Live data from Hacker News

Government launches login.gov to simplify access to public services

18f.gsa.gov

161–170 of 173 posts

Re: Government launches login.gov to simplify access to public services

#161

In case you are wondering how it handles password encryption and storage, it appears to use a custom password hash based on SHA256 and scrypt: https://github.com/18F/identity-idp/blob/980c2aa26397f530673... Passwords appear to be stored in the users table in the "encrypted_password" column, and it does not appear that any database-based security is used. This is one RCE/SQLI vulnerability away from exposing the passw…

Based upon the various negative findings by the GSA IG's office I don't expect much from 18F. If you can't be bothered to comply with required government IT security requirements why should I trust you to comply with the ones you have made up for yourself.

Re: Government launches login.gov to simplify access to public services

#162

Earlier quoted context omitted.

Well, yeah. I can choose to not use Facebook (for the most part). I can't choose to not use the federal government. Plus, disliking and being wary of government is quintessentially American—it goes back to our roots as a country. As an example that just popped into my head, look at DACA: a bunch of undocumented persons told the federal government about their undocumented status (in exchange for something good) and no…

Those are valid points, but I think they miss the point of the question: are you more scared about data security in an online identity provider provided by the government or Facebook et. al.? Your answers were more about things the government can do to screw you over. It can do those things if your data is stored in Facebook as well: search warrants, compliance orders, subpoenas, etc. will all result in the governmen…

I like the other commenter's remarks about warrants.

> are you more scared about data security in an online identity provider provided by the government or Facebook et. al.?

Fair question. I'd still choose Facebook, mostly because they have an economic incentive not to screw it up. The government, on the other hand, has no such incentives. I mean, I trust both about as far as I can throw them, but at least one stays in business by practicing good security.

Re: Government launches login.gov to simplify access to public services

#163
post #159
post #140

Earlier quoted context omitted.

With the government you have free speech rights, so you can sue them if they close your account. With private companies you have no free speech rights and they can close your account whenever they want. So account closure seems like a positive point of government-controlled login.

Look up the secrecy and lack of oversight over the so-called "terrorist" watchlist and the calls for scope creep, and see if you are so confident about those first amendment rights. I'm sure failure to log in would not be considered a first amendment right. I agree that the government should be a far more dependable provider than any private sector organization. But the recent (last 20 years) enthusiasm for scope cre…

Does the government deny passports or driver licenses/IDs to people on those lists? Because that would be the equivalent here.

I'm not saying the government wouldn't do it. I'm saying you would have constitutional basis to sue, which you don't have for companies.

Some lawsuits against the no fly list have been successful. https://www.aclu.org/blog/national-security/victory-no-fly-l...

Re: Government launches login.gov to simplify access to public services

#164

This appears valuable and well executed, but I worry that private businesses will be eager to outsource their authentication to this service, if they are allowed to. And once it's fully stood up, I suspect the government would be all too eager to oblige. This might be convenient, but might also mark the beginning of a major new point of U.S. government control over the Internet, with all the surveillance and other ci…

It's much easier to technically enforce that this doesn't get used with private sites than tell people not to use SSNs

Re: Government launches login.gov to simplify access to public services

#165
post #3

Earlier quoted context omitted.

Its important to remember that login.gov isn't an account its an Identity Provider. It will allow you to prove to an agency that you are who you say you are, but all the account information will be stored by the agency.

Will it? Apparently login.gov doesn't even ask for your real name?

Sure, but other services using it will. And the login.gov account will be a handy new primary key for relating disparate databases across government resources.

Re: Government launches login.gov to simplify access to public services

#166

Earlier quoted context omitted.

Those are valid points, but I think they miss the point of the question: are you more scared about data security in an online identity provider provided by the government or Facebook et. al.? Your answers were more about things the government can do to screw you over. It can do those things if your data is stored in Facebook as well: search warrants, compliance orders, subpoenas, etc. will all result in the governmen…

The point is, a warrant is a tiny bit more difficult to get than no warrant. Having all that data on their own site bypasses the need for one.

True, but having all the data on the government's site may (may) make it more secure from being leaked to sources other than the government. This isn't a statement of the government's software quality, but one of incentives: large private companies have not, historically, suffered much (legally or in terms of growth/revenue) from data breaches. The government losing data that it has independent reasons to keep safe is probably a larger perceptual risks, since government departments/funding can be suddenly cut in the wake of disasters of this nature, and elections can be lost. TL;DR the feedback loop for bad security might be more direct if the government is the one doing the securing. That's a troublesome prospect in several regards, but is plausible, I think.

Re: Government launches login.gov to simplify access to public services

#167
post #110

Earlier quoted context omitted.

I know very well how oauth works, thanks, but I'm not sure why you thought that had anything to do with my comment. The invasion of privacy comes from websites insisting on knowing who I am and refusing to allow me to make anonymous/pseudonymous accounts. If there's a convenient API to do so provided by the government, that's bad for users. > Only the ones where you chose to use their service. There are hundreds of w…

> your skepticism on this topic is wildly miscalibrated The reason I'm not worried about the government finding out which websites I visit is because they already know, from traffic inspection at the ISP level. Don't think I'm the one miscalibrated here. Beyond that, the problem with this "but they might do something bad!" argument is not that it's false, it's that it's always true in every case. Literally every gove…

Speak for yourself. It's non-trivial (in fact, very challenging) for the government to identify which websites I use. I don't have to put in much work to make this happen. If everyone started requiring the use of a dragnet surveillance program just to log in to services, it would become next to impossible to protect yourself.

Re: Government launches login.gov to simplify access to public services

#168
post #84

Earlier quoted context omitted.

I'm pretty certain they can already do that though.

How?

Through all the drag net surveillance the NSA performs and using tools like those unveiled by Snowden and other whistleblowers.

Re: Government launches login.gov to simplify access to public services

#169
post #167

Earlier quoted context omitted.

> your skepticism on this topic is wildly miscalibrated The reason I'm not worried about the government finding out which websites I visit is because they already know, from traffic inspection at the ISP level. Don't think I'm the one miscalibrated here. Beyond that, the problem with this "but they might do something bad!" argument is not that it's false, it's that it's always true in every case. Literally every gove…

Speak for yourself. It's non-trivial (in fact, very challenging) for the government to identify which websites I use. I don't have to put in much work to make this happen. If everyone started requiring the use of a dragnet surveillance program just to log in to services , it would become next to impossible to protect yourself.

> If everyone started requiring the use of a dragnet surveillance program just to log in to services, it would become next to impossible to protect yourself.

Yes, this is true. If all websites start requiring their visitors to do something their visitors overwhelmingly don't want, the result would be something their visitors don't want. Kind of suggests that they won't do that, yes?

We will probably have to agree to disagree here; you're imagining a world where oauth.fed.gov slowly becomes more and more widespread until it's ubiquitous and we have no other options, and that just doesn't sound realistic to me. (I think it would struggle for adoption even if it were implemented perfectly and had the best privacy controls possible, due to exactly the fears you're enumerating in this discussion) But we are talking about something hypothetical, so either of us could be right.

At any rate thanks for arguing forcefully but staying respectful and on topic!

Re: Government launches login.gov to simplify access to public services

#170
post #167

Earlier quoted context omitted.

Speak for yourself. It's non-trivial (in fact, very challenging) for the government to identify which websites I use. I don't have to put in much work to make this happen. If everyone started requiring the use of a dragnet surveillance program just to log in to services , it would become next to impossible to protect yourself.

> If everyone started requiring the use of a dragnet surveillance program just to log in to services, it would become next to impossible to protect yourself. Yes, this is true. If all websites start requiring their visitors to do something their visitors overwhelmingly don't want, the result would be something their visitors don't want. Kind of suggests that they won't do that, yes? We will probably have to agree to…

Users generally hate Facebook login but sites use it anyway because it's good for advertising and lets them outsource fraud avoidance to Facebook. The same and more benefits (to sites, not users) apply to government provided auth.

Again, please look at what's happening in South Korea. I think you're vastly underestimating how likely businesses are to adopt such a thing and how likely the government is to gradually incentivize (and eventually force) businesses into using it.

Post reply on HN