Unfortunate it’s not login.gov but definitely an improvement over their bespoke customer identity and access management solution.
ghaff•37m ago
And 1990s era website design (maybe). I'll have to retrieve my credentials from somewhere I guess. Not sure why they're not unifying it with other government websites.
toomuchtodo•34m ago
The arc of progress is like the visibility curve over the horizon. We keep sailing.
qgin•34m ago
Does anyone remember their crazy Ovaltine-decoder-ring two factor auth that they had for a while? They mailed you a physical card with custom grid of numbers and letters and the login challenge would be to submit the letters an numbers at various grid points.
dbalatero•31m ago
Yeah, there's no mandate for government agencies to use login.gov AFAIK, so they can either go with login.gov or buy the private id.me solution. In general it's not a slamdunk to get agencies to cooperate and use their services, it seems.
toomuchtodo•29m ago
Login.gov has some technical gaps for agency customer identity use cases, which is why you don’t see it used by some agencies yet (depending on their customer identity assurance requirements). The outstanding technical gaps will be closed eventually, at which point id.me can be phased out as a private for profit idp vendor.
> GSA has closed most of the gaps GAO identified in 2024 and 2025, but the remaining recommendation has a direct operational consequence. GSA has developed a public roadmap and created a Partner Advisory Group, but GAO says those steps do not demonstrate that the specific technical challenges agencies identified have been resolved or that mutually agreed-upon time frames have been established.
> GAO will continue monitoring GSA's progress. Until those time frames are established, the federal government's government-wide identity verification service retains an unresolved implementation gap as fraud and identity-theft threats continue to evolve.
Why did the US gov decide to rely on a TLD controlled by Montenegro for this seemingly important and sensitive service?
noinsight•28m ago
It’s funny… In Finland they went with hightrust.id (Indonesia) too.
isiahl•26m ago
It’s not even a government service. It’s a private business they have entrusted with authentication for the government.
varispeed•22m ago
textbook fascism (marriage of corporations and government).
rho138•3m ago
Queue the flag/downvote storm for callimg out the system that provably doesn’t work.
waldrews•32m ago
TreasuryDirect's login and account recovery experience has been notorious for years, both for user experience and for people easily getting locked out for weeks. It's good they're being careful with this rollout, as it serves both individual and institutional accounts where dollar amounts involved are epic even by bank standards, and rarely checked by hand, so even single account breaches are serious.
shevy-java•19m ago
> To set up a new ID.me account, you’ll need two government-issued forms of identity ready.
That will be rolled out before anyone can access the world wide web. And they will continue to claim it is for the protection of kids ...
toomuchtodo•42m ago
ghaff•37m ago
toomuchtodo•34m ago
qgin•34m ago
dbalatero•31m ago
toomuchtodo•29m ago
https://legis1.com/news/logingov-technical-issues-gsas-platf...
> GSA has closed most of the gaps GAO identified in 2024 and 2025, but the remaining recommendation has a direct operational consequence. GSA has developed a public roadmap and created a Partner Advisory Group, but GAO says those steps do not demonstrate that the specific technical challenges agencies identified have been resolved or that mutually agreed-upon time frames have been established.
> GAO will continue monitoring GSA's progress. Until those time frames are established, the federal government's government-wide identity verification service retains an unresolved implementation gap as fraud and identity-theft threats continue to evolve.
https://www.gao.gov/products/gao-26-109261