system and identity theft threats from outside:

- The independent IRS Oversight Board, in a report issued last month, outlined some $32 million in spending it said was needed to enhance the tax agency's security. "Disrupting IRS returns processing and stealing sensitive information could wreak havoc on the economy and financial markets," it said.




- Separately, IRS Commissioner Douglas Shulman will testify before Congress on Thursday about scams in which people are fooled into revealing their Social Security numbers and other confidential information by e-mails and phone calls purported to be coming from the IRS. The tax agency said last month that taxpayers this year had already forwarded to the agency 33,000 'phishing' scam e-mails reflecting more than 1,500 different schemes.

Inside the IRS, Monday's inspector general report dealt specifically with the thousands of routers and data switches that connect networks and direct computer traffic among the tax agency's offices. It suggested that "an unscrupulous person could divert data traffic through a third-party system on its way to the intended destination."

A review found that the IRS had authorized 374 accounts for employees and contractors that could be used to perform system administration duties. But of those, 141 either had expired authorizations or had never been properly authorized.

There was particular concern that 27 of the 55 employees and contractor who apparently had not been authorized had accessed routers and switches to change security configurations.

In addition, system administrations circumvented authentication controls by setting up 34 unauthorized accounts that appeared to be shared-use accounts, the report found. During the fiscal 2007, some 4.4 million of the 5.2 million accesses to the control system were made by these 34 user accounts.

The IRS issued a statement Monday saying it had "taken a number of steps to improve the control and monitoring of routers and switches. The IRS emphasizes it is not aware that any taxpayer data has been compromised due to a security breach. We continue to work to improve our security capabilities of our technology assets, and we have extensive intrusion-monitoring capabilities to watch for potential breaches."

The IG's office faulted the IRS for not adequately reviewing the "audit trail" logs that could help identify questionable activity.

"As a result, malicious persons could exploit vulnerabilities in the routers and switches to gain unauthorized access to sensitive information and disrupt computer operations with little chance of detection," the report said.

The IRS, in response, agreed to most of the report's recommendations for tightening controls. It said it would lock employee use accounts after 45 days of inactivity and remove those accounts after 90 days without use. It also said it would ensure that no unauthorized or unnecessary shared accounts exist in the control system.

The report follows a study by the congressional Government Accountability Office in January prodding the tax agency to fix dozens of information security weaknesses that left taxpayer records vulnerable to tampering or disclosure.

Then-acting IRS Commissioner Linda Stiff responded at the time that the agency recognized "there is significant work to be accomplished to address our information security deficiencies and we are taking aggressive steps to correct previously reported weaknesses."

There have been several widely publicized information-security incidents concerning government agencies other than the IRS. Perhaps the biggest was two years ago when a computer hard drive containing millions of names, Social Security numbers and birth dates was stolen from a Veterans Affairs employee's home in Maryland. The hard drive was later recovered.

Less than two months ago, a laptop computer containing medical records on 2,500 patients enrolled in a National Institutes of Health study was stolen from a researcher's car.

And last month, Secretary of State Condoleezza Rice apologized to presidential candidates Hillary Rodham Clinton, Barack Obama and John McCain after it was discovered that workers had snooped into their passport records.






  web blackamericaweb.com
Google


LIFE
WORK
PLAY

More Headlines

THE COLOR OF MONEY COLUMN: Uncertainty about the inflation outlook remains high

We've all been so focused on whether we are officially in a recession that we may not have paid enough attention to the creeping threat of inflation.

THE COLOR OF MONEY COLUMN: The wisdom of Big Mama's generation about mortgages was right

The fact is, the wisdom of Big Mama's generation about mortgages was right. They understood the risks. If you pay off your mortgage before you retire, you have more financial flexibility. You have a ...

Preventing and Combating Identity Theft

Clever thieves can counterfeit your financial identity by stealing your personal information. They can make credit card purchases, write bogus checks, withdraw your savings and more—all in your name and without your knowledge.

COLOR OF MONEY JUNE BOOK CLUB SELECTION: "Changing Your Course"

The desire to change course is often the result of some kind of wake-up call," the Blanchard’s write in their new book "Changing Your Course: The 5-Step Guide to Getting the Life ...

Choosing a Mortgage That's Right for You

Chase wants to share this key less to help you discover, establish and preserve a legacy for you and your family.

THE COLOR OF MONEY COLUMN: College Students after Graduation May Come Home to Live

Many parents already know this, but it's likely that after four, perhaps five or even six years of school, many college graduates -- faced with a tight job market, higher gas and food costs, and ...

Two Easy Steps to Creating a Budget You Can Live With

I know that most of you loathe the thought of being on a budget. The word “budget” alone conjures up images of deprivation – making us think about every thing we can’t have, can’t ...

Everyone Should Own a Home, Right? Wrong! Why Some People Shouldn’t Become Homeowners

I’m a big believer in home ownership. Having your own house can help you build wealth, get tax breaks that aren’t available to renters, and create a great financial legacy for generations to ...



Copyright © 2001-2005 BlackAmericaWeb.com, Inc. All Rights Reserved.
About Us | Advertise | Help | Privacy Policy | Search | Terms of Use | Unsubscribe