Live data from Hacker News

IRS to ditch biometric requirement for online access

krebsonsecurity.com

131–140 of 181 posts

Re: IRS to ditch biometric requirement for online access

#131

“Login.gov is already used to access 200 websites run by 28 Federal agencies and over 40 million Americans have accounts,” Wyden wrote in a letter to the IRS today. “Unfortunately, login.gov has not yet reached its full potential, in part because many agencies have flouted the Congressional mandate that they use it, and because successive Administrations have failed to prioritize digital identity. The cost of this in…

That's debatable. login.gov would certainly be better than id.me, but a centralized database of everyone sounds like a problem in all cases. A unique identifier for everyone is the path to more social/technological control.

Here in France, some people from the anti-nazi resistance from the 40s later got into heated arguments about the national ID card, which had been made mandatory by the collaborationist regime. The idea is that if there were reliable/secure unique identifiers during WWII, the resistance movement could not have existed at all, and could not have saved countless lives.

To this day, France is one of the rare countries where it's perfectly legal to walk anywhere without any identifying document with you. This doesn't mean that you won't be harassed by fascist cops though, depending on what you look like.

I'm pretty much against fraud in the common sense of the word. But the biggest frauds are done by the rich and don't require to make up new identities. They're hidden in plain sight with lawyers and contracts with offshore corporations. I personally couldn't care that social services fraud costs the government some millions every year, when tax evasion and corrupt-government contracts (remember the Pentagon audit?) account for literally trillions going missing and nobody in government wants to do anything about that.

Re: IRS to ditch biometric requirement for online access

#133

Earlier quoted context omitted.

> I think we've fairly well established that the complexity of the code isn't the problem. The IRS knows what you owe and could just tell you if they wanted to. The IRS has no way to know which of your expenditures are tax-deductible.

If you think you can do better than the standard deductions, you’re more than welcome to itemize — just like today. Pretending that the current system is as good as it can get the for the vast majority of individuals is disingenuous. Just look at every other country that sends out prefilled forms.

> Pretending that the current system is as good as it can get the for the vast majority of individuals is disingenuous

Pretending the IRS "knows exactly what you owe and could just tell you" is just as disingenuous. In both cases, it's more complicated than that.

Re: IRS to ditch biometric requirement for online access

#134
post #26

Earlier quoted context omitted.

All things being equal, the US government is simultaneously (1) the single most legitimate non-medical third party that needs to access my personal data, and (2) the single best entity to hold my data in terms of personal recourse . That's not saying much, but it is better than the open scorn and disrespect for my privacy that corporations offer. The solution to government breaches is what it's always been: to make t…

Good point, gov has less reason to sell your data

Doesn’t stop usps for making money from spam, or from speed traps from being primarily dedicated to revenue from out of towners.

Re: IRS to ditch biometric requirement for online access

#135
post #119

Earlier quoted context omitted.

You pick AOC and Bernie as examples of people fighting for the middle class. AOC's Green New Deal would've destroyed the middle class. She probably means well, but she really is just a useful idiot.

Please evaluate your filters. If you believe this you are in a bubble. It’s the economic and historical equivalent of belief in a flat earth. The “New Deal” saved the middle class. A “green” new deal could do it again. We have an incredible need and opportunity to (re)build infrastructure in this country. That’s where the middle class can thrive. The green new deal was an olive branch as much as anything. An opportun…

You really did a good job at convincing me.

- assume my "filters" are wrong. A difference of opinions doesn't mean my filters are wrong. It simply means I made different conclusions. If you want to support AOC and her policies, go for it. I won't partake.

- believe I'm in a bubble. Right. That's why I'm on HN; because I'm in a bubble and you think exactly as I do?

- Now I believe in a flat earth. That's just a wasted comment.

- Pointing to the "New Deal" that "saved the middle class". It's highly debatable if the New Deal prolonged the Great Depression or not. While it helped many Americans keep food on the table, no doubt, it didn't stop the Great Depression. Regardless, I can turn around and say, I want the "____ New Deal", and it must be good because that's what I called it? That's a laughable concept.

By your measure, healthcare actually became more affordable after the Affordable Healthcare Act became law - because that's the title of the law?

Regardless, I agree that the infrastructure can be improved. My state is already doing it. They've rebuilt an interchange in record time because a bridge wall collapsed. What is your state doing?

Stating that everyone should have access to "high-quality health care" or "economic security" isn't an olive branch. Obviously no one disagrees with that. The discussion is "how", and that's the only important discussion to have.

But, if you want to stick with mudslinging and belittling those who disagree with you, go for it.

Re: IRS to ditch biometric requirement for online access

#136
Interesting news. But I see a lot of negative comments regarding the biometrics.

Here's my two cents.

I'm the founder of a biometric users identity check solution, called Typing AI Biometrics ( https://typing.ai ). We identify users by the way they type. Typing biometrics can be used as a two factor (2FA) or multi factor (MFA) authentication method.

Instead of combining the usual username + password with an OTP code that you recive on your smartphone or email, you can combine the basic username + password with a typing pattern check, it's much more secure and efficient. The typing signature translated into a 300+ encrypted characters hash, which is (up until now) impossible to break.

You can even remove the username + password and combine the typing biometrics check (known as keystroke dynamics) with an OTP verification. Biometrics are the future of authentication and authorization, because they are unique to each person, but only with the promise of not keeping and sharing the users data.

You can AMA on this Show HN thread: https://news.ycombinator.com/item?id=30130447

Re: IRS to ditch biometric requirement for online access

#137
post #136

Interesting news. But I see a lot of negative comments regarding the biometrics. Here's my two cents. I'm the founder of a biometric users identity check solution, called Typing AI Biometrics ( https://typing.ai ). We identify users by the way they type. Typing biometrics can be used as a two factor (2FA) or multi factor (MFA) authentication method. Instead of combining the usual username + password with an OTP code…

So then, I need to type the same password the same way every time?

If I set up an account while I'm still waking up, and then try to use it after lunch and coffee, wouldn't I get locked out due to inputting faster than expected?

Or what if I'm on the phone with someone, and trying to type with one hand? That would probably lock me out, right?

Re: IRS to ditch biometric requirement for online access

#138
post #126

I recently needed to access some information on the IRS website, and had to do a 3 hour, very annoying, ID.me registration. Everything failed. The OCR software thought the issue date of my passport was my birthday (so I wasn't old enough to register), fail. The 'link' they send via SMS to take photos of your ID, failed (wouldn't load). A VPN was needed to do some steps from outside the US. I was kicked out of the 'qu…

I’m glad you mentioned the spam from id.me. When I first came across it a few years ago I thought it was a scam due to the heavy marketing of third party “deals” on the site. Not a good look.

Re: IRS to ditch biometric requirement for online access

#139

Earlier quoted context omitted.

This is a really good point - if the tax code were a few dozen pages for the common case instead of a few hundred , then you might not even need tax-prep software in the first place. "The best program is the one that doesn't exist", to quote a popular refrain. Ongoing software projects require periodic refactoring to reduce complexity and increase comprehension - why would the law be any different?

I think we've fairly well established that the complexity of the code isn't the problem. The IRS knows what you owe and could just tell you if they wanted to. Having citizens exposed directly to the mechanics of it during the filing process is a policy choice and the way to fix that is to change the policy, not try to reinvent the tax code from first principles. This is a complex set of laws yes but it is also detail…

> I think we've fairly well established that the complexity of the code isn't the problem.

I've never heard this claimed before; I'm interested to see your evidence, because it's also not obviously true.

Re: IRS to ditch biometric requirement for online access

#140

What was the vendor selection process for ID.me? Their UX, privacy, and security practices seem terrible. What’s the real story on how ID.me became so pervasive in the public sector with such a terrible product?

They are FedRAMP moderate, which follows NIST SP 800-53, so it can't be that bad?
Post reply on HN