“Login.gov is already used to access 200 websites run by 28 Federal agencies and over 40 million Americans have accounts,” Wyden wrote in a letter to the IRS today. “Unfortunately, login.gov has not yet reached its full potential, in part because many agencies have flouted the Congressional mandate that they use it, and because successive Administrations have failed to prioritize digital identity. The cost of this in…
IRS to ditch biometric requirement for online access
11–20 of 181 posts
Re: IRS to ditch biometric requirement for online access
#12What I would like to see next is an investigation into why this process was considered at all and how the vendor was selected. I find this entire situation deeply suspicious, since MOST online services (including financial services) do not need this kind of invasive verification process and do not require interfacing with a random third-party. My cynical guess is that id.me has some connection (like via political don…
Let us also find out why a non governmental entity is handling security screenings:
Re: IRS to ditch biometric requirement for online access
#13“Login.gov is already used to access 200 websites run by 28 Federal agencies and over 40 million Americans have accounts,” Wyden wrote in a letter to the IRS today. “Unfortunately, login.gov has not yet reached its full potential, in part because many agencies have flouted the Congressional mandate that they use it, and because successive Administrations have failed to prioritize digital identity. The cost of this in…
Re: IRS to ditch biometric requirement for online access
#14The fact that this was even being considered shows how pitifully little anyone learned from the Equifax breach.
The pattern I see is:
1. Company collects and stores private consumer info.
2. Company gets hacked.
3. Company share price unaffected.
4. Company sued in class-action lawsuit.
5. Company settles by offering discounted/free products to victims of the hack. ("A $50 value!") Lawyers make a few million.
Result: company gets more users' info as they sign up to claim the discounted products.
Sounds like a good deal if the company is too big to fail.
Re: IRS to ditch biometric requirement for online access
#15Re: IRS to ditch biometric requirement for online access
#16the core of the thought is -- if the government interaction is flawed such that it is not actually doing only what it says it is doing, to the detriment of most ordinary people, and is subject to insider gaming with rewards to do so THEN additional and perhaps draconian requirements on the ordinary individual, do not solve the flaws, burden and antagonize an ordinary person, and the implementation becomes a new attention target WITH new penalties attached, for the ordinary person. hth
--
American here
"perhaps better known as the online identity verification service that many states now use to help staunch the loss of billions of dollars in unemployment insurance and pandemic assistance stolen each year by identity thieves"
In the great State of California, billions in unemployment benefits were sent to the wrong people.. because their internal systems were designed to delay, deny and deprive, I say. Actual people with real jobs were repeatedly refused, while insiders who knew how to fill out paperwork, and apparently knew where the blind spots were, filed hundreds of claims in the early pandemic days. A newly appointed Director (young, tech savvy woman) soon stopped making public statements, and the situation nearly two years later, is not resolved. This is at a time when California has record income to the State.
Now, some people may jump on this and say "well, you see how photo ID would have helped that" and, with incomplete knowledge and personal opinion, I say no, it would not solve it. You see, people with real jobs, with every real paper filed, were denied benefits, while insiders were pulling checks with both hands, using certain kinds of identities that would slip through. How would ever more restriction, requirement and verification, have helped here?
I am deeply against the collective government making ever more demands on citizens for "papers, please" enrollment to massive money social services (edit e.g. govt unemployment benefits). It is not going to have the desired effect, despite superficial evidence otherwise. Additionally this represents a slippery slope where the ability to interact as an individual will be eroded, and opportunity for insider graft will increase
Re: IRS to ditch biometric requirement for online access
#17124 comments about a week back: https://news.ycombinator.com/item?id=30126118
Treasury reconsiders IRS’s use of ID.me face recognition for web - https://news.ycombinator.com/item?id=30126118 - Jan 2022 (121 comments)
IRS Will Require Facial Recognition Scans to Access Your Taxes - https://news.ycombinator.com/item?id=30011145 - Jan 2022 (20 comments)
IRS Will Soon Require Selfies for Online Access - https://news.ycombinator.com/item?id=29996614 - Jan 2022 (428 comments)
Re: IRS to ditch biometric requirement for online access
#18“Login.gov is already used to access 200 websites run by 28 Federal agencies and over 40 million Americans have accounts,” Wyden wrote in a letter to the IRS today. “Unfortunately, login.gov has not yet reached its full potential, in part because many agencies have flouted the Congressional mandate that they use it, and because successive Administrations have failed to prioritize digital identity. The cost of this in…
I was extremely confused when I was asked to create an ID.me account for IRS. I have implemented Login.gov for some projects and it's rather easy; I can't see why they'd choose something else.
Login.gov is a fine authentication service, but cannot deliver the identity assurance level (IAL-2) required to identify people. (It may not be able to deliver AAL-2 authentication soon either as standard evolve.) Uploading a picture of your drivers license is not a meaningful validation of your identity.
The reaction of the Senators here is the equivalent of “I’m shocked to hear there is gambling happening here”. Typical pandering. Literally every drivers license and ID in the country is running through a biometric identity provider run by a contractor to identity duplicate licenses. Many DMVs outsource credential production to a third party.
I don’t think ID.me is the best solution, but it is better than providing a trivially stolen number “what was your AGI last year” that facilitates billions of dollars of fraud annually.
Re: IRS to ditch biometric requirement for online access
#19The fact that this was even being considered shows how pitifully little anyone learned from the Equifax breach.
Forget Equifax ... how about the Office of Personnel Management? People may well have lost their lives as a result. We may not know for decades. https://www.lawfareblog.com/why-opm-hack-far-worse-you-imagi... Oh, and the IRS has already been breached at least once. I'm not wild about waiting for the next one. Maybe government is not the best group to be holding your personal data. https://www.nytimes.com/2015/05/27/b…
The solution to government breaches is what it's always been: to make the breached data less valuable. Hacking the IRS would be significantly less appealing if we criminalized corporate use of SSNs as credentials.
Re: IRS to ditch biometric requirement for online access
#20The fact that this was even being considered shows how pitifully little anyone learned from the Equifax breach.
Hopefully id.me will get booted from other government agencies as well.