Our server costs ~$56 per month to run. Please consider donating or becoming a Patron to help keep the site running. Help us gain new members by following us on Twitter and liking our page on Facebook!
Current time: August 14, 2025, 9:58 pm

Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Ask a computer security expert.
#24
RE: Ask a computer security expert.
(May 27, 2015 at 4:15 pm)KevinM1 Wrote: Hey Tib, thoughts on the veracity of this AV chart?

http://chart.av-comparatives.org/chart1.php

I'm currently using BitDefender for my PC and Android phone based on the numbers there.

Also, what would you have done differently than the IRS to prevent the breach?  In case you're not aware, 100,000 people's tax records were stolen from the IRS' transcript site.  It used weak authentication - just a SSN and valid email address - and people who had stolen others' identities simply entered their stolen info, provided an email address, and had unfettered access to those individulals' records.

Talking with a friend, I suggested two factor authentication, but access could be a problem since not everyone owns/has access to a cellphone or PC.  Is there anything else that could be done in that case?

AV-Comparatives are pretty thorough and open about their testing techniques, so I'd definitely trust them as an independent testing organisation. From the looks of the graph, BitDefender seems like a good choice. Might have to switch over from Kaspersky when our license runs out.

As for the IRS breach, I believe more validation of the user identity should have been performed. For instance, you should not be able to take a social security number and a mailing address (both of which are pretty easy pieces of information to get...your employer likely has both) and get copies of tax records. Rather, what should happen is the following:

1) User without an IRS.gov account enters their SSN and address.
2) IRS.gov checks the SSN and address match what they have on file, and asks user to enter an email address / username.
3) IRS.gov then mails a randomly generated password to the user's mailing address, which they can combine with their username to log in.

It's not a perfect system, as a really dedicated attacker could sit and wait for the mail I suppose, but ultimately those cases of fraud are going to happen one way or the other anyway.
Reply



Messages In This Thread
Ask a computer security expert. - by Tiberius - May 22, 2015 at 1:12 am
RE: Ask a computer security expert. - by Minimalist - May 22, 2015 at 1:44 am
RE: Ask a computer security expert. - by Alex K - May 22, 2015 at 3:03 am
RE: Ask a computer security expert. - by pocaracas - May 22, 2015 at 5:38 am
RE: Ask a computer security expert. - by ignoramus - May 22, 2015 at 7:23 am
RE: Ask a computer security expert. - by Napoléon - May 22, 2015 at 7:50 am
RE: Ask a computer security expert. - by pocaracas - May 22, 2015 at 9:22 am
RE: Ask a computer security expert. - by Napoléon - May 22, 2015 at 8:32 pm
RE: Ask a computer security expert. - by pocaracas - May 23, 2015 at 5:51 am
RE: Ask a computer security expert. - by Chad32 - May 22, 2015 at 8:16 am
RE: Ask a computer security expert. - by vorlon13 - May 22, 2015 at 9:55 am
RE: Ask a computer security expert. - by Whateverist - May 22, 2015 at 10:00 am
RE: Ask a computer security expert. - by pocaracas - May 22, 2015 at 10:13 am
RE: Ask a computer security expert. - by Whateverist - May 22, 2015 at 10:15 am
RE: Ask a computer security expert. - by ignoramus - May 23, 2015 at 6:06 am
RE: Ask a computer security expert. - by ignoramus - May 23, 2015 at 11:37 pm
RE: Ask a computer security expert. - by vorlon13 - May 23, 2015 at 11:06 am
RE: Ask a computer security expert. - by Tiberius - May 24, 2015 at 1:20 am
RE: Ask a computer security expert. - by Minimalist - May 24, 2015 at 1:45 am
Ask a computer security expert. - by Tiberius - May 25, 2015 at 9:07 am
RE: Ask a computer security expert. - by KevinM1 - May 27, 2015 at 4:15 pm
RE: Ask a computer security expert. - by Minimalist - May 27, 2015 at 5:11 pm
RE: Ask a computer security expert. - by Tiberius - May 28, 2015 at 12:10 am
RE: Ask a computer security expert. - by KevinM1 - May 30, 2015 at 6:07 pm
RE: Ask a computer security expert. - by pocaracas - May 30, 2015 at 7:07 pm

Possibly Related Threads...
Thread Author Replies Views Last Post
  Ask a computer security expert (part 2) Tiberius 31 14005 July 18, 2017 at 3:28 pm
Last Post: Edwardo Piet
  Ask a psychiatric/hospital security guard... Bob Kelso 34 9157 September 20, 2015 at 9:27 pm
Last Post: Bob Kelso



Users browsing this thread: 1 Guest(s)