Live data from Hacker News

IRS to adopt Login.gov as user authentication tool

fedscoop.com

141–150 of 193 posts

Re: IRS to adopt Login.gov as user authentication tool

#141
post #136

Earlier quoted context omitted.

It's disingenuous as hell to clump "cities" together, as if going to Anacostia in DC is the same as going to Georgetown. If you live in a city and carry a gun, you're not protecting yourself, you're escalating the violence. Getting robbed is exceedingly rare anywhere in the US, and trying to stop a robbery with a gun is among the stupidest things a person can do. Further, robbing someone doesn't mean you should die,…

> It's disingenuous as hell to clump "cities" together, as if going to Anacostia in DC is the same as going to Georgetown. I don't understand what you're arguing. Cities unequivocally see more crime than rural areas, even in nicer areas within a city (which may only be 1 mile from the "bad parts"). > Getting robbed is exceedingly rare anywhere in the US, and trying to stop a robbery with a gun is among the stupidest…

Haha, yeah a lot of people are arguing that thieves should die.

And no, “cities“ are not one solid, unbroken group, they are not universally more dangerous than rural areas.

Re: IRS to adopt Login.gov as user authentication tool

#142

Earlier quoted context omitted.

Those steps were a prerequisite to get your NEXUS enrollment -- not to get a login.gov account. The only thing you have to do to enroll in login.gov is verify your email address. And optional feature of login.gov is to verify your identity further by uploading a photo of a state ID, and entering your SSN and phone number. When you validated your identity in person with CBP, this was not that.

> When you validated your identity in person with CBP, this was not that. This isn't snarking at you directly, just all I'm really hearing is that the government will happily mix whatever it knows about me for its own purposes but when it comes to making things easier for me (wherein they've literally seen me in person and looked over a stack of my identifying documents), no way that's "violating my privacy." If we a…

The premise of that sentiment is simply not true. There is no all-seeing panopticon. The government in the US is quite siloed. The federal government is pretty dang siloed itself, and the US is potentially the most siloed government on the planet if we also consider state and local governments.

Re: IRS to adopt Login.gov as user authentication tool

#143
post #114

Earlier quoted context omitted.

Well I consider for example requirement to carry ID in France as the schizophrenia or worse from the government side. Brings out the worst associations

In the United States you are pretty much required to give your name to police if they ask for it. They will run that name and if it's doesn't check out, match the picture on their computer, etc you will be arrested for providing a false name. In many states they can also demand you present photo identification and skip all of that. Practically speaking the United States has been a "papers please" country for a long t…

>"In the United States you are pretty much required to give your name to police if they ask for it. They will run that name and if it's doesn't check out, match the picture on their computer, etc you will be arrested for providing a false name. In many states they can also demand you present photo identification and skip all of that."

Stop and identify" statutes are laws in several U.S. states that authorize police to lawfully order people whom they reasonably suspect of a crime to state their name. If there is not reasonable suspicion that a crime has been committed, is being committed, or is about to be committed, an individual is not required to provide identification, even in these states

Re: IRS to adopt Login.gov as user authentication tool

#144

Earlier quoted context omitted.

I don't even think a HIPAA-covered entity could hold their data to the standard of zero-knowledge encryption... since, you know, they have to be able to use patient data.

in theory they could but I doubt most patients want to have to remotely authorize their provider any time someone wants to access their record.

In a healthcare context, the patient often may not physically be able to.

Re: IRS to adopt Login.gov as user authentication tool

#145

Earlier quoted context omitted.

in theory they could but I doubt most patients want to have to remotely authorize their provider any time someone wants to access their record.

They could authorize an agent to authorize provider usage. The agent could apply provider-specific policies, and potentially monitor record requests to try to identify fraud, waste, or abuse, and so forth. The patient regularly reviews a report of actions taken by the agent to adjust configuration or revoke authorization. Could be an interesting approach!

It also needs to be a system that is workable when you scrape an unconscious person off the street with no next-of-kin available. It's not possible to have the patient or their agent hold the sole key for data that is created before the patient/agent is first available. Really, the best you can do in that situation is exactly what HIPAA requires.

Re: IRS to adopt Login.gov as user authentication tool

#146

Earlier quoted context omitted.

They could authorize an agent to authorize provider usage. The agent could apply provider-specific policies, and potentially monitor record requests to try to identify fraud, waste, or abuse, and so forth. The patient regularly reviews a report of actions taken by the agent to adjust configuration or revoke authorization. Could be an interesting approach!

It also needs to be a system that is workable when you scrape an unconscious person off the street with no next-of-kin available. It's not possible to have the patient or their agent hold the sole key for data that is created before the patient/agent is first available. Really, the best you can do in that situation is exactly what HIPAA requires.

Good point, implied consent does make such a system unworkable.

Re: IRS to adopt Login.gov as user authentication tool

#147

Earlier quoted context omitted.

They could authorize an agent to authorize provider usage. The agent could apply provider-specific policies, and potentially monitor record requests to try to identify fraud, waste, or abuse, and so forth. The patient regularly reviews a report of actions taken by the agent to adjust configuration or revoke authorization. Could be an interesting approach!

It also needs to be a system that is workable when you scrape an unconscious person off the street with no next-of-kin available. It's not possible to have the patient or their agent hold the sole key for data that is created before the patient/agent is first available. Really, the best you can do in that situation is exactly what HIPAA requires.

Agent should not be individual it should be an third party service or organization( could even by governmental) which shouldn't have uptime concerns. The policy setup would be complex to do without expert assistance anyway.

Re: IRS to adopt Login.gov as user authentication tool

#148
post #37

Earlier quoted context omitted.

> The IRS system is, by far, the worst I've ever had to deal with That's by design

> That's by design It actually is, too. There are two large, influential groups of stakeholders who purposefully lobby for a painful user experience. The first, of course, is the tax-prep industry (e.g. Intuit/TurboTax and H&R Block). They make more money when people get fed up with bullshit and pay someone else to deal with it. The second is the anti-tax activists. If taxes exist, they want the process of taxation t…

I used TurboTax for the first time recently so I could file taxes to get my ACP discount for cheap Internet for poor people. I needed to file a $0 tax return, but where I received stimulus payments. Their system just got stuck in a horrible loop because I was in some weird edge case. Their first "expert" was terribly rude to me. Luckily the second guy was super nice and we hacked away at the UI until we found a way out. tl;dr: TurboTax is as clunky as the IRS

Re: IRS to adopt Login.gov as user authentication tool

#149
post #5

login.gov is open source! They also encrypt user data in a way that they can't access it without the user's password, precluding the formation of a national registry that could be used towards nefarious and anti-democratic purposes. As a result, account recovery looks a lot like re-registration, which I think is a great thing. https://github.com/18F/identity-idp It's built on Rails, and I'm really impressed at the en…

> login.gov is open source! They also encrypt user data in a way that they can't access it without the user's password, precluding the formation of a national registry that could be used towards nefarious and anti-democratic purposes

The website is still full of Google trackers, so it looks like it's already handing some user data over to private for-profit 3rd parties. Not a great sign, but I guess we can be happy we're not being forced to give them face-scans, fingerprints, or DNA I guess.

Re: IRS to adopt Login.gov as user authentication tool

#150
post #136

Earlier quoted context omitted.

> It's disingenuous as hell to clump "cities" together, as if going to Anacostia in DC is the same as going to Georgetown. I don't understand what you're arguing. Cities unequivocally see more crime than rural areas, even in nicer areas within a city (which may only be 1 mile from the "bad parts"). > Getting robbed is exceedingly rare anywhere in the US, and trying to stop a robbery with a gun is among the stupidest…

Haha, yeah a lot of people are arguing that thieves should die. And no, “cities“ are not one solid, unbroken group, they are not universally more dangerous than rural areas.

Where are they arguing that? We’re moved far away from OP. The original point that Americans “live in fear” is what I object to.

You’ve turned the conversation into something else entirely. You think the entire country of 350M lives in fear? Seriously? I get that HN loves to shit on Americans but what exactly is your point here?

My first comment says “many cities see crime” somehow that became “all cities see crime everywhere” in your mind.

Post reply on HN