Why sign in to the Community?

  • Submit a question
  • Check your notifications
Sign in to the Community or Sign in to TurboTax and start working on your taxes
New Member
posted Jun 4, 2019 11:50:26 AM

What should I do if I accidentally purchased Turbotax from an unauthorized reseller (greentaxexpert.com)? Is there a way to verify my download is safe?

I purchased TurboTax Home And Business 2017 from greentaxexpert.com, which I now realize appears not to be an authorized reseller. Is there any way to verify that the download has not been modified or infected by them (i.e. an SHA hash of the official download). 

0 5 1458
5 Replies
Level 4
Jun 4, 2019 11:50:27 AM

Unfortunately, we are not authorized to publish the hash codes. I’m glad that you were able to get your money back.

Level 15
Jun 4, 2019 11:50:29 AM

Sorry, they don't release their hash values, for various reasons.  You can try and return it, or dispute the charge with your bank, or take the chance.  

New Member
Jun 4, 2019 11:50:30 AM

Thanks for your feedback. I was able to use the apple codesign utility to verify that the signature on the app appears to be correct, but I will see if I can get a refund. That output includes the sha1 and sha256 hashes, is it acceptable to post them here in the hope that someone with an official copy can verify them?

New Member
Jun 4, 2019 11:50:31 AM

FWIW, all indications are that the files from them were unmodified: both the original download and the subsequent updates appear to be properly signed by Intuit. When I requested that my order be canceled and refunded, they did so promptly.

Level 15
Jun 4, 2019 11:50:33 AM

I don't know if the moderators would permit the hashes to be published.  (To an extent, doing so would assist others in cheating Turbotax of revenue).  The other concern is that, even if this particular unlicensed merchant is only selling pirate copies of unmodified software, we have seen reports of other merchants selling modified software, or collecting credit card numbers for nefarious purposes and never delivering the software.  Publishing the hashes might give other customers a false sense of security.