CRA HACKED!

Imagine how bad those fake CRA calls are gonna be when they can quote your personal details and last year's income. 😔
 
  • Like
Reactions: 3ml
Pretty pathetic, our government, who is suppose to have top notch security cause income tax and identity information stolen can hurt you big time, has failed the public once again. I honestly have lost faith in the leaders and the administration of our country to help and protect us as so many things have been mismanaged. Under Trudeaus administration we have had corruption at the highest level by Trudeau himself.

The first violation was with the a publicly paid family vacation amounting to 271,000$ to an Island owned by Aga Khan a business man that was registered to lobby the office of the PM and also did business with the federal Government. Major conflict of interest. Vacation amounts for the PM should also be capped at significantly lower amounts.

The second violation was when Trudeau improperly pressured former justice minister Jody Wilson-Raybould to reach a deferred prosecution agreement with Quebec engineering giant SNC-Lavalin to help the company avoid criminal prosecution on fraud and bribery charges.

Now the WE Charity where he and the government sole sourced a contract, without tendering it out, to a group who he and his family was tied into as Friends His mother earned 250,000$ for 32 speaking events, That amounts to 7800$ per lets say an hour of speaking time, and his brother got 32000$ for eight events or 4000$ an hour. Trudeau's finance Minister also took a trip to Kenya paid by the WE Charity which amounted to over 42000$ which he did not reimburse until the WE Charity scandal was exposed. His friends at the WE Charity were to receive over 48 million dollars for giving out 900 million of tax payers money to students during covid. Now that's a chunk of change. If that contract had have been tendered I am quite sure some other party could have done it for significantly less. I would have done it for 5 million. I am quite sure I could hire the call center manpower for 9 months, rent a location, set up all the computers and telecommunication systems, make banking arrangement for funds distribution etc etc for less than 3.5 million... That is 1.5 million in my pocket.

Now this fuck up with the CRA. I can also go on about other flagrant things Trudeau has done (increased the deficit by a third tipping it over a trillion dollars in the last year, that is unheard of ... wait till u see the tax hike when Trudeau is succeeded) , however I think it is time to relieve this guy of his position as he has lost control of government, lost the faith of the Canadian public, and he is a criminal when you look at the misuse of our hard earned tax payers money.
 
Here is more on the CRA hack. I don't feel comfortable that they have plug the hole in their software that was hacked. I thought that was why we had a GCkey that was encrypted and hackers could not get around that. Damn I had to send away for a code to be able to set up my login credentials and wait 30 days or so to get it. In the article I am going to post is below ... They say in the article that the gained access to user accounts by credential stuffing ... and they got these passwords and user names from other sites ... hmmm that sounds a little fishy if you ask me cause if you look at the second attack ... someone new an easy way around their software which seems like it might have been an attack from someone knowledgeable in the CRA's software i.e. internal. Makes me nervous as to whether there are other holes and whether they had someone inside compromising them. Should ask Trudeau if he was aware of this major Mishap and is he going to have the internal staff investigated. I would look at the ppl who manage, configure or have developed the security software as they should in the know of any holes in the software. I don't trust government ...lol. See link below

The first attack occurred when hackers involved in the GCKey attack gained access to 3,400 CRA accounts.

A second attack took place last week where hackers took advantage of a vulnerability in the agency's software that allowed them to bypass the normally-required security question and gain access to a user accounts.

The third attack took place over the weekend, causing CRA to temporarily cut off access to its online services on Sunday, including services connected to My Account, My Business Account and Represent a Client.


Just an update. Read that the CRA said that ppl should use 2 factor authentication if it is available, It appears it is not available on the CRA site. hmmmmmm
 
Last edited:
  • Like
Reactions: 3ml

Just an update. Read that the CRA said that ppl should use 2 factor authentication if it is available, It appears it is not available on the CRA site. hmmmmmm

It's affected very very few accounts and most seem to be from zero factor web users who use samelogin/samepassword everywhere. We're not talking about the twenty million other people who are doing their CRA business safely and without zero chances of being hacked. To me, this "hack" is making my eyes roll.

If you're doing your CRA business online and banking online(I have a hard time believing you wouldn't do both if you do one) and not using your bank as a 3rd party authenticator to secure your CRA with a gigantic set of credentials you don't even know, you're a lunatic because your bank to CRA authentication is about as secure as it will ever get. That and if it gets hacked (outside of you being an idiot and using samelogin/samepassword everywhere), the bank has a legal obligation to be on the hook if they are somehow mid-stream hacked.

No offence but call me when significant numbers show up on a real hack that isn't in part because of an idiot user or something that is patched within hours because of a bit of faulty code that got vetted too soon.
 
It's affected very very few accounts and most seem to be from zero factor web users who use samelogin/samepassword everywhere. We're not talking about the twenty million other people who are doing their CRA business safely and without zero chances of being hacked. To me, this "hack" is making my eyes roll.

If you're doing your CRA business online and banking online(I have a hard time believing you wouldn't do both if you do one) and not using your bank as a 3rd party authenticator to secure your CRA with a gigantic set of credentials you don't even know, you're a lunatic because your bank to CRA authentication is about as secure as it will ever get. That and if it gets hacked (outside of you being an idiot and using samelogin/samepassword everywhere), the bank has a legal obligation to be on the hook if they are somehow mid-stream hacked.

No offence but call me when significant numbers show up on a real hack that isn't in part because of an idiot user or something that is patched within hours because of a bit of faulty code that got vetted too soon.
Haha ... you don't think that the CRA didn't keep the reported number of accounts hacked down for political reasons... come on, And you think that them saying it was credential stuffing from so called other sources was the main hack ... I don't believe a thing that comes out of the mouths of government as they always have alternative agendas and give a little of the truth and a lot of lies.

And I do use bank to CRA authentication, and in you implication, I am not an lunatic in this regard ... I have worked in the systems development and coding line work for numerous years and have worked in security and audit as well. And I have got numerous refunds on my banks visa for purchases that were made in the US that did not follow the pattern of any purchases I had made in the past, I am well aware of banks and their associates being on the line for security breaches outside my control.

Your making a big assumption when your saying that patches get installed within hours and get vetted to soon by government ... I have worked for government they are one of the most methodical and pain stakingly thorough and slow group of testers and implementers that I have ever worked with as they are afraid of an implementation going wrong and getting blamed. Its more likely they installed the code wrong through the migration process through to production rather than the fact that the vetted wasn't good enough. Most code installations go wrong because of incorrect installation instructions or production control regressing the code by installing an earlier version of the code from the wrong staging areas.

And don't worry, I won't be calling you anytime soon. I have made it very well on my own thank you.

I will not be responding any further to these type of comments as saying things like someone is a 'you're a lunatic' or 'you being an idiot' on this board is not why I am here. There is professional ways of writing up comments and there is unprofessional. It appears in your mind that most ppl are idiots or lunatics, no most people are human ... cheers PG
 
It's affected very very few accounts and most seem to be from zero factor web users who use samelogin/samepassword everywhere. We're not talking about the twenty million other people who are doing their CRA business safely and without zero chances of being hacked. To me, this "hack" is making my eyes roll.

If you're doing your CRA business online and banking online(I have a hard time believing you wouldn't do both if you do one) and not using your bank as a 3rd party authenticator to secure your CRA with a gigantic set of credentials you don't even know, you're a lunatic because your bank to CRA authentication is about as secure as it will ever get. That and if it gets hacked (outside of you being an idiot and using samelogin/samepassword everywhere), the bank has a legal obligation to be on the hook if they are somehow mid-stream hacked.

No offence but call me when significant numbers show up on a real hack that isn't in part because of an idiot user or something that is patched within hours because of a bit of faulty code that got vetted too soon.


any breach of security is not acceptable. to say its only note worthy when its " significant numbers " is wrong in my opinion.

We all have our area's of expertise. You have come out and said what yours is. I am not in a position to reveal what mine is however let me just say odds are I know a tad more about internet security and even past hacks of the government then most of the members here, yourself included.

What is reported is always massaged to make it look better. The truth only comes out when a whistle blower speaks up and even then what that person says is heavily discredited.
 
any breach of security is not acceptable. to say its only note worthy when its " significant numbers " is wrong in my opinion.

We all have our area's of expertise. You have come out and said what yours is. I am not in a position to reveal what mine is however let me just say odds are I know a tad more about internet security and even past hacks of the government then most of the members here, yourself included.

What is reported is always massaged to make it look better. The truth only comes out when a whistle blower speaks up and even then what that person says is heavily discredited.


well said
 
Haha ... you don't think that the CRA didn't keep the reported number of accounts hacked down for political reasons... come on, And you think that them saying it was credential stuffing from so called other sources was the main hack ... I don't believe a thing that comes out of the mouths of government as they always have alternative agendas and give a little of the truth and a lot of lies.

And I do use bank to CRA authentication, and in you implication, I am not an lunatic in this regard ... I have worked in the systems development and coding line work for numerous years and have worked in security and audit as well. And I have got numerous refunds on my banks visa for purchases that were made in the US that did not follow the pattern of any purchases I had made in the past, I am well aware of banks and their associates being on the line for security breaches outside my control.

Your making a big assumption when your saying that patches get installed within hours and get vetted to soon by government ... I have worked for government they are one of the most methodical and pain stakingly thorough and slow group of testers and implementers that I have ever worked with as they are afraid of an implementation going wrong and getting blamed. Its more likely they installed the code wrong through the migration process through to production rather than the fact that the vetted wasn't good enough. Most code installations go wrong because of incorrect installation instructions or production control regressing the code by installing an earlier version of the code from the wrong staging areas.

And don't worry, I won't be calling you anytime soon. I have made it very well on my own thank you.

I will not be responding any further to these type of comments as saying things like someone is a 'you're a lunatic' or 'you being an idiot' on this board is not why I am here. There is professional ways of writing up comments and there is unprofessional. It appears in your mind that most ppl are idiots or lunatics, no most people are human ... cheers PG

You will learn to skip his posts.
LOL
 
We now have a Finance Minister ( Christina Alexandra Freeland ) who's educational background is Bachelor of Arts degree in Russian history and literature from Harvard University and a Master of Studies degree in Slavonic Studies from St Antony's College, Oxford, and her career before politics was in Journalism.. Tell me how that qualifies you for the Minister of Finance. In the private enterprise to become a VP Finance of a Company you need several years experience in Finance at at high level in a major company and normally a CPA designation or an MBA. There should be minimum educational requirement and experience to be put in the countries senior Finance position. My comment that 'Trudeau is an idiot ' I repeat again.
 
Last edited:
We now have a Finance Minister ( Christina Alexandra Freeland ) who's educational background is Bachelor of Arts degree in Russian history and literature from Harvard University and a Master of Studies degree in Slavonic Studies from St Antony's College, Oxford, and her career before politics was in Journalism.. Tell me how that qualities you for the Minister of Finance. In the private enterprise to become a VP Finance of a Company you need several years experience in Finance at at high level in a major company and normally a CPA designation or an MBA. There should be minimum educational requirement and experience to be put in the countries senior Finance position. My comment that 'Trudeau is an idiot ' I repeat again.


Yes but does she look good in a skirt?
 
Top