[Paper Review] Security Assessment of E-Tax Filing Websites
This paper evaluates the technical security and user perception of trust in 43 e-tax filing websites globally, identifying critical gaps in encryption, authentication, and security indicators. It proposes actionable best practices and novel security enhancements—such as stronger session management and transparent security signaling—based on findings that many sites lack robust protections despite high user trust.
Technical security is only part of E-Commerce security operations; human usability and security perception play major and sometimes dominating factors. For instance, slick websites with impressive security icons but no real technical security are often perceived by users to be trustworthy (and thus more profitable) than plain vanilla websites that use powerful encryption for transmission and server protection. We study one important type of E-Commerce transaction website, E-Tax Filing, that is exposed to large populations. We assess a large number of international (5), Federal (USA), and state E-Tax filing websites (38) for both technical security protection and human perception of security. As a result of this assessment, we identify security best practices across these E-Tax Filing websites and recommend additional security techniques that have not been found in current use by E-Tax Filing websites.
Motivation & Objective
- To evaluate the technical security posture of international, federal, and state-level e-tax filing websites.
- To assess how users perceive security based on visual cues and website design, independent of actual technical safeguards.
- To identify common security shortcomings across e-tax platforms that compromise user data and trust.
- To establish a set of security best practices based on empirical assessment of real-world implementations.
- To recommend advanced security mechanisms not currently deployed in existing e-tax systems.
Proposed method
- Conducted a comprehensive security assessment of 43 e-tax filing websites, including 5 international, 1 federal (USA), and 38 state-level platforms.
- Evaluated technical controls such as TLS/SSL implementation, session management, input validation, and server hardening.
- Analyzed visual and interface elements (e.g., security badges, trust indicators) to assess their impact on user perception of security.
- Compared observed security practices against established security standards and best practices in web application security.
- Identified discrepancies between perceived security (based on UI/UX) and actual technical security strength.
- Proposed a set of enhanced security techniques not currently in use, such as improved session timeouts and client-side security validation.
Experimental results
Research questions
- RQ1To what extent do e-tax filing websites implement strong technical security controls such as end-to-end encryption and secure authentication?
- RQ2How do visual security indicators influence users' perception of trust, regardless of actual technical security?
- RQ3What are the most common technical vulnerabilities present in e-tax filing websites across different jurisdictions?
- RQ4How do the security practices of federal and state-level e-tax platforms compare to international standards?
- RQ5What novel or underutilized security mechanisms could significantly improve the security posture of e-tax systems?
Key findings
- Many e-tax filing websites, including federal and state platforms, lack proper implementation of transport-layer security (TLS), leaving data transmissions vulnerable.
- Despite weak technical security, websites with prominent security badges or professional designs were perceived as significantly more trustworthy by users.
- A substantial number of sites used outdated or insecure cryptographic protocols, such as weak TLS configurations or no encryption for sensitive data.
- User perception of security was heavily influenced by visual cues rather than actual technical safeguards, indicating a critical gap in security communication.
- No e-tax filing website examined implemented advanced security mechanisms such as client-side input validation or robust session expiration policies.
- The study identified a clear disconnect between perceived security (driven by design) and actual technical security, highlighting the need for transparency and stronger controls.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.