Canada shutters tax filing website over 'Heartbleed' bug

April 9, 2014

Canada's tax agency shuttered its website Wednesday after warning that encrypted taxpayer data could be vulnerable to the "Heartbleed" bug.

The Canada Revenue Agency (CRA) said the decision, which comes only three weeks before the annual income tax filing deadline, was taken as a "preventative" measure.

"The CRA has temporarily shut down public access to our online services to safeguard the integrity of the information we hold," it said.

Later the CRA said it was "working on a remedy" and hoped to have its website back up and running in three to four days.

Canadian taxpayers are expected to file their tax returns for 2013 with the Canadian Revenue Agency by April 30.

Missing the filing deadline usually results in stiff penalties, but the CRA said "consideration" would be given to anyone affected by the website service interruption.

The agency last week said in a Twitter message that it was processing 1,763 online returns per minute—a seasonal high.

As of March 24, 6,787,284 tax returns had been filed with the government agency, it said. Of those, 83.5 percent were filed online.

There are an estimated 22 million taxpayers in Canada.

The freshly-discovered flaw in online-data scrambling software OpenSSL allows hackers to eavesdrop on online communications, steal data, impersonate websites and unlock encrypted data.

OpenSSL is commonly used to protect passwords, credit card numbers and other data sent via the Internet.

More than half of websites use the software, but not all versions have the same vulnerability, according to heartbleed.com.

Cyber security firm Fox-It estimates that the vulnerability has existed for about two years, since the version of OpenSSL at issue was released.

Computer security specialists, website masters and others began fretting about the bug this week after several reports of hacking.

The CRA said it would investigate any theft and abuse of taxpayer information resulting from security breaches.

Explore further: Heartbleed bug find triggers OpenSSL security advisory

Related Stories

Heartbleed bug find triggers OpenSSL security advisory

April 8, 2014

A flaw called Heartbleed in OpenSSL, which is a software library used for the protection and security of millions of websites, was uncovered by Neel Mehta of Google Security, who first reported it to the OpenSSL team, triggering ...

Heartbleed bug causes major security headache (Update 3)

April 9, 2014

A confounding computer bug called "Heartbleed" is causing major security headaches across the Internet as websites scramble to fix the problem and Web surfers wonder whether they should change their passwords to prevent theft ...

Software glitch delays 660,000 tax refunds

March 14, 2013

The Internal Revenue Service says 660,000 taxpayers will have their refunds delayed by up to six weeks because of a problem with the software they used to file their tax returns.

Recommended for you

'Droneboarding' takes off in Latvia

January 22, 2017

Skirted on all sides by snow-clad pine forests, Latvia's remote Lake Ninieris would be the perfect picture of winter tranquility—were it not for the huge drone buzzing like a swarm of angry bees as it zooms above the solid ...

Singapore 2G switchoff highlights digital divide

January 22, 2017

When Singapore pulls the plug on its 2G mobile phone network this year, thousands of people could be stuck without a signal—digital have-nots left behind by the relentless march of technology.

Making AI systems that see the world as humans do

January 19, 2017

A Northwestern University team developed a new computational model that performs at human levels on a standard intelligence test. This work is an important step toward making artificial intelligence systems that see and understand ...

0 comments

Please sign in to add a comment. Registration is free, and takes less than a minute. Read more

Click here to reset your password.
Sign in to get notified via email when new comments are made.