Live data from Hacker News

IRS to adopt Login.gov as user authentication tool

fedscoop.com

101–110 of 193 posts

Re: IRS to adopt Login.gov as user authentication tool

#101

They should keep the data from id.me and migrate it instead of making people who used id.me sign up and verify all over again.

id.me probably wrote not doing this into their contract to prevent the IRS from trying to break it.

Re: IRS to adopt Login.gov as user authentication tool

#102
post #86

Earlier quoted context omitted.

> They also encrypt user data in a way that they can't access it without the user's password I love how low our standards for government sites have gotten where this is seen as a plus and not something that's expected

Isn't the US corporate standard even lower? Outside of maybe Google, Facebook, or HIPAA-covered entities. Corporate customer databases I've seen have rarely even been need-to-know access limited, much less actually encrypted to internal users.

Absolutely. People do what they need, no more.

It’s getting better as people shift to cloud and inherit better controls, or implement better controls for cost avoidance reasons.

Re: IRS to adopt Login.gov as user authentication tool

#103
post #15

I'm a foreigner (yes, I know, sorry, sorry) who is a "US Person" and thus needs to (and, to be perfectly clear, is happy to, I'm sorry, I'm not-sorry, I'm sorry about being not-sorry?) pay US income tax. The IRS system is, by far, the worst I've ever had to deal with, and in this I'm comparing the US to countries like Rwanda, where, for some weird reason, I'm also required to pay taxes. Getting an ITIN (sort-of like…

[deleted]

Re: IRS to adopt Login.gov as user authentication tool

#104
post #5

login.gov is open source! They also encrypt user data in a way that they can't access it without the user's password, precluding the formation of a national registry that could be used towards nefarious and anti-democratic purposes. As a result, account recovery looks a lot like re-registration, which I think is a great thing. https://github.com/18F/identity-idp It's built on Rails, and I'm really impressed at the en…

That's assuming what's in the repo is the same code that is deployed.

Re: IRS to adopt Login.gov as user authentication tool

#105
Meanwhile, I’ve spent over a month trying to get verified as myself via ID.me and their broken process that can’t handle Americans living abroad, with foreign secondary documents. A typical round with customer service takes about a week, and then I was told that someone will be able to verify electric bills that aren’t in English, but then that turned out to be weeks ago and it’s yet to happen. This is all merely to set the stage for being ELIGIBLE for a human to do a video conference verification with me, which they hopefully will deign to do.

A singular corporation (ID.me) holds every American’s ability to login to their government tax profile hostage, and we pay them for the pleasure of this rotten monopoly and abuse of public trust. I just want to pay my taxes, sigh. It should be as easy as any other bill or process. Making taxpayers suffer more does not generate extra revenue for the state. There is literally no call nor need for all this extra stressful nonsense making people sweat every April. It’s actually counterproductive to fund raising for state activities. Bureaucracy steals lives and health for wasteful ends that do not benefit the group. The likelihood of reforming our deliberately and absurdly arcane tax system is about as high as large corps and oligarchs paying their fair share, nevertheless we should insist.

That said, I’m cautiously optimistic about this excellent announcement to reduce future peoples suffering.

I also gladly submitted biometric video scans and it still wasn’t good enough for ID.me So, I wonder if I’ll still be trying to get verified by the time this new system rolls out…

Re: IRS to adopt Login.gov as user authentication tool

#106

Earlier quoted context omitted.

> yet they live essentially petrified of violent crime to the point of carrying a deadly weapon for self-defense on their person at all times That's an odd way of stating it. They're concerned, so they're arming themselves.. but continuing on with their lives. Sounds like the opposite of "petrified" to me.

They won't go places (businesses, cities, etc) that don't allow guns. They routinely talk about and consider scenarios when, where, and how they'd fire on someone. They select clothes based on what will conceal a firearm (or select the daily firearm make/model based on what can be concealed with their clothing that day). It's clearly a major driving force in their lives. Perhaps petrified wasn't the best use of words…

I am not going to debate generic gun carry but I completely support being able to own and carry guns / rifles in the wilderness for example. It is pathetic when for example in Canada bear attacks construction crew, pulls a women and kills her and the others are not able to protect since they were not allowed to carry.

Re: IRS to adopt Login.gov as user authentication tool

#107
post #69

Earlier quoted context omitted.

When it comes down to it the US has a fear driven culture, down to what essentially becomes paranoia. US violent crime statistics are at near all-time lows. Yet I know many, many people that will not leave their house without at least one firearm. This is in small towns that haven't seen a violent crime justifying the use of deadly force in many years. Many of these same people refuse to "live in fear" of the coronav…

I know you're just sharing your anecdote, but the vast majority (over 80%) of Americans live in urban areas. Many cities do in fact see violent crime. Although I don't own a firearm myself, I totally understand why someone else would want one in my neighborhood. Violent crime is not unusual where I live. Don't let your bubble from small town USA distort your view of the entire country.

My bubble extends well beyond "small town USA".

Paradoxically, I don't have a single friend in Chicago, Denver, Miami, Los Angeles, etc that carries a gun. These cities run the spectrum of gun laws and all have higher crime rates than a small town yet fear of violent crime runs higher in communities where it's non-existent.

This is anecdotal but statistics back it up. Most gun ownership is rural, personal protection is often cited as the primary factor, most gun ownership is handguns (i.e. not hunting), and white males (small town friends) love guns and carry everyday.

https://www.pewresearch.org/social-trends/2017/06/22/the-dem...

Re: IRS to adopt Login.gov as user authentication tool

#108

If you use Customs and Border Patrol's trusted traveler programs (or some other gov sites), you may already have a login.gov account since that is what they have been using for a few years now.

I just wonder what kind of extra hoops we'll have to go through to use an existing login.gov account with the IRS. I read in some article somewhere that the IRS didn't use login.gov because it isn't "as verified" or some kind of thing as the IRS needs. Yet the reason I have a login.gov account is for my NEXUS enrollment which means I've been fingerprinted, background checked, had my passport number linked, and been i…

IRS was trying to remotely validate you to an IAL2 level.

I believe that although you are validated to a higher level with a trusted traveller program, they cannot or have not been able to share that validation with IRS directly.

Re: IRS to adopt Login.gov as user authentication tool

#109
post #43

Earlier quoted context omitted.

TreasuryDirect, the site that has case-insensitive passwords, disallows password managers, disallows the use of your actual keyboard to enter your password, and has this dumb on-screen keyboard with tiny keys that ultimately accomplishes nothing? Super trash. It still amuses me how few people, even those who claim security expertise, don't understand that commercial malware is able to hook the driver stack (and or br…

The TreasuryDirect site makes me want to give the authority to the USDS/18F to proactively come in and say we're taking over your public facing website infrastructure to any executive branch agency. There's no excuse for something to look and behave like it hasn't been touched since 1996.

It’s been touched since then. Back in those days, their “MFA” was a wallet card that you had the match up for a code. It was like the old copy protection schemes used for games like Sim City.

Re: IRS to adopt Login.gov as user authentication tool

#110
post #94
post #17

Has anyone here worked on government websites or APIs? I'm curious what the experience was like.

I spent a couple of years with the USDS ( https://usds.gov/ ). USDS, along with 18F, are largely responsible for login.gov, as well as a lot of other really great projects. Overall fantastic experience if you're open to an adventure! I could probably spend a week telling war stories, but the main takeaway is that you can't look at government as just another sector waiting to be brought up to speed. Government is an e…

Not that different! Hi Alex. :)
Post reply on HN