Live data from Hacker News

IRS to ditch biometric requirement for online access

krebsonsecurity.com

21–30 of 181 posts

Re: IRS to ditch biometric requirement for online access

#22

Earlier quoted context omitted.

I was extremely confused when I was asked to create an ID.me account for IRS. I have implemented Login.gov for some projects and it's rather easy; I can't see why they'd choose something else.

Easy, the answer is right here: https://developers.login.gov/overview Login.gov is a fine authentication service, but cannot deliver the identity assurance level (IAL-2) required to identify people. (It may not be able to deliver AAL-2 authentication soon either as standard evolve.) Uploading a picture of your drivers license is not a meaningful validation of your identity. The reaction of the Senators here is the eq…

No third party/private solution is appropriate here.

The government that oversees the issuing of these IDs and attests that they are sufficient for government use (Real ID) cannot themselves validate said ID?

Corruption or incompetence are the only paths that lead to outsourcing federal identity verification.

Re: IRS to ditch biometric requirement for online access

#24

What I would like to see next is an investigation into why this process was considered at all and how the vendor was selected. I find this entire situation deeply suspicious, since MOST online services (including financial services) do not need this kind of invasive verification process and do not require interfacing with a random third-party. My cynical guess is that id.me has some connection (like via political don…

>why this process was considered at all

Tax Refund theft. The IRS pays out billions every year in returns filed by scammers.

Re: IRS to ditch biometric requirement for online access

#25

“Login.gov is already used to access 200 websites run by 28 Federal agencies and over 40 million Americans have accounts,” Wyden wrote in a letter to the IRS today. “Unfortunately, login.gov has not yet reached its full potential, in part because many agencies have flouted the Congressional mandate that they use it, and because successive Administrations have failed to prioritize digital identity. The cost of this in…

I was extremely confused when I was asked to create an ID.me account for IRS. I have implemented Login.gov for some projects and it's rather easy; I can't see why they'd choose something else.

I've also implemented login.gov as an identity provider of last resort for a system that requires identity proofing (IAL2). It works great once folks are signed up and verified for a login.gov account, but the identity assurance process always seems to end up requiring a piece of mail sent to new users' homes. The phone/utility verification process never seems to work right, and the postal mail option adds a week's delay (or more) to our user enrollment process. In my and several test users' cases, we've had our phone numbers in our names for literally decades, so it isn't a matter of public records being ambiguous.

We've also had problems getting login.gov to proof new users with national but not state IDs. For example, we have someone with a passport but no driver's license. They should be able to use just the passport for identity proofing since the passport itself requires two or more forms of SUPERIOR/STRONG evidence (per NIST SP 800-63-3), but login.gov must not authenticate the passport with the State Department, meaning it fails 800-63A 4.4.1.2 (evidence collection requirements) rule 1 and must implement rule 2, instead (collect two pieces of STRONG evidence, i.e., national _and_ state IDs both). It's really frustrating because I cannot demand my users go out and get (pay for) state IDs they don't otherwise want or need.

All that said, even though login.gov isn't perfect, I do like it and am very impressed with 18F/TTS's work. They've done a very thorough job with their SAML implementation compared to the ADFSes/Oktas/Pings/etc. of the world.

Re: IRS to ditch biometric requirement for online access

#26
post #10

Earlier quoted context omitted.

Forget Equifax ... how about the Office of Personnel Management? People may well have lost their lives as a result. We may not know for decades. https://www.lawfareblog.com/why-opm-hack-far-worse-you-imagi... Oh, and the IRS has already been breached at least once. I'm not wild about waiting for the next one. Maybe government is not the best group to be holding your personal data. https://www.nytimes.com/2015/05/27/b…

All things being equal, the US government is simultaneously (1) the single most legitimate non-medical third party that needs to access my personal data, and (2) the single best entity to hold my data in terms of personal recourse . That's not saying much, but it is better than the open scorn and disrespect for my privacy that corporations offer. The solution to government breaches is what it's always been: to make t…

Good point, gov has less reason to sell your data

Re: IRS to ditch biometric requirement for online access

#29

Earlier quoted context omitted.

Easy, the answer is right here: https://developers.login.gov/overview Login.gov is a fine authentication service, but cannot deliver the identity assurance level (IAL-2) required to identify people. (It may not be able to deliver AAL-2 authentication soon either as standard evolve.) Uploading a picture of your drivers license is not a meaningful validation of your identity. The reaction of the Senators here is the eq…

No third party/private solution is appropriate here. The government that oversees the issuing of these IDs and attests that they are sufficient for government use (Real ID) cannot themselves validate said ID? Corruption or incompetence are the only paths that lead to outsourcing federal identity verification.

The only IDs issued widely by the US government are military credentials, immigration credentials, and passports. Driver’s licenses are issued by states and other entities. They are also fraught with problems as millions of people do not have REAL IDs, yet need to interact with government.

The problem is that any bartender who has scanned your drivers license has the information required to scam an online validation without some other validation.

If you want good online validation for the public, you need a third party right now. In the future, in some states, you’ll be able to use a mobile drivers license, provided you own a smartphone. Also problematic, as the government has to support everyone. Foreign nationals pay tax. People in nursing homes who cannot appear before a DMV need to pay taxes.

You can yak about corruption and incompetence, but that honestly attests to ignorance on the topic.

Re: IRS to ditch biometric requirement for online access

#30

Earlier quoted context omitted.

Easy, the answer is right here: https://developers.login.gov/overview Login.gov is a fine authentication service, but cannot deliver the identity assurance level (IAL-2) required to identify people. (It may not be able to deliver AAL-2 authentication soon either as standard evolve.) Uploading a picture of your drivers license is not a meaningful validation of your identity. The reaction of the Senators here is the eq…

No third party/private solution is appropriate here. The government that oversees the issuing of these IDs and attests that they are sufficient for government use (Real ID) cannot themselves validate said ID? Corruption or incompetence are the only paths that lead to outsourcing federal identity verification.

The government cannot build a competent identity solution because a majority of voters believe that to do so presages something from genocide ("Papiere, bitte!") to the literal end of the world (“Mark of the Beast”).
Post reply on HN