Live data from Hacker News

IRS to adopt Login.gov as user authentication tool

fedscoop.com

121–130 of 193 posts

Re: IRS to adopt Login.gov as user authentication tool

#121

Meanwhile, I’ve spent over a month trying to get verified as myself via ID.me and their broken process that can’t handle Americans living abroad, with foreign secondary documents. A typical round with customer service takes about a week, and then I was told that someone will be able to verify electric bills that aren’t in English, but then that turned out to be weeks ago and it’s yet to happen. This is all merely to…

Same here. I hate ID.me and their piece of crap system. Never managed to get it working after wasting so much time. Luckily, I don't _need it_, so at the end I just gave up and used different methods. Would hate it if I'm actually unemployed and had to use that terrible firm.

Re: IRS to adopt Login.gov as user authentication tool

#122

In Canada, the Canada Revenue Agency (CRA) allows you you to leverage existing relationships with banks and credit unions, "Sign-in Partners": * https://www.canada.ca/en/revenue-agency/services/e-services/... * https://www.canada.ca/en/revenue-agency/services/e-services/... * https://verified.me/government-sign-in-by-verified-me/ You can also create a stand-alone account with the CRA if you wish. Other federal agenci…

It's not a good choice. The Canadian government still doesn't understand the internet. There should be no obligatory private intermediaries between a citizen and the government no matter online or offline.

It should provide an online identity service, just like it already provides offline government-issued IDs (e.g. passports) without involving banks or other private institutions.

Re: IRS to adopt Login.gov as user authentication tool

#123
post #81

Earlier quoted context omitted.

How is it different from working with a private company? Lots of stakeholders? More documented testing procedures?

Someone said it best upthread: the incentives are different. If you are a leader in the bureaucracy, your incentive is to not personally fail, which is not the same as to succeed. There is an army of auditors waiting to question every decision, so the obvious way to avoid that is to not make any. Balancing the need to do something without deciding anything is an art of sorts.

Also, to be clear, those incentives aren't coming from within the bureaucracy. For example, let's say that a program tries to do something and it totally doesn't work. A news story about this will be roughly the same if $10,000 is spent as if $100,000 is spent as if $1,000,000 is spent.

That creates an incentive never to label anything a failure and just keep pumping good money after bad - that's how to avoid the negative article.

Re: IRS to adopt Login.gov as user authentication tool

#124

In Canada, the Canada Revenue Agency (CRA) allows you you to leverage existing relationships with banks and credit unions, "Sign-in Partners": * https://www.canada.ca/en/revenue-agency/services/e-services/... * https://www.canada.ca/en/revenue-agency/services/e-services/... * https://verified.me/government-sign-in-by-verified-me/ You can also create a stand-alone account with the CRA if you wish. Other federal agenci…

It's not a good choice. The Canadian government still doesn't understand the internet. There should be no obligatory private intermediaries between a citizen and the government no matter online or offline. It should provide an online identity service, just like it already provides offline government-issued IDs (e.g. passports) without involving banks or other private institutions.

> There should be no obligatory private intermediaries between a citizen and the government no matter online or offline.

As I stated in my post:

> You can also create a stand-alone account with the CRA if you wish.

See Option 2:

* https://www.canada.ca/en/revenue-agency/services/e-services/...

The provinces of Alberta and BC also have identity providers (since they issue driver licenses and health cards) which the CRA allows (Option 3).

Re: IRS to adopt Login.gov as user authentication tool

#125
post #86

Earlier quoted context omitted.

Isn't the US corporate standard even lower? Outside of maybe Google, Facebook, or HIPAA-covered entities. Corporate customer databases I've seen have rarely even been need-to-know access limited, much less actually encrypted to internal users.

I don't even think a HIPAA-covered entity could hold their data to the standard of zero-knowledge encryption... since, you know, they have to be able to use patient data.

in theory they could but I doubt most patients want to have to remotely authorize their provider any time someone wants to access their record.

Re: IRS to adopt Login.gov as user authentication tool

#126
post #114

Earlier quoted context omitted.

It's an example of American schizophrenia. No National ID because tyranny! Monitoring everyone constantly? That's keeping us safe!

Well I consider for example requirement to carry ID in France as the schizophrenia or worse from the government side. Brings out the worst associations

In the United States you are pretty much required to give your name to police if they ask for it. They will run that name and if it's doesn't check out, match the picture on their computer, etc you will be arrested for providing a false name. In many states they can also demand you present photo identification and skip all of that.

Practically speaking the United States has been a "papers please" country for a long time.

What we're talking about here is a standardized, national ID. It's currently a weird patchwork of driver's licenses, identification cards, etc - each of which are slightly different variants issued by each of the states. So we don't have a standardized national ID. We have at least 50 of them, all with different formats, different issuing criteria, different validity, etc. We've tried to have some bare minim standards for years (REAL ID act) but the mandatory compliance date for that keeps getting pushed (currently next year).

Re: IRS to adopt Login.gov as user authentication tool

#127
post #5

login.gov is open source! They also encrypt user data in a way that they can't access it without the user's password, precluding the formation of a national registry that could be used towards nefarious and anti-democratic purposes. As a result, account recovery looks a lot like re-registration, which I think is a great thing. https://github.com/18F/identity-idp It's built on Rails, and I'm really impressed at the en…

How does encrypting user data preclude nefarious and anti-democratic purposes?

If disabling your login.gov account locks you out of you bank account, the ability to travel, your library account, your email account, your social media accounts, your school, your children's school, your mortgage, your ability to pay your rent and utilities, your ability to seek employment, vote...

When your life is consolidated to SSO, your life is controlled by those who control the SSO service. The fact that they encrypt your data doesn't change that reality.

Re: IRS to adopt Login.gov as user authentication tool

#128
post #73

Earlier quoted context omitted.

> yet your entire life is accessible to the NSA. I'll bet you money that most Americans are not okay with this either.

They're nominally "not ok" with it, unless it's couched in some piece of legislation like the PATRIOT Act or snuck into a Defense Authorization Act, particularly after a national tragedy happens. Then a lot (a majority?) of Americans will suddenly be ok with the "if you got nothing to hide you got nothing to fear" mantra. I'm actually not a huge fan when people act like Americans are a a bunch of flag-waving morons,…

> "if you got nothing to hide you got nothing to fear" mantra.

I know people like this and it's not a good mantra to follow. I have to remind them that all that needs to happen is to have political winds go the other direction and soon something they do regularly becomes illegal or suspicious. So dumb to give up privacy for safety.

Re: IRS to adopt Login.gov as user authentication tool

#129

Earlier quoted context omitted.

I just wonder what kind of extra hoops we'll have to go through to use an existing login.gov account with the IRS. I read in some article somewhere that the IRS didn't use login.gov because it isn't "as verified" or some kind of thing as the IRS needs. Yet the reason I have a login.gov account is for my NEXUS enrollment which means I've been fingerprinted, background checked, had my passport number linked, and been i…

Those steps were a prerequisite to get your NEXUS enrollment -- not to get a login.gov account. The only thing you have to do to enroll in login.gov is verify your email address. And optional feature of login.gov is to verify your identity further by uploading a photo of a state ID, and entering your SSN and phone number. When you validated your identity in person with CBP, this was not that.

> When you validated your identity in person with CBP, this was not that.

This isn't snarking at you directly, just all I'm really hearing is that the government will happily mix whatever it knows about me for its own purposes but when it comes to making things easier for me (wherein they've literally seen me in person and looked over a stack of my identifying documents), no way that's "violating my privacy."

If we are going to have an all-seeing panopticon can't it at least be convenient?

Re: IRS to adopt Login.gov as user authentication tool

#130

Earlier quoted context omitted.

I don't even think a HIPAA-covered entity could hold their data to the standard of zero-knowledge encryption... since, you know, they have to be able to use patient data.

in theory they could but I doubt most patients want to have to remotely authorize their provider any time someone wants to access their record.

They could authorize an agent to authorize provider usage. The agent could apply provider-specific policies, and potentially monitor record requests to try to identify fraud, waste, or abuse, and so forth. The patient regularly reviews a report of actions taken by the agent to adjust configuration or revoke authorization. Could be an interesting approach!
Post reply on HN