A year after outcry, IRS still doesn’t offer taxpayers alternative to ID.me
cyberscoop.com
cyberscoop.com
I know anything like this is going to be more complicated than it seems. Integration of lots of legacy systems, of which the federla government is probably about as complicated as it gets, with the most security-sensitive application possible.
Still, and I'm really not an expert here, but I am astonished that $187 million could possibly not be enough to get this done. If it can't be done for $187 million, it seems likely it will never be done.
But, intended with real humility and not sarcasm, I would love to hear more from someone who has more context. $187 million just seems astonishing.
Or maybe the quote is wrong that it "hasn't been widely rolled out"?
I certainly don't see my tax returns that way.. is that a commonly held view?
Then you can see where they've ever lived, and who with. All for free
It is very right, because social security numbers are not meant to be a secret.
What is wrong is being liable for a debt (or whatever) because a creditor failed to properly verify the identity of a borrower.
Those whole situation can be easily fixed by removing the ability of lenders and governments to claim they verified identity by simply asking for SSN/date if birth.
We have pocket computers with video cameras that can record and transmit spoken agreements within seconds, and we have a nationwide network of USPS offices that already do in person identity verification for issuing passports. Executing the solution is basically done, all that is left is political.
You're never liable for a debt you didn't sign for. If someone else used your information, don't pay it. The court will always side with you.
Also, credit and credit reporting is utility/infrastructure with how life is lived, including access to a place to live. So much that the federal government obligated credit reporting agencies to provide people an annual report. Having to spend time and money to fix it is also a liability, in my opinion.
I think it's wrong in some senses: Login.gov has been rolled out to the SSA, OSHA, Treasury, RRB, VA, DHS, and quite a few other orgs and agencies. There's no one good metric for these things, but if you measure it by org/agency size and/or budget, Login.gov looks very good.
I agree that $187 million is an eye-popping number, and I wish we had the ability to put it into context: it's entirely possible that $187 million spent means that each agency is saving $X million in separate/legacy maintenance each year.
Edit: Another framing is that, if the GSA's user predictions are correct[1], Login.gov will end up costing a little under $2 USD per user.
[1]: https://federalnewsnetwork.com/it-modernization/2022/06/gsa-...
As posted elsewhere in the thread: this is ~$40m/year for an IdP/login scheme for the entire USG (and, increasingly, state and local governments). That's significantly less than the engineering talent at companies like Okta and Authy probably cost each year, even before factoring in overhead and non-engineering roles.
All things considered, this looks like a very efficient use of taxpayer money to me. Particularly since it seems to have been primarily paid for on GS pay grades, not with private contractors.
At average FAANG salaries with overhead (benefits, space, equipment both desk and datacenter/cloud, internal workplace support functions like Recruiting, IT, HR, ER, DEI...) that's 60 people.
That's not many when dealing with multiple massive counterparties. You'll see ratios of non-dev to dev easily 10:1 to 30:1.
Yes, they could genuinely spend $187M so far on a project accomplishing only 2 devs x 5 years worth of work and rework.
The IRS estimated that the average taxpayer spends $240 and 13 hours of time on their taxes. Multiply by 157 million taxpayers and that's $37 billion and 2 billion hours of labor. Although likely skewed by a small % who hire professionals, plenty of people spend $100+ on services like TurboTax.
The IRS spending a couple billion to make the tax process a little bit easier is really not a big deal. $187 million is nothing, and if that's all it costs to streamline their ID verification process, then it means the government is much more efficient with our tax dollars than people give it credit for.
Even on a $2/mo VPS that's enough for image recognition in something as slow as Python. What gives?
>
> LoadError: cannot load such file -- sassc
>
> Try make run for a short time, then use Ctrl+C to kill it
That's.. confidence making.
The difference is it's not a forced central ID system, which is the primary difference between a useful tool and the foundation of a police state. "Your papers, please" was a meme before there was even the concept of memes.
Passports being optional and expensive, they don't fit the same utility as a universal ID system, but you're right, they could.
> The difference is it's not a forced central ID system, which is the primary difference between a useful tool and the foundation of a police state
Laughable bullshit. Specific technical things, especially ones with actual utility, such as ID cards, or speeding cameras, are not "the foundation of a police state". A police state is a systemic thing, and can be achieved with low tech (Stasi) or high tech solutions (drones doing facial recognition and pattern tracking) regardless of utilities available to the general population.
What you actually want is laws and systems preventing police abuses, spying without just cause, tracking en masse, etc.. Refusing utilities that have actual real life applications that are genuinely useful because they could be abused isn't preventing anything. Do you forget the Patriot Act and everything that came out of it? The US president ordering the execution of an American citizen without due trial? Guantanamo? Police abuses on a massive scale? And I'm sorry, it's ID cards that are the foundation of a police state? Your efforts are misguided and wasted.
And again, the US federal government already has multiple ways of knowing everything about anyone - like with IRS records and not to mention credit reporting agencies and telecoms selling this kind of data to whoever, including government agencies. That ship has long ago sailed, why not actually make it into something useful?
If you had a real counterproposal involving an achievable goal, such as legislation strengthening protections of existing national ID systems, making them cheaper or more accessible to encourage adoption, or anything at all other than a national forced ID system, it would be a more credible argument. Several states have already passed laws prohibiting compliance with such systems. It's never going to happen without decades of brutal legal battles in a country that can barely pass a budget from year to year.
In other words, the "laughable bullshit" is in fact the default policy and people with your convictions are going to have to be much more convincing of the utility you claim it will bring, which is arguable at best. You say my efforts are wasted, but I don't recall having made any, and here we are with no national ID, and a strong bipartisan opposition to the idea.
I'm not going to bother with the breathless whataboutism, because it's completely irrelevant. The plain fact is that citizens on average don't need to identify themselves to the federal government that often, and those who do already have avenues through which to do it. That's a lot of inertia, and your arguments have so far been insufficiently compelling to overcome it. I remain confident that these conditions will persist.
ID is a basic component of pretty much any functioning bureaucracy. Further, we already have near universal ID at the state level, what about the federal government makes it so much more magically tyrannical than the states?
Name a government in existence that functions without a central identification infrastructure of some sort. Having ID isn’t what leads to totalitarianism, it is a ubiquitous fact of having a bureaucracy that delivers services to its citizens.
In most instance, having government id is not a harbinger of risk of totalitarianism. There are more important things to focus on.
Within living memory, the United States of America.
And before "but drivers licenses are not national" they effectively are via cooperation between the various states and between the states and the federal government
I have tried to get info out of IRS on the topic using FOIA requests, but they have not been forthcoming. I think there is heartburn over the whole ID.me situation (which they rushed into due to return fraud that occurred due to lacking knowledge based proofing systems, and got blindsided by the PR fallout of suboptimal machine vision/facial recognition tech and overzealous marketing).
The article states Charles Rettig, who was then IRS commissioner, argued that login.gov can’t meet their request rate requirements, and yet it serves over 220 agency websites and is the primary identity provider for the Social Security Administration website since September 2021. I would be very interested in the technical challenges being more publicly available versus hand waving by the bureaucracy.
https://secure.ssa.gov/RIL/SiView.action
There was recent funding to have the USPS perform in person identity proofing; login.gov appears to be leveraging this. They are also working to offer login.gov to state unemployment systems concurrently (a colleague is on this team).
https://fcw.com/digital-government/2022/05/postal-service-sh...
https://fcw.com/digital-government/2022/10/labor-department-...
https://www.login.gov/help/verify-your-identity/verify-your-...
https://tcf.org/content/commentary/biden-budget-would-signif...
https://www.gao.gov/assets/730/720919.pdf
> In addition to the forthcoming work with the jobless aid system, USPS is also working with GSA's Login.gov, a shared sign-on and identity proofing service.
> “The Postal Service’s unmatched retail footprint offers a unique opportunity for government agencies, such as the General Services Administration that need to complete an in-person proofing. We are actively working with government agencies to do this today,” a USPS spokesperson told FCW.
> In-person identity proofing is offered for Login.gov at seven USPS locations in Washington D.C., Maryland and Virginia, according to the Login.gov website. Individuals start the process online and then bring state-issued identification and proof of address to be reviewed in-person to match the digital application with the real person behind it.
My note/opinion: stronger requirements are necessary to enable login.gov to deliver whatever gap private identity providers (id.me) are offering and require federal agencies to use login.gov
Then login.gov can support the addition of known crypto IDs as alternate signatures and a review that can also happen at any of the interaction points (some USPS branches, DoL/DMV, Homeland Security offices for enhanced passport ID stuff).
https://www.muckrock.com/news/archives/2018/sep/06/foia-faq-...
The UK digital government team have written about this at length, eg https://gds.blog.gov.uk/2021/10/19/single-sign-on-what-we-le...
Not so great for sending secret messages, but really great for an identity toehold.
(That's even before quibbling over whether PGP would be the right choice for civil cryptographic identities, which it probably isn't.)
- Go to the post office, have ID verified, papers verified, pictures taken, GPG keys created multiple so you can revoke one and leap-frog to another without being in an orphaned state, ID card printed that has a GPG signed PDF417 [1] code on both sides and a color picture.
- Lost card? Go back to post office and have them revoke your card and your active GPG key. Get new card that uses one of your unused GPG public keys that have already been uploaded to the various government servers.
- No RFID, no NFC, no Magstrip, no eco-friendly plastic. Make this thing nearly indestructible and only the PDF417 is used by sensors and can be scanned or photographed by someone paying their taxes or filing other government forms.
- Braille dots along top of card to make it easy to find the card and to show which way to hold and insert card in readers that should also have corresponding braille dots.
If people are fraudulently abusing the social security number system, stealing other people's numbers and so on, then they should be prosecuted for fraud.
Implementing a Chinese-style facial recognition and social credit score program in order to keep tabs on everyone is just another authoritarian fantasy project, and government incompetence during the pandemic is no excuse for creating such a dystopian system.
One party wants to empower the Gestapo and the other party wants to empower the STASI. What could go wrong?
your comment is equivalent to telling developers to stop wasting time on endless security fixes when we should just make computer hacking illegal, and prosecute people for it.
Who's going to do that? My spouse had an Oakland luxury apartment rented in her name, with her social security number and everything. But Oakland PD won't do anything, and nobody else cares either. The apartment management wasn't even sure they could evict because of covid restrictions at the time. It's fully reported, not our problem anymore.
If!? Basically every SSN has been breached. It's statistically certain at this point with how many breaches there have been. You think its feasible to prosecute that much fraud? For the same org thats paying $200m for broken websites?
Who is doing this?
Also, even the “social credit score” system in China has been greatly overblown and misinterpreted in western media. [0]
[0] https://www.wired.co.uk/article/china-social-credit-system-e...