login.gov is open source! They also encrypt user data in a way that they can't access it without the user's password, precluding the formation of a national registry that could be used towards nefarious and anti-democratic purposes. As a result, account recovery looks a lot like re-registration, which I think is a great thing. https://github.com/18F/identity-idp It's built on Rails, and I'm really impressed at the en…
The major problem with login.gov from the IRS' perspective is that it doesn't provide identity verification which is absolutely needed. We will see how they work around that, but they still may have to outsource that to someone like id.me.
IRS to adopt Login.gov as user authentication tool
181–190 of 193 posts
Re: IRS to adopt Login.gov as user authentication tool
#182Earlier quoted context omitted.
Interesting that you limit this claim to the century that saw two world wars and the largest ethnic extermination program in history. ID systems back then weren't any more thorough than the SSN every American is required to have and use for a litany of purposes today. I do not really see how replacing your SSN with a public/private key pair that you use to cryptographically sign tax returns, loan applications, or ele…
"ID systems back then weren't any more thorough than the SSN every American is required to have and use for a litany of purposes today" would imply that a more formal way to record IDs, namely a centralized database of personal information would be an even more efficient way for a government to top the largest ethnic extermination program in history. And before you say "but that can never happen!", stop for a second…
Unless you want to argue that the lack of security is a feature, and that rampant identity theft is somehow stopping the US government from perpetrating the next holocaust.
Re: IRS to adopt Login.gov as user authentication tool
#183Earlier quoted context omitted.
Ah yes. Good to know that it’s not just the TSA i should dislike. I’m reminded of the line Logan Roy uses on Succession, something along the lines of “when i arrived in America there was nothing these people couldn’t do. Now they’ve pissed it all away”. Feels like it’ll be hard to see the US continue to be a major player unless it can get out of its own away at some point.
Can you name some countries you think are "major players" if the US isn't or won't be? >it’s not just the TSA i should dislike. You should try interacting with Australian or Canadian border forces if you want to see a true organization you should dislike. Hard to see Australia or Canada being even minor players if they can't deal with that dysfunction.
I’m both Australian and Canadian, so maybe I’m bias but comparing them to the TSA is a stretch imo.
Re: IRS to adopt Login.gov as user authentication tool
#184Earlier quoted context omitted.
I'm American, and I firmly believe that anyone who carries a gun in their daily life is living in abject and completely irrational fear based on a fundamental, tragic innumeracy. And if you think me saying "And no, “cities“ are not one solid, unbroken group" means “all cities see crime everywhere”, you've gotten yourself very lost, friend.
This describes You seem to be lost yourself. What exactly do you disagree with me on from the original comment?
Re: IRS to adopt Login.gov as user authentication tool
#185Is this the same authentication platform that TreasuryDirect uses? edit - looks like no. On the one hand a single sign on to both would have been nice, OTOH TreasuryDirect's authentication system is a PITA.
TreasuryDirect, the site that has case-insensitive passwords, disallows password managers, disallows the use of your actual keyboard to enter your password, and has this dumb on-screen keyboard with tiny keys that ultimately accomplishes nothing? Super trash. It still amuses me how few people, even those who claim security expertise, don't understand that commercial malware is able to hook the driver stack (and or br…
Re: IRS to adopt Login.gov as user authentication tool
#186login.gov is open source! They also encrypt user data in a way that they can't access it without the user's password, precluding the formation of a national registry that could be used towards nefarious and anti-democratic purposes. As a result, account recovery looks a lot like re-registration, which I think is a great thing. https://github.com/18F/identity-idp It's built on Rails, and I'm really impressed at the en…
> login.gov is open source! They also encrypt user data in a way that they can't access it without the user's password, precluding the formation of a national registry that could be used towards nefarious and anti-democratic purposes The website is still full of Google trackers, so it looks like it's already handing some user data over to private for-profit 3rd parties. Not a great sign, but I guess we can be happy w…
Re: IRS to adopt Login.gov as user authentication tool
#187Earlier quoted context omitted.
It's not a good choice. The Canadian government still doesn't understand the internet. There should be no obligatory private intermediaries between a citizen and the government no matter online or offline. It should provide an online identity service, just like it already provides offline government-issued IDs (e.g. passports) without involving banks or other private institutions.
> There should be no obligatory private intermediaries between a citizen and the government no matter online or offline. As I stated in my post: > You can also create a stand-alone account with the CRA if you wish. See Option 2: * https://www.canada.ca/en/revenue-agency/services/e-services/... The provinces of Alberta and BC also have identity providers (since they issue driver licenses and health cards) which the CR…
You can't reuse the CRA login with all other government services. I'm talking about a single identity provider accepted by any government service, like a driver's license or a health card.
Re: IRS to adopt Login.gov as user authentication tool
#188I'm a foreigner (yes, I know, sorry, sorry) who is a "US Person" and thus needs to (and, to be perfectly clear, is happy to, I'm sorry, I'm not-sorry, I'm sorry about being not-sorry?) pay US income tax. The IRS system is, by far, the worst I've ever had to deal with, and in this I'm comparing the US to countries like Rwanda, where, for some weird reason, I'm also required to pay taxes. Getting an ITIN (sort-of like…
Re: IRS to adopt Login.gov as user authentication tool
#189Earlier quoted context omitted.
> login.gov is open source! They also encrypt user data in a way that they can't access it without the user's password, precluding the formation of a national registry that could be used towards nefarious and anti-democratic purposes The website is still full of Google trackers, so it looks like it's already handing some user data over to private for-profit 3rd parties. Not a great sign, but I guess we can be happy w…
Do you expect the government to host their own analytics? Should they maintain data centers, CDNs, and serve from their own AZ as well?
Yes. I do. There are alternatives to Google that work just fine (assuming they genuinely _need_ analytics in the first place). There's no reason using a government service should involve you handing data over to Google (or any private for-profit company).
Re: IRS to adopt Login.gov as user authentication tool
#190Earlier quoted context omitted.
> login.gov is open source! They also encrypt user data in a way that they can't access it without the user's password, precluding the formation of a national registry that could be used towards nefarious and anti-democratic purposes The website is still full of Google trackers, so it looks like it's already handing some user data over to private for-profit 3rd parties. Not a great sign, but I guess we can be happy w…
Do you expect the government to host their own analytics? Should they maintain data centers, CDNs, and serve from their own AZ as well?
No analyzing your citizens behavior on a government site (that you paid) should be done by private company's (to make money out of your data)...what a question....