Earlier quoted context omitted.
It also needs to be a system that is workable when you scrape an unconscious person off the street with no next-of-kin available. It's not possible to have the patient or their agent hold the sole key for data that is created before the patient/agent is first available. Really, the best you can do in that situation is exactly what HIPAA requires.
Agent should not be individual it should be an third party service or organization( could even by governmental) which shouldn't have uptime concerns. The policy setup would be complex to do without expert assistance anyway.
IRS to adopt Login.gov as user authentication tool
151–160 of 193 posts
Re: IRS to adopt Login.gov as user authentication tool
#152Earlier quoted context omitted.
In the United States you are pretty much required to give your name to police if they ask for it. They will run that name and if it's doesn't check out, match the picture on their computer, etc you will be arrested for providing a false name. In many states they can also demand you present photo identification and skip all of that. Practically speaking the United States has been a "papers please" country for a long t…
>"In the United States you are pretty much required to give your name to police if they ask for it. They will run that name and if it's doesn't check out, match the picture on their computer, etc you will be arrested for providing a false name. In many states they can also demand you present photo identification and skip all of that." Stop and identify" statutes are laws in several U.S. states that authorize police t…
Re: IRS to adopt Login.gov as user authentication tool
#153Earlier quoted context omitted.
The main issue is if it's required. Not so worried about myself - I'm a veteran which means my fingerprints and DNA are already on file with the feds somewhere :), but US Citizens with no particular connection to the federal government absolutely shouldn't have to need a "National ID."
And yet, everyone suffers because of it. We have endless SSN breaches because at the end of the day, having a unique ID for people is really valuable! We could have something way safer, but we get stuck with the status quo which satisfies no one.
Re: IRS to adopt Login.gov as user authentication tool
#154As mentioned in the article, the IRS had originally planned to use ID.me — a private company — before backing down. Previous discussion here: https://news.ycombinator.com/item?id=30126118
Re: IRS to adopt Login.gov as user authentication tool
#155Earlier quoted context omitted.
> They also encrypt user data in a way that they can't access it without the user's password I love how low our standards for government sites have gotten where this is seen as a plus and not something that's expected
My country lets me use Google's SSO (arguably should probably also support Apple and have better 2FA options) - why wouldn't yours? If someone wants to use facial recognition - why not? If someone wants to use insecure username/password and risk a compromise - let them do it. FWIW big tech has probably 99.99% of people's faces, I'd guess at least 90% is tied to an identity.
Re: IRS to adopt Login.gov as user authentication tool
#156Earlier quoted context omitted.
Agent should not be individual it should be an third party service or organization( could even by governmental) which shouldn't have uptime concerns. The policy setup would be complex to do without expert assistance anyway.
Maybe so, but that's a different thing than the zero-knowledge encryption that this branch of the comment thread was originally about.
Re: IRS to adopt Login.gov as user authentication tool
#157Try putting in 2 lower security passwords but then backspace deleting them and you get.
zxcvbn.feedback.use_a_few_words_avoid_common_phraseszxcvbn.feedback.no_need_for_symbols_digits_or_uppercase_letters
visible on the screen. I get it isn't a technical issue but still, doesn't give me confidence
Re: IRS to adopt Login.gov as user authentication tool
#158Issues with login.gov don't make me very confident. Try putting in 2 lower security passwords but then backspace deleting them and you get. zxcvbn.feedback.use_a_few_words_avoid_common_phraseszxcvbn.feedback.no_need_for_symbols_digits_or_uppercase_letters visible on the screen. I get it isn't a technical issue but still, doesn't give me confidence
Re: IRS to adopt Login.gov as user authentication tool
#159Earlier quoted context omitted.
I thought it was that login.gov does single-sign-on (SSO) and ID.me does SSO and identify verification at both the signup and sign-in level.
Login.gov absolutely cares about your identity. Case in point: login.gov will share your SSN to the provider(irs.gov in this case), if appropriate permissions are requested.
Re: IRS to adopt Login.gov as user authentication tool
#160Earlier quoted context omitted.
>"In the United States you are pretty much required to give your name to police if they ask for it. They will run that name and if it's doesn't check out, match the picture on their computer, etc you will be arrested for providing a false name. In many states they can also demand you present photo identification and skip all of that." Stop and identify" statutes are laws in several U.S. states that authorize police t…
I've had to identify myself for flipping off a cop (unmarked car) who honked his horn at me because he didn't like me exercising my freedom of movement. This power gets abused all the time.