IRS to adopt Login.gov as user authentication tool
fedscoop.com
fedscoop.com
https://github.com/18F/identity-idp
It's built on Rails, and I'm really impressed at the engineering decisions that were made here, from choice of technologies to level of transparency. I wish all public sector projects could exhibit the same leadership and competence demonstrated for login.gov--the interface is even a pleasure to use, which is hard to say for most government online services outside of the UK and parts of Canada in my experience. Bravo!
I love how low our standards for government sites have gotten where this is seen as a plus and not something that's expected
Corporate customer databases I've seen have rarely even been need-to-know access limited, much less actually encrypted to internal users.
It’s getting better as people shift to cloud and inherit better controls, or implement better controls for cost avoidance reasons.
If someone wants to use facial recognition - why not? If someone wants to use insecure username/password and risk a compromise - let them do it.
FWIW big tech has probably 99.99% of people's faces, I'd guess at least 90% is tied to an identity.
Still I do prefer this to ID.me which I needed to use for CA unemployment.
If disabling your login.gov account locks you out of you bank account, the ability to travel, your library account, your email account, your social media accounts, your school, your children's school, your mortgage, your ability to pay your rent and utilities, your ability to seek employment, vote...
When your life is consolidated to SSO, your life is controlled by those who control the SSO service. The fact that they encrypt your data doesn't change that reality.
The website is still full of Google trackers, so it looks like it's already handing some user data over to private for-profit 3rd parties. Not a great sign, but I guess we can be happy we're not being forced to give them face-scans, fingerprints, or DNA I guess.
Yes. I do. There are alternatives to Google that work just fine (assuming they genuinely _need_ analytics in the first place). There's no reason using a government service should involve you handing data over to Google (or any private for-profit company).
No analyzing your citizens behavior on a government site (that you paid) should be done by private company's (to make money out of your data)...what a question....
A singular corporation (ID.me) holds every American’s ability to login to their government tax profile hostage, and we pay them for the pleasure of this rotten monopoly and abuse of public trust. I just want to pay my taxes, sigh. It should be as easy as any other bill or process. Making taxpayers suffer more does not generate extra revenue for the state. There is literally no call nor need for all this extra stressful nonsense making people sweat every April. It’s actually counterproductive to fund raising for state activities. Bureaucracy steals lives and health for wasteful ends that do not benefit the group. The likelihood of reforming our deliberately and absurdly arcane tax system is about as high as large corps and oligarchs paying their fair share, nevertheless we should insist.
That said, I’m cautiously optimistic about this excellent announcement to reduce future peoples suffering.
I also gladly submitted biometric video scans and it still wasn’t good enough for ID.me So, I wonder if I’ll still be trying to get verified by the time this new system rolls out…
I'm an American abroad and I spent roughly 8 hours spread across 5 days getting access to my irs.gov account. And yes, I actually recorded time spent on this chore.
The worst part was not the facial recognition. It was the fact that I had an address outside of the USA and they would not recognize a non-USA utility company for address verification. This was stupid for two reasons. The first being the obvious requirement that a non-resident have a contract with a utility company in the USA, and the second being that the IRS has been mailing me at my non-USA address for years. The IRS already had my address, but I had to verify it with ID.me.
The other worst part was they never told me WHY my various utility bills and bank statements were being rejected. At one point they told me I had to translate a bank statement, and that was the most feedback I ever got. But then I translated it and they rejected it for an unknown reason.
I eventually got my registration through them by getting a USA bank to recognize my foreign address. Luckily I also had an old W-2 laying around from years ago when I briefly worked in the states. Do they expect my current employer to give me a W-2?
Finally, on their stupid video call I was told I needed to have all of this documentation, which I dutifully prepared, and then all the person cared about was me holding my passport up to the camera.
Completely broken process for Americans abroad. To the point where they're likely breaking some US law by making it so difficult for non-residents to register for IRS access.
I hated it and I hope ID.me dies in a pit of bankruptcy.
Both options were incorrectly spelled. There was no way to proceed and spell the name correctly.
Their support desk basically told us it wasn't their fault and to go away.
* https://www.canada.ca/en/revenue-agency/services/e-services/...
* https://www.canada.ca/en/revenue-agency/services/e-services/...
* https://verified.me/government-sign-in-by-verified-me/
You can also create a stand-alone account with the CRA if you wish. Other federal agencies use the 'partner' system as well.
It's basically SAML.
[1] https://en.wikipedia.org/wiki/List_of_banks_and_credit_union... [2] https://en.wikipedia.org/wiki/List_of_largest_banks_in_the_U...
It should provide an online identity service, just like it already provides offline government-issued IDs (e.g. passports) without involving banks or other private institutions.
As I stated in my post:
> You can also create a stand-alone account with the CRA if you wish.
See Option 2:
* https://www.canada.ca/en/revenue-agency/services/e-services/...
The provinces of Alberta and BC also have identity providers (since they issue driver licenses and health cards) which the CRA allows (Option 3).
You can't reuse the CRA login with all other government services. I'm talking about a single identity provider accepted by any government service, like a driver's license or a health card.
Yet the reason I have a login.gov account is for my NEXUS enrollment which means I've been fingerprinted, background checked, had my passport number linked, and been interviewed in person by two different governments. That seems pretty identity verified to me.
If I have to go through some other step, especially if it involves yet another biometric or interview check, that's going to be annoying.
The only thing you have to do to enroll in login.gov is verify your email address.
And optional feature of login.gov is to verify your identity further by uploading a photo of a state ID, and entering your SSN and phone number. When you validated your identity in person with CBP, this was not that.
This isn't snarking at you directly, just all I'm really hearing is that the government will happily mix whatever it knows about me for its own purposes but when it comes to making things easier for me (wherein they've literally seen me in person and looked over a stack of my identifying documents), no way that's "violating my privacy."
If we are going to have an all-seeing panopticon can't it at least be convenient?
I believe that although you are validated to a higher level with a trusted traveller program, they cannot or have not been able to share that validation with IRS directly.
Maybe it's a coincidence but it seems like the two agencies work together. They also apparently withhold government services if they think you owe them money. Not sure if I think that's amazing, or petty. Leaning towards amazing though.
edit - looks like no. On the one hand a single sign on to both would have been nice, OTOH TreasuryDirect's authentication system is a PITA.
It still amuses me how few people, even those who claim security expertise, don't understand that commercial malware is able to hook the driver stack (and or browser's network stack) and intercept pre-encrypted HTTPS traffic.
Hooking traffic rather than keystrokes is preferred because in order to resell that stolen data the data needs CONTEXT. A stream of keys is difficult to interpret into anything meaningful at scale, whereas "HTTPS POST Request to URI [xyz] with fields [X & Y] with values [J & W]" is very monetizable.
What I am saying is TreasuryDirect's on-screen keyboard "security" stuff is complete nonsense, it has no technical merit at all. None. Worse still it also hurts users of accessible technologies, touch-screens, or users using password managers (essentially promoting password re-use, a common problem).
Even something as simple as disabling navigation links/buttons after being clicked before the next page load would mostly solve this and save hours of frustration having to re-login through their god awful signin flow every time.
So hopefully other agencies will move away from ID.me as well.
Sponsored News needs a much more prominent badge. #bringbacktheblinktag
I'm curious what the experience was like.
The "FedRamp" contract overhaul pretty much locks in the requirements and specifications to these above implementations.
I have designed an API that revolves around and side-steps this that currently serves 60 million US civilians...but in the end, the security assessment pretty much comes down to the Privacy Acts interpretations and the common sense security landscape.
If you are a leader in the bureaucracy, your incentive is to not personally fail, which is not the same as to succeed.
There is an army of auditors waiting to question every decision, so the obvious way to avoid that is to not make any. Balancing the need to do something without deciding anything is an art of sorts.
That creates an incentive never to label anything a failure and just keep pumping good money after bad - that's how to avoid the negative article.
I could probably spend a week telling war stories, but the main takeaway is that you can't look at government as just another sector waiting to be brought up to speed. Government is an entire industry unto itself, with incentives that seem fully alien to anyone from the private sector. Money doesn't flow according to the laws of capitalist physics, but by byzantine congressional allocation. Understanding how things actually get done requires a ton of time, networking, study, and empathy.
Career government techies are extremely risk adverse (for a lot of very good reasons). If you want to make an impact, it helps to be able to take on a lot of the risk that nobody else wants to. For me, that meant promoting open-source alternatives to various entrenched products (cough, MS Access, cough) and accepting all the blame if the higher-ups don't like it. For this reason, it helps not to look at this as a career.
Going up against the entrenched interests can be frustratingly hard. It feels like everything is subtly working against you. Or, not so subtly- On more than one occasion I had teammates get singled out by the federal IT press. Somehow I managed to stay anonymous, but the threat was there. Fortunately, I felt a strong sense of support from my bosses, as well as a lot of righteous fury from seeing so many failed, hundred million dollar projects that could have just been a simple web app.
Granted, it's been about five years since I was in government. I would be curious to know if things are different nowadays :)
Try putting in 2 lower security passwords but then backspace deleting them and you get.
zxcvbn.feedback.use_a_few_words_avoid_common_phraseszxcvbn.feedback.no_need_for_symbols_digits_or_uppercase_letters
visible on the screen. I get it isn't a technical issue but still, doesn't give me confidence
The lower tier is like and Internet account. Validate with a password and 2fa, etc.
The next tier is required to log in to certain sites and requires you to upload ID etc to verify.
Once you have verified with that, you have an extra set of attributes to do more sensitive things on certain sites.
The IRS system is, by far, the worst I've ever had to deal with, and in this I'm comparing the US to countries like Rwanda, where, for some weird reason, I'm also required to pay taxes.
Getting an ITIN (sort-of like a SSN, except you're not supposed to use it like that, otherwise they will send Ted Cruz after you...) is an absolute pain, mostly because you can only request it by phone, and literally nobody you talk to is able to spell your name right, DESPITE you repeating it endlessly in just about any spelling alphabet possible.
So, you now have a dozen-or-so ITINs (again, like SSNs), all in different names, none of them yours. So, you file your taxes using the ITIN in the names that is closest to yours, and specify this on your tax forms.
You send in your forms, and your check, which is cashed immediately. Repeat the next year, and so on.
Now, after FOURTEEN years or so, you get sent a letter, informing you of a tax audit, and demanding you are physically present in Austin, Texas, two weeks from the postmark of the letter (never mind it reached you three months after that, and never mind you're located in Europe, which at that time was denied access to the US due to COVID-19).
So, you get a lawyer, which costs close to US$ 8000. The lawyer contacts the IRS, which continues to insist on an in-person interview in the past.
So, now you're out US$ 8000, and can never travel to the US again.
But, yeah, lovely that they now allow additional login tools...
That's by design
I mean, I'm happy to pay my US taxes. Heck, I'm even happy to pay someone to pay my US taxes. But... neither of those options seem to work?
I mean, just to back to Rwanda: it's an east-African country that is pretty much a dictatorship and had a real-life genocide less than 20 years ago.
Yet, in Rwanda, I can just use my native cell phone number as my tax identifier, pay then what I need to pay, and be done with it.
In the US, I am probably known under a dozen ITINs, and literally none of that is my fault: it's just that the IRS agents that created those ITINs were unaware of, like, any spelling alphabet ever. Even ITINs created using a fax (that's a TIFF-over-POTS, for you millennials) got completely misspelled.
And now I'm supposed to spend tens of thousands of dollars to prove I've paid my taxes?
OK, now I now the answer to my initial question...
You also have corporate interests that profit from convoluted tax filing and lobby the government to keep it confusing so individuals continue to use their products.
But, it seem like a particular US infliction to make paying taxes as hard as possible? Plus, they sanction you in extreme ways if you don't manage to jump through all the hoops?
I pay taxes in many jurisdictions. Here is my experience: Netherlands (my home country): the tax authorities send me a proposal about payable taxes. This includes income from my business, my partner's job, our common investments, and some investments/business interests that are exclusive to me. I correct whatever is required (with the deadline being April 1st), and I'll get my final settlement sometime in June/July.
Germany/France: I provide the tax authorities with my Dutch tax identification number, and they confirm they're fine with that in 3-4 months time. Rwanda, Nigeria and Zimbabwe: I also provide my native tax details (sometimes using my mobile number, sometimes using my NL 'SSN'), and they're fine with that, sometimes after billing me a small percentage over some income.
US: I honestly have non idea where I stand. The IRS refuses to talk to me, yet summons me to physical meetings in the past that I cannot legally attend. I have hired several attorneys, none of which seem to be able to help.
I probably owe several HUNDREDS of dollars in US tax. I've not visited the US since 2004, and have not done any business there since 2002.
Yet... I'm apparently a much-wanted tax fugitive in the US. Does that count on a FAANG-inbound resume?
I have to assume that they have some serious database problems that they are completely unable to handle, likely because of staffing and budget cuts that appear to have been intended to cripple them.
It actually is, too. There are two large, influential groups of stakeholders who purposefully lobby for a painful user experience.
The first, of course, is the tax-prep industry (e.g. Intuit/TurboTax and H&R Block). They make more money when people get fed up with bullshit and pay someone else to deal with it.
The second is the anti-tax activists. If taxes exist, they want the process of taxation to be painful. Not just in terms of the dollar amount. They want people to have an active and visceral reaction to taxes. As such, they lobby against anything streamlining taxes and push for the process to be as high-friction and frustrating as possible.
>it’s not just the TSA i should dislike.
You should try interacting with Australian or Canadian border forces if you want to see a true organization you should dislike. Hard to see Australia or Canada being even minor players if they can't deal with that dysfunction.
I’m both Australian and Canadian, so maybe I’m bias but comparing them to the TSA is a stretch imo.
I think when being passive aggressive starts to harm readability, maybe you should just say what you're trying to say.
The challenge with an ITIN is it blurs into immigration, visa status, whether you are violating visa terms, whether your ITIN - which you can get on a tourist visa - is an indication that you're trying to build a life here when you're just supposed to be a tourist, and so on. That doesn't even get into property ownership, or being a director or shareholder in a US corporation with an ITIN and various visa types.
???
France as a foreigner:
You arrive in the country, your employer already declares all taxes for you. While you may not have a tax ID to log in to impots.gouv.fr yet, everything is already registered in your name (because you gave either your SSN, or your visa number, or anything else). You send a letter to ask for a username/password to use to log in on the website, which arrives about two weeks later.
Your taxes are collected monthly, and at the end of the year you pay the leftover/get paid what you overpaid. You can tell the state at any point how much you think you will earn, and it gets reevaluated. Your yearly tax filing is prefilled, and there's no need for any software.
As an employer, the URSSAF website is, while hell to navigate, very clear in how much you owe. Give out your SIRET/SIREN, your tax report, and your taxes are done.
And yeah, the SSN isn't necessary. It is however usable for SSO through ameli.fr, for your taxes and many other services.
I just want an ITIN that is, like, actually in my name. Plus the IRS to agree that I do not owe any taxes in the 20-or-so ITINs that they have issued in various misspelled variations of my name.
But yeah, to get any clarity, I apparently need to go to Austin, Texas, in 2020.
And time machines are "easy to deal with", apparently?
So, what more is there, exactly, to my story? My name is pretty simple, but, like many European names, has 3 parts, as well as some 'unexpected' letter combinations.
As far as I know, you can only request an ITIN by phone. Possibly, this can also be done online now, but that wasn't the case in the 1999-2009 period that I'm talking about here.
Also, the person that answers the phone... how do I say this? Is not exactly fluent in English... Or Spanish (which I can at least spell my name in as well)... Or any human language?
So, you get a new ITIN, with a random ASCII string as a name. And, to file a valid tax form, your ITIN needs to match your name... Which you provide in a PDF.
See where the problem lies here? You want me to upload a few scans of US government letters/forms with my actual name horribly misspellt? You want to see my attorney invoices? Certified PDFs only, I assume?
What, exactly, is the burden of proof you place upon me here?
It's amazing how massive systems often have no viable process for "As an end user, some of the data in the system is incorrect, and I would like to get it corrected."
Once it's in the system via the setup process, it's there. And most people down the line working with it don't even know what system it's originally coming from.
Edit: F.ex. if someone lied about their age when getting their Social Security # (this before issue-at-birth, so it had to be applied for in person), so as to be considered old enough to work, and then decades later wanted to set the record straight to avoid collecting benefits at too young an actual age, they would probably be told by a Social Security employee that doing so was more trouble than it was worth. ... Hypothetically speaking.
The two options presented before my comment are not the only ones.
They already do!
There is so many quasi-national tracking and gov approved monopolies that they already get what they need.
Everywhere is tracked with license plate scanners, so you can't go anywhere.
Everyone realistically uses VISA or mastercard, so you can't buy anything. If you don't you're still probably banked and connected to credit agencies, so you can still be tracked. Good luck getting cash without the gov knowing. Just look at the IRS data.
You register with the gov to drive, so your IDed already by someone.
NSA et al. track god knows what about you across the internet and abroad, and where they don't go some ad network goes.
I think the only thing that we don't track is guns... and thats probably something we should track.
Fingerprint and DNA are a completely different thing, and crazily intrusive to collect on a central location.
DNA is collected on all military members. Ostensibly, they tell you it's to identify your remains if necessary. I'm sure it's used for that also :D
The most intrusive thing they did to me was the polygraph :)
Hard disagree. If you live in the US you have a connection to the federal government. I'm not saying everyone should have fingerprints or DNA on file but a national ID is something I'm fully behind. The shit show that is social security numbers, KYC, and other ways to identify a person are such a pain and for literally no good reason that I can see.
Now as a matter of authentication - verifying the identifier, we have left this up to the states in the past, with opt-in federal IDs for various purposes. Though with RealID this is being standardized. Login.gov is a way to have a digital equivalent.
But every state has an ID system, and they're all known to each other, and tied to your SSN which is a national id number. We already essentially have all the parts, just messier.
> my fingerprints and DNA are already on file with the feds somewhere
Same. Probably same for lots of people.
> US Citizens with no particular connection to the federal government
We all have a connection... we live in the US!
We first got an income tax during the civil war, and the 16th ammendment before the 1920s. Thats the relationship we've had with the government. How many people alive "almost never dealt with the federal government directly" at any point in their life?
By virtue of living here, you already have a connection. At minimum, you have to tax various taxes.
If it's just Uncle Sam that's the problem, then we use something like RealID at the state level.
In my mind, governments are like companies both are comprised of people making decisions which may or may not align with my personal interests. I want a GDPR for the government.
I do not really see how replacing your SSN with a public/private key pair that you use to cryptographically sign tax returns, loan applications, or election ballots would make a repeat of World War II any more or less likely; I just see it making identity theft a lot harder. Any government that decides it has the will and power to start a genocide isn't going to be stopped by antiquated blue paper cards.
And before you say "but that can never happen!", stop for a second and rethink that. It has happened many, many times in human history, and it will absolutely happen again somewhere unless we do our best to confound it.
Unless you want to argue that the lack of security is a feature, and that rampant identity theft is somehow stopping the US government from perpetrating the next holocaust.
US violent crime statistics are at near all-time lows. Yet I know many, many people that will not leave their house without at least one firearm. This is in small towns that haven't seen a violent crime justifying the use of deadly force in many years. Many of these same people refuse to "live in fear" of the coronavirus yet they live essentially petrified of violent crime to the point of carrying a deadly weapon for self-defense on their person at all times (not to mention the likely hundreds-thousands of rounds of ammunition and small arsenal they keep at home).
We're terrified of a national ID "because big brother" yet almost no one cared or batted an eye at the Snowden revelations "because terrorism". 9/11 was 20 years ago and killed 3,000 people. Tragedy for sure but never before in human history has the trajectory and cultural makeup of a country (let alone a superpower) been so drastically altered by what is essentially a rounding error in terms of deaths in two decades. If warrantlessly surveilling an entire population isn't big government/brother I don't know what is.
The ATF isn't allowed to have a searchable database because "the government is going to take away our guns" yet your entire life is accessible to the NSA.
It's truly bizarre.
That's an odd way of stating it. They're concerned, so they're arming themselves.. but continuing on with their lives. Sounds like the opposite of "petrified" to me.
And don't for one second pretend Americans are "continuing on with their lives", what a joke; gun culture is huge in the US, people are absolutely obsessed with the things.
Hardly a more obvious "not over it" situation exists than Americans and their guns.
It's clearly a major driving force in their lives. Perhaps petrified wasn't the best use of words. I'll suggest terrified as an alternative but the actual reality is all the same.
I've been kidnapped and robbed at gunpoint in the US. I'm pretty sure if I had a firearm that situation would have been worse. I would have either gotten myself killed or suffered the trauma of killing someone and watching them die. This isn't a movie where you go bang and the bad guy cleanly falls to the ground. Death by firearm is brutal and changes you forever (as my ex-military friends will tell you). Life isn't Hollywood and anyone who thinks their life will be the same and just fine after using that weapon is either a bona fide psychopath or delusional.
I also can't imagine waking up everyday and strapping a gun to myself just to leave the house. I'd consider that fear winning and an event that I've long sense gotten over continuing to have an outsized amount of control and power over me. I got out of my traumatic event losing an iPhone and $100. After a few months of initial PTSD my life hasn't changed one bit. I won.
I'm more speaking to the motivation behind absolute, 100% carry everyday. It's completely emotional, fear driven, and not in any way supported/justified by the data.
I'll bet you money that most Americans are not okay with this either.
I'm actually not a huge fan when people act like Americans are a a bunch of flag-waving morons, because I think that people who say that are often being extremely reductive to a borderline-offensive level [1], but in this case I do think Americans are uniquely ok with pretending their rights don't exist when they're convinced it's for a greater good.
[1] Disclosure, I'm American
Check Canada. We are way more screwed up in this department
I know people like this and it's not a good mantra to follow. I have to remind them that all that needs to happen is to have political winds go the other direction and soon something they do regularly becomes illegal or suspicious. So dumb to give up privacy for safety.
I'm not a fan of that, and the only way I can think of to avoid this being an issue is for them not to have the information in the first place.
Practically speaking the United States has been a "papers please" country for a long time.
What we're talking about here is a standardized, national ID. It's currently a weird patchwork of driver's licenses, identification cards, etc - each of which are slightly different variants issued by each of the states. So we don't have a standardized national ID. We have at least 50 of them, all with different formats, different issuing criteria, different validity, etc. We've tried to have some bare minim standards for years (REAL ID act) but the mandatory compliance date for that keeps getting pushed (currently next year).
Stop and identify" statutes are laws in several U.S. states that authorize police to lawfully order people whom they reasonably suspect of a crime to state their name. If there is not reasonable suspicion that a crime has been committed, is being committed, or is about to be committed, an individual is not required to provide identification, even in these states
Don't let your bubble from small town USA distort your view of the entire country.
If you live in a city and carry a gun, you're not protecting yourself, you're escalating the violence.
Getting robbed is exceedingly rare anywhere in the US, and trying to stop a robbery with a gun is among the stupidest things a person can do.
Further, robbing someone doesn't mean you should die, and killing someone over property is evil beyond comprehension. No society should support it, and very few do (nearly nowhere in the US, for example).
I don't understand what you're arguing. Cities unequivocally see more crime than rural areas, even in nicer areas within a city (which may only be 1 mile from the "bad parts").
> Getting robbed is exceedingly rare anywhere in the US, and trying to stop a robbery with a gun is among the stupidest things a person can do.
> Further, robbing someone doesn't mean you should die, and killing someone over property is evil beyond comprehension. No society should support it, and very few do (nearly nowhere in the US, for example).
1. Not everywhere is the same. Just because you feel comfortable in your bubble doesn't mean that owning a firearm is a ridiculous proposition for all. In my past 10 years of living in Atlanta, I've witnessed or been a victim of enough crime to fully understand why some folks here choose to own a gun.
2. The second part is totally ridiculous. Nobody is arguing that all thieves should die.
And no, “cities“ are not one solid, unbroken group, they are not universally more dangerous than rural areas.
You’ve turned the conversation into something else entirely. You think the entire country of 350M lives in fear? Seriously? I get that HN loves to shit on Americans but what exactly is your point here?
My first comment says “many cities see crime” somehow that became “all cities see crime everywhere” in your mind.
And if you think me saying "And no, “cities“ are not one solid, unbroken group" means “all cities see crime everywhere”, you've gotten yourself very lost, friend.
You seem to be lost yourself. What exactly do you disagree with me on from the original comment?
Violent crime rates in the city very low relative to the past.
You are much more likely to be injured or killed in a suburban car accident than an urban assault/murder/mugging.
Paradoxically, I don't have a single friend in Chicago, Denver, Miami, Los Angeles, etc that carries a gun. These cities run the spectrum of gun laws and all have higher crime rates than a small town yet fear of violent crime runs higher in communities where it's non-existent.
This is anecdotal but statistics back it up. Most gun ownership is rural, personal protection is often cited as the primary factor, most gun ownership is handguns (i.e. not hunting), and white males (small town friends) love guns and carry everyday.
https://www.pewresearch.org/social-trends/2017/06/22/the-dem...
And yet, I know people in each of those cities that own firearms.
> This is anecdotal but statistics back it up. Most gun ownership is rural...
The study you cited doesn't support that claim. What the study says is "Among those who live in rural areas, 46% say they are gun owners, compared with 28% of those who live in the suburbs and 19% in urban areas."
You're failing to consider that <20% of the population lives in rural areas according to the latest 2010 census: https://www.census.gov/programs-surveys/geography/guidance/g...
This means <10% of the population is a rural gun owner. Your study also states "When it comes to hunting, however, rural gun owners are far more likely than their urban or suburban counterparts to say it is as an important reason they own a gun; 48% of gun owners in rural areas say this." Also note the study says 30% of rural firearm owners do so for sport shooting, 15% as part of a collection, and 8% as a requirement for their job.
Less than half of rural gun owners do so solely for protection. All in all, <4% of the US population owns a gun in a rural area solely for protection. That's a pretty far cry from your original claim that Americans live in a culture of fear.
Because much of Europe has living memory of national registries used for fatal purposes.
[1] https://en.wikipedia.org/wiki/Commission_nationale_de_l%27in...
Replacing SSNs with an alternative built on public-key cryptography seems like the best way forward. I do not understand the opposition to this. Having citizens sign their tax returns, loan applications, etc. with their private key instead of just writing their SSN on it would eliminate most SSN-related identity theft and fraud.
https://news.ycombinator.com/newsguidelines.html
We detached this subthread from https://news.ycombinator.com/item?id=30431203 and marked it off topic.