Feeds

US govt password security still dismal

Clueless civil servants leave citizens at risk

Providing a secure and efficient Helpdesk

The importance of keeping passwords secret is endlessly reiterated by security firms, banks, and others. Yet US government tax service workers are still to pick up on the message, it seems.

Three in five (60 per cent) US Internal Revenue Service workers readily gave up their user names and agreed to change passwords to ones suggested by government auditors posing as help-desk employees. Only 35 per cent fell for same type of social engineering trick in similar tests on a sample of workers three years ago, while 71 per cent flunked the test in 2001.

Based on the results of the latest audit, the Treasury Department's inspector general concluded: "Employees either do not fully understand security requirements for password protection or do not place a sufficiently high priority on protecting taxpayer data in their day-to-day work."

Workers who flunked the test were asked why they exposed their login credentials to potential hackers. "Some of the notable reasons given were that the employee thought the scenario sounded legitimate and believable, did not think changing his or her password was the same as disclosing the password, or had experienced past computer problems," the report ((pdf) concludes.

Treasury Department auditors recommend that a refresher on password security and the perils of social engineering is administered to tax office workers. Furthermore, workers need to report suspicious requests to IRS computer security personnel for investigation. More internal audits on password security, involving disciplining careless or negligent workers is also needed, the report recommends.

Although attempts to attack the IRS's systems are commonplace, no successful attack has been recorded to date. The report notes that unless password security awareness is improved IRS workers might be exploited as the "weakest link" in facilitating future attacks, aimed at extracting taxpayer information for the purposes of identity theft or other forms of cybercrime. ®

Choosing a cloud hosting partner with confidence

More from The Register

next story
Shellshock: 'Larger scale attack' on its way, warn securo-bods
Not just web servers under threat - though TENS of THOUSANDS have been hit
Apple's new iPhone 6 vulnerable to last year's TouchID fingerprint hack
But unsophisticated thieves need not attempt this trick
PEAK IPV4? Global IPv6 traffic is growing, DDoS dying, says Akamai
First time the cache network has seen drop in use of 32-bit-wide IP addresses
Oracle SHELLSHOCKER - data titan lists unpatchables
Database kingpin lists 32 products that can't be patched (yet) as GNU fixes second vuln
Who.is does the Harlem Shake
Blame it on LOLing XSS terroristas
Researchers tell black hats: 'YOU'RE SOOO PREDICTABLE'
Want to register that domain? We're way ahead of you.
Stunned by Shellshock Bash bug? Patch all you can – or be punished
UK data watchdog rolls up its sleeves, polishes truncheon
prev story

Whitepapers

A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.