Half of Free E-File Services Don’t Protect Consumers Enough: Audit


document.createElement(‘aside’);



Accounting Today News

http://www.accountingtoday.com

Print

Email

Reprints


 

Six of 13 IRS-approved free e-filing services Web sites failed in taking steps to help protect consumers from fraudulent and malicious e-mail, according to a recent audit.

The Online Trust Alliance’s 2016 IRS Free E-File Audit Honor Roll report evaluates the privacy, security and consumer protection practices of the sites by assessing nearly 50 criteria, standards and internationally accepted privacy practices. The sites that performed specifically well received the honor roll status.

The OTA evaluated the IRS-approved e-filing sites using both its industry-developed methodology and the IRS’s security and privacy mandated standards. Seven sites scored high in all areas of the audit, five failed due to poor consumer protection, and three failed for their site security. Most failing sites did not properly authenticate e-mail addresses, which leaves consumers open to spear phishing and malicious e-mail scams, OTA said.

Based on the IRS security mandates for these tax providers announced in 2010 and updated in 2015, one provider was out of compliance for failing to adopt extended validation SSL certificates, safeguards for assuring a Web site owner’s identity to help prevent spoofing and fraud. Other providers were out of compliance for failing to provide adequate third-party audits of their privacy policy and Web activities, implement anti-botnet protection for fraudulent account signups, and regularly scan their sites for SSL vulnerabilities.

The OTA has been in contact with the IRS regarding the findings. “The failure rate of over one-third should concern customers and the IRS,” said OTA executive director and president Craig Spiezle.

Be the first to comment on this post using the section below.

‘);
var $text = $(”).text(text);
var $meta = $(”);

var $newComment = $comment.append($text).append($meta);
if ($(‘.no-comments’).length) {
$(‘.no-comments’).after($(”).append($newComment));
$(‘.no-comments’).remove();
} else {
$(‘#comments-box .comment’).last().after($newComment);
}

$(‘.comments-count’).each(function(){
$(this).text(+$(this).text()+1);
});
}

function ajaxBusyTest() {
buttonOff();
setTimeout(buttonOn, 3000);
}

var commentOptions = {
client_id: ‘webcpa_news’,
story_id: ‘77308’,
user_id: ”,
comment_message: ” // textarea or NOCOMMENT
};

function postComment(options, callback, doButtonOff) {
callback = callback || function(){};
doButtonOff = typeof doButtonOff === ‘undefined’ ? true : doButtonOff;

var opts = $.extend(true, {}, commentOptions);
$.extend(true, opts, options);

if (doButtonOff) buttonOff();

$.ajax({
type:”POST”,
url: ‘/apps/custom/ajax_post_comment.php’,
data: opts,
success: function(data) {
callback($.parseJSON(data));
if (doButtonOff) buttonOn();
}
});
};

function showNotification(message) {
$.fancybox(message+’

Return to article.’);
};

$.fn.extend({
charWarden: function (outSelector, limit) {
return this.each(function(){
var $this = $(this);
var $out = $(outSelector);
var _limit = limit;
var _chars = 0;
function handler(e) {
_chars = e.target.value.length;
var left = _limit – _chars;
if (left = (page-1)*listCount i 3 (page (pageCount -2)) {
showMin = pageCount – 4;
if (showMin ‘;
if (page 1) {text += ‘

  • «
  • ‹
  • ‘;}
    while (count ‘ + count + ”;
    if (showMax != count) {
    text += ‘ | ‘;
    }
    text += ”;
    count++;
    }
    if (page ›

  • »
  • ‘;}
    text += ”;
    $(pagination).html(text);
    }
    function scrollToTop(){
    $(‘html, body’).animate({
    scrollTop: parseInt($(“#comments”).offset().top)
    }, 700);
    }
    showPage(page);
    if (pageCount 1){
    buildPagination(page,pageCount);
    $(pagination+” li.arrow_double_right a”).live(‘click’,function(){
    page = pageCount;
    showPage(page);
    buildPagination(page,pageCount);
    scrollToTop();
    });
    $(pagination+” li.arrow_right a”).live(‘click’,function(){
    showPage(++page);
    buildPagination(page,pageCount);
    scrollToTop();
    });
    $(pagination+” li.numbers a”).live(‘click’,function(){
    page = $(this).data(‘number’);
    //console.log(“pageCount: “+pageCount+” page: “+page);
    showPage(page);
    buildPagination(page,pageCount);
    scrollToTop();
    });
    $(pagination+” li.arrow_left a”).live(‘click’,function(){
    showPage(–page);
    buildPagination(page,pageCount);
    scrollToTop();
    });
    $(pagination+” li.arrow_double_left a”).live(‘click’,function(){
    page = 1;
    showPage(page);
    buildPagination(page,pageCount);
    scrollToTop();
    });
    }
    }

    $(function(){ // DOM ready
    paginateComments();
    $(‘.scroll-into-view’).each(function(i){if (i == 0) this.scrollIntoView();});

    $(‘.reset-form’).click(function(e){
    e.preventDefault();
    this.form.reset();
    });

    $(‘#comment_message’).charWarden(‘#chars-remaining’, 4096);

    $(‘.comment-notify’).click(function(e) {
    e.preventDefault();
    var options = {
    comment_notify: ‘TRUE’,
    comment_message: ‘NOCOMMENT’
    };
    var notification = function(data) {
    if (data.success) {
    $(‘.not-following’).hide();
    $(‘.following’).show();
    showNotification(data.success);
    } else if (data.error) {
    showNotification(data.error);
    }
    };
    postComment(options, notification);
    });

    $(‘#wrapperForm’).on(‘submit’, function(e) {
    e.preventDefault();
    var options = {
    comment_notify: $(‘#comment_notify’).prop(‘checked’) ? ‘TRUE’ : ”,
    comment_message: $(‘#comment_message’).val()
    };
    var notification = function(data) {
    if (data.success) {
    if ($(‘#comment_notify:checked’).length) {
    $(‘.not-following’).hide();
    $(‘.following’).show();
    }
    document.wrapperForm.reset();
    addPostOptimistically(options.comment_message);
    $(‘#comment_message’).change();
    } else if (data.error) {
    showNotification(data.error);
    }
    };
    postComment(options, notification);
    });

    $(‘a.username’).fancybox({
    ‘hideOnOverlayClick’: false,
    ‘centerOnScroll’ : true,
    ‘autoScale’ : false,
    ‘autoDimensions’ : false,
    ‘width’: 435,
    ‘height’: 205,
    ‘onClosed’: function() {
    if ($(‘#do-refresh’).length) location.reload();
    }
    });
    }); // end DOM ready
    })(jQuery);