Hacker News new | ask | show | jobs
by jtzhou 4035 days ago
Unbelievable that the IRS would have this "Get Transcript" feature readily available via the web without any password, or better two-factor authentication. It's already been taken offline, but was up for a long time.

Will there be punitive lawsuits against the IRS as there were for Target and likely will be for Anthem?

1 comments

I think the hackers were attacking the initial sign-up, not already created accounts. So I don't see how you could use 2FA.