Live data from Hacker News

IRS to ditch biometric requirement for online access

krebsonsecurity.com

41–50 of 181 posts

Re: IRS to ditch biometric requirement for online access

#41

Earlier quoted context omitted.

The only IDs issued widely by the US government are military credentials, immigration credentials, and passports. Driver’s licenses are issued by states and other entities. They are also fraught with problems as millions of people do not have REAL IDs, yet need to interact with government. The problem is that any bartender who has scanned your drivers license has the information required to scam an online validation…

You continue to make some good points, but at the end of the day, this is a government function and responsibility, not that of a private company. Login.gov can use the same AWS services in GovCloud as ID.me uses (Rekognition, available since 2017 in GovCloud). With USDS and 18F, it cannot be argued GSA (which Login.gov falls under) doesn’t have the skills available to build this capability. This is a call to enhance…

USPS is already the agent for a national id program in all but name — passports and passport cards, which are much better than DMV issues credentials in many ways.

As another poster mentioned, the problem is that both progressive and conservative constituencies are strongly against meaningful national identity for different reasons, some of which are insane.

It’s a policy problem that won’t be solved in our lifetime. Our best bet long term is for states to issue mobile credentials, but even that is problematic because it will disenfranchise people.

Re: IRS to ditch biometric requirement for online access

#42

Earlier quoted context omitted.

No third party/private solution is appropriate here. The government that oversees the issuing of these IDs and attests that they are sufficient for government use (Real ID) cannot themselves validate said ID? Corruption or incompetence are the only paths that lead to outsourcing federal identity verification.

I generally agree with you. However: Real ID validates that you are the person you are at the time of issuance, but does not guarantee that the possessor of the ID is that person. This stems from the fact that an ID is "something you have". Like any secure system, you should use multifactor authentication. The facial scan is "something you are", so the combination of ID and scan provides that. One might also use "som…

I think the difficulty is that the (federal) government can't currently do anything except the "something you know" part. It can't use "something you have" (because too many people are opposed to federal government issued ID), and "something you are" appears beyond the scope of the federal govt to implement (correctly) at this time.

Re: IRS to ditch biometric requirement for online access

#43

“Login.gov is already used to access 200 websites run by 28 Federal agencies and over 40 million Americans have accounts,” Wyden wrote in a letter to the IRS today. “Unfortunately, login.gov has not yet reached its full potential, in part because many agencies have flouted the Congressional mandate that they use it, and because successive Administrations have failed to prioritize digital identity. The cost of this in…

I recently had to sign up for login.gov (to renew my Global Entry, after they moved away from their own one-off CBP login system) and was pleasantly surprised with how good it was. Hopefully the TreasuryDirect.gov folks migrate some day

Are they still giving out those decoder cards?

Re: IRS to ditch biometric requirement for online access

#44

Earlier quoted context omitted.

No third party/private solution is appropriate here. The government that oversees the issuing of these IDs and attests that they are sufficient for government use (Real ID) cannot themselves validate said ID? Corruption or incompetence are the only paths that lead to outsourcing federal identity verification.

The only IDs issued widely by the US government are military credentials, immigration credentials, and passports. Driver’s licenses are issued by states and other entities. They are also fraught with problems as millions of people do not have REAL IDs, yet need to interact with government. The problem is that any bartender who has scanned your drivers license has the information required to scam an online validation…

> If you want good online validation for the public, you need a third party right now.

In all reality, this is fine. I have no particular problem with using facial recognition, but I want it regulated and I want recourse.

Fine, outsource it to ID.me. But the terms of service better be a page, maximum, and include the ability for me to appeal a decision that says I am not who I say I am and to use other forms of validation that may be slower or more procedural (such as presenting myself to a Post Office). I want no binding arbitration clause in the agreement, and if that means the Federal government has to indemnify ID.me, then so be it. I want it in the TOS that the data ID.me uses for this will be segregated and kept for a very limited time and that I have the right to review and correct it.

Use the third party for what they are good for but enforce suitable rights for the rest. This is doable, it just wasn't fully done here.

Re: IRS to ditch biometric requirement for online access

#45

Earlier quoted context omitted.

The only IDs issued widely by the US government are military credentials, immigration credentials, and passports. Driver’s licenses are issued by states and other entities. They are also fraught with problems as millions of people do not have REAL IDs, yet need to interact with government. The problem is that any bartender who has scanned your drivers license has the information required to scam an online validation…

You continue to make some good points, but at the end of the day, this is a government function and responsibility, not that of a private company. Login.gov can use the same AWS services in GovCloud as ID.me uses (Rekognition, available since 2017 in GovCloud). With USDS and 18F, it cannot be argued GSA (which Login.gov falls under) doesn’t have the skills available to build this capability. This is a call to enhance…

> You continue to make some good points, but at the end of the day, this is a government function and responsibility, not that of a private company.

Private companies have been part of the government discharging its responsibilities since first days of the Republic. You'd probably be shocked when you learn who does credit monitoring after government servers get hacked, by the way.

By your logic the government couldn't use cloud computing (run by a private company), couldn't use computer hardware even if they wanted to run a private cloud (hardware is built by private companies).

Re: IRS to ditch biometric requirement for online access

#46

Earlier quoted context omitted.

Easy, the answer is right here: https://developers.login.gov/overview Login.gov is a fine authentication service, but cannot deliver the identity assurance level (IAL-2) required to identify people. (It may not be able to deliver AAL-2 authentication soon either as standard evolve.) Uploading a picture of your drivers license is not a meaningful validation of your identity. The reaction of the Senators here is the eq…

login.gov meets IAL2 since it NIST SP 800-63-3 "allows for remote or in-person identity proofing" (800-63A page 8). Likewise, TOTP is explicitly mentioned as an allowed multi-factor OTP authenticator (800-63B pages 20-21). I'm not aware of changes in SP 800-63-4 that would affect login.gov's current implementation, but it's been a minute since I last read the -4 draft and could be wrong.

Login.gov permits me if the IRS could do identity proofing.

The IRS can't do identity proofing (hence the need for ID.me, which is implementing "remote or in-person identity proofing"), and login.gov doesn't do it for the agency. Login.gov can only record whether the identity was created at IAL-1 or IAL-2.

Use of login.gov is orthogonal to the question of ID.me.

Re: IRS to ditch biometric requirement for online access

#47
post #14

The fact that this was even being considered shows how pitifully little anyone learned from the Equifax breach.

What lesson do you think organizations learned from that breach? (As it relates to this article.) The pattern I see is: 1. Company collects and stores private consumer info. 2. Company gets hacked. 3. Company share price unaffected. 4. Company sued in class-action lawsuit. 5. Company settles by offering discounted/free products to victims of the hack. ("A $50 value!") Lawyers make a few million. Result: company gets…

> Sounds like a good deal if the company is too big to fail.

I don't know why Equifax is too big to fail. But then again, I don't know why Goldman Sachs was too big to fail either.

Re: IRS to ditch biometric requirement for online access

#48

“Login.gov is already used to access 200 websites run by 28 Federal agencies and over 40 million Americans have accounts,” Wyden wrote in a letter to the IRS today. “Unfortunately, login.gov has not yet reached its full potential, in part because many agencies have flouted the Congressional mandate that they use it, and because successive Administrations have failed to prioritize digital identity. The cost of this in…

If the IRS (or Sen. Wyden) is looking for a "core government service" which has been inappropriately commercialized, they might start with tax preparation.

This article[1] has more details. Sen. Wyden[2] has been pushing for more funding to IRS to develop its free file program, but Turbotax has been successful via their lobbying of Republican politicians and some Democratic politicians in preventing it from happening.

1. https://www.propublica.org/article/inside-turbotax-20-year-f... 2. https://www.nytimes.com/2021/07/19/opinion/intuit-turbotax-f...

Re: IRS to ditch biometric requirement for online access

#49

“Login.gov is already used to access 200 websites run by 28 Federal agencies and over 40 million Americans have accounts,” Wyden wrote in a letter to the IRS today. “Unfortunately, login.gov has not yet reached its full potential, in part because many agencies have flouted the Congressional mandate that they use it, and because successive Administrations have failed to prioritize digital identity. The cost of this in…

If the IRS (or Sen. Wyden) is looking for a "core government service" which has been inappropriately commercialized, they might start with tax preparation.

Sen. Wyden's already been fighting that fight for more than a decade. https://www.congress.gov/bill/111th-congress/senate-bill/301...

Re: IRS to ditch biometric requirement for online access

#50

Earlier quoted context omitted.

I generally agree with you. However: Real ID validates that you are the person you are at the time of issuance, but does not guarantee that the possessor of the ID is that person. This stems from the fact that an ID is "something you have". Like any secure system, you should use multifactor authentication. The facial scan is "something you are", so the combination of ID and scan provides that. One might also use "som…

I think the difficulty is that the (federal) government can't currently do anything except the "something you know" part. It can't use "something you have" (because too many people are opposed to federal government issued ID), and "something you are" appears beyond the scope of the federal govt to implement (correctly) at this time.

Every IRS, Social Security, DHS/CBP, and USPS branch are locations where they could proof your identity in person. It is simply a matter of will to implement the policy and enable the software features for government employees to perform the function.

I would also propose finding ways to drastically reduce the cost of issuing smart passport cards, and slowly transforming that into a national ID over time as the electorate composition changes. Your passport number eventually becomes your national ID number.

Post reply on HN