RU version is available. Content is displayed in original English for accuracy.
Advertisement
Advertisement
⚡ Community Insights
Discussion Sentiment
71% Positive
Analyzed from 1551 words in the discussion.
Trending Topics
#system#login#gov#government#account#identity#using#treasurydirect#don#password

Discussion (46 Comments)Read Original on HackerNews
And of course this will be used to track down illegal aliens.
[1] https://www.biometricupdate.com/202202/downwind-of-irs-decis...
I'll now quote from https://www.snopes.com/fact-check/fascism-corporations-corpo... , which thoroughly rejects that interpretation:
"In other words, corporatism in Mussolini's fascism was not a free-market capitalist system. Far from it. It did not allow for the kind of competition, innovation, market entry, and research and development characteristic of modern capitalism, and it was closely ruled in every way by the state with Mussolini at its head.
Anything that draws a direct link between what are now referred to as corporations (large, powerful private companies operating in a modern free-market capitalist system) and Mussolini's corporatism, is founded on a misunderstanding — most likely caused by the similarity between the words."
I’m really sad to see that’s yet another thing the current administration is destroying
For IAL2 identity proofing, Login.gov is only for US persons, i.e. validating US-issued credentials. Meanwhile. ID.me has support to validate foreign passports.
So, if TreasuryDirect supports foreign customers, it makes sense to offer ID.me, but it seems inappropriate not to offer Login.gov for customers who are US persons!
Glad I don't actually need to login to my irs account lately.
I still pay my taxes by physical check, because they won’t let me pay digitally unless I sign in with ID.me.
Let's be honest, the US government can control basically any domain it wants. I doubt Montenegro is going to cause any problems for it.
ID.me is a private third party system, that I won’t ever use.
They used to support TOTP directly, but removed it in favor of their proprietary mobile apps. It's still TOTP under the hood though, just requires a couple API calls to "activate" it.
The more third parties they throw into the mix, especially when it's just to increase security theater, the more convinced I am that I should be mailing in any financial government paperwork, even if I am eligible to do so electronically.
Treasury is requiring she get a medallion signature guarantee from a bank to access her funds but, like 40%+ of her generation, she uses online banking with no accessible branch. Treasury insists she can get this from any bank, but as the guarantor is liable for a loss, there's no way they will provide this to a non-client. They generally won't even make their ordinary notary public available.
So she is now switching financial institutions simply to access a modest amount in her TreasuryDirect account. If you are thinking about gifting saving bonds to someone: do them a favor and don't.
Is it though?
With a service-specific system, if the system gets compromised, you lose your data on that system. With a centralized system that still happens, but then on top of that, there is also a centralized service to get compromised where you also lose your data on that system and every other system using it. The centralized system also ossifies with whatever flaws were present in the naive early implementation like the ancient credit card networks have, because once untold agencies and private entities are using it, anyone who wants to change anything about it is inundated with objections from thousands of entities who don't want to have to redo their integrations.
Meanwhile your activity is then correlated between different accounts. You have retailers using id.me to "verify military, student, teacher, nurse, or first responder status" for discounts. Not only do they get your name via computer instead of a physical document you would object if they tried to copy, you're now using the same system you use for taxes and healthcare. Is ICE going to use this against people? Are foreign intelligence agencies going to silently compromise it and use it against the domestic population? That's inevitable once you allow a centralized system like that to exist.
If you want to do this properly then you publish a reference implementation for an authentication system and let every organization run their own independent instance of it. That way a) none of the accounts are tied together and b) you can improve the system whenever you want and people can adopt the new version independently instead of needing to coordinate the entire world before you can change a single API parameter.
Had to constantly popup Chrome DevTools and "fix" the dom element to let paste work.
https://legis1.com/news/logingov-technical-issues-gsas-platf...
> GSA has closed most of the gaps GAO identified in 2024 and 2025, but the remaining recommendation has a direct operational consequence. GSA has developed a public roadmap and created a Partner Advisory Group, but GAO says those steps do not demonstrate that the specific technical challenges agencies identified have been resolved or that mutually agreed-upon time frames have been established.
> GAO will continue monitoring GSA's progress. Until those time frames are established, the federal government's government-wide identity verification service retains an unresolved implementation gap as fraud and identity-theft threats continue to evolve.
https://www.gao.gov/products/gao-26-109261
That will be rolled out before anyone can access the world wide web. And they will continue to claim it is for the protection of kids ...