frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Tell HN: H&R Block tax software installs a TLS backdoor

10•yifanlu•3h ago
Just a PSA for folks here in the US because tax season is coming up and some of you may be using H&R Block Business 2025. I discovered that the software installs a root CA named "WK ATX ServerHost 2024" (expiry 2049) into your local machine trusted root certificate store. They also helpfully include the private key to this certificate in a DLL file. This certificate does not identify itself as "H&R Block" anywhere and does not get uninstalled when you uninstall the software.

I've been able to successfully use this root CA + mitmproxy to manipulate TLS traffic on a brand new virtual machine on the same network with a DNS spoofing attack. Demo: https://www.youtube.com/watch?v=5paxvYkz1QE

To test if your machine is vulnerable visit this page: https://hrbackdoor.yifanlu.com and if you do not get any warning or error message from your browser then you have the backdoor installed. If your browser does complain, you can choose to visit the page anyways for more details on the vulnerability.

Is it negligence or a "real" back door? It's impossible to tell and since the private key is out there, anyone can use it so the point is moot. There is no legitimate reason why they need to install a wildcard root CA under a different name. When I contacted them about it their statement includes "similar findings have been identified through internal security assessments" meaning they know about this issue but have not fixed it. I would not trust H&R Block software at this point.

If you didn't get bit by this, congratulations. See this post as a reminder to audit your trusted root CA store.

Comments

sloaken•2h ago
Thanks for the warning.
raw_anon_1111•1h ago
When will these companies learn?

https://michael.team/zoom/

altairprime•24m ago
Curious: is it carrying a SHA-1 self-signature?

Tell HN: Your AI startup is a Next.js page, OpenAI_API_KEY, & Stripe invoice

6•poupdich•1h ago•4 comments

Tell HN: H&R Block tax software installs a TLS backdoor

10•yifanlu•3h ago•3 comments

Structural Friction: A metric for human coordination cost

2•davidvartanian•7h ago•0 comments

Ask HN: Are you using a Pivotal Tracker successor? Which one?

2•antfarm•9h ago•0 comments

Spotify playing ads for paid subscribers

139•IncandescentGas•2d ago•124 comments

Ask HN: What do you look for in your first 10 hires?

27•neilk17•1d ago•30 comments

Ask HN: What is it like being in a CS major program these days?

212•tathagatadg•4d ago•202 comments

Ask HN: The new wave of AI agent sandboxes?

10•ATechGuy•1d ago•4 comments

Ask HN: Broken "Public Research Articles" Link: Any Support for Google Scholar?

4•yann-gael•20h ago•2 comments

Ask HN: How to Find a Job in the UK

8•0x3444ac53•1d ago•6 comments

Ask HN: Can we make up/downvotes/flags visible on Hacker News Archives (delayed)

5•gpt5•19h ago•1 comments

How are Iranian drones getting their guidance?

6•dottenad•19h ago•4 comments

Ask HN: How do you deal with people who trust LLMs?

147•basilikum•1d ago•194 comments

Anchor: Hardware-based authentication using SanDisk USB devices

2•rewant•1d ago•0 comments

Tell HN: If working with agents means this, robots, please take my job

12•tiredagent•22h ago•10 comments

Ask HN: Are we ready for vulnerabilities to be words instead of code?

4•lielcohen•22h ago•11 comments

TTal – CLI that turns Claude Code into a multi-agent software factory

5•neilbb•1d ago•3 comments

European municipalities leak citizen data to US companies

9•sam_lowry_•1d ago•2 comments

Ask HN: Who is still using Windsurf and why?

9•mak8•1d ago•9 comments

Ask HN: Is vibe coding a new mandatory job requirement?

33•newswangerd•2d ago•71 comments

Tell HN: AI tools are making me lose interest in CS fundamentals

98•Tim25659•4d ago•92 comments

I built a game where you argue consumer rights against AI bots

6•dragonmann•1d ago•3 comments

Ask HN: Have you cancelled any software subscriptions because AI replaced them?

8•maxim_bg•1d ago•10 comments

Ask HN: Is Claude down Again?

10•rreyes1979•2d ago•6 comments

Open AI is actively censoring information about voting today in the US

11•resters•2d ago•16 comments

Ask HN: Why is everyone on HN obsessed with Rust?

15•goldkey•1d ago•10 comments

Ask HN: How are you protecting yourself from skill atrophy?

6•xpnsec•2d ago•14 comments

Claude Code 500s

16•bavarianbob•3d ago•5 comments

You've reached the end!