US Treasury says IRS still hasn't fixed vulnerabilities in tax processing systems

By Angela Gunn | Published October 17, 2008, 5:20 PM

Vulnerabilities in two IRS systems -- including the Customer Account Data Engine (CADE) developed to replace all existing tax processing systems at the agency -- were known and repeatedly raised during the nine-year development process but not addressed, according to an in-house report.

A statement from the Treasury Inspector General for Tax Administration (TIGTA), which released the September report publicly on Thursday, says that "Security weaknesses in controls over sensitive data protection, system access, monitoring of system access, and disaster recovery have continued to exist even though key phases of the CADE and the AMS have been deployed. As a result, the IRS is jeopardizing the confidentiality, integrity, and availability of an increasing volume of tax information for millions of taxpayers as these systems are put into operation."

The 29-page report (PDF available here) covers problems with the CADE and with the Account Management Systems (AMS), which employees use to work with data in CADE. Both are core technologies in future buildout of the IRS' computer systems.

The TIGTA report said that the vulnerabilities are such that an intruder could gain access to taxpayer data "with little chance of detection." Moreover, the systems aren't built for big trouble: the report says that in case of emergency, they "could not be recovered effectively and efficiently."

CADE has been in development since 1999 -- two years after the IRS designated security to be a "material weakness" of the agency and promised to do better. The system began processing 1040EZ filings in 2004 and so far this year has handled 28.1 million returns, or about 19.8 of all tax returns filed. It's also the machine working through this year's one-time economic-stimulus payouts. Development, operation and maintenance through 2012 is scheduled to cost over $1 billion.

The three-page, 22-item list of vulnerabilities TIGTA found in seven months of testing is, in that light, a little sad. Among the highlights: security events and unauthorized access to CADE accounts by privileged users (eg, a sysadmin with the urge to browse records, as happened with the Presidential candidates at State Department offices this year) aren't logged; contractors can make changes to configuration settings without notice, approval or security checks; the system can't identify and process all its error codes, leaving it vulnerable to crashes; backups and data shared with other agencies weren't encrypted; there were no procedures for disabling inactive accounts, such as those of former employees.

Most surprisingly, the report said that the system had no protection against malicious code -- in other words, $1 billion did not buy the IRS an antivirus package.

These vulnerabilities, the report charges, were known to the agency during the development process and certainly at the time of accreditation -- the moment when the agency says 'close enough for government work,' takes responsibility for whatever comes after, and flips the switch. "The system owners did not consider the security vulnerabilities to be significant enough either to give an interim authority to operate or delay development," the report said. "We disagree..."

A response from the CIO of the Treasury Department is included at the end of the report. Arthur Gonzalez says that the IRS has "already fixed nearly half of the vulnerabilities outlined in the report prior to publication" and states that the service has 'action plans' in place to address the remainder.

Mr. Gonzalez also notes that the agency's request to have the full contents of the report classified Sensitive But Unclassified -- a term of some controversy in the era of the Homeland Security Act -- were not granted, to the agency's strong objection.

The Office of Audit appears to be less than moved by that response, and with the agency emphasis on continuing existing oversight processes. "As stated in the report, we believe that the existing security vulnerabilities were not caused by process deficiencies," the auditors retort. "Instead, IRS offices did not carry out their responsibilities for ensuring that security weaknesses were corrected before deployment."

Comments

View comments by with a score of at least

Now if we just got rid of the IRS we wouldn't be having this problem :)

Score: 0

|

I second that!!

Score: 0

|

fixing anything pertaining to the federal government is like trying to plug up a black hole in space.

Score: 0

|

The government consistently ranks near or at the bottom for security and upgrade compliance...

Is anyone surprised?

Score: 0

|

You'd have thought that they'd want to spend the money seeing as they spend it willy-nilly on everything else under the sun.

Score: 0

|

Got that right, foxfyre -- and Treasury's even worse than the average. The most recent House Committee of Government Reform report card on federal security shows Treasury pulling an F. The year before, an F again. Between 2003 and 2005 they scored in the D- range, but before that? That's right, F in 2002 and F in 2001, the first year of the report. I mean, it's not the Department of Agriculture's unbroken fail streak, but *really*...

Score: 0

|

Will Firefox beat IE9 to Direct2D rendering?

Just days after Microsoft executives gave conference attendees a peek at a new rendering technology, a Mozilla contributor revealed he's working on the same thing.

AOL's decision to rebrand as Aol. takes a bad brand and makes it worse

The idea behind the social Web is to crowd source before bringing out something new. But not at AOL, which new logo debuted with a cry of "fail!" across the blogosphere and Twittersphere today.

Microsoft's Bob Muglia and Ray Ozzie on Silverlight vs. standards

Bob Muglia: "We're trying to provide people with an environment that has capabilities that you just simply can't do today in the standards-based world."

Uh-oh, netbooks -- not Windows 7 -- will lift 2009 PC sales

Santa may bring a lump of coal to the Windows PC industry this holiday season. Netbook sales will sap PC margins, while weak Windows 7 PC sales could further drive down average selling prices.

Kindle 2 update adds battery life, native PDF reader

Amazon has pushed out an update to the Kindle 2 e-reader that lengthens battery life and adds a native PDF viewer.

Safari on iPhone gets competition from a $1 browser app

Apple likes to say it gives iPhone users a full browsing experience, but a new competitor tries to incorporate more desktop browser features.

Action Replay maker sues Microsoft for Xbox 360 'predatory technological barriers'

Third-party video game accessory maker Datel has filed an antitrust lawsuit against Microsoft over the Xbox 360's recent Dashboard update.

Where there's smoke: Apple warranty stance raises troubling questions

Carmi Levy | Wide Angle Zoom: Smoking can be dangerous not only for your lungs, it appears, but for your Apple hardware warranty.

Microsoft's .NET Micro Framework is now free and open source

The latest version of Microsoft's .NET Micro framework is now in the hands of the FOSS community.

Google's value proposition for Chrome OS: Should we feel insulted?

For a search engine that has direct access to all the world's online history, it appears to have taught Google nothing about selling a machine.

E-book readers will be in short supply this holiday season

E-readers are hot this year, and a lot of compelling new products have been released, but are there enough electrophoretic displays to go around?