Some CRA Accounts Have Been Breached . . . | Page 2 | General financial discussion | Discussion forum

Please consider registering
guest

sp_LogInOut Log In sp_Registration Register

Register | Lost password?
Advanced Search

— Forum Scope —




— Match —





— Forum Options —





Minimum search word length is 3 characters - maximum search word length is 84 characters

No permission to create posts
sp_Feed Topic RSS sp_TopicIcon
Some CRA Accounts Have Been Breached . . .
August 18, 2020
5:49 pm
Patch002
Member
Members
Forum Posts: 82
Member Since:
October 27, 2018
sp_UserOfflineSmall Offline

A couple of weeks ago I was ranting about CRA's MyAccount and sign-in partner.

https://www.highinterestsavings.ca/forum/general-financial-discussion/cra-myaccount-security/

Now this breach occurred. However, the more that I read about it, the more that I believe that CRA could have had adequate security but for whatever reason did not. i.e. 2-step verification, Recaptcha option (for preventing 'bots).

In practice, every website that you have an account with has your particular password recorded (this is logical otherwise you couldn't access the website). When (not if) the entity is breached, the criminals stole your userid (which many times is your email address) and, you have to assume, your password. This is why when the breach is reported, the customer is always asked to change his/her password asap.

Folks, you have to assume that every password you have with account with an entity will one day be stolen. With that in mind, create a different password for each application.

I know that they say to change your passwords every 90 days. How about change your passwords every time that a "breach" is reported (this is probably about the same frequency).

I am not a security expert, I am an accountant who has taken auditing courses over 30 years ago. I know an internal control "weakness" when I see it. I am surprised that these IT professionals could not see it.

August 19, 2020
6:15 am
davidgeorge
Member
Members
Forum Posts: 335
Member Since:
May 20, 2016
sp_UserOfflineSmall Offline

The CRA "My Account" is still not working as of now. The government IT service is terrible!

I logged into my account using "CRA Login" after clicking "each image containing a truck" (CRA added this security measure) and answering a security question. But, when I clicked "Next" to get into my account details, there was an error message.

August 19, 2020
7:03 am
savemoresaveoften
Member
Members
Forum Posts: 2994
Member Since:
March 30, 2017
sp_UserOfflineSmall Offline

Patch002 said
A couple of weeks ago I was ranting about CRA's MyAccount and sign-in partner.

https://www.highinterestsavings.ca/forum/general-financial-discussion/cra-myaccount-security/

Now this breach occurred. However, the more that I read about it, the more that I believe that CRA could have had adequate security but for whatever reason did not. i.e. 2-step verification, Recaptcha option (for preventing 'bots).

In practice, every website that you have an account with has your particular password recorded (this is logical otherwise you couldn't access the website). When (not if) the entity is breached, the criminals stole your userid (which many times is your email address) and, you have to assume, your password. This is why when the breach is reported, the customer is always asked to change his/her password asap.

Folks, you have to assume that every password you have with account with an entity will one day be stolen. With that in mind, create a different password for each application.

I know that they say to change your passwords every 90 days. How about change your passwords every time that a "breach" is reported (this is probably about the same frequency).

I am not a security expert, I am an accountant who has taken auditing courses over 30 years ago. I know an internal control "weakness" when I see it. I am surprised that these IT professionals could not see it.  

I second all website that contains financial info etc should have 2-step verification in place, that should be a requirement.

August 19, 2020
9:54 am
Dean
Valhalla Mountains, British Columbia
Member
Members
Forum Posts: 2158
Member Since:
January 12, 2019
sp_UserOfflineSmall Offline

Dean said
.
UPDATE ... The CRA expects their site to be available again by 'Wednesday'.

Source ➡ https://www.bnnbloomberg.ca/cra-expects-online-services-back-wednesday-following-breaches-1.1480865

    Dean

  

Well here we are at 'Wednesday' ... and it's Still not available ❗ sf-confused

    Dean

sf-cool " Live Long, Healthy ... And Prosper! " sf-cool

August 19, 2020
10:08 am
AltaRed
BC Interior
Member
Members
Forum Posts: 3143
Member Since:
October 27, 2013
sp_UserOfflineSmall Offline

Would rather it take CRA all week to do it right than to rush it.

August 19, 2020
10:20 am
Dean
Valhalla Mountains, British Columbia
Member
Members
Forum Posts: 2158
Member Since:
January 12, 2019
sp_UserOfflineSmall Offline

AltaRed said

Would rather it take CRA all week to do it right than to rush it.  

I wouldn't worry ... unless they're owed money, the CRA are Masters at moving slowly.

Who knows ... maybe they meant 'Next' Wednesday ... LOL sf-laugh

    Dean

sf-cool " Live Long, Healthy ... And Prosper! " sf-cool

August 19, 2020
10:22 am
AltaRed
BC Interior
Member
Members
Forum Posts: 3143
Member Since:
October 27, 2013
sp_UserOfflineSmall Offline

AFAIK, there are no income tax related payments due to CRA until end of September.

August 19, 2020
10:32 am
Kidd
Member
Banned
Forum Posts: 840
Member Since:
February 27, 2018
sp_UserOfflineSmall Offline

I just received my tax installment bill for sept 15th and dec 15th.

To all the freeloaders riding ON the wagon, you're welcome.

August 19, 2020
11:00 am
JenE
Member
Members
Forum Posts: 417
Member Since:
May 24, 2016
sp_UserOfflineSmall Offline

Don’t feel bad, Kidd, many, many people probably wish they were earning enough to have to pay that amount of taxes. A friend of mine complains that she earns too much to take advantage of OAS. You may have a good idea of what I say to her.sf-surprised

August 19, 2020
12:04 pm
Bill
Member
Members
Forum Posts: 4024
Member Since:
September 11, 2013
sp_UserOfflineSmall Offline

Not sure why CRA current bills are showing instalments due Sept 15 when no tax payments are due until Sept 30.

August 19, 2020
1:06 pm
pwm
Headingley MB
Member
Members
Forum Posts: 110
Member Since:
October 21, 2018
sp_UserOfflineSmall Offline

"To all the freeloaders riding ON the wagon, you're welcome."

Saying "your welcome" implies that they thanked you for your payment KIDD. Unfortunately it's exactly the opposite. Instead of being thankful for the generous government benefits that you and I pay for, they resent us because we were successful and they were not. BTW, I've got you beat as I will be paying $17,506 at the end of September. That's a total of April's payment on filing and 3 installment payments for me and my wife that I've held off on and my installments are a lot more than yours.

Classic example is my wife's sister. She pays no income tax at all, and gets the GIS, the Ontario Trillium Benefit and the HST refund, but complains that the government doesn't do anything for seniors. She has no idea how much she is benefiting and she was a teacher for 30 years.

August 19, 2020
1:29 pm
AltaRed
BC Interior
Member
Members
Forum Posts: 3143
Member Since:
October 27, 2013
sp_UserOfflineSmall Offline

Bill said
Not sure why CRA current bills are showing instalments due Sept 15 when no tax payments are due until Sept 30.  

The installment letter in the Default option starts off with saying payment for June 15th and Sept 15th is not due until Sept 30th. Installment dates are fixed but payment dates have been deferred. What is not clear about that?

August 19, 2020
1:33 pm
Oscar
Member
Members
Forum Posts: 290
Member Since:
October 17, 2018
sp_UserOfflineSmall Offline

pwm said
"To all the freeloaders riding ON the wagon, you're welcome."

Saying "your welcome" implies that they thanked you for your payment KIDD. Unfortunately it's exactly the opposite. Instead of being thankful for the generous government benefits that you and I pay for, they resent us because we were successful and they were not. BTW, I've got you beat as I will be paying $17,506 at the end of September. That's a total of April's payment on filing and 3 installment payments for me and my wife that I've held off on and my installments are a lot more than yours.

Classic example is my wife's sister. She pays no income tax at all, and gets the GIS, the Ontario Trillium Benefit and the HST refund, but complains that the government doesn't do anything for seniors. She has no idea how much she is benefiting and she was a teacher for 30 years.  

Teacher for 30 years with no pension ? What's her secret ?

August 19, 2020
1:35 pm
JenE
Member
Members
Forum Posts: 417
Member Since:
May 24, 2016
sp_UserOfflineSmall Offline

pmw - doesn’t your sister-in-law receive a pension from her teaching job? How is she able to get all the benefits you listed? Even so, personally, I’d rather not qualify for them, preferring to earn enough to stand on my own two feet.

August 19, 2020
1:52 pm
pwm
Headingley MB
Member
Members
Forum Posts: 110
Member Since:
October 21, 2018
sp_UserOfflineSmall Offline

Teacher for 30 years with no pension ?

Unscrupulous investment advisors from CI convinced her to take the commuted value of her pension and invest it with them. Also they sold her an unreasonable amount of inappropriate life insurance. That's the answer in a nutshell.

August 19, 2020
2:34 pm
Dean
Valhalla Mountains, British Columbia
Member
Members
Forum Posts: 2158
Member Since:
January 12, 2019
sp_UserOfflineSmall Offline

AltaRed said

Would rather it take CRA all week to do it right than to rush it.  

Dean said

I wouldn't worry ... unless they're owed money, the CRA are Masters at moving slowly.

Who knows ... maybe they meant 'Next' Wednesday ... LOL sf-laugh

    Dean

  

And here's a Very Good example of just how 'Slow' the CRA can be ... and one of the Main reasons they're 'In The Fix', they're in today . . .

Today's CTV News article https://www.ctvnews.ca/canada/cra-cyberattack-victims-say-they-notified-agency-about-hack-long-before-breaches-confirmed-1.5070362
.

    Dean

sf-cool " Live Long, Healthy ... And Prosper! " sf-cool

August 19, 2020
4:28 pm
Alexandre
Member
Members
Forum Posts: 1232
Member Since:
November 8, 2018
sp_UserOfflineSmall Offline

pwm said
"To all the freeloaders riding ON the wagon, you're welcome."

Saying "your welcome" implies that they thanked you for your payment KIDD. Unfortunately it's exactly the opposite.

Not everyone like that. I was writing thank you to Kidd, because it is people like him who will be paying my OAS, and my GIS, and OHIP, etc., etc. when I hit the certain age - but decided against posting it, because it could be considered sarcastic instead of sincere.

By the way, checking my tax return from the last year I was employed full time, it says "Total income tax deducted: $55,248.06"
I think that would be enough for two seniors collecting OAS+GIS in that year. Whoever you were, you are welcome.

August 19, 2020
4:42 pm
krwilson
Member
Members
Forum Posts: 149
Member Since:
March 15, 2019
sp_UserOfflineSmall Offline

CRA accounts are back online and now you must do a 3 page captcha before you get logged in.

August 19, 2020
5:34 pm
Vatox
Member
Members
Forum Posts: 1218
Member Since:
October 29, 2017
sp_UserOfflineSmall Offline

krwilson said
CRA accounts are back online and now you must do a 3 page captcha before you get logged in.  

Not sure what you mean. I used Login-Partner and it’s the same as always. I guess if you login through CRA, you need to fully verify yourself before they accept that it’s really you.

August 19, 2020
5:57 pm
Dean
Valhalla Mountains, British Columbia
Member
Members
Forum Posts: 2158
Member Since:
January 12, 2019
sp_UserOfflineSmall Offline

krwilson said

CRA accounts are back online and now you must do a 3 page captcha before you get logged in.  

Yes, they announced that earlier (https://www.ctvnews.ca/politics/cra-online-services-working-again-after-attacks-shut-them-down-for-days-1.5071304).

But you Still can't access your CRA ''My Account', via your 'My Service Canada Account'.

Who knows ... maybe they'll have that fixed by next Tuesday sf-wink

    Dean

sf-cool " Live Long, Healthy ... And Prosper! " sf-cool

No permission to create posts

Please write your comments in the forum.