Live data from Hacker News

IRS to adopt Login.gov as user authentication tool

fedscoop.com

111–120 of 193 posts

Re: IRS to adopt Login.gov as user authentication tool

#111

If you use Customs and Border Patrol's trusted traveler programs (or some other gov sites), you may already have a login.gov account since that is what they have been using for a few years now.

I just wonder what kind of extra hoops we'll have to go through to use an existing login.gov account with the IRS. I read in some article somewhere that the IRS didn't use login.gov because it isn't "as verified" or some kind of thing as the IRS needs. Yet the reason I have a login.gov account is for my NEXUS enrollment which means I've been fingerprinted, background checked, had my passport number linked, and been i…

I think the IRS must already have a pretty good relationship with CBP. A few years ago, the IRS sent me a letter claiming I owed them a large quantity of money. It was a mistake, because my idiot broker messed up the paperwork. (Schwab equity awards. What a disaster.) At about the same time, I applied to renew Global Entry. Nothing happened on the Global Entry application for months, as I worked with a tax expert to correct my tax return. Several months later, I got mail from the IRS saying the case was resolved (they owed me $70, it turned out), and the same day my new Global Entry card arrived.

Maybe it's a coincidence but it seems like the two agencies work together. They also apparently withhold government services if they think you owe them money. Not sure if I think that's amazing, or petty. Leaning towards amazing though.

Re: IRS to adopt Login.gov as user authentication tool

#112
post #106

Earlier quoted context omitted.

They won't go places (businesses, cities, etc) that don't allow guns. They routinely talk about and consider scenarios when, where, and how they'd fire on someone. They select clothes based on what will conceal a firearm (or select the daily firearm make/model based on what can be concealed with their clothing that day). It's clearly a major driving force in their lives. Perhaps petrified wasn't the best use of words…

I am not going to debate generic gun carry but I completely support being able to own and carry guns / rifles in the wilderness for example. It is pathetic when for example in Canada bear attacks construction crew, pulls a women and kills her and the others are not able to protect since they were not allowed to carry.

Absolutely agree - I have no intention of debating guns generally (ownership or carry). I own guns, always have, and had a concealed carry permit for many years. However in my case the permit was more for practical reasons - I lived in an apartment and there are some weird grey areas with guns in "common areas" otherwise. I think I actually "concealed carried" a few times and was generally uncomfortable and put-off by it (personally).

I'm more speaking to the motivation behind absolute, 100% carry everyday. It's completely emotional, fear driven, and not in any way supported/justified by the data.

Re: IRS to adopt Login.gov as user authentication tool

#113
post #81

Earlier quoted context omitted.

It's standards based just like any other SSO these days: OpenID Connect and SAML. Is there something specific you want to know?

How is it different from working with a private company? Lots of stakeholders? More documented testing procedures?

Someone said it best upthread: the incentives are different.

If you are a leader in the bureaucracy, your incentive is to not personally fail, which is not the same as to succeed.

There is an army of auditors waiting to question every decision, so the obvious way to avoid that is to not make any. Balancing the need to do something without deciding anything is an art of sorts.

Re: IRS to adopt Login.gov as user authentication tool

#114

Earlier quoted context omitted.

The NSA acting like a creepy Big Brother-secret police organization is a separate issue.

It's an example of American schizophrenia. No National ID because tyranny! Monitoring everyone constantly? That's keeping us safe!

Well I consider for example requirement to carry ID in France as the schizophrenia or worse from the government side. Brings out the worst associations

Re: IRS to adopt Login.gov as user authentication tool

#115
post #73

Earlier quoted context omitted.

> yet your entire life is accessible to the NSA. I'll bet you money that most Americans are not okay with this either.

They're nominally "not ok" with it, unless it's couched in some piece of legislation like the PATRIOT Act or snuck into a Defense Authorization Act, particularly after a national tragedy happens. Then a lot (a majority?) of Americans will suddenly be ok with the "if you got nothing to hide you got nothing to fear" mantra. I'm actually not a huge fan when people act like Americans are a a bunch of flag-waving morons,…

>" I do think Americans are uniquely ok with pretending their rights don't exist when they're convinced it's for a greater good."

Check Canada. We are way more screwed up in this department

Re: IRS to adopt Login.gov as user authentication tool

#116
post #5

login.gov is open source! They also encrypt user data in a way that they can't access it without the user's password, precluding the formation of a national registry that could be used towards nefarious and anti-democratic purposes. As a result, account recovery looks a lot like re-registration, which I think is a great thing. https://github.com/18F/identity-idp It's built on Rails, and I'm really impressed at the en…

That's assuming what's in the repo is the same code that is deployed.

You can make similar counterproductive claims about everything. How can you assume that your senses and all humans are not gaslighting you?

Re: IRS to adopt Login.gov as user authentication tool

#117
post #43

Earlier quoted context omitted.

The TreasuryDirect site makes me want to give the authority to the USDS/18F to proactively come in and say we're taking over your public facing website infrastructure to any executive branch agency. There's no excuse for something to look and behave like it hasn't been touched since 1996.

It’s been touched since then. Back in those days, their “MFA” was a wallet card that you had the match up for a code. It was like the old copy protection schemes used for games like Sim City.

That almost makes it worse!

Re: IRS to adopt Login.gov as user authentication tool

#118
post #69

Earlier quoted context omitted.

I know you're just sharing your anecdote, but the vast majority (over 80%) of Americans live in urban areas. Many cities do in fact see violent crime. Although I don't own a firearm myself, I totally understand why someone else would want one in my neighborhood. Violent crime is not unusual where I live. Don't let your bubble from small town USA distort your view of the entire country.

It's disingenuous as hell to clump "cities" together, as if going to Anacostia in DC is the same as going to Georgetown. If you live in a city and carry a gun, you're not protecting yourself, you're escalating the violence. Getting robbed is exceedingly rare anywhere in the US, and trying to stop a robbery with a gun is among the stupidest things a person can do. Further, robbing someone doesn't mean you should die,…

I think most people not from DC will not even know where Anacostia is, you can probably just say SE or something.

Re: IRS to adopt Login.gov as user authentication tool

#119
post #18

As mentioned in the article, the IRS had originally planned to use ID.me — a private company — before backing down. Previous discussion here: https://news.ycombinator.com/item?id=30126118

And rather controversially require face recognition for login. Good idea in that having another secret only really you should own is good, poor execution in allowing a third party of collect and probably sell something so very personal. I'm glad they backed off.

Re: IRS to adopt Login.gov as user authentication tool

#120
post #5

login.gov is open source! They also encrypt user data in a way that they can't access it without the user's password, precluding the formation of a national registry that could be used towards nefarious and anti-democratic purposes. As a result, account recovery looks a lot like re-registration, which I think is a great thing. https://github.com/18F/identity-idp It's built on Rails, and I'm really impressed at the en…

That's assuming what's in the repo is the same code that is deployed.

If you want to go down that rabbit hole, you may want to (re)read Ken Thompson's Reflections on Trusting Trust at https://www.cs.cmu.edu/~rdriley/487/papers/Thompson_1984_Ref...
Post reply on HN