frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Tell HN: H&R Block tax software installs a TLS backdoor

8•yifanlu•1h ago
Just a PSA for folks here in the US because tax season is coming up and some of you may be using H&R Block Business 2025. I discovered that the software installs a root CA named "WK ATX ServerHost 2024" (expiry 2049) into your local machine trusted root certificate store. They also helpfully include the private key to this certificate in a DLL file. This certificate does not identify itself as "H&R Block" anywhere and does not get uninstalled when you uninstall the software.

I've been able to successfully use this root CA + mitmproxy to manipulate TLS traffic on a brand new virtual machine on the same network with a DNS spoofing attack. Demo: https://www.youtube.com/watch?v=5paxvYkz1QE

To test if your machine is vulnerable visit this page: https://hrbackdoor.yifanlu.com and if you do not get any warning or error message from your browser then you have the backdoor installed. If your browser does complain, you can choose to visit the page anyways for more details on the vulnerability.

Is it negligence or a "real" back door? It's impossible to tell and since the private key is out there, anyone can use it so the point is moot. There is no legitimate reason why they need to install a wildcard root CA under a different name. When I contacted them about it their statement includes "similar findings have been identified through internal security assessments" meaning they know about this issue but have not fixed it. I would not trust H&R Block software at this point.

If you didn't get bit by this, congratulations. See this post as a reminder to audit your trusted root CA store.

Comments

sloaken•51m ago
Thanks for the warning.
raw_anon_1111•9m ago
When will these companies learn?

https://michael.team/zoom/

YouTube asks users if videos "feel like AI slop" to flag low-quality content

https://www.dexerto.com/youtube/youtube-is-asking-users-if-videos-feel-like-ai-slop-to-flag-low-q...
1•randycupertino•39s ago•0 comments

Show HN: SoftwareInspect – Side-by-side SaaS comparisons

https://softwareinspect.com
1•andersmyrmel•43s ago•0 comments

Show HN: EvalsHub: Your AI is failing in production and you don't know it

https://www.evalshub.ai
1•neilsharma425•1m ago•0 comments

John Earnest Interviewed about K, Lil, Decker

https://alexalejandre.com/programming/interview-with-john-earnest/
1•veqq•5m ago•0 comments

How we monitor internal coding agents for misalignment

https://openai.com/index/how-we-monitor-internal-coding-agents-misalignment/
1•phillco•5m ago•0 comments

Wikipedia RFC on banning LLM contributions

https://en.wikipedia.org/wiki/Wikipedia:Writing_articles_with_large_language_models/RfC
1•hackerBanana•5m ago•0 comments

Gemini AI threatened me with death – documented evidence

https://sites.google.com/view/amenintare-gemini/
1•marinescu•7m ago•0 comments

GR IV Monochrome Camera (Monochrome-Dedicated CMOS Image Sensor)

https://www.ricoh-imaging.co.jp/english/products/gr-4-mono/feature/
1•reconnecting•9m ago•0 comments

12GB of VRAM runs more intelligence than you think in 2026

https://twitter.com/sudoingX/status/2035000411342659979
1•tosh•9m ago•0 comments

Graph over Tables: Why We Built a Context Graph Instead of a CMDB

https://stlabs.com/engineering/graph-over-tables
1•eatonphil•9m ago•0 comments

Attention Residuals

https://github.com/MoonshotAI/Attention-Residuals
2•GaggiX•12m ago•0 comments

What is noctourism–and why is it on the rise?

https://www.nationalgeographic.com/travel/article/what-is-noctourism-rise-of-after-dark-activities
1•bookofjoe•13m ago•0 comments

BYD's bet on EVs is paying off as drivers ditch gas amid rising oil prices

https://electrek.co/2026/03/20/byd-ev-demand-surges-drivers-ditch-gas-amid-rising-oil-prices/
4•ironyman•16m ago•0 comments

404 Deno CEO not found: Deno's decline and layoffs

https://dbushell.com/2026/03/20/denos-decline-and-layoffs/
2•emschwartz•16m ago•0 comments

Rick Rubin interviews Adam Neumann [video]

https://www.youtube.com/watch?v=RAHsF4A8GLM
1•helloplanets•17m ago•0 comments

AI took me to a punk rock show

https://100daysofnetworks.substack.com/p/day-81-of-100daysofnetworks
2•ojoffe•18m ago•0 comments

AI Security Startup Xbow Valued at More Than $1B

https://www.bloomberg.com/news/articles/2026-03-18/ai-security-startup-xbow-now-valued-at-more-th...
1•eatonphil•19m ago•0 comments

The End of Dijkstra's Algorithm? Breaking the Sorting Barrier for Shortest Paths [video]

https://www.youtube.com/watch?v=bo6WRAr8BEk
1•matt_d•20m ago•0 comments

Show HN: Launch an AI agent swarm for ARC-AGI-3 with plain-English prompts

https://arc-agi-swarm.vercel.app/
1•surferbayarea•20m ago•0 comments

Border0 Is Joining Tailscale

https://tailscale.com/blog/border0-joins-tailscale
2•eatonphil•21m ago•0 comments

Single-Tasking in the Age of AI

https://newsletter.humanwhocodes.com/posts/single-tasking-in-the-age-of-ai
1•vinipolicena•21m ago•0 comments

Switzerland's $2B Tunnel U-Turn [video]

https://www.youtube.com/watch?v=bzTntRHmpa8
1•HiroProtagonist•21m ago•0 comments

Life TV: Video with two bits to spare

https://maurycyz.com/projects/lifetv/
1•maurycyz•21m ago•0 comments

Tech Workers Max Out Their A.I. Use

https://www.nytimes.com/2026/03/20/technology/tokenmaxxing-ai-agents.html
3•chrisaycock•22m ago•0 comments

A Housing Playbook (Outline) for the Rust Belt

https://www.governance.fyi/p/a-housing-playbook-outline-for-the
1•toomuchtodo•23m ago•0 comments

Delve caught running fake SoC 2 / ISO 27001 compliance reports

https://old.reddit.com/r/startups/comments/1rz15ui/i_will_not_promote_psa_delve_yc_w24_startup/
1•wslh•25m ago•0 comments

How I made a shooter game in 64 KB

https://www.youtube.com/watch?v=qht68vFaa1M
1•PaulHoule•26m ago•0 comments

Hetzner erases Zaborona Media website for debt of 174 EUR

https://zaborona.com/index.html
3•Klaster_1•27m ago•1 comments

Show HN: Carbon linting for Terraform PRs – open methodology, no credentials

https://github.com/omrdev1/greenops-cli
1•grafikui•28m ago•0 comments

OpenAI is throwing everything into building an automated researcher

https://www.technologyreview.com/2026/03/20/1134438/openai-is-throwing-everything-into-building-a...
2•joozio•29m ago•0 comments