Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • This makes me so angry.
  • Why on earth are they not using login.gov
  • Many gov sites allow one or the other. Really neither is a good solution. Is it "safe" to have everyone in the country, citizen or not, in possession of a login on a .gov site?
  • good grief. Guess I'll redeem my i series now. btw AI says print the redemption confirmation details while logged in prior to the cutover because you'll need them for taxes in 2027.
  • Last time I filed state taxes, I didn't qualify to use free electronic filing, because I was too poor, so I mailed in my taxes. I was a little concerned that postal employees present a security risk, but I'm not convinced it's more than the increased attack surface from whatever third parties handle electronic submission.

    The more third parties they throw into the mix, especially when it's just to increase security theater, the more convinced I am that I should be mailing in any financial government paperwork, even if I am eligible to do so electronically.

  • Unfortunate it’s not login.gov but definitely an improvement over their bespoke customer identity and access management solution.
  • And 1990s era website design (maybe). I'll have to retrieve my credentials from somewhere I guess. Not sure why they're not unifying it with other government websites.
  • Yeah, there's no mandate for government agencies to use login.gov AFAIK, so they can either go with login.gov or buy the private id.me solution. In general it's not a slamdunk to get agencies to cooperate and use their services, it seems.
  • > definitely an improvement over their bespoke customer identity and access management solution

    Is it though?

    With a service-specific system, if the system gets compromised, you lose your data on that system. With a centralized system that still happens, but then on top of that, there is also a centralized service to get compromised where you also lose your data on that system and every other system using it. The centralized system also ossifies with whatever flaws were present in the naive early implementation like the ancient credit card networks have, because once untold agencies and private entities are using it, anyone who wants to change anything about it is inundated with objections from thousands of entities who don't want to have to redo their integrations.

    Meanwhile your activity is then correlated between different accounts. You have retailers using id.me to "verify military, student, teacher, nurse, or first responder status" for discounts. Not only do they get your name via computer instead of a physical document you would object if they tried to copy, you're now using the same system you use for taxes and healthcare. Is ICE going to use this against people? Are foreign intelligence agencies going to silently compromise it and use it against the domestic population? That's inevitable once you allow a centralized system like that to exist.

    If you want to do this properly then you publish a reference implementation for an authentication system and let every organization run their own independent instance of it. That way a) none of the accounts are tied together and b) you can improve the system whenever you want and people can adopt the new version independently instead of needing to coordinate the entire world before you can change a single API parameter.

  • I was happy when they got rid of the virtual keyboard you had to type your password onto, such a pain since you also couldn't paste into the password field to autocomplete from a password manager.

    Had to constantly popup Chrome DevTools and "fix" the dom element to let paste work.

  • Does anyone remember their crazy Ovaltine-decoder-ring two factor auth that they had for a while? They mailed you a physical card with custom grid of numbers and letters and the login challenge would be to submit the letters an numbers at various grid points.
    by qgin
  • A young relative of mine is having a miserable time cashing Treasury bonds that were gifted to her through TreasuryDirect for her tuition.

    Treasury is requiring she get a medallion signature guarantee from a bank to access her funds but, like 40%+ of her generation, she uses online banking with no accessible branch. Treasury insists she can get this from any bank, but as the guarantor is liable for a loss, there's no way they will provide this to a non-client. They generally won't even make their ordinary notary public available.

    So she is now switching financial institutions simply to access a modest amount in her TreasuryDirect account. If you are thinking about gifting saving bonds to someone: do them a favor and don't.

  • Brick-and-mortar banks often don't want to provide these to existing clients, either. I got the runaround from mine when I tried to open a TreasuryDirect account.
  • I had a real PITA with medallion signature a while back. The local branch couldn't do it and, in spite of providing all my documents, the central location also couldn't do it for some reason. Ended up having to drive 45 minutes to my brokerage and they handled in about 5 minutes (was a stock transfer) but it was a real nuisance. It seemed like a bunch of things were suddenly much easier during COVID but they seem to have mostly reverted.

    I got some I bonds from Treasury Direct when interest rates were going crazy. It's not a lot in the scheme of things. I should clear them out and consolidate as I've done with other investments.

  • Does anyone know if there are any reasonable alternatives here if I don't want to create an ID.me account and hand my PII over to them? Do I just need to liquidate my positions and close my account out, or can I manage it offline via correspondence somehow? Seems absurd to have so quick a turnaround on this with no alternative options.
  • Even if you liquidate your account, without an id.me account, you will not be able to access your 1099.
  • In case anyone is interested in using TOTP two-factor authentication with their ID.md account, I made a script for setting that up: https://github.com/chenxiaolong/id-me-otpauth

    They used to support TOTP directly, but removed it in favor of their proprietary mobile apps. It's still TOTP under the hood though, just requires a couple API calls to "activate" it.

  • Though they recommend their own app, id.me directly supports any standard compatible authenticator app. I use it with Google Authenticator TOTP. It's also SOTA for creating and accepting passkeys on ChromeOS as well as Android. Probably Apple, too!

    Other built-in available MFA methods include: security key; NFC mobile security key; Push Notifications (id.me app); text message or phone call; and passkeys.

  • TreasuryDirect's login and account recovery experience has been notorious for years, both for user experience and for people easily getting locked out for weeks. It's good they're being careful with this rollout, as it serves both individual and institutional accounts where dollar amounts involved are epic even by bank standards, and rarely checked by hand, so even single account breaches are serious.
  • The IRS backed off from using "ID.me" back in 2022.[1] But apparently it is back. Is Treasury requiring face recognition, like last time?

    And of course this will be used to track down illegal aliens.

    [1] https://www.biometricupdate.com/202202/downwind-of-irs-decis...

  • Why did the US gov decide to rely on a TLD controlled by Montenegro for this seemingly important and sensitive service?
  • Note it is also ridiculous that these sites are allowed to do facial captures.
  • They didn’t. The federal government has login.gov which things were slowly consolidating towards.

    ID.me is a private third party system, that I won’t ever use.

  • It is not only the .me TLD we should think about. Before .me and even during, there was also the .me.gov back when domains and such things were more delineated. There is the peril of not only contending with Montenegro but also the outside chance of Maine. Let's face it, .me was never a safe choice as a top-level domain for any country (or locality). It seems like a vanity TLD to too many people and it competes for a name space it has no place in. What we probably need is a whole new TLD specifically and only for something like this. I am sure IANA is capable, though policing it would be a nightmare, unless it were handed off to something like the defense department.

    So many privacy concerns.

  • It’s funny… In Finland they went with hightrust.id (Indonesia) too.
  • > US gov decide to rely on a TLD controlled by Montenegro

    Let's be honest, the US government can control basically any domain it wants. I doubt Montenegro is going to cause any problems for it.

  • Personally, I love that you go to irs.gov and the top tells you it's a us govenrment sit eand how to know (tld is .gov) ... But then you try to login and get hijacked by a site affiliated with a different country.

    Glad I don't actually need to login to my irs account lately.

  • And we even have login.gov, too! (… which I really hope replaces ID.montengro one of these days, but … I guess not, if the Treasury is adopting it now.)
  • It’s not even a government service. It’s a private business they have entrusted with authentication for the government.