Treasury reconsiders IRS’s use of ID.me face recognition for web
bloomberg.com
bloomberg.com
We need a reliable link-to-meatspace authentication provider for the consumption of government services. That's obvious.
But why are we outsourcing it to an external company, which may not be subject to the same purview as the government itself, particularly in terms of legally-mandated transparency, accountability, and universal service?
I suspect half of this is anchored in the "mark of the beast" crowd who is terrified at the thought of any sort of coherent national identity document system. After all, if we had a central "Department of Identity" already, adding some sort of account system linked to the pre-authenticated passports and driver's licenses you already have would be trivial and within their wheelhouse.
If you look at it a certain way, we're not considering the general problem of identity, just "association with government accounts". We already have an established set of roots-of-trust and dispute resolution protocols for figuring out which accounts you're attached to. All we need is a tech-friendly set of credentials to supplement the paper passport/driver's license/social security card.
If anything, decentralization would be difficult for the legal system to work with. How do you force everyone else to accept an update from the courts, especially if they're politically opposed to, or disincentived to, accept the update? You could try to tie legal acceptability to staying up to date, but then you'd create a huge liability for software bugs.
It feels like it would turn into every other abused aspect of employment law: widely exploited both because of technical incompetence and the knowledge most will get away with it.
If the outcome that they want to avoid is actually a global ID system, you'd think that a private corporation (that could offer its services to multiple countries, interoperably) would be more worrying to them.
It's not like, by opposing a government-run ID system, they've prevented the existence of an ID system that the government accepts (and could mandate nationally).
That's just temporary embarrassed millionaire syndrome and financial greed.
> A corporation can't arrest me, shoot me, confiscate my property, or otherwise tell me what to do outside any voluntary contract with them.
I think that while corporations may be more likely to have risk, the risk may not be as big as if it were done by a government. So, high chance of risk but maybe lower damage vs low chance and higher damage may end up being a wash and may explain why some people fear the government more than corporations.
And a corporation hired to, say, run a prison can shoot you.
Corporations have done all things, even within the boundaries of the USA.
You are welcome to argue that this should not have been possible, should not be possible etc., and very few people, including me, are going to disagree with you.
But if we're going to talk about what actually happens in the real world rather than what should happen, everything you've said there is factually untrue.
States use violence routinely, corporations may order a hit on someone maybe once in a blue moon. Usually any violence they do is by co-opting government mechanisms already in place.
And btw I am a left-libertarian who criticizes both states and corporations
Multi signature cryptography and webs of trust are pretty mature concepts at this point. Using public notary systems could provide the real world authentication to publish keys, so the protocols could be developed around the idea that additional bureacracy and government shouldn't be needed - use the systems already in place wherever possible.
You can add it back into the sshd_config in /etc.
See the recent Zero Trust memo, https://news.ycombinator.com/item?id=30101411
Bonus points to the state of Florida DEO for removing any human staff from their phone answering system. It's just an automated menu that always leads to forced disconnection and useless advice to check their useless website.
Why even have a government if it's adversarial to its own citizens?
The point is to be adversarial to the correct citizens, e.g., poor people and minorities. That's just basic conservatism these days.
It was ass, but at least it worked. You never got the video chat option?
https://www.congress.gov/bill/117th-congress/house-bill/4258...
Do this or you can't use a government service online. Ok terrorist.
> “We believe in the importance of protecting the privacy of taxpayers, while also ensuring criminals are not able to gain access to taxpayer accounts,” LaManna added, arguing that it’s been “impossible” for the IRS to develop its own cutting-edge identification program because of “the lack of funding for IRS modernization.”
Yea, sure trust a private org on data storage. Data breaches never happen..(Drizly I'm talking about you)
This statement seems absurd. The IRS website doesn't support filing taxes online like a normal country because the tax preparation companies have lobbied to prevent it.
0: https://secure.ssa.gov/RIL/ (gonna have to wait till tomorrow morning to see it, as it has hours of operation for some reason)
1: https://www.login.gov/help/verify-your-identity/how-to-verif...
Unfortunately: There were some senators who contact form was broken. (One in texas and I think one in wyomey was another.. other than that I got responses of "we don't give responses to non-constituents)
That's a bit disturbing. Senators' work on committees affects everyone in the country, not just residents of the senator's home state, and one's own senators may not have a seat on that committee.
Thank you for sharing your thoughts with me. As a matter of professional courtesy to my U.S. Senate colleagues, I defer to them and encourage you to contact your U.S. Senator with this issue. In addition, I deeply value my correspondence with South Carolinians; because of the high volume of mail I receive on a daily basis, I will give preference to responding to my constituents.
Contact information for your U.S. Senator can be found at www.senate.gov. Thank you for your time and have a great day.
For written communication, yeah most of us don't have a fax machine, but there are services online that let you upload a PDF to be faxed. They also accept snail mail, but it is very slow.
For context, this isn’t just “it takes a couple of days for a letter to cross the country.” Here’s the note from my local congressperson’s contact page, for example:
> All postal mail sent to my offices must be scanned for security purposes, which means it will take an additional two weeks for me to receive it.
Regarding faxes, it’s also worth checking with your local library—mine offers scan-to-email and faxing as a free service.
That is no longer relevant when they step out of the bounds of representative politics and form special social groups that dictate the laws and behavior of offices that we have to deal with. You can't just have your cake and eat it too.
I wonder if the internet and other tools that have reduced the costs of communication have been nudging many of us more towards wanting direct democracy, not representative democracy, without even realizing the shift or how it conflicts with the underlying structure of our government.
I'm curious, what are your thoughts related to how people see the government in terms of representative vs direct (or other forms of) democracy?
Kept getting this cryptic error: "Field contains invalid characters or format."
Eventually I found through trial and error that the problem was APOSTROPHES. So I'm, it's, that's, they're, etc are all out.
It amazes me that not only do they not support such commonly used phrases in their messaging system (which pretty clearly means they've never tested it with any thing remotely resembling a real world message), but also that they couldn't even have the decency to give a more descriptive message so I didn't have to go on a punctuation whack-a-mole.
For added fun, they used Authorize.net but instead of just storing a transaction ID in their infinite brilliance they decided to store name, number, expiry, and CVV code! They didn't even have user accounts or saved payments, it was all more or less a guest checkout flow for all their orders so customers couldn't even look this up on their site after the transaction. Once an order had been filled there wasn't even any usage of the old order data and they never deleted any of it. A quick row count showed ~750,000 entries going back for years.
People that do things like filtering all apostrophes in a form send shivers up my spine. God only knows what horrors lurk beneath the surface on that California government site.
I also sent them a letter a while back about the National Security Letter law incursion in HK.. their response a month ago "intenational events are very sensitive subjects .. blah blah blah... vague non related comment on 'we believe on human rights.'"
Her class is part of the reason I tend to write 'representatives', when I describe senators and congressmen.
If I had charisma, I would be running myself.
That's the downside of living in IL and it being mostly a D voting base.
Their contact forms aren't broken, they literally just don't represent you unless you live in their state.
OK fine, whatever. But then even after filling up all kinds of info, uploading pictures of my driver's licence and having literally scanned my face, it wouldn't let me login, because it can't "verify" me.
I've been filing taxes online for many years without issue.
I can't believe a private company gets to decide whether I can access IRS services.
If you can’t verify your identity online, you can call the telephone number on the letter you received from the IRS telling you that you may be eligible to receive advance Child Tax Credit payments (Letter 6416)
But... the link to Letter 6416 goes to a PDF that has no phone numbers on it at all.
So although id.me might not be strictly speaking mandatory, in this case it seems impossible to avoid, since the "alternative option" isn't really there.
It's a Kafkaesque nightmare.
this is presumably not the same as "the link to Letter 6416"
https://www.irs.gov/credits-deductions/2021-child-tax-credit...
To me it reads like Letter 6416 is meant to add specificity to "the letter" in the previous sentence.
EDIT: I've found other examples of Letter 6416 online on non-IRS websites that do have a phone number at the upper right. I'm not sure if the phone number's absence from the sample PDF on the IRS website means it has been removed, or if non-sample copies would have a phone number.
You can search for something more secure, sure - but don't break the damn system for the millions of people who need it and refuse to deal with ID.me.
So much of this sounds like another overengineered solution to a problem that shouldn't exist.
They couldn't store more than 500MB of emails per employee, which was ~45TB uncompressed in 2014. Because of budgetary constraints.
Because they paid some dude rosemaro a half billion for an IT contract, among other things
The government lost tens of hundreds of billions in unemployment fraud during COVID, and tax refund fraud is huge.
If you look at the fraud activity reported in the media in places like California, most of that was using breach data. Validating at IAL2 would probably eliminate 90% of that.
Tax return fraud is a huge business too, especially for people with large refunds due to EIC.
I'm confused by your question because I get the impression you were assuming I wanted to delegate such info collection to a 3rd party and that you would not that want, but maybe I've got that wrong. Is that what you were implying?
I think yes that's the case and yet I do think there are some services that are more in-house to the government and less farmed out, but I'm not sure.
For example, I think the unemployment departments at the state level are often government-run, but I could be wrong. Not sure how much the passport process is contracted out, but I would assume not too much but maybe it is.
Like a few years back when they were stealing tax refunds by filing before you or filing for people who'd passed away that tax year.
Login.gov supports and encourages security keys (yubikey etc) as 2FA. I hope it does see wider adoption soon by more agencies, esp IRS.
What I don't understand is why any customer of id.me believes id.me's characterization of how much fraud there is, and how effective they are. How many of id.me's claims have been independently verified?
The USG has also openly applied facial recognition already, for things like border control. They're not really hurting for data sources.
Here's the link target: https://account.id.me/ccpa
ID.me doesn't even have to be loyal to our government. There's no requirement for that.
I'm also not defending the government's decision to use ID.me; I'm not happy about it. But I think the reason behind it isn't some shadowy data harvesting plan by the USG; it's probably something between "we didn't want to do the paperwork to authorize, fund, and build this internally" and "someone's nephew works at ID.me."
Why was that not good enough for IRS?
At least it seems like the IRS registration is good enough to log into SSA.
It is very common for the government to use its various arms to institute large data collection efforts in the name of national security. A selfie video of yourself on a modern day phone provides for the government a high definition facial recognition vector for identification purposes. I'm sure you can imagine all of the use cases of having this critical data.
Personal Story: My wife and I travelled abroad right before COVID in early 2020. On the way back, we didn't interface with any customs agents at the airport. Instead, there was a portable robot that took our pictures and advised us to proceed to exit. I can only imagine which image database it referenced for a perfect match to allow entry (passport, driver's license, social media?, etc). From a security standpoint, I would assume that the matching capability/requirement of such system had to have been best of the best.
Just saying. It's important to speak up.
One interesting quote is:
> Does ID.me maintain a database of faces that map back to original photos and who has access to the database?
> ID.me retains the selfie that was used during the identity verification process. ID.me is the only entity with access to this database. The only time biometric information is shared with a government agency is when there is apparent fraud and identity theft tied to the account associated with the agency.
I wonder if id.me keeps a copy of the photo of the government ID.
Things that discourage people from using thier system just makes their life easier. Theres's no consequence to the department and it's not their problem.
The spend cycle can slow if we radically reduce federal spending/income. Move truly necessary services to the States.
That won't happen, so opt out. Structure your life to avoid qualifying as a person who files a return.
Say what?
> Move truly necessary services to the States
The way some states behave, this is exactly what I don't want for America