itonewbie
Level 15

ProConnect Tax users are not the most active in this Community but for those who sign on regularly to this forum, you should be aware of the security risk and take actions as necessary.

This is a flaw that was previously highlighted to Intuit when this Community, in its current format, was first rolled out and it was fixed.  But lately (and don't know when), it has resurfaced and it was brought to the attention of Intuit, who confirmed that their team "hopefully can get this fixed asap".  Since it's been a week and there's been no change, it's only fair that the Community should be made aware.

This vulnerability is relevant to only ProConnect Tax users, AFAIK.  If you use the same Intuit account for both this Community and ProConnect Tax (which many, if not most, probably do), signing into this Community will also log you in automatically to ProConnect Tax (even though it has a totally different URL).  Unbeknownst to you, this flaw exposes you to an enlarged attack surface for potential hackers, however low that risk may be.  You wouldn't want to leave your bank account logged in while you're not using it, why would tax pros want to take a chance with ProConnect Tax?  The fact that Intuit decides not to address this as a matter of priority is very concerning.

In the meantime, I would suggest that each time you log into this Community, open another tab for ProConnect Tax, and log off from ProConnect Tax manually.  Interestingly, this flaw works only in one direction - logging off from ProConnect Tax will not sign you off this Community.

@IntuitBettyJo @IntuitGabi Could you please escalate this again to the right parties and confirm when this will be fixed?  Many thanks!

---------------------------------------------------------------------------------
Still an AllStar