Live data from Hacker News

IRS to adopt Login.gov as user authentication tool

fedscoop.com

91–100 of 193 posts

Re: IRS to adopt Login.gov as user authentication tool

#91
post #66

Earlier quoted context omitted.

Sorry, I'm not blurring my ITIN with immigration status or whatever. I have not visited the US since 2004, I have no desire to return, and I have not done any business there since 2002. I just want an ITIN that is, like, actually in my name. Plus the IRS to agree that I do not owe any taxes in the 20-or-so ITINs that they have issued in various misspelled variations of my name. But yeah, to get any clarity, I apparen…

Sounds like there’s a lot more to your story than you’ve shared here.

Thanks for the passive-aggressive accusation there!

So, what more is there, exactly, to my story? My name is pretty simple, but, like many European names, has 3 parts, as well as some 'unexpected' letter combinations.

As far as I know, you can only request an ITIN by phone. Possibly, this can also be done online now, but that wasn't the case in the 1999-2009 period that I'm talking about here.

Also, the person that answers the phone... how do I say this? Is not exactly fluent in English... Or Spanish (which I can at least spell my name in as well)... Or any human language?

So, you get a new ITIN, with a random ASCII string as a name. And, to file a valid tax form, your ITIN needs to match your name... Which you provide in a PDF.

See where the problem lies here? You want me to upload a few scans of US government letters/forms with my actual name horribly misspellt? You want to see my attorney invoices? Certified PDFs only, I assume?

What, exactly, is the burden of proof you place upon me here?

Re: IRS to adopt Login.gov as user authentication tool

#92
post #21

Earlier quoted context omitted.

And yet, everyone suffers because of it. We have endless SSN breaches because at the end of the day, having a unique ID for people is really valuable! We could have something way safer, but we get stuck with the status quo which satisfies no one.

Use revokable public/private keypairs. The two options presented before my comment are not the only ones.

I'd be perfectly fine with that. My ideal scenario would essentially be a national ID that's also a smart card with u2f/federation. I realize there's a ton of details with accessibility but like, we have the technology.

Re: IRS to adopt Login.gov as user authentication tool

#93

Earlier quoted context omitted.

When it comes down to it the US has a fear driven culture, down to what essentially becomes paranoia. US violent crime statistics are at near all-time lows. Yet I know many, many people that will not leave their house without at least one firearm. This is in small towns that haven't seen a violent crime justifying the use of deadly force in many years. Many of these same people refuse to "live in fear" of the coronav…

The NSA acting like a creepy Big Brother-secret police organization is a separate issue.

It's an example of American schizophrenia. No National ID because tyranny! Monitoring everyone constantly? That's keeping us safe!

Re: IRS to adopt Login.gov as user authentication tool

#94
post #17

Has anyone here worked on government websites or APIs? I'm curious what the experience was like.

I spent a couple of years with the USDS (https://usds.gov/). USDS, along with 18F, are largely responsible for login.gov, as well as a lot of other really great projects. Overall fantastic experience if you're open to an adventure!

I could probably spend a week telling war stories, but the main takeaway is that you can't look at government as just another sector waiting to be brought up to speed. Government is an entire industry unto itself, with incentives that seem fully alien to anyone from the private sector. Money doesn't flow according to the laws of capitalist physics, but by byzantine congressional allocation. Understanding how things actually get done requires a ton of time, networking, study, and empathy.

Career government techies are extremely risk adverse (for a lot of very good reasons). If you want to make an impact, it helps to be able to take on a lot of the risk that nobody else wants to. For me, that meant promoting open-source alternatives to various entrenched products (cough, MS Access, cough) and accepting all the blame if the higher-ups don't like it. For this reason, it helps not to look at this as a career.

Going up against the entrenched interests can be frustratingly hard. It feels like everything is subtly working against you. Or, not so subtly- On more than one occasion I had teammates get singled out by the federal IT press. Somehow I managed to stay anonymous, but the threat was there. Fortunately, I felt a strong sense of support from my bosses, as well as a lot of righteous fury from seeing so many failed, hundred million dollar projects that could have just been a simple web app.

Granted, it's been about five years since I was in government. I would be curious to know if things are different nowadays :)

Re: IRS to adopt Login.gov as user authentication tool

#95
post #86

Earlier quoted context omitted.

> They also encrypt user data in a way that they can't access it without the user's password I love how low our standards for government sites have gotten where this is seen as a plus and not something that's expected

Isn't the US corporate standard even lower? Outside of maybe Google, Facebook, or HIPAA-covered entities. Corporate customer databases I've seen have rarely even been need-to-know access limited, much less actually encrypted to internal users.

I don't even think a HIPAA-covered entity could hold their data to the standard of zero-knowledge encryption... since, you know, they have to be able to use patient data.

Re: IRS to adopt Login.gov as user authentication tool

#96
post #69

Earlier quoted context omitted.

I know you're just sharing your anecdote, but the vast majority (over 80%) of Americans live in urban areas. Many cities do in fact see violent crime. Although I don't own a firearm myself, I totally understand why someone else would want one in my neighborhood. Violent crime is not unusual where I live. Don't let your bubble from small town USA distort your view of the entire country.

You are still quite unlikely to be a victim of violent crime by a stranger if you are not actively involved in the drug trade in the city. Violent crime rates in the city very low relative to the past. You are much more likely to be injured or killed in a suburban car accident than an urban assault/murder/mugging.

Exactly. In my age range (25-44) I'm more likely to die by heart disease (9.8%), cancer (10%), suicide (11%, most by firearm), and unintentional injury (34.2%) (plus "other" at 20%). Homicide is the cause of 6.2% of deaths in my age range and in the highest percentage of the population (10-24) it's still outpaced by suicide and unintentional injury. After age 45 homicide isn't even in the top 10.

https://www.cdc.gov/nchs/data/nvsr/nvsr70/nvsr70-09-508.pdf

Re: IRS to adopt Login.gov as user authentication tool

#97
post #9

The VA still uses ID.me - so most veterans have an account anyway (I needed one to get a certificate of eligibility for a VA home loan). I had to add an authorization for the IRS on my ID.me to stop the child credit advance checks from coming last year (that should have never been an opt-out). I also had a few other govt systems I needed to access when I was a defense worker that used it. So hopefully other agencies…

ID.me was founded by two veterans, so unlikely to move off of that anytime soon.

Re: IRS to adopt Login.gov as user authentication tool

#99

If you use Customs and Border Patrol's trusted traveler programs (or some other gov sites), you may already have a login.gov account since that is what they have been using for a few years now.

I just wonder what kind of extra hoops we'll have to go through to use an existing login.gov account with the IRS. I read in some article somewhere that the IRS didn't use login.gov because it isn't "as verified" or some kind of thing as the IRS needs. Yet the reason I have a login.gov account is for my NEXUS enrollment which means I've been fingerprinted, background checked, had my passport number linked, and been i…

Those steps were a prerequisite to get your NEXUS enrollment -- not to get a login.gov account.

The only thing you have to do to enroll in login.gov is verify your email address.

And optional feature of login.gov is to verify your identity further by uploading a photo of a state ID, and entering your SSN and phone number. When you validated your identity in person with CBP, this was not that.

Re: IRS to adopt Login.gov as user authentication tool

#100
post #40
post #33

Earlier quoted context omitted.

Yes, but WHY? I mean, I'm happy to pay my US taxes. Heck, I'm even happy to pay someone to pay my US taxes. But... neither of those options seem to work? I mean, just to back to Rwanda: it's an east-African country that is pretty much a dictatorship and had a real-life genocide less than 20 years ago. Yet, in Rwanda, I can just use my native cell phone number as my tax identifier, pay then what I need to pay, and be…

There are some groups who oppose effectively all taxes and seek to make paying tax as hard as possible so that other people will agree with them that taxes are a pain. For example see Americans for Tax Reform working to torpedo California’s push to simplify state taxes a few years back. You also have corporate interests that profit from convoluted tax filing and lobby the government to keep it confusing so individual…

Is it possible to sue for conspiring to make life purposely difficult? For example if I interfere with someone's lawful use / enjoinment of their property it is a low level criminal offence. Should not that be the same for making / conspiring the life difficult for the purpose of extorting money?
Post reply on HN