Does e-tax 2010 have a security hole?
update The denizens of global security mailing list Bugtraq have started discussing whether the Australian Taxation Office’s e-tax 2010 software — currently being used by millions of Australians to submit their tax returns — has a security hole in it, due to the way it deals with remote Secure Socket Layer (SSL) certificates. The breaches were unintentionally discovered when a security expert, known only as Dave B, became fed up with the ATO’s restrictions on the use of alternative operating systems other than Windows — he tried to do a workaround so he didn’t have to use Microsoft’s platform. At first Dave B thought that the software did not check the SSL certificate of involved domains and would work if the certificate came from a valid certificate authority. Other tests were made and he found that a “freshly generated” self-signed certificate would be accepted by the software — so the SSL certificate does not need to be signed by a certificate authority. e-tax will communicate via t