Live data from Hacker News

IRS to ditch biometric requirement for online access

krebsonsecurity.com

1–10 of 181 posts

Re: IRS to ditch biometric requirement for online access

#3
What I would like to see next is an investigation into why this process was considered at all and how the vendor was selected. I find this entire situation deeply suspicious, since MOST online services (including financial services) do not need this kind of invasive verification process and do not require interfacing with a random third-party. My cynical guess is that id.me has some connection (like via political donations) to those who had the power to effect this change.

It also looks like many states use id.me for various purposes (example https://www.reuters.com/business/states-using-idme-rival-ide...). I would also want those decisions revisited and investigated.

Re: IRS to ditch biometric requirement for online access

#4
Success is possible. Fingers crossed Login.gov is the solution they’re moving to [1]. Big thanks to everyone who complained to the IRS or their Congressional reps.

Onward to yeeting ID.me from state and local government next [2].

[1] “The IRS will also continue to work with its cross-government partners to develop authentication methods that protect taxpayer data and ensure broad access to online tools.” (From IRS’ press release on the topic in a sibling comment)

[2] https://www.gsa.gov/blog/2021/02/18/logingov-to-provide-auth...

Re: IRS to ditch biometric requirement for online access

#6
“Login.gov is already used to access 200 websites run by 28 Federal agencies and over 40 million Americans have accounts,” Wyden wrote in a letter to the IRS today. “Unfortunately, login.gov has not yet reached its full potential, in part because many agencies have flouted the Congressional mandate that they use it, and because successive Administrations have failed to prioritize digital identity. The cost of this inaction has been billions of dollars in fraud, which has in turn fueled a black market for stolen personal data, and enabled companies like ID.me to commercialize what should be a core government service.”

not great!

Re: IRS to ditch biometric requirement for online access

#10

The fact that this was even being considered shows how pitifully little anyone learned from the Equifax breach.

Forget Equifax ... how about the Office of Personnel Management? People may well have lost their lives as a result. We may not know for decades.

https://www.lawfareblog.com/why-opm-hack-far-worse-you-imagi...

Oh, and the IRS has already been breached at least once. I'm not wild about waiting for the next one. Maybe government is not the best group to be holding your personal data.

https://www.nytimes.com/2015/05/27/business/breach-exposes-i...

Post reply on HN