IRS Awards Equifax $7.25M Contract to Help 'Verify Taxpayer Identities'
gizmodo.com
gizmodo.com
And there wouldn't be any issue of "restricting certain people from voting" because the federal government would have to provide everyone with one anyway. It could also lead to safer and more verifiable voting on voting machines (even though I still believe nothing beats pen and paper at this).
Republicans don't want a national ID and Democrats don't want to anger their base.
I am not a huge fan of the idea (from the Republican side although I'm not a Republican) but at this point I don't even care because companies cannot be trusted to handle this.
* Do replacements cost money?
* Do I have to go somewhere in person to get the card? Is it within walking distance?
* What are the days and the hours that this place is open?
* ... (there are so many more questions but most importantly)
* How do we pay for it?
If it were done benevolently and with the best of intentions, it could work. But it isn't.
I'm a 30-something middle-class white male who works in tech in a large Canadian city with excellent public transit. I don't have a driver's license, and I'm constantly running into idiotic barriers because I don't have one. People and processes seem to assume that I do and when confronted with the contrary, a lot of people don't really know what to do.
[1] http://www.icbc.com/driver-licensing/getting-licensed/Pages/...
It wouldn't stop the issue of Republicans closing polling stations in minority communities, but it's a start.
Of course the democrats fall for the trap every time, because using security as an excuse for taking away rights is almost as good as using child porn as an excuse for censorship and monitoring. People go "oh yeah, that sounds reasonable"
We should not.
You don't have EU-issued ID, we don't need US-issued ID.
When you drop off your clothes at a dry cleaner, they give you a ticket that lets you pick them up again. They don't need an ID number that lets them correlate your dry cleaning with your Amazon purchases and your phone's location history and your medical records and your tax returns. And we shouldn't give them one.
Literally none of those things require a national ID anyway. You can just give them that information, if you want to.
The ID only allows to it to happen without your consent. Including all the things you don't want, like price discrimination.
If one exists then they'll use it without your permission. Or refuse service to anyone who doesn't provide it. Which means it needs to not exist.
> Doesn't mean the government should have issues identifying people when needed (for government services, for example).
Any government agency is free to give you an ID card used to identify you to that agency in the future, the same as any private entity -- but then companies can't require you to have one because not all citizens interact with any given agency. And then nothing stops you from closing any account in good standing and reopening a new one with a different ID number.
Correlating every interaction you have with government is not a feature. The IRS does not need to know who has applied for a hunting license or vice versa. The FBI should not have access to the list of books you've checked out from the public library. These things should all be separate from each other.
But I do think people are excessively paranoid / anti government today, so maybe just my bias is showing.
What you need is CONTROL OVER YOUR OWN IDENTITY. YOU SHOULD HAVE DIFFERENT IDS IN DIFFERENT DOMAINS.
It is You who should choose to tell domain A that you are X on domain B. Tracking you across domains and cross-correlating databases shouldn't be as easy as looking for the same ID!
You should use devices under your control to store private keys that let you authenticate. YOU should provision other devices, and repudiate compromised ones. And YOU should be able to see your friends joining domains like porn.com ONLY IF THEY WANT YOU TO.
https://github.com/Qbix/auth is a humble proposal for how to get from here to there.
People are constantly unable to produce their identifying information - requiring them to have multiple IDs and remember which ones belong to which things is just never going to happen. I don't know what the solution is, but people in tech don't seem to realise just how hard the majority of people find it to recount anything with any accuracy.
Many sites, like the DMV, don't allow hyphens in names. So my other name is Abdul Rasheed Bustamam.
Some sites don't like hyphens or spaces. So I become Abdul R Bustamam. R being my middle initial, and I don't have a middle name.
Then, some sites have a length limit so I often become Abdul Rashee Bustamam.
These are for organizations like insurance, government, credit cards; when I checked and froze my credit I counted about eight different "legal" names that I have.
I use a password/email manager to manage passwords, but unfortunately there's no name manager :)
Websites invariably fail to accept my postal code because of one of two issues: I did put in a space, or I did not put in a space.
It's mind-blowing to me that website developers can't come up with a solution to this problem other than (mistakenly) telling me what my postal code should or should not look like, when the rules are pretty simple.
The other cardinal sin: Canada Post will sell you a gigantic database of postal codes and associated addresses, so you can look up an address for a given postal code. In many cases a postal code will tell you a specific street, specific side of the street, or in the case of condos or apartment buildings, will identify a specific building, so this is great for making sure the delivery address makes sense.
Unfortunately, new buildings and their postal codes are being created all the time, so I've had a few cases where I couldn't order something online because my (three year old) postal code wasn't in their database, so they just gave me an error saying "check your postal code and try again". I ended up having to get a friend of mine to order my wife's birthday present once because it wouldn't accept my postal code for either billing or shipping.
All of this because someone thought they'd be smart and fucked it up.
http://www.cbc.ca/news/technology/canada-post-sues-over-post...
If you don't have it, you can still authenticate via biometrics at those places where you previously made an account. But biometrics only works in person, because remotely it is susceptible to replay attacks.
A huge number of purchases started failing because users, confused, would type 'Visa' into the 'Name on card' field instead of their own name, and then wouldn't bother putting their own name into any of the other fields.
He ended up changing the HTML to have a drop-down which was completely ignored on the backend just so we wouldn't have failing purchases and a huge support load anymore.
In other words, when presented with a card form that didn't ask what type of card it was, people assumed that inputting the card type (which a graphic made very clear was highlighted already) was more important than putting the cardholder name in.
We learned a lot of other lessons on that project about not assuming people could ever figure things out on their own.
Equifax and capable in the same sentence? Oh IRS...
The hackers should incorporate! Then two businesses would be capable of providing the service.
Would it be 'ethical hacking' if you hacked companies like Equifax so you could offer their data to tax-payer-funded clients for cheaper than companies like Equifax do?
</silliness>
> As noted in public records, the short-term contract was awarded to Equifax to prevent a lapse in service during a protest on another contract. The service relates to assisting in ongoing identity validation needs of the IRS. Equifax provided these identity proofing services to the IRS under a previous contract.
And this: https://krebsonsecurity.com/2017/10/usps-informed-delivery-i...
> "Perhaps this wouldn’t be such a big deal if the USPS notified residents by snail mail when someone signs up for the service at their address, but it doesn’t."
That should be part of the authentication to enable the service (enter a code on the mailer to finalize setup). The fact that it doesn't send anything is just mind boggling.
It feels like they have House of Cards syndrome. They can't write something more ridiculous than real life.
If they are the only business capable why not make them bid anyway just in case?
Surely, if anything goes wrong---it will at least be the things the government wants to go wrong.
https://investor.equifax.com/news-and-events/news/2010/10-04...
The greater problem here is the theory of competition when it comes to government, since it is often the case that there is little or no competition, and entrenched monopoly providers of government services and services to the government (separate things).
Obvious to me that certain functions and competencies must remain inside the government and outside the profit motive. The inevitable outcome of niche provision of government services tends to be a parasitic relationship between government and corporate provider, and this ultimately costs citizens more in the long run - and not just taxes!
I'm guessing they will use the last 6 digits of the SSN for verification purposes.
> the IRS has determined Equifax is the only business capable of providing this service
We all know that isn't true. There is something very rotten with this.
Anyone in possession of the Equifax breach data can get validated as 143 million different individuals.
Authentication is verifying someone is the person represented by a valid ID
Authorization in this case is some authenticated person having the legal authority to look at or fill out someone's tax paperwork, not necessarily the same as the person under discussion, consider my accountant or my wife's PoA over her elderly uncle, doing taxes and financial things.
You can be super black pilled about the IRS or perhaps slightly more white pilled that they're only doing validation... if I live at 221B Baker Street and I type in 2218 Baker Street it would be nice if that could be caught and fixed. Yeah, yeah, I know, reality is probably some fuzzy location in between.
Although it sounds weird for a company based on gatekeeping "secret" data (which hasn't been secret in a long time) to allow its secret data to leak, its an old business model to create a problem which surprisingly enough you also have a profitable solution. Its highly likely in a year or two we'll all have Equifax smart chip ID cards. Like a military CAC card but with 100 times more users.
The 143 million PII records likely represent almost every adult taxpayer in the US. These records didn't need to be released purposefully. Even if stolen, nothing but the possession of those records may be needed to authenticate as almost any one of the adult taxpayers in the US.
> Authentication is verifying someone is the person represented by a valid ID
Why do you believe that auth in this context requires validity of ID or even an ID of any kind?
> Its highly likely in a year or two we'll all have Equifax smart chip ID cards.
I'm not convinced this is a highly likely scenario.
This is par for the course with procurement, isn't it?
/snark
featuring: NK, Trump, Blockchains, Brexit, Nature doing Nature things, pending economic bubble burst, et al.