Live data from Hacker News

Government launches login.gov to simplify access to public services

18f.gsa.gov

61–70 of 173 posts

Re: Government launches login.gov to simplify access to public services

#61
This looks promising.

I'm currently in Denmark and they have this inane two-factor authentication system for all (e.g. banks and not just public) services that uses physical printed cards with 150 codes each; when you are close to using one up you need to get another one in the mail. https://en.wikipedia.org/wiki/NemID

Hopefully if this requires 2FA it can use the TOTP open standard, etc.

Re: Government launches login.gov to simplify access to public services

#62

This appears valuable and well executed, but I worry that private businesses will be eager to outsource their authentication to this service, if they are allowed to. And once it's fully stood up, I suspect the government would be all too eager to oblige. This might be convenient, but might also mark the beginning of a major new point of U.S. government control over the Internet, with all the surveillance and other ci…

In many countries (e.g. Denmark), this is already the case.

https://en.wikipedia.org/wiki/NemID

Re: Government launches login.gov to simplify access to public services

#63

This appears valuable and well executed, but I worry that private businesses will be eager to outsource their authentication to this service, if they are allowed to. And once it's fully stood up, I suspect the government would be all too eager to oblige. This might be convenient, but might also mark the beginning of a major new point of U.S. government control over the Internet, with all the surveillance and other ci…

> Now seems like the time to set the expectation that this service may not ever be used by private websites. Wha-huh? Why? What specifically is wrong with login.gov (or any government agency) running an oauth server and private websites allowing users to authenticate with it? How does that result in "a major new point of U.S. government control over the Internet"?

It allows them to see what you log in to and thus what services you use, much like Facebook can often do as well. (Although luckily I haven't seen that as the only option anywhere yet - that might not be the case for a system that everyone in one's target audience might be forced to use.)

Re: Government launches login.gov to simplify access to public services

#64
post #63

Earlier quoted context omitted.

> Now seems like the time to set the expectation that this service may not ever be used by private websites. Wha-huh? Why? What specifically is wrong with login.gov (or any government agency) running an oauth server and private websites allowing users to authenticate with it? How does that result in "a major new point of U.S. government control over the Internet"?

It allows them to see what you log in to and thus what services you use, much like Facebook can often do as well. (Although luckily I haven't seen that as the only option anywhere yet - that might not be the case for a system that everyone in one's target audience might be forced to use.)

I'm pretty certain they can already do that though.

Re: Government launches login.gov to simplify access to public services

#65
post #60

Earlier quoted context omitted.

I'm not saying that it's not better net , I’m saying that, insofar as there is an internal or external risk of compromise or abuse, a single government identity provider poses the same kind of risk as a single government profile would provide.

I pity the fool who hacks such a strategic government service. The expression "threw away the key" comes to mind for what might happen to them.

Improper (but not necessarily unsupported from above) internal use is at least as worrisome as hacking, and centralization reduced the size of the necessary conspiracy and the probability of detection and whistleblowing.)

Re: Government launches login.gov to simplify access to public services

#66
post #63

Earlier quoted context omitted.

> Now seems like the time to set the expectation that this service may not ever be used by private websites. Wha-huh? Why? What specifically is wrong with login.gov (or any government agency) running an oauth server and private websites allowing users to authenticate with it? How does that result in "a major new point of U.S. government control over the Internet"?

It allows them to see what you log in to and thus what services you use, much like Facebook can often do as well. (Although luckily I haven't seen that as the only option anywhere yet - that might not be the case for a system that everyone in one's target audience might be forced to use.)

> Now seems like the time to set the expectation that this service may not ever be used by private websites.

Oh shit! The government knows I bought something from custom-fishing-lures.com! Ruuuuun!

Seriously, what you just listed is a reason not to use the government's Oauth for every website and ban all other implementations. What OP seemed to say, and what I disputed, is the idea that this service should not ever be used by any private website even as one of several options.

Re: Government launches login.gov to simplify access to public services

#67
post #6

This is kinda cool, but it's also a little concerning. One of the ways our government protects our privacy is specifically by not centralizing information. Just because you pay taxes or have healthcare doesn't mean the police has that info, for example. The efficiency of connecting a large number of governmental agencies to a single account for you is pretty concerning, it puts all the data in one spot that can be ex…

I know I'm not supposed to say this, but you obviously either didn't read the article or read it but didn't understand it, and perhaps you would be better off reading it more closely before commenting. The article lays out that this is not centralizing information, but is merely allowing a bunch of different agencies to use it as an identity provider. The same way I can, say, connect to my spotify via my Google+ acco…

> The same way I can, say, connect to my spotify via my Google+ account, but that doesn't mean that google has all of my spotify playlists.

Yes they do. Spotify is asking Google, "Hey, does this web browser have the ability to log in to Spotify as this fellow?" Google can say yes whenever they want, and Spotify is completely trusting the answer.

Google is supposed to only say yes when it's your browser, and not when it's a Google employee's browser, but you have absolutely no way of knowing that.

When you use a third-party site for authentication, the security properties are exactly the same as if you had generated a new random password, wrote it down, and gave it to the third party.

Re: Government launches login.gov to simplify access to public services

#68

This appears valuable and well executed, but I worry that private businesses will be eager to outsource their authentication to this service, if they are allowed to. And once it's fully stood up, I suspect the government would be all too eager to oblige. This might be convenient, but might also mark the beginning of a major new point of U.S. government control over the Internet, with all the surveillance and other ci…

[deleted]

Re: Government launches login.gov to simplify access to public services

#69

Given that this is a typical identity provider, I'm curious there's interest to make this service available to the saas industry at large. For example, I'd rather NOT have to manage login credentials for my bank, mortgage car payment, and various airlines. I'd rather let login.gov handle it. Moreover, as a saas provider, I wouldn't mind deferring this liability to someone other than google or facebook.

To me, this is the right attitude towards this. Really? Are you more scared by your own democratic government than by facebook? Besides i'm not even american, so whatever

[deleted]

Re: Government launches login.gov to simplify access to public services

#70

Earlier quoted context omitted.

To me, this is the right attitude towards this. Really? Are you more scared by your own democratic government than by facebook? Besides i'm not even american, so whatever

Well, yeah. I can choose to not use Facebook (for the most part). I can't choose to not use the federal government. Plus, disliking and being wary of government is quintessentially American—it goes back to our roots as a country. As an example that just popped into my head, look at DACA: a bunch of undocumented persons told the federal government about their undocumented status (in exchange for something good) and no…

[deleted]
Post reply on HN