IRS to ditch biometric requirement for online access
51–60 of 181 posts
Re: IRS to ditch biometric requirement for online access
#52“Login.gov is already used to access 200 websites run by 28 Federal agencies and over 40 million Americans have accounts,” Wyden wrote in a letter to the IRS today. “Unfortunately, login.gov has not yet reached its full potential, in part because many agencies have flouted the Congressional mandate that they use it, and because successive Administrations have failed to prioritize digital identity. The cost of this in…
If the IRS (or Sen. Wyden) is looking for a "core government service" which has been inappropriately commercialized, they might start with tax preparation.
Re: IRS to ditch biometric requirement for online access
#53Earlier quoted context omitted.
No third party/private solution is appropriate here. The government that oversees the issuing of these IDs and attests that they are sufficient for government use (Real ID) cannot themselves validate said ID? Corruption or incompetence are the only paths that lead to outsourcing federal identity verification.
The government cannot build a competent identity solution because a majority of voters believe that to do so presages something from genocide ("Papiere, bitte!") to the literal end of the world (“Mark of the Beast”).
Like no, I don't trust the government to protect the big bucket of PII on everyone in digital form. Not because of lizard people but because the government can barely keep it's own sites secure. Giving them more dangerous data in the form of bulk PII is the wrong move.
Login.gov was the first thing, in a long time, that was well executed. I need to see more things like that to restore my faith. ID.me is the wrong direction.
Re: IRS to ditch biometric requirement for online access
#54Earlier quoted context omitted.
If the IRS (or Sen. Wyden) is looking for a "core government service" which has been inappropriately commercialized, they might start with tax preparation.
This article[1] has more details. Sen. Wyden[2] has been pushing for more funding to IRS to develop its free file program, but Turbotax has been successful via their lobbying of Republican politicians and some Democratic politicians in preventing it from happening. 1. https://www.propublica.org/article/inside-turbotax-20-year-f... 2. https://www.nytimes.com/2021/07/19/opinion/intuit-turbotax-f...
Re: IRS to ditch biometric requirement for online access
#55Earlier quoted context omitted.
The government cannot build a competent identity solution because a majority of voters believe that to do so presages something from genocide ("Papiere, bitte!") to the literal end of the world (“Mark of the Beast”).
We are still in the same universe where the OPM breach happened, right? Like no, I don't trust the government to protect the big bucket of PII on everyone in digital form. Not because of lizard people but because the government can barely keep it's own sites secure. Giving them more dangerous data in the form of bulk PII is the wrong move. Login.gov was the first thing, in a long time, that was well executed. I need…
I do agree ID.me is the wrong approach. And login.gov should be used in some form over a private enterprise. But, my concern is two-fold… it’s a private entity that I don’t really want to do business with. And the process described by Krebs was impossible - can we really expect everybody to have email, valid phone (what if they aren’t the account owner for the phone), photo ID, and whatever else was required?
Re: IRS to ditch biometric requirement for online access
#56Earlier quoted context omitted.
All things being equal, the US government is simultaneously (1) the single most legitimate non-medical third party that needs to access my personal data, and (2) the single best entity to hold my data in terms of personal recourse . That's not saying much, but it is better than the open scorn and disrespect for my privacy that corporations offer. The solution to government breaches is what it's always been: to make t…
>the single best entity to hold my data in terms of personal recourse what type of recourse are you talking about? Voting your representatives out?
Re: IRS to ditch biometric requirement for online access
#57Earlier quoted context omitted.
No third party/private solution is appropriate here. The government that oversees the issuing of these IDs and attests that they are sufficient for government use (Real ID) cannot themselves validate said ID? Corruption or incompetence are the only paths that lead to outsourcing federal identity verification.
The only IDs issued widely by the US government are military credentials, immigration credentials, and passports. Driver’s licenses are issued by states and other entities. They are also fraught with problems as millions of people do not have REAL IDs, yet need to interact with government. The problem is that any bartender who has scanned your drivers license has the information required to scam an online validation…
I should not under any circumstances need to enter into a direct agreement with a private entity like id.me in order to access public services. The government might reasonably subcontract out some of the work, but public services need public accountability. The government service itself needs to be the direct counterparty to the public.
Re: IRS to ditch biometric requirement for online access
#58Re: IRS to ditch biometric requirement for online access
#59“Login.gov is already used to access 200 websites run by 28 Federal agencies and over 40 million Americans have accounts,” Wyden wrote in a letter to the IRS today. “Unfortunately, login.gov has not yet reached its full potential, in part because many agencies have flouted the Congressional mandate that they use it, and because successive Administrations have failed to prioritize digital identity. The cost of this in…
I was extremely confused when I was asked to create an ID.me account for IRS. I have implemented Login.gov for some projects and it's rather easy; I can't see why they'd choose something else.
Scanned my Driver's License at 200dpi.
"Unable to find a face in the image you uploaded."
Okay, 300dpi.
"Unable to find a face in the image you uploaded."
Huh.
Scan at 72dpi.
Success.
Scan back of DL at 72dpi.
"Unable to read barcode."
Scan back of DL at 200dpi.
"Unable to read barcode."
Scan at 300dpi.
Success.
What a shitshow.
Re: IRS to ditch biometric requirement for online access
#60The fact that this was even being considered shows how pitifully little anyone learned from the Equifax breach.
What lesson do you think organizations learned from that breach? (As it relates to this article.) The pattern I see is: 1. Company collects and stores private consumer info. 2. Company gets hacked. 3. Company share price unaffected. 4. Company sued in class-action lawsuit. 5. Company settles by offering discounted/free products to victims of the hack. ("A $50 value!") Lawyers make a few million. Result: company gets…