SlideShare a Scribd company logo
1 of 18
Download to read offline
3/8/2016
© 2016 Online Trust Alliance. All Rights Reserved. Updates Visit https://otalliance.org/TaxFraud 1
© 2016 All rights reserved. Online Trust Alliance (OTA) Slide 1
2016 IRS Free e-File
Audit & Honor Roll
Briefing
March 8, 2016
© 2016 All rights reserved. Online Trust Alliance (OTA) Slide 2
Geoff Noakes Flavio Martins Mike Jones Craig Spiezle Jeff Wilbur
Senior Director VP of Operations Dir, Prod Management Exec Dir & President Chairman
Symantec DigiCert Agari Online Trust Alliance Online Trust Alliance
Program Panelists
3/8/2016
© 2016 Online Trust Alliance. All Rights Reserved. Updates Visit https://otalliance.org/TaxFraud 2
© 2016 All rights reserved. Online Trust Alliance (OTA) Slide 3
Mission to enhance online trust and empower users, while
promoting innovation and the vitality of the internet.
• Goal to help educate businesses, policy makers and stakeholders
while developing and advancing best practices and tools to
enhance the protection of users' security, privacy and identity.
• Collaborative public-private partnerships, benchmark reporting,
meaningful self-regulation and data stewardship.
• U.S. based 501(c)(3) tax-exempt charitable organization.
• Global focus & charter.
• Supported by dues, donations and grants.
Who is OTA?
© 2016 All rights reserved. Online Trust Alliance (OTA) Slide 4
Why We Care
• Tax time is “Christmas” for cybercriminals
• Increased precision targeting tax payers
▫ Spoofed & malicious email
▫ Deceptive search ads
▫ Look-a-like domains
▫ Malicious advertising on legitimate web sites
• Account takeovers and ransomware targeting tax providers
and businesses.
• Ongoing attacks targeting IRS & State Agencies
• Decreasing consumer trust
3/8/2016
© 2016 Online Trust Alliance. All Rights Reserved. Updates Visit https://otalliance.org/TaxFraud 3
© 2016 All rights reserved. Online Trust Alliance (OTA) Slide 5
Audit & Honor Roll Objectives
• Promote best practices and provide resources to assist the
public and private sectors to help enhance their security,
data protection and privacy practices.
• Recognize leadership and commitment to best practices
which promote online trust and confidence.
• Offer assistance to the IRS and e-file sites to help improve
their consumer protection, security and privacy practices.
• Assist consumers in making informed decisions about the
security and privacy practices of sites they frequent.
• Shift the discussion from compliance to stewardship.
© 2016 All rights reserved. Online Trust Alliance (OTA) Slide 6
• OTA does not endorse or recommend any e-file service.
• Analysis and methodology is based on global industry
standards for data security and responsible privacy practices in
addition to the IRS’s e-file security mandate.
• Users should review any service provider, banking and
commerce site and consider the practices and policies based
on their “risk appetite.”
• Data may have changed since the audit.
• To date, the Free File Alliance, a trade organization created to
advance the business interests of e-file firms, has yet to
respond to OTA’s offer to review and assist their members.
Disclaimers
3/8/2016
© 2016 Online Trust Alliance. All Rights Reserved. Updates Visit https://otalliance.org/TaxFraud 4
© 2016 All rights reserved. Online Trust Alliance (OTA) Slide 7
Consumer
Protection
PrivacySecurity
Audit & Honor Roll Overview
• Analysis of ~1,000 web sites
▫ FDIC Banking 100
▫ Internet Retailer Top 500
▫ Top 50 Social
▫ Top 50 News/Media
▫ Top 50 Federal Gov’t
▫ OTA Members
▫ Top IoT 50 (Smart Home, Wearables)
▫ 2016 Presidential Candidates (23)
▫ Free e-file Tax Sites (13)
• Scoring
▫ Up to 100 points in each category
▫ Bonus points for emerging practices
▫ Penalty points
 Vulnerabilities, privacy policies, data breach, fines/settlement
▫ Honor Roll = 80% of total points, 55% or better in each category
© 2016 All rights reserved. Online Trust Alliance (OTA) Slide 8
e-file Sites – How They Compare
3/8/2016
© 2016 Online Trust Alliance. All Rights Reserved. Updates Visit https://otalliance.org/TaxFraud 5
© 2016 All rights reserved. Online Trust Alliance (OTA) Slide 9
Honor Roll vs. Failing Grades
E-FILE TAX FILING SERVICES
ONLINE AUDIT RESULTS
Honor Roll Failed
eSmart Tax 1040.com
ezTaxReturn.com 1040Now
FreeTaxUSA FileYourTaxes.com
H&R Block Free Tax Return.com
TaxAct Jackson Hewitt
TaxSlayer OLT On-Line Taxes
TurboTax
© 2016 All rights reserved. Online Trust Alliance (OTA) Slide 10
Comparison of Failure Rates
3/8/2016
© 2016 Online Trust Alliance. All Rights Reserved. Updates Visit https://otalliance.org/TaxFraud 6
© 2016 All rights reserved. Online Trust Alliance (OTA) Slide 11
• 4 sites had no email authentication at all
• 3 sites failed Site Security – old ciphers or lack of current
protocols
Reasons for Failing
© 2016 All rights reserved. Online Trust Alliance (OTA) Slide 12
• Base points
▫ Email authentication
 SPF and DKIM at top-level
and subdomains
▫ DMARC record and policy
▫ DMARC reject/quarantine
• Bonus points
▫ TLS for email
▫ DNSSEC
• Penalty points
▫ Domain locking (not locked )
• Can the app or website be spoofed, fooling a person
to open/download an update, open an attachment or
simply open an email with a drive-by exploit?
• Does the site or app exercise best practice to help
prevent brand-jacking and domain abuse?
Consumer Protection
Consumer
Protection
PrivacySecurity
3/8/2016
© 2016 Online Trust Alliance. All Rights Reserved. Updates Visit https://otalliance.org/TaxFraud 7
© 2016 All rights reserved. Online Trust Alliance (OTA) Slide 13
Why Care?
© 2016 All rights reserved. Online Trust Alliance (OTA) Slide 14
Email Authentication + DMARC
• Authenticates Message Path
• Authorized senders in DNS
SPF DKIM
• Authenticates Message Content
• Public encryption keys in DNS
DMARC
Consistency
A method to
leverage the
best of SPF
and DKIM
Policy
Senders can
declare how to
process
unauthenticated
email
Visibility
Reports on
how receivers
process
received email
Aggregated
Insights
Telemetry into
mail streams
(RUA)
Failure &
Spoofed
email reports
(RUF)
3/8/2016
© 2016 Online Trust Alliance. All Rights Reserved. Updates Visit https://otalliance.org/TaxFraud 8
© 2016 All rights reserved. Online Trust Alliance (OTA) Slide 15
• At lower end of authentication adoption, especially
SPF @ TLD and DKIM – 4 sites had no authentication
• At higher end of DMARC adoption
Consumer Protection Scores
2015/2016 AUDIT RESULTS BY SECTOR
CONSUMER PROTECTION ADOPTION
IR100 FDIC FED SOCIAL NEWS IoT
2016
PRES
E-FILE
SPF (any) 94% 87% 80% 92% 80% 62% 100% 69%
SPF (TLD) 85% 73% 70% 92% 62% 52% 91% 62%
DKIM (any) 93% 68% 50% 78% 64% 30% 100% 62%
DKIM (TLD) 31% 30% 28% 56% 16% 14% 78% 38%
SPF and DKIM 90% 63% 48% 76% 56% 30% 100% 62%
DMARC Record 20% 24% 14% 48% 10% 2% 4% 38%
DMARC (R or Q)* 15% 21% 14% 58% 20% 0% 0% 20%
TLS 42% 38% 38% 36% 14% 24% 57% 31%
DNSSEC 0% 1% 90% 0% 4% 4% 0% 0%
Domain Lock 100% 97% 100% 94% 92% 88% 96% 92%
© 2016 All rights reserved. Online Trust Alliance (OTA) Slide 16
Site Security
• Base points
▫ Server & SSL implementation
▫ Failure of any component =
Failure of Site Security
Consumer
Protection
PrivacySecurity
• Bonus points
▫ EV SSL
▫ Always On SSL (AOSSL)
• Penalty points
▫ XSS / iFrame vulnerabilities
▫ Malware
▫ Malicious links
▫ Bot risk
Best practices to secure data in
transit and collected by websites, and
prevent malicious exploits running
against clients’ devices, including
desktop, mobile and IoT devices
3/8/2016
© 2016 Online Trust Alliance. All Rights Reserved. Updates Visit https://otalliance.org/TaxFraud 9
© 2016 All rights reserved. Online Trust Alliance (OTA) Slide 17
Component Failure = Fail
© 2016 All rights reserved. Online Trust Alliance (OTA) Slide 18
Evolving Threats & Site Issues
3/8/2016
© 2016 Online Trust Alliance. All Rights Reserved. Updates Visit https://otalliance.org/TaxFraud 10
© 2016 All rights reserved. Online Trust Alliance (OTA) Slide 19
EV SSL Certificates
• Extra validation required to obtain certificate
• Provides users with indicator of trust (green browser bar)
• Mandated by IRS for free e-file sites
Internet Explorer
Chrome
Firefox
Steady year-over-year growth
© 2016 All rights reserved. Online Trust Alliance (OTA) Slide 20
2015/2016 AUDIT RESULTS BY SECTOR
SITE SECURITY ADOPTION
IR100 FDIC FED SOCIAL NEWS IoT
2016
PRES
E-FILE
EV SSL 24% 67% 11% 21% 8% 4% 4% 92%
Always On SSL 15% 78% 17% 35% 14% 20% 70% 54%
Web App Firewall 47% 32% 46% 12% 28% 36% 35% 8%
Site Security Scores
• Top adoption of EV SSL (due to IRS mandate).
• Low level of AOSSL adoption compared to leading financial
firms, putting data at risk.
• Lowest adoption of web application firewall.
3/8/2016
© 2016 Online Trust Alliance. All Rights Reserved. Updates Visit https://otalliance.org/TaxFraud 11
© 2016 All rights reserved. Online Trust Alliance (OTA) Slide 21
• Base points
▫ Privacy policy
▫ Third-party trackers on site
▫ Do Not Track disclosure
• Bonus points
▫ Use of Icons
▫ Tag mgmt or privacy solution
▫ Honoring DNT
• Penalty points
▫ WHOIS (if Private vs Public)
▫ Data Breach Incidents
▫ FTC / State Settlements
Best practices providing users
clear notice and control of the
data being collected, tracked and
shared with third parties
Privacy
Consumer
Protection
PrivacySecurity
© 2016 All rights reserved. Online Trust Alliance (OTA) Slide 22
Privacy Practices & Disclosures
• Data mining and sharing of site visitors’ data observed including
“re-targeting” was unexpected and concerning
3/8/2016
© 2016 Online Trust Alliance. All Rights Reserved. Updates Visit https://otalliance.org/TaxFraud 12
© 2016 All rights reserved. Online Trust Alliance (OTA) Slide 23
Privacy – Bonus Points
Layered Notice & Icons
• Publishers Clearing House
http://privacy.pch.com/
• Reduced word count from
over 4,000 words to 475!
• Adds clarity, readability &
transparency
• Added bonus points for icons
© 2016 All rights reserved. Online Trust Alliance (OTA) Slide 24
• Lags many sectors in transparency & discoverability.
• Fail to follow IRS’s lead in offering policies in Spanish.
• While they maintain privacy of the tax return, since the IRS
directs consumers to these sites, it is surprising that many
are collecting site data traffic and sharing it with affiliate
marketing, ad networks, re-targeting and other entities.
• 12 of 13 do not provide any disclosure on honoring
Do-Not-Track, a violation of California law which would lead
to increased failures per the methodology planned for the
June audit.
Privacy Concerns
3/8/2016
© 2016 Online Trust Alliance. All Rights Reserved. Updates Visit https://otalliance.org/TaxFraud 13
© 2016 All rights reserved. Online Trust Alliance (OTA) Slide 25
• Strong following of mandates (with exceptions) for EV SSL,
privacy seal and public domain registration.
• Questionable adherence to use of challenge/response, meant
to prevent auto bot signup/submission.
• Password rules are followed, but OTA (and the White House)
recommends multi-factor authentication.
Audit of IRS Mandates
ADOPTION OF IRS MANDATES
EV SSL 92%
Challenge/Response for Filing* 38%
Privacy Seal 92%
Public Domain Registration 100%
* Tested for account setup/login, not all the way to filing
© 2016 All rights reserved. Online Trust Alliance (OTA) Slide 26
Audit Update
• Outreach has been positive, several sites have addressed
some deficiencies, though oversight remains a concern.
• Email authentication
▫ The 4 sites with no authentication have added SPF records
(though 1 is invalid)
▫ The 3 valid SPF sites have also added DMARC records
▫ The other failing site has made no changes
• Site security
▫ Of the 3 failing sites, one has improved to “A-”, one has no
change, and one has made improvements, but still fails
• EV SSL certificates – Now at 100%
• New vulnerabilities since the audit
3/8/2016
© 2016 Online Trust Alliance. All Rights Reserved. Updates Visit https://otalliance.org/TaxFraud 14
© 2016 All rights reserved. Online Trust Alliance (OTA) Slide 27
© 2016 All rights reserved. Online Trust Alliance (OTA) Slide 28
• Free e-file Tax Site Audit https://otalliance.org/TaxFraud
• 2016 Presidential Candidate Audit
https://otalliance.org/2016Candidates
• IoT Working Group https://otalliance.org/IoT
• Email Integrity & Security https://otalliance.org/eauth
• Public Policy - https://otalliance.org/initiatives/public-policy
• Online Trust Honor Roll - https://otalliance.org/HonorRoll
• Email Integrity Audit – https://otalliance.org/emailaudit
• admin@otalliance.org +1 425-455-7400
Resources
3/8/2016
© 2016 Online Trust Alliance. All Rights Reserved. Updates Visit https://otalliance.org/TaxFraud 15
© 2016 All rights reserved. Online Trust Alliance (OTA) Slide 29
Back Up Slides
© 2016 All rights reserved. Online Trust Alliance (OTA) Slide 30
Email Authentication Basics
Email Authentication
• SPF: Path-based. Sender publishes list of authorized servers.
Email receiver checks if server is authorized to send for domain.
• DKIM: Signature-based. Sender inserts signature into email.
Email receiver checks signature regardless of source.
• DKIM+SPF = Resilient email authentication infrastructure
3/8/2016
© 2016 Online Trust Alliance. All Rights Reserved. Updates Visit https://otalliance.org/TaxFraud 16
© 2016 All rights reserved. Online Trust Alliance (OTA) Slide 31
Transport Layer Security
Rapidly being adopted standard for secure email
• TLS uses Public Key Infrastructure (PKI) to encrypt
messages between mail servers. This encryption makes it
difficult for hackers to intercept and read messages.
• TLS supports the use of digital certificates to authenticate
the receiving servers. Authentication of sending servers is
optional. This process verifies receivers (or senders) are
who they say they are, which helps to prevent spoofing.
https://otalliance.org/best-practices/transport-layered-security-tls-email
https://www.google.com/transparencyreport/saferemail/
© 2016 All rights reserved. Online Trust Alliance (OTA) Slide 32
Always On SSL (AOSSL)
• Helps secure sensitive data, especially for users of public
Wi-Fi hot spots. Counters sidejacking which allows
hackers to intercept cookies (typically used to retain
user-specific information such as username, password
and session data) when they are transmitted without the
protection of SSL encryption.
• https://otalliance.org/resources/always-ssl-aossl
AOSSL – Bonus Points
3/8/2016
© 2016 Online Trust Alliance. All Rights Reserved. Updates Visit https://otalliance.org/TaxFraud 17
© 2016 All rights reserved. Online Trust Alliance (OTA) Slide 33
Privacy Scores
© 2016 All rights reserved. Online Trust Alliance (OTA) Slide 34
Outside the Scope
• If 70% of tax payers qualify for free filing; why do
only 3% take advantage of it?
▫ Discoverability?
▫ Usability?
▫ Free may end up being fee
• Deeper dive in advertising linkages, sharing
• Expanded audit of authorized e-File providers.
3/8/2016
© 2016 Online Trust Alliance. All Rights Reserved. Updates Visit https://otalliance.org/TaxFraud 18
© 2016 All rights reserved. Online Trust Alliance (OTA) Slide 35
OTA Global Collaboration

More Related Content

Viewers also liked

HES2011 - Richard Johnson - A Castle Made of Sand Adobe Reader X Sandbox
HES2011 - Richard Johnson - A Castle Made of Sand Adobe Reader X SandboxHES2011 - Richard Johnson - A Castle Made of Sand Adobe Reader X Sandbox
HES2011 - Richard Johnson - A Castle Made of Sand Adobe Reader X SandboxHackito Ergo Sum
 
Web Application Attack Report (Edition #1 - July 2011)
Web Application Attack Report (Edition #1 - July 2011)Web Application Attack Report (Edition #1 - July 2011)
Web Application Attack Report (Edition #1 - July 2011)Imperva
 
Future strategic-issues-and-warfare
Future strategic-issues-and-warfareFuture strategic-issues-and-warfare
Future strategic-issues-and-warfareDonald Stephen
 
Vocación profesional
Vocación profesionalVocación profesional
Vocación profesionalLeslie Abanto
 
соборность украины
соборность украинысоборность украины
соборность украиныryabich1976
 
The 5 Promises at Siegfried
The 5 Promises at SiegfriedThe 5 Promises at Siegfried
The 5 Promises at SiegfriedKevin Kucharski
 
Assetbasedcommunitydevelopmentpowerpoint 150923173847-lva1-app6891
Assetbasedcommunitydevelopmentpowerpoint 150923173847-lva1-app6891Assetbasedcommunitydevelopmentpowerpoint 150923173847-lva1-app6891
Assetbasedcommunitydevelopmentpowerpoint 150923173847-lva1-app6891Tony Lee
 
Академія Google та наукометричні бази
Академія Google та наукометричні базиАкадемія Google та наукометричні бази
Академія Google та наукометричні базиTatyana Nosenko
 
The Journey to Enterprise PaaS (Cloud Foundry Summit 2014)
The Journey to Enterprise PaaS (Cloud Foundry Summit 2014)The Journey to Enterprise PaaS (Cloud Foundry Summit 2014)
The Journey to Enterprise PaaS (Cloud Foundry Summit 2014)VMware Tanzu
 

Viewers also liked (14)

HES2011 - Richard Johnson - A Castle Made of Sand Adobe Reader X Sandbox
HES2011 - Richard Johnson - A Castle Made of Sand Adobe Reader X SandboxHES2011 - Richard Johnson - A Castle Made of Sand Adobe Reader X Sandbox
HES2011 - Richard Johnson - A Castle Made of Sand Adobe Reader X Sandbox
 
Web Application Attack Report (Edition #1 - July 2011)
Web Application Attack Report (Edition #1 - July 2011)Web Application Attack Report (Edition #1 - July 2011)
Web Application Attack Report (Edition #1 - July 2011)
 
Future strategic-issues-and-warfare
Future strategic-issues-and-warfareFuture strategic-issues-and-warfare
Future strategic-issues-and-warfare
 
Web Application Security 101
Web Application Security 101Web Application Security 101
Web Application Security 101
 
Vocación profesional
Vocación profesionalVocación profesional
Vocación profesional
 
соборность украины
соборность украинысоборность украины
соборность украины
 
The 5 Promises at Siegfried
The 5 Promises at SiegfriedThe 5 Promises at Siegfried
The 5 Promises at Siegfried
 
SC Resume Feb 2016
SC Resume Feb 2016SC Resume Feb 2016
SC Resume Feb 2016
 
Assetbasedcommunitydevelopmentpowerpoint 150923173847-lva1-app6891
Assetbasedcommunitydevelopmentpowerpoint 150923173847-lva1-app6891Assetbasedcommunitydevelopmentpowerpoint 150923173847-lva1-app6891
Assetbasedcommunitydevelopmentpowerpoint 150923173847-lva1-app6891
 
Sistema urbano
Sistema urbanoSistema urbano
Sistema urbano
 
Академія Google та наукометричні бази
Академія Google та наукометричні базиАкадемія Google та наукометричні бази
Академія Google та наукометричні бази
 
Dining etiquette-ppt
Dining etiquette-pptDining etiquette-ppt
Dining etiquette-ppt
 
συμπαν
συμπανσυμπαν
συμπαν
 
The Journey to Enterprise PaaS (Cloud Foundry Summit 2014)
The Journey to Enterprise PaaS (Cloud Foundry Summit 2014)The Journey to Enterprise PaaS (Cloud Foundry Summit 2014)
The Journey to Enterprise PaaS (Cloud Foundry Summit 2014)
 

Similar to IRS Free File Audit & Honor Roll Briefing Highlights Security and Privacy

Creating Trust for the Internet of Things
Creating Trust for the Internet of ThingsCreating Trust for the Internet of Things
Creating Trust for the Internet of ThingsPECB
 
The State of Marketing Technology Today The State of Marketing Technology Today
The State of Marketing Technology Today The State of Marketing Technology Today The State of Marketing Technology Today The State of Marketing Technology Today
The State of Marketing Technology Today The State of Marketing Technology Today Ghostery, Inc.
 
Webinar Deck - Protect Your Users' Online Privacy
Webinar Deck - Protect Your Users' Online Privacy Webinar Deck - Protect Your Users' Online Privacy
Webinar Deck - Protect Your Users' Online Privacy Ensighten
 
Cybercrime - Stealing in the Connected Age
Cybercrime - Stealing in the Connected AgeCybercrime - Stealing in the Connected Age
Cybercrime - Stealing in the Connected Agedlblumen
 
Privacy and the GDPR: How Cloud computing could be your failing
Privacy and the GDPR: How Cloud computing could be your failingPrivacy and the GDPR: How Cloud computing could be your failing
Privacy and the GDPR: How Cloud computing could be your failingIT Governance Ltd
 
Ghostery MCM - May 2016
Ghostery MCM - May 2016Ghostery MCM - May 2016
Ghostery MCM - May 2016Ghostery, Inc.
 
E-commerce Optimization: Using Load Balancing and CDN to Improve Website Perf...
E-commerce Optimization: Using Load Balancing and CDN to Improve Website Perf...E-commerce Optimization: Using Load Balancing and CDN to Improve Website Perf...
E-commerce Optimization: Using Load Balancing and CDN to Improve Website Perf...Imperva Incapsula
 
Using Data Analytics to Find and Deter Procure to Pay Fraud
Using Data Analytics to Find and Deter Procure to Pay FraudUsing Data Analytics to Find and Deter Procure to Pay Fraud
Using Data Analytics to Find and Deter Procure to Pay FraudFraudBusters
 
Implementing and Auditing GDPR Series (9 of 10)
Implementing and Auditing GDPR Series (9 of 10) Implementing and Auditing GDPR Series (9 of 10)
Implementing and Auditing GDPR Series (9 of 10) Jim Kaplan CIA CFE
 
AWS 金融服務概覽與區塊鍊案例分享
AWS 金融服務概覽與區塊鍊案例分享AWS 金融服務概覽與區塊鍊案例分享
AWS 金融服務概覽與區塊鍊案例分享Amazon Web Services
 
A Global Marketer's Guide to Privacy
A Global Marketer's Guide to PrivacyA Global Marketer's Guide to Privacy
A Global Marketer's Guide to PrivacyFLUZO
 
A New Era of Email Deliverability: Tools of 250ok
A New Era of Email Deliverability: Tools of 250okA New Era of Email Deliverability: Tools of 250ok
A New Era of Email Deliverability: Tools of 250okMarketo
 
Quick Response Fraud Detection
Quick Response Fraud DetectionQuick Response Fraud Detection
Quick Response Fraud DetectionFraudBusters
 
Effective General Ledger and Journal Entry Fraud Detection Using Data Analytics
Effective General Ledger and Journal Entry Fraud Detection Using Data AnalyticsEffective General Ledger and Journal Entry Fraud Detection Using Data Analytics
Effective General Ledger and Journal Entry Fraud Detection Using Data AnalyticsFraudBusters
 
Emerging Trends in Information Security and Privacy
Emerging Trends in Information Security and PrivacyEmerging Trends in Information Security and Privacy
Emerging Trends in Information Security and Privacylgcdcpas
 
DV 2016: Making Sense of the Current Legal Landscape
DV 2016: Making Sense of the Current Legal LandscapeDV 2016: Making Sense of the Current Legal Landscape
DV 2016: Making Sense of the Current Legal LandscapeTealium
 
CIO Cloud Summit nyc_backupify
CIO Cloud Summit nyc_backupifyCIO Cloud Summit nyc_backupify
CIO Cloud Summit nyc_backupifyDatto
 
Lag. Crackle. Pause. Keeping Your Unified Communications in Check.
Lag. Crackle. Pause. Keeping Your Unified Communications in Check.Lag. Crackle. Pause. Keeping Your Unified Communications in Check.
Lag. Crackle. Pause. Keeping Your Unified Communications in Check.Zenoss
 
Media-Scanner-for-Data-Protection-Ad-Tags
Media-Scanner-for-Data-Protection-Ad-TagsMedia-Scanner-for-Data-Protection-Ad-Tags
Media-Scanner-for-Data-Protection-Ad-TagsKenan Marks
 

Similar to IRS Free File Audit & Honor Roll Briefing Highlights Security and Privacy (20)

Creating Trust for the Internet of Things
Creating Trust for the Internet of ThingsCreating Trust for the Internet of Things
Creating Trust for the Internet of Things
 
The State of Marketing Technology Today The State of Marketing Technology Today
The State of Marketing Technology Today The State of Marketing Technology Today The State of Marketing Technology Today The State of Marketing Technology Today
The State of Marketing Technology Today The State of Marketing Technology Today
 
Webinar Deck - Protect Your Users' Online Privacy
Webinar Deck - Protect Your Users' Online Privacy Webinar Deck - Protect Your Users' Online Privacy
Webinar Deck - Protect Your Users' Online Privacy
 
Cybercrime - Stealing in the Connected Age
Cybercrime - Stealing in the Connected AgeCybercrime - Stealing in the Connected Age
Cybercrime - Stealing in the Connected Age
 
Privacy and the GDPR: How Cloud computing could be your failing
Privacy and the GDPR: How Cloud computing could be your failingPrivacy and the GDPR: How Cloud computing could be your failing
Privacy and the GDPR: How Cloud computing could be your failing
 
Ghostery MCM - May 2016
Ghostery MCM - May 2016Ghostery MCM - May 2016
Ghostery MCM - May 2016
 
E-commerce Optimization: Using Load Balancing and CDN to Improve Website Perf...
E-commerce Optimization: Using Load Balancing and CDN to Improve Website Perf...E-commerce Optimization: Using Load Balancing and CDN to Improve Website Perf...
E-commerce Optimization: Using Load Balancing and CDN to Improve Website Perf...
 
Using Data Analytics to Find and Deter Procure to Pay Fraud
Using Data Analytics to Find and Deter Procure to Pay FraudUsing Data Analytics to Find and Deter Procure to Pay Fraud
Using Data Analytics to Find and Deter Procure to Pay Fraud
 
Implementing and Auditing GDPR Series (9 of 10)
Implementing and Auditing GDPR Series (9 of 10) Implementing and Auditing GDPR Series (9 of 10)
Implementing and Auditing GDPR Series (9 of 10)
 
AWS 金融服務概覽與區塊鍊案例分享
AWS 金融服務概覽與區塊鍊案例分享AWS 金融服務概覽與區塊鍊案例分享
AWS 金融服務概覽與區塊鍊案例分享
 
A Global Marketer's Guide to Privacy
A Global Marketer's Guide to PrivacyA Global Marketer's Guide to Privacy
A Global Marketer's Guide to Privacy
 
A New Era of Email Deliverability: Tools of 250ok
A New Era of Email Deliverability: Tools of 250okA New Era of Email Deliverability: Tools of 250ok
A New Era of Email Deliverability: Tools of 250ok
 
GDPR Series Session 4
GDPR Series Session 4GDPR Series Session 4
GDPR Series Session 4
 
Quick Response Fraud Detection
Quick Response Fraud DetectionQuick Response Fraud Detection
Quick Response Fraud Detection
 
Effective General Ledger and Journal Entry Fraud Detection Using Data Analytics
Effective General Ledger and Journal Entry Fraud Detection Using Data AnalyticsEffective General Ledger and Journal Entry Fraud Detection Using Data Analytics
Effective General Ledger and Journal Entry Fraud Detection Using Data Analytics
 
Emerging Trends in Information Security and Privacy
Emerging Trends in Information Security and PrivacyEmerging Trends in Information Security and Privacy
Emerging Trends in Information Security and Privacy
 
DV 2016: Making Sense of the Current Legal Landscape
DV 2016: Making Sense of the Current Legal LandscapeDV 2016: Making Sense of the Current Legal Landscape
DV 2016: Making Sense of the Current Legal Landscape
 
CIO Cloud Summit nyc_backupify
CIO Cloud Summit nyc_backupifyCIO Cloud Summit nyc_backupify
CIO Cloud Summit nyc_backupify
 
Lag. Crackle. Pause. Keeping Your Unified Communications in Check.
Lag. Crackle. Pause. Keeping Your Unified Communications in Check.Lag. Crackle. Pause. Keeping Your Unified Communications in Check.
Lag. Crackle. Pause. Keeping Your Unified Communications in Check.
 
Media-Scanner-for-Data-Protection-Ad-Tags
Media-Scanner-for-Data-Protection-Ad-TagsMedia-Scanner-for-Data-Protection-Ad-Tags
Media-Scanner-for-Data-Protection-Ad-Tags
 

More from CASCouncil

100 Percent Encrypted Web New Challenges For TLS RSA Conference 2017
100 Percent Encrypted Web New Challenges For TLS RSA Conference 2017100 Percent Encrypted Web New Challenges For TLS RSA Conference 2017
100 Percent Encrypted Web New Challenges For TLS RSA Conference 2017CASCouncil
 
Six Reasons http Will Become a Thing of the Past
Six Reasons http Will Become a Thing of the PastSix Reasons http Will Become a Thing of the Past
Six Reasons http Will Become a Thing of the PastCASCouncil
 
What Kind of SSL/TLS Certificate Do I Need?
What Kind of SSL/TLS Certificate Do I Need?What Kind of SSL/TLS Certificate Do I Need?
What Kind of SSL/TLS Certificate Do I Need?CASCouncil
 
Payments Security – Vital Information all Payment Processors need to know
Payments Security – Vital Information all Payment Processors need to knowPayments Security – Vital Information all Payment Processors need to know
Payments Security – Vital Information all Payment Processors need to knowCASCouncil
 
TLS Certificates on the Web – The Good, The Bad and The Ugly
TLS Certificates on the Web – The Good, The Bad and The Ugly TLS Certificates on the Web – The Good, The Bad and The Ugly
TLS Certificates on the Web – The Good, The Bad and The Ugly CASCouncil
 
Symantec’s View of the Current State of ECDSA on the Web
Symantec’s View of the Current State of ECDSA on the WebSymantec’s View of the Current State of ECDSA on the Web
Symantec’s View of the Current State of ECDSA on the WebCASCouncil
 
CA/Browser Forum—To effect positive changes to improve internet security
CA/Browser Forum—To effect positive changes to improve internet security  CA/Browser Forum—To effect positive changes to improve internet security
CA/Browser Forum—To effect positive changes to improve internet security CASCouncil
 
Update on the Work of the CA / Browser Forum
Update on the Work of the CA / Browser ForumUpdate on the Work of the CA / Browser Forum
Update on the Work of the CA / Browser ForumCASCouncil
 
Extended Validation Builds Trust
Extended Validation Builds TrustExtended Validation Builds Trust
Extended Validation Builds TrustCASCouncil
 
Heartbleed Bug Vulnerability: Discovery, Impact and Solution
Heartbleed Bug Vulnerability: Discovery, Impact and SolutionHeartbleed Bug Vulnerability: Discovery, Impact and Solution
Heartbleed Bug Vulnerability: Discovery, Impact and SolutionCASCouncil
 
New Ideas on CAA, CT and Public Key Pinning for a Safer Internet
New Ideas on CAA, CT and Public Key Pinning for a Safer InternetNew Ideas on CAA, CT and Public Key Pinning for a Safer Internet
New Ideas on CAA, CT and Public Key Pinning for a Safer InternetCASCouncil
 
Alternatives and Enhancements to CAs for a Secure Web
Alternatives and Enhancements to CAs for a Secure WebAlternatives and Enhancements to CAs for a Secure Web
Alternatives and Enhancements to CAs for a Secure WebCASCouncil
 
Addressing non-FQDNs and new gTLDs in SSL Baseline Requirements
Addressing non-FQDNs and new gTLDs in SSL Baseline Requirements Addressing non-FQDNs and new gTLDs in SSL Baseline Requirements
Addressing non-FQDNs and new gTLDs in SSL Baseline Requirements CASCouncil
 
State of the Web
State of the WebState of the Web
State of the WebCASCouncil
 
Trust Service Providers: Self-Regulatory Processes
Trust Service Providers: Self-Regulatory ProcessesTrust Service Providers: Self-Regulatory Processes
Trust Service Providers: Self-Regulatory ProcessesCASCouncil
 
Certificates, Revocation and the new gTLD's Oh My!
Certificates, Revocation and the new gTLD's Oh My!Certificates, Revocation and the new gTLD's Oh My!
Certificates, Revocation and the new gTLD's Oh My!CASCouncil
 
CAs And The New Paradigm Shift
CAs And The New Paradigm ShiftCAs And The New Paradigm Shift
CAs And The New Paradigm ShiftCASCouncil
 
CA Self Regulation
CA Self RegulationCA Self Regulation
CA Self RegulationCASCouncil
 
New Window of Opportunity
New Window of OpportunityNew Window of Opportunity
New Window of OpportunityCASCouncil
 

More from CASCouncil (20)

100 Percent Encrypted Web New Challenges For TLS RSA Conference 2017
100 Percent Encrypted Web New Challenges For TLS RSA Conference 2017100 Percent Encrypted Web New Challenges For TLS RSA Conference 2017
100 Percent Encrypted Web New Challenges For TLS RSA Conference 2017
 
Six Reasons http Will Become a Thing of the Past
Six Reasons http Will Become a Thing of the PastSix Reasons http Will Become a Thing of the Past
Six Reasons http Will Become a Thing of the Past
 
What Kind of SSL/TLS Certificate Do I Need?
What Kind of SSL/TLS Certificate Do I Need?What Kind of SSL/TLS Certificate Do I Need?
What Kind of SSL/TLS Certificate Do I Need?
 
Payments Security – Vital Information all Payment Processors need to know
Payments Security – Vital Information all Payment Processors need to knowPayments Security – Vital Information all Payment Processors need to know
Payments Security – Vital Information all Payment Processors need to know
 
TLS Certificates on the Web – The Good, The Bad and The Ugly
TLS Certificates on the Web – The Good, The Bad and The Ugly TLS Certificates on the Web – The Good, The Bad and The Ugly
TLS Certificates on the Web – The Good, The Bad and The Ugly
 
Symantec’s View of the Current State of ECDSA on the Web
Symantec’s View of the Current State of ECDSA on the WebSymantec’s View of the Current State of ECDSA on the Web
Symantec’s View of the Current State of ECDSA on the Web
 
CA/Browser Forum—To effect positive changes to improve internet security
CA/Browser Forum—To effect positive changes to improve internet security  CA/Browser Forum—To effect positive changes to improve internet security
CA/Browser Forum—To effect positive changes to improve internet security
 
Update on the Work of the CA / Browser Forum
Update on the Work of the CA / Browser ForumUpdate on the Work of the CA / Browser Forum
Update on the Work of the CA / Browser Forum
 
Extended Validation Builds Trust
Extended Validation Builds TrustExtended Validation Builds Trust
Extended Validation Builds Trust
 
CA Day 2014
CA Day 2014 CA Day 2014
CA Day 2014
 
Heartbleed Bug Vulnerability: Discovery, Impact and Solution
Heartbleed Bug Vulnerability: Discovery, Impact and SolutionHeartbleed Bug Vulnerability: Discovery, Impact and Solution
Heartbleed Bug Vulnerability: Discovery, Impact and Solution
 
New Ideas on CAA, CT and Public Key Pinning for a Safer Internet
New Ideas on CAA, CT and Public Key Pinning for a Safer InternetNew Ideas on CAA, CT and Public Key Pinning for a Safer Internet
New Ideas on CAA, CT and Public Key Pinning for a Safer Internet
 
Alternatives and Enhancements to CAs for a Secure Web
Alternatives and Enhancements to CAs for a Secure WebAlternatives and Enhancements to CAs for a Secure Web
Alternatives and Enhancements to CAs for a Secure Web
 
Addressing non-FQDNs and new gTLDs in SSL Baseline Requirements
Addressing non-FQDNs and new gTLDs in SSL Baseline Requirements Addressing non-FQDNs and new gTLDs in SSL Baseline Requirements
Addressing non-FQDNs and new gTLDs in SSL Baseline Requirements
 
State of the Web
State of the WebState of the Web
State of the Web
 
Trust Service Providers: Self-Regulatory Processes
Trust Service Providers: Self-Regulatory ProcessesTrust Service Providers: Self-Regulatory Processes
Trust Service Providers: Self-Regulatory Processes
 
Certificates, Revocation and the new gTLD's Oh My!
Certificates, Revocation and the new gTLD's Oh My!Certificates, Revocation and the new gTLD's Oh My!
Certificates, Revocation and the new gTLD's Oh My!
 
CAs And The New Paradigm Shift
CAs And The New Paradigm ShiftCAs And The New Paradigm Shift
CAs And The New Paradigm Shift
 
CA Self Regulation
CA Self RegulationCA Self Regulation
CA Self Regulation
 
New Window of Opportunity
New Window of OpportunityNew Window of Opportunity
New Window of Opportunity
 

Recently uploaded

Azure Monitor & Application Insight to monitor Infrastructure & Application
Azure Monitor & Application Insight to monitor Infrastructure & ApplicationAzure Monitor & Application Insight to monitor Infrastructure & Application
Azure Monitor & Application Insight to monitor Infrastructure & ApplicationAndikSusilo4
 
Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...
Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...
Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...HostedbyConfluent
 
Key Features Of Token Development (1).pptx
Key  Features Of Token  Development (1).pptxKey  Features Of Token  Development (1).pptx
Key Features Of Token Development (1).pptxLBM Solutions
 
Swan(sea) Song – personal research during my six years at Swansea ... and bey...
Swan(sea) Song – personal research during my six years at Swansea ... and bey...Swan(sea) Song – personal research during my six years at Swansea ... and bey...
Swan(sea) Song – personal research during my six years at Swansea ... and bey...Alan Dix
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonetsnaman860154
 
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure serviceWhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure servicePooja Nehwal
 
Understanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitectureUnderstanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitecturePixlogix Infotech
 
AI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsAI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsMemoori
 
SIEMENS: RAPUNZEL – A Tale About Knowledge Graph
SIEMENS: RAPUNZEL – A Tale About Knowledge GraphSIEMENS: RAPUNZEL – A Tale About Knowledge Graph
SIEMENS: RAPUNZEL – A Tale About Knowledge GraphNeo4j
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerThousandEyes
 
Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slidespraypatel2
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountPuma Security, LLC
 
Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Allon Mureinik
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024Rafal Los
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreternaman860154
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking MenDelhi Call girls
 
Unblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesUnblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesSinan KOZAK
 
Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for PartnersEnhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for PartnersThousandEyes
 
Pigging Solutions Piggable Sweeping Elbows
Pigging Solutions Piggable Sweeping ElbowsPigging Solutions Piggable Sweeping Elbows
Pigging Solutions Piggable Sweeping ElbowsPigging Solutions
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticscarlostorres15106
 

Recently uploaded (20)

Azure Monitor & Application Insight to monitor Infrastructure & Application
Azure Monitor & Application Insight to monitor Infrastructure & ApplicationAzure Monitor & Application Insight to monitor Infrastructure & Application
Azure Monitor & Application Insight to monitor Infrastructure & Application
 
Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...
Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...
Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...
 
Key Features Of Token Development (1).pptx
Key  Features Of Token  Development (1).pptxKey  Features Of Token  Development (1).pptx
Key Features Of Token Development (1).pptx
 
Swan(sea) Song – personal research during my six years at Swansea ... and bey...
Swan(sea) Song – personal research during my six years at Swansea ... and bey...Swan(sea) Song – personal research during my six years at Swansea ... and bey...
Swan(sea) Song – personal research during my six years at Swansea ... and bey...
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonets
 
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure serviceWhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
 
Understanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitectureUnderstanding the Laravel MVC Architecture
Understanding the Laravel MVC Architecture
 
AI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsAI as an Interface for Commercial Buildings
AI as an Interface for Commercial Buildings
 
SIEMENS: RAPUNZEL – A Tale About Knowledge Graph
SIEMENS: RAPUNZEL – A Tale About Knowledge GraphSIEMENS: RAPUNZEL – A Tale About Knowledge Graph
SIEMENS: RAPUNZEL – A Tale About Knowledge Graph
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slides
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path Mount
 
Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreter
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
 
Unblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesUnblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen Frames
 
Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for PartnersEnhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
 
Pigging Solutions Piggable Sweeping Elbows
Pigging Solutions Piggable Sweeping ElbowsPigging Solutions Piggable Sweeping Elbows
Pigging Solutions Piggable Sweeping Elbows
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
 

IRS Free File Audit & Honor Roll Briefing Highlights Security and Privacy

  • 1. 3/8/2016 © 2016 Online Trust Alliance. All Rights Reserved. Updates Visit https://otalliance.org/TaxFraud 1 © 2016 All rights reserved. Online Trust Alliance (OTA) Slide 1 2016 IRS Free e-File Audit & Honor Roll Briefing March 8, 2016 © 2016 All rights reserved. Online Trust Alliance (OTA) Slide 2 Geoff Noakes Flavio Martins Mike Jones Craig Spiezle Jeff Wilbur Senior Director VP of Operations Dir, Prod Management Exec Dir & President Chairman Symantec DigiCert Agari Online Trust Alliance Online Trust Alliance Program Panelists
  • 2. 3/8/2016 © 2016 Online Trust Alliance. All Rights Reserved. Updates Visit https://otalliance.org/TaxFraud 2 © 2016 All rights reserved. Online Trust Alliance (OTA) Slide 3 Mission to enhance online trust and empower users, while promoting innovation and the vitality of the internet. • Goal to help educate businesses, policy makers and stakeholders while developing and advancing best practices and tools to enhance the protection of users' security, privacy and identity. • Collaborative public-private partnerships, benchmark reporting, meaningful self-regulation and data stewardship. • U.S. based 501(c)(3) tax-exempt charitable organization. • Global focus & charter. • Supported by dues, donations and grants. Who is OTA? © 2016 All rights reserved. Online Trust Alliance (OTA) Slide 4 Why We Care • Tax time is “Christmas” for cybercriminals • Increased precision targeting tax payers ▫ Spoofed & malicious email ▫ Deceptive search ads ▫ Look-a-like domains ▫ Malicious advertising on legitimate web sites • Account takeovers and ransomware targeting tax providers and businesses. • Ongoing attacks targeting IRS & State Agencies • Decreasing consumer trust
  • 3. 3/8/2016 © 2016 Online Trust Alliance. All Rights Reserved. Updates Visit https://otalliance.org/TaxFraud 3 © 2016 All rights reserved. Online Trust Alliance (OTA) Slide 5 Audit & Honor Roll Objectives • Promote best practices and provide resources to assist the public and private sectors to help enhance their security, data protection and privacy practices. • Recognize leadership and commitment to best practices which promote online trust and confidence. • Offer assistance to the IRS and e-file sites to help improve their consumer protection, security and privacy practices. • Assist consumers in making informed decisions about the security and privacy practices of sites they frequent. • Shift the discussion from compliance to stewardship. © 2016 All rights reserved. Online Trust Alliance (OTA) Slide 6 • OTA does not endorse or recommend any e-file service. • Analysis and methodology is based on global industry standards for data security and responsible privacy practices in addition to the IRS’s e-file security mandate. • Users should review any service provider, banking and commerce site and consider the practices and policies based on their “risk appetite.” • Data may have changed since the audit. • To date, the Free File Alliance, a trade organization created to advance the business interests of e-file firms, has yet to respond to OTA’s offer to review and assist their members. Disclaimers
  • 4. 3/8/2016 © 2016 Online Trust Alliance. All Rights Reserved. Updates Visit https://otalliance.org/TaxFraud 4 © 2016 All rights reserved. Online Trust Alliance (OTA) Slide 7 Consumer Protection PrivacySecurity Audit & Honor Roll Overview • Analysis of ~1,000 web sites ▫ FDIC Banking 100 ▫ Internet Retailer Top 500 ▫ Top 50 Social ▫ Top 50 News/Media ▫ Top 50 Federal Gov’t ▫ OTA Members ▫ Top IoT 50 (Smart Home, Wearables) ▫ 2016 Presidential Candidates (23) ▫ Free e-file Tax Sites (13) • Scoring ▫ Up to 100 points in each category ▫ Bonus points for emerging practices ▫ Penalty points  Vulnerabilities, privacy policies, data breach, fines/settlement ▫ Honor Roll = 80% of total points, 55% or better in each category © 2016 All rights reserved. Online Trust Alliance (OTA) Slide 8 e-file Sites – How They Compare
  • 5. 3/8/2016 © 2016 Online Trust Alliance. All Rights Reserved. Updates Visit https://otalliance.org/TaxFraud 5 © 2016 All rights reserved. Online Trust Alliance (OTA) Slide 9 Honor Roll vs. Failing Grades E-FILE TAX FILING SERVICES ONLINE AUDIT RESULTS Honor Roll Failed eSmart Tax 1040.com ezTaxReturn.com 1040Now FreeTaxUSA FileYourTaxes.com H&R Block Free Tax Return.com TaxAct Jackson Hewitt TaxSlayer OLT On-Line Taxes TurboTax © 2016 All rights reserved. Online Trust Alliance (OTA) Slide 10 Comparison of Failure Rates
  • 6. 3/8/2016 © 2016 Online Trust Alliance. All Rights Reserved. Updates Visit https://otalliance.org/TaxFraud 6 © 2016 All rights reserved. Online Trust Alliance (OTA) Slide 11 • 4 sites had no email authentication at all • 3 sites failed Site Security – old ciphers or lack of current protocols Reasons for Failing © 2016 All rights reserved. Online Trust Alliance (OTA) Slide 12 • Base points ▫ Email authentication  SPF and DKIM at top-level and subdomains ▫ DMARC record and policy ▫ DMARC reject/quarantine • Bonus points ▫ TLS for email ▫ DNSSEC • Penalty points ▫ Domain locking (not locked ) • Can the app or website be spoofed, fooling a person to open/download an update, open an attachment or simply open an email with a drive-by exploit? • Does the site or app exercise best practice to help prevent brand-jacking and domain abuse? Consumer Protection Consumer Protection PrivacySecurity
  • 7. 3/8/2016 © 2016 Online Trust Alliance. All Rights Reserved. Updates Visit https://otalliance.org/TaxFraud 7 © 2016 All rights reserved. Online Trust Alliance (OTA) Slide 13 Why Care? © 2016 All rights reserved. Online Trust Alliance (OTA) Slide 14 Email Authentication + DMARC • Authenticates Message Path • Authorized senders in DNS SPF DKIM • Authenticates Message Content • Public encryption keys in DNS DMARC Consistency A method to leverage the best of SPF and DKIM Policy Senders can declare how to process unauthenticated email Visibility Reports on how receivers process received email Aggregated Insights Telemetry into mail streams (RUA) Failure & Spoofed email reports (RUF)
  • 8. 3/8/2016 © 2016 Online Trust Alliance. All Rights Reserved. Updates Visit https://otalliance.org/TaxFraud 8 © 2016 All rights reserved. Online Trust Alliance (OTA) Slide 15 • At lower end of authentication adoption, especially SPF @ TLD and DKIM – 4 sites had no authentication • At higher end of DMARC adoption Consumer Protection Scores 2015/2016 AUDIT RESULTS BY SECTOR CONSUMER PROTECTION ADOPTION IR100 FDIC FED SOCIAL NEWS IoT 2016 PRES E-FILE SPF (any) 94% 87% 80% 92% 80% 62% 100% 69% SPF (TLD) 85% 73% 70% 92% 62% 52% 91% 62% DKIM (any) 93% 68% 50% 78% 64% 30% 100% 62% DKIM (TLD) 31% 30% 28% 56% 16% 14% 78% 38% SPF and DKIM 90% 63% 48% 76% 56% 30% 100% 62% DMARC Record 20% 24% 14% 48% 10% 2% 4% 38% DMARC (R or Q)* 15% 21% 14% 58% 20% 0% 0% 20% TLS 42% 38% 38% 36% 14% 24% 57% 31% DNSSEC 0% 1% 90% 0% 4% 4% 0% 0% Domain Lock 100% 97% 100% 94% 92% 88% 96% 92% © 2016 All rights reserved. Online Trust Alliance (OTA) Slide 16 Site Security • Base points ▫ Server & SSL implementation ▫ Failure of any component = Failure of Site Security Consumer Protection PrivacySecurity • Bonus points ▫ EV SSL ▫ Always On SSL (AOSSL) • Penalty points ▫ XSS / iFrame vulnerabilities ▫ Malware ▫ Malicious links ▫ Bot risk Best practices to secure data in transit and collected by websites, and prevent malicious exploits running against clients’ devices, including desktop, mobile and IoT devices
  • 9. 3/8/2016 © 2016 Online Trust Alliance. All Rights Reserved. Updates Visit https://otalliance.org/TaxFraud 9 © 2016 All rights reserved. Online Trust Alliance (OTA) Slide 17 Component Failure = Fail © 2016 All rights reserved. Online Trust Alliance (OTA) Slide 18 Evolving Threats & Site Issues
  • 10. 3/8/2016 © 2016 Online Trust Alliance. All Rights Reserved. Updates Visit https://otalliance.org/TaxFraud 10 © 2016 All rights reserved. Online Trust Alliance (OTA) Slide 19 EV SSL Certificates • Extra validation required to obtain certificate • Provides users with indicator of trust (green browser bar) • Mandated by IRS for free e-file sites Internet Explorer Chrome Firefox Steady year-over-year growth © 2016 All rights reserved. Online Trust Alliance (OTA) Slide 20 2015/2016 AUDIT RESULTS BY SECTOR SITE SECURITY ADOPTION IR100 FDIC FED SOCIAL NEWS IoT 2016 PRES E-FILE EV SSL 24% 67% 11% 21% 8% 4% 4% 92% Always On SSL 15% 78% 17% 35% 14% 20% 70% 54% Web App Firewall 47% 32% 46% 12% 28% 36% 35% 8% Site Security Scores • Top adoption of EV SSL (due to IRS mandate). • Low level of AOSSL adoption compared to leading financial firms, putting data at risk. • Lowest adoption of web application firewall.
  • 11. 3/8/2016 © 2016 Online Trust Alliance. All Rights Reserved. Updates Visit https://otalliance.org/TaxFraud 11 © 2016 All rights reserved. Online Trust Alliance (OTA) Slide 21 • Base points ▫ Privacy policy ▫ Third-party trackers on site ▫ Do Not Track disclosure • Bonus points ▫ Use of Icons ▫ Tag mgmt or privacy solution ▫ Honoring DNT • Penalty points ▫ WHOIS (if Private vs Public) ▫ Data Breach Incidents ▫ FTC / State Settlements Best practices providing users clear notice and control of the data being collected, tracked and shared with third parties Privacy Consumer Protection PrivacySecurity © 2016 All rights reserved. Online Trust Alliance (OTA) Slide 22 Privacy Practices & Disclosures • Data mining and sharing of site visitors’ data observed including “re-targeting” was unexpected and concerning
  • 12. 3/8/2016 © 2016 Online Trust Alliance. All Rights Reserved. Updates Visit https://otalliance.org/TaxFraud 12 © 2016 All rights reserved. Online Trust Alliance (OTA) Slide 23 Privacy – Bonus Points Layered Notice & Icons • Publishers Clearing House http://privacy.pch.com/ • Reduced word count from over 4,000 words to 475! • Adds clarity, readability & transparency • Added bonus points for icons © 2016 All rights reserved. Online Trust Alliance (OTA) Slide 24 • Lags many sectors in transparency & discoverability. • Fail to follow IRS’s lead in offering policies in Spanish. • While they maintain privacy of the tax return, since the IRS directs consumers to these sites, it is surprising that many are collecting site data traffic and sharing it with affiliate marketing, ad networks, re-targeting and other entities. • 12 of 13 do not provide any disclosure on honoring Do-Not-Track, a violation of California law which would lead to increased failures per the methodology planned for the June audit. Privacy Concerns
  • 13. 3/8/2016 © 2016 Online Trust Alliance. All Rights Reserved. Updates Visit https://otalliance.org/TaxFraud 13 © 2016 All rights reserved. Online Trust Alliance (OTA) Slide 25 • Strong following of mandates (with exceptions) for EV SSL, privacy seal and public domain registration. • Questionable adherence to use of challenge/response, meant to prevent auto bot signup/submission. • Password rules are followed, but OTA (and the White House) recommends multi-factor authentication. Audit of IRS Mandates ADOPTION OF IRS MANDATES EV SSL 92% Challenge/Response for Filing* 38% Privacy Seal 92% Public Domain Registration 100% * Tested for account setup/login, not all the way to filing © 2016 All rights reserved. Online Trust Alliance (OTA) Slide 26 Audit Update • Outreach has been positive, several sites have addressed some deficiencies, though oversight remains a concern. • Email authentication ▫ The 4 sites with no authentication have added SPF records (though 1 is invalid) ▫ The 3 valid SPF sites have also added DMARC records ▫ The other failing site has made no changes • Site security ▫ Of the 3 failing sites, one has improved to “A-”, one has no change, and one has made improvements, but still fails • EV SSL certificates – Now at 100% • New vulnerabilities since the audit
  • 14. 3/8/2016 © 2016 Online Trust Alliance. All Rights Reserved. Updates Visit https://otalliance.org/TaxFraud 14 © 2016 All rights reserved. Online Trust Alliance (OTA) Slide 27 © 2016 All rights reserved. Online Trust Alliance (OTA) Slide 28 • Free e-file Tax Site Audit https://otalliance.org/TaxFraud • 2016 Presidential Candidate Audit https://otalliance.org/2016Candidates • IoT Working Group https://otalliance.org/IoT • Email Integrity & Security https://otalliance.org/eauth • Public Policy - https://otalliance.org/initiatives/public-policy • Online Trust Honor Roll - https://otalliance.org/HonorRoll • Email Integrity Audit – https://otalliance.org/emailaudit • admin@otalliance.org +1 425-455-7400 Resources
  • 15. 3/8/2016 © 2016 Online Trust Alliance. All Rights Reserved. Updates Visit https://otalliance.org/TaxFraud 15 © 2016 All rights reserved. Online Trust Alliance (OTA) Slide 29 Back Up Slides © 2016 All rights reserved. Online Trust Alliance (OTA) Slide 30 Email Authentication Basics Email Authentication • SPF: Path-based. Sender publishes list of authorized servers. Email receiver checks if server is authorized to send for domain. • DKIM: Signature-based. Sender inserts signature into email. Email receiver checks signature regardless of source. • DKIM+SPF = Resilient email authentication infrastructure
  • 16. 3/8/2016 © 2016 Online Trust Alliance. All Rights Reserved. Updates Visit https://otalliance.org/TaxFraud 16 © 2016 All rights reserved. Online Trust Alliance (OTA) Slide 31 Transport Layer Security Rapidly being adopted standard for secure email • TLS uses Public Key Infrastructure (PKI) to encrypt messages between mail servers. This encryption makes it difficult for hackers to intercept and read messages. • TLS supports the use of digital certificates to authenticate the receiving servers. Authentication of sending servers is optional. This process verifies receivers (or senders) are who they say they are, which helps to prevent spoofing. https://otalliance.org/best-practices/transport-layered-security-tls-email https://www.google.com/transparencyreport/saferemail/ © 2016 All rights reserved. Online Trust Alliance (OTA) Slide 32 Always On SSL (AOSSL) • Helps secure sensitive data, especially for users of public Wi-Fi hot spots. Counters sidejacking which allows hackers to intercept cookies (typically used to retain user-specific information such as username, password and session data) when they are transmitted without the protection of SSL encryption. • https://otalliance.org/resources/always-ssl-aossl AOSSL – Bonus Points
  • 17. 3/8/2016 © 2016 Online Trust Alliance. All Rights Reserved. Updates Visit https://otalliance.org/TaxFraud 17 © 2016 All rights reserved. Online Trust Alliance (OTA) Slide 33 Privacy Scores © 2016 All rights reserved. Online Trust Alliance (OTA) Slide 34 Outside the Scope • If 70% of tax payers qualify for free filing; why do only 3% take advantage of it? ▫ Discoverability? ▫ Usability? ▫ Free may end up being fee • Deeper dive in advertising linkages, sharing • Expanded audit of authorized e-File providers.
  • 18. 3/8/2016 © 2016 Online Trust Alliance. All Rights Reserved. Updates Visit https://otalliance.org/TaxFraud 18 © 2016 All rights reserved. Online Trust Alliance (OTA) Slide 35 OTA Global Collaboration