Archive for April, 2007

Filing your taxes online?

Thursday, April 5th, 2007

The Motley Fool has a nice blog post on issues involved in electronic filing of tax returns.

There are a couple of important points to be made here. First of all…

  • The IRS has all your information and it will be in digital format (accessible by computer);
  • You are exposed to some points of vulnerability when filing electronically, rather than on paper;
  • The information on your PC is vulnerable to theft (whether you send it electronically or just use tax software);
  • Your information is vulnerable on the Internet-accessible servers to which you upload your data; but
  • On the flip side of the coin, paper returns are subject to loss, theft and mishandling as well, both in transit and within the IRS.

It is somewhat similar to using a credit card. You can risk online theft when conducting an e-commerce transaction, or real-world theft when handing over your card to a minimum wage worker over a store counter. Risks exist both ways.

At this time I think the jury is out on which is safer, but, for the record, I file electronically.

More news on Wireless Insecurity

Thursday, April 5th, 2007

I was just sent a link to an improved attack on WEP for WiFi. WEP (Wired Equivalent Privacy) is no such thing. Erik Tews, Andrei Pychkine and Ralf-Philipp Weinmann at the technical university Darmstadt in Germany have a paper and proof of concept implementation of an improved attack on WEP. This attack should be able to compromise WEP security in under a minute under normal conditions with an inexpensive laptop.

In reality over half of deployed wireless nodes have no security enabled at all, so WEP is certainly an improvement on that. A much better solution exists called WPA. It is available on almost all WiFi devices, and should be used wherever possible. While WPA is not perfect, there are no efficient attacks against WPA, however experts are still not confident in its security. If you have a high security application, stick with a wire, and/or use a strong VPN within the WiFI connection. I am a belt and suspenders kind of guy, so I like to use multiple layers of security whenever possible.