Tell HN: H&R Block tax software installs a TLS backdoor

137 points
1/21/1970
2 days ago
by yifanlu

Comments


giantg2

I'm wondering if download source matters. Seems like most are downloaded straight from their site, but curious if they still offer CDs or if sellers like Amazon have the direct installer downloads.

5 hours ago

raw_anon_1111

When will these companies learn?

https://michael.team/zoom/

2 days ago

WarOnPrivacy

    "If you have an SSL error in your H&R Block Software, 
    here’s what you need to know."
https://www.hrblock.com/tax-center/support/software/technica...
2 days ago

TheClassic

I have the non-business edition installed and still get a privacy error attempting to load your page, so this seems specific to the business edition. Thanks for the heads up.

2 days ago

GoldenMonkey

Aren't mac's more secure by default. Receive the warning using mac with h&r block 2025 installed.

a day ago

snarkanon

These stupid tax software companies' business editions seem to support only MS-Windows. No idea why, they already support macOS on other editions.

Anyone know of any business editions available on macOS?

20 hours ago

majorchord

> No idea why

Probably because business users on macs are a rounding error, no offense.

20 hours ago

musicale

Welcome to CrapOS 26H1! We think you'll love it. Also, if you install tax software it might enable anyone to read all of your "encrypted" TLS connections regardless of what browser or app you might be using.

Click "I AGREE" to accept this as part of our mandatory user abuse and subjugation agreement.

2 days ago

altairprime

Curious: is it carrying a SHA-1 self-signature?

2 days ago

sloaken

Thanks for the warning.

2 days ago