Online Tax declaration - potential DOS
Sunday, April 30th, 2006It’s very easy to DOS someone’s access to Norwegian’s tax declaration online system. If you happen to know their personal ID (not too hard to find if you really want), you can enter 3 erroneous passwords on the Altinn web site and get the online access blocked for one hour
update. Even better! When you fail for the 3rd time, it doesn’t check how long passed since the second. I’ve tried with a delay superior of one hour, and it still failed me. This can clearly be improved: they should add a least the last failure timestamp together with the failure counter.
The problem is interesting: how do you maintain some kind of secure authentication? Every site has his own strategy and the chosen balance between security and ease of use never quite the same.