SIGNAL GRIDv0.1

Tell HN: H&R Block tax software installs a TLS backdoor

1 sources1 storiesFirst seen 3/20/2026Score24Mixed Progress
Single Source
CoverageRecencyEngagementVelocityBignessConfidenceClipability
Bigness
24
Coverage
13
Recency
65
Engagement
16
Velocity
0
Confidence
49
Clipability
60
Polarization
0
Claims
4
Contradictions
0
Breakthrough
50

Sentiment Mix

Positive0%
Neutral0%
Negative100%

Geography

North America

Expert Signals

yifanlu

author1 mention

Hacker News

source1 mention

AI-Generated Claims

Generated from linked receipts; click sources for full context.

Just a PSA for folks here in the US because tax season is coming up and some of you may be using H&R Block Business 2025.

Supported by 1 story

I discovered that the software installs a root CA named "WK ATX ServerHost 2024" (expiry 2049) into your local machine trusted root certificate store.

Supported by 1 story

Demo: https://www.youtube.com/watch?v=5paxvYkz1QETo test if your machine is vulnerable visit this page: https://hrbackdoor.yifanlu.com and if you do not get any warning or error message from your browser then you have the backdoor installed.

Supported by 1 story

If your browser does complain, you can choose to visit the page anyways for more details on the vulnerability.Is...

Supported by 1 story

Related Events

Timeline (1 stories)

Mar 20 08:29 PMFirst
Tell HN: H&R Block tax software installs a TLS backdoor
Hacker News83 engagement

Receipts (1)

Bias Snapshot

Center
Left 0%Center 100%Right 0%