Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • Last time I filed state taxes, I didn't qualify to use free electronic filing, because I was too poor, so I mailed in my taxes. I was a little concerned that postal employees present a security risk, but I'm not convinced it's more than the increased attack surface from whatever third parties handle electronic submission.

    The more third parties they throw into the mix, especially when it's just to increase security theater, the more convinced I am that I should be mailing in any financial government paperwork, even if I am eligible to do so electronically.

  • Unfortunate it’s not login.gov but definitely an improvement over their bespoke customer identity and access management solution.
  • A young relative of mine is having a miserable time cashing Treasury bonds that were gifted to her through TreasuryDirect for her tuition.

    Treasury is requiring she get a medallion signature guarantee from a bank to access her funds but, like 40%+ of her generation, she uses online banking with no accessible branch. Treasury insists she can get this from any bank, but as the guarantor is liable for a loss, there's no way they will provide this to a non-client. They generally won't even make their ordinary notary public available.

    So she is now switching financial institutions simply to access a modest amount in her TreasuryDirect account. If you are thinking about gifting saving bonds to someone: do them a favor and don't.

  • Does anyone know if there are any reasonable alternatives here if I don't want to create an ID.me account and hand my PII over to them? Do I just need to liquidate my positions and close my account out, or can I manage it offline via correspondence somehow? Seems absurd to have so quick a turnaround on this with no alternative options.
  • In case anyone is interested in using TOTP two-factor authentication with their ID.md account, I made a script for setting that up: https://github.com/chenxiaolong/id-me-otpauth

    They used to support TOTP directly, but removed it in favor of their proprietary mobile apps. It's still TOTP under the hood though, just requires a couple API calls to "activate" it.

  • TreasuryDirect's login and account recovery experience has been notorious for years, both for user experience and for people easily getting locked out for weeks. It's good they're being careful with this rollout, as it serves both individual and institutional accounts where dollar amounts involved are epic even by bank standards, and rarely checked by hand, so even single account breaches are serious.
  • The IRS backed off from using "ID.me" back in 2022.[1] But apparently it is back. Is Treasury requiring face recognition, like last time?

    And of course this will be used to track down illegal aliens.

    [1] https://www.biometricupdate.com/202202/downwind-of-irs-decis...

  • Why did the US gov decide to rely on a TLD controlled by Montenegro for this seemingly important and sensitive service?

Explore Birbla archives