Live data from Hacker News

Government launches login.gov to simplify access to public services

18f.gsa.gov

121–130 of 173 posts

Re: Government launches login.gov to simplify access to public services

#121

This appears valuable and well executed, but I worry that private businesses will be eager to outsource their authentication to this service, if they are allowed to. And once it's fully stood up, I suspect the government would be all too eager to oblige. This might be convenient, but might also mark the beginning of a major new point of U.S. government control over the Internet, with all the surveillance and other ci…

> This appears valuable and well executed

How can you tell? You are looking at a PR piece that links to a web site that mentions 'security experts' in every other sentence. It's not proven to be valuable or well executed.

Re: Government launches login.gov to simplify access to public services

#122
post #116
post #71

Earlier quoted context omitted.

Repercussions? For the OPM hack, I got a form letter and a year (I think, I didn't use it) of credit monitoring. That was some of my most intimate information. That was a huge invasion of my privacy. I didn't even get a phone call. I didn't even get a sincere apology.

Just as an FYI, I think they extended the period to 10 years. I agree that it was handled poorly!

I froze my credit. I am in a position where I don't need credit and can get credit by virtue of assets if I did need to. I was, for lack of a better phrase, pretty pissed off. I got a form letter and something about credit monitoring in one of those weird security envelopes, as I recall.

Ten years? Yeah, that'll help. I pretty much admitted to everything I'd ever done, on those forms. It wasn't just me impacted, it had names of my friends and family. Then, I'm guessing it had all the notes I didn't see, from things like the interviews.

I don't have any real enemies, or any reason to be afraid, but that makes me no less angry and feel no less violated. Meh... I try to let the anger go, so it only pops up when I discuss it. There's nothing I can do to change it. I do consider it the greatest violation of trust ever enacted on me by the government. There was no reason for me to even be in the system any more, I am retired.

[redacted]

Oh well... If you can get away with it, freeze your credit. This does, curiously, impact your credit score. The peace of mind is worth it. Sorry for the novella.

Re: Government launches login.gov to simplify access to public services

#123
post #46

Earlier quoted context omitted.

To add to this, a US government site does not need this, because only the US government site can register a .gov domain.

They can be taken over.

In which case EV wouldn't get you anything, right (since presumably it would be verified and issued before the site was taken over)?

Re: Government launches login.gov to simplify access to public services

#124

Earlier quoted context omitted.

This is a US Digital Service project for 18F. Probably the best engineers in the world working on it.

Hmm...you have to move to Washington DC to work for them, they won't pay for relocation, salaries are capped by federal pay grades and are lower than a tech company in SF or Seattle would pay, no bonuses (or stock options, obviously). I'm sure they have some bright (and altruistic) employees, but I'm not sure the best engineers in the world would work there when they can earn far more compensation at a tech company.

Many people want to make software for the public good via the public sector. For some, the opportunity to do that outweighs the benefits of earning top-of-the-line paychecks.

It seems deeply cynical to correlate geographic areas with salaries and infer that the best engineers in the world will be drawn there, bar none. There are other incentives. Some might even say that engineering of this sort is better executed, or more trustworthy, when performed by people with civic motivations rather than mercenary ones.

Re: Government launches login.gov to simplify access to public services

#125

Earlier quoted context omitted.

Given the alternative of handing out my SSN and hoping for the best, I'd be more than happy to use this for banking and related services. Presumably, third-party use would be covered by some form of ToS, and maybe we'd see actual repercussions for leaking data that originated here.

Wouldn't it be entertaining if the SSN leak was just a really clever PR boost for the Trump administration? I'm certainly entertaining conspiracy theory level ludicrousy, but it is entertaining.

The EquiFax thing would only be good PR for Trump's administration if they used it as an attempt to push through legislation that would prevent these kinds of things from happening in future - like a reasoned and functional (and minimum privilege) national identification service - while Alex Jones-types would normally be up in arms I think they would support it it Trump sold it as the system additionally to make it easy to identify illegal immigrants and members of the "alt-left".

Re: Government launches login.gov to simplify access to public services

#126

This is kinda cool, but it's also a little concerning. One of the ways our government protects our privacy is specifically by not centralizing information. Just because you pay taxes or have healthcare doesn't mean the police has that info, for example. The efficiency of connecting a large number of governmental agencies to a single account for you is pretty concerning, it puts all the data in one spot that can be ex…

It's hard to say that our government really protects our privacy by scattering copies of our information across a constellation of bureaucracies. And protect from who? Who's really more dangerous than our government itself?

login.gov is obviously a good idea. Can you imagine how awful government website's internal authentication software must be? This is like Auth0 for government agencies. It will probably be 10x worse than Auth0 but 10x better than the atrocities probably being committed right now.

Re: Government launches login.gov to simplify access to public services

#127

Earlier quoted context omitted.

To me, this is the right attitude towards this. Really? Are you more scared by your own democratic government than by facebook? Besides i'm not even american, so whatever

Well, yeah. I can choose to not use Facebook (for the most part). I can't choose to not use the federal government. Plus, disliking and being wary of government is quintessentially American—it goes back to our roots as a country. As an example that just popped into my head, look at DACA: a bunch of undocumented persons told the federal government about their undocumented status (in exchange for something good) and no…

Those are valid points, but I think they miss the point of the question: are you more scared about data security in an online identity provider provided by the government or Facebook et. al.?

Your answers were more about things the government can do to screw you over. It can do those things if your data is stored in Facebook as well: search warrants, compliance orders, subpoenas, etc. will all result in the government having access to your data unless strong encryption is used on your data (which, as we've seen with Apple, is still not enough sometimes).

I think (though I may be wrong) that the question had more to do with whether you trust this solution to be more secure against external/accidental breach than a solution offered by Facebook. I don't know the answer to that question, though.

Re: Government launches login.gov to simplify access to public services

#128

Earlier quoted context omitted.

> It's probably more difficult to coerce a private company into hacking its users, than it is for the NSA/FBI/IRS/Whatever to hack it's own system. This is a fantasy. I'm shocked to find people parroting this argument mere years after Snowden.

Don't you think it's easier for the government to hack its own code than someone else's ?

Maybe, but where "hacking someone else's" might just be issuing a search warrant, the difference in difficulties is like the difference between swatting a mosquito and swatting a gnat.

Re: Government launches login.gov to simplify access to public services

#129

Earlier quoted context omitted.

> Now seems like the time to set the expectation that this service may not ever be used by private websites. Oh shit! The government knows I bought something from custom-fishing-lures.com! Ruuuuun! Seriously, what you just listed is a reason not to use the government's Oauth for every website and ban all other implementations. What OP seemed to say, and what I disputed, is the idea that this service should not ever b…

Don't ever trust anyone who takes your stuff at the threat of violence.

This is the basis for the "taxation is theft" argument. It's very weak and wry.

The state exists as the means for ensuring positive societal outcomes, such as providing services that the private competitive market cannot or will not supply (tragedy of the commons, game theory, etc). One such possible service is an identity service - and we already have that through a hodge-podge of things like SSN, driving licenses, passports, etc. A consolidation of these services means greater efficiency, less waste, and therefore lower taxes.

I'd respect the libertarian position more if it were framed as "greater utility of government" instead of the dogmatic "less government".

Re: Government launches login.gov to simplify access to public services

#130
A total nit pick, but why do people have such a hard time consistently naming something as simple as a boolean variable? If we remember that naming is one of the hardest things in software engineering, why don't we put more thought into it?

From the documentation in the README: https://github.com/18F/identity-idp

  disable_email_sending: ‘true’
  enable_load_testing_mode: ‘true’
  telephony_disabled: ‘true’
Multiple directions, multiple naming conventions, strings?!?!?. Just seems like a recipe for failure. I feel like this would be more clear:

  load_testing_mode: true
  send_email: false
  telephony: false
When you write your conditionals, it makes it so much easier to read:

  if !disable_email_sending
     do_send_email
vs.

  if send_email
    do_send_email
Here is the line in actual use...

https://github.com/18F/identity-idp/blob/df549cf9a1fc2c21e3e...

I'd personally rather have the positive condition first as it is easier for me to follow logically in my head.

Post reply on HN