Last time I filed state taxes, I didn't qualify to use free electronic filing, because I was too poor, so I mailed in my taxes. I was a little concerned that postal employees present a security risk, but I'm not convinced it's more than the increased attack surface from whatever third parties handle electronic submission.<p>The more third parties they throw into the mix, especially when it's just to increase security theater, the more convinced I am that I should be mailing in any financial government paperwork, even if I am eligible to do so electronically.
Does anyone know if there are any reasonable alternatives here if I don't want to create an ID.me account and hand my PII over to them? Do I just need to liquidate my positions and close my account out, or can I manage it offline via correspondence somehow? Seems absurd to have so quick a turnaround on this with no alternative options.
The IRS backed off from using "ID.me" back in 2022.[1] But apparently it is back.
Is Treasury requiring face recognition, like last time?<p>And of course this will be used to track down illegal aliens.<p>[1] <a href="https://www.biometricupdate.com/202202/downwind-of-irs-decision-to-back-off-biometric-authentication-more-change" rel="nofollow">https://www.biometricupdate.com/202202/downwind-of-irs-decis...</a>
Why did the US gov decide to rely on a TLD controlled by Montenegro for this seemingly important and sensitive service?
Personally, I love that you go to irs.gov and the top tells you it's a us govenrment sit eand how to know (tld is .gov) ... But then you try to login and get hijacked by a site affiliated with a different country.<p>Glad I don't actually need to login to my irs account lately.
It’s not even a government service. It’s a private business they have entrusted with authentication for the government.
And we even have login.gov, too! (… which I really hope replaces ID.montengro one of these days, but … I guess not, if the Treasury is adopting it now.)
They didn’t. The federal government has login.gov which things were slowly consolidating towards.<p>ID.me is a private third party system, that I won’t ever use.
> US gov decide to rely on a TLD controlled by Montenegro<p>Let's be honest, the US government can control basically any domain it wants. I doubt <i>Montenegro</i> is going to cause any problems for it.
It’s funny… In Finland they went with hightrust.id (Indonesia) too.
TreasuryDirect's login and account recovery experience has been notorious for years, both for user experience and for people easily getting locked out for weeks. It's good they're being careful with this rollout, as it serves both individual and institutional accounts where dollar amounts involved are epic even by bank standards, and rarely checked by hand, so even single account breaches are serious.
In case anyone is interested in using TOTP two-factor authentication with their ID.md account, I made a script for setting that up: <a href="https://github.com/chenxiaolong/id-me-otpauth" rel="nofollow">https://github.com/chenxiaolong/id-me-otpauth</a><p>They used to support TOTP directly, but removed it in favor of their proprietary mobile apps. It's still TOTP under the hood though, just requires a couple API calls to "activate" it.
Unfortunate it’s not login.gov but definitely an improvement over their bespoke customer identity and access management solution.
I was happy when they got rid of the virtual keyboard you had to type your password onto, such a pain since you also couldn't paste into the password field to autocomplete from a password manager.<p>Had to constantly popup Chrome DevTools and "fix" the dom element to let paste work.
Does anyone remember their crazy Ovaltine-decoder-ring two factor auth that they had for a while? They mailed you a physical card with custom grid of numbers and letters and the login challenge would be to submit the letters an numbers at various grid points.
So like a one-time-pad? Except not, since it sounds like they re-use it for each login. If they had sent you a pad of codes, with instructions to tear off the top page each time, that would be closer.
I’ve compiled the entire sordid history of TreasuryDirect authentication in their Wikipedia article: <a href="https://en.wikipedia.org/wiki/TreasuryDirect" rel="nofollow">https://en.wikipedia.org/wiki/TreasuryDirect</a>
That type of system is actually still in use in a lot of industries—either as a primary factor or a fallback for folks who might need to log in without a working device. Think healthcare workers who forgot their phone but need to order a surgery, or outdoor safety workers updating the toughbook after a day of work that might damage phones.
Yes, I had one of those cards. It made you feel like you were accessing government secrets. In 2007.
I still have mine! It was really excellent before camera phones.
Yeah, there's no mandate for government agencies to use login.gov AFAIK, so they can either go with login.gov or buy the private id.me solution. In general it's not a slamdunk to get agencies to cooperate and use their services, it seems.
Login.gov had/has some technical gaps for agency customer identity use cases, which is why you don’t see it used by some agencies yet (depending on their customer identity assurance requirements). The outstanding technical gaps will be closed eventually, at which point id.me can be phased out as a private for profit idp vendor.<p><a href="https://legis1.com/news/logingov-technical-issues-gsas-platform-lacks" rel="nofollow">https://legis1.com/news/logingov-technical-issues-gsas-platf...</a><p>> GSA has closed most of the gaps GAO identified in 2024 and 2025, but the remaining recommendation has a direct operational consequence. GSA has developed a public roadmap and created a Partner Advisory Group, but GAO says those steps do not demonstrate that the specific technical challenges agencies identified have been resolved or that mutually agreed-upon time frames have been established.<p>> GAO will continue monitoring GSA's progress. Until those time frames are established, the federal government's government-wide identity verification service retains an unresolved implementation gap as fraud and identity-theft threats continue to evolve.<p><a href="https://www.gao.gov/products/gao-26-109261" rel="nofollow">https://www.gao.gov/products/gao-26-109261</a>
And 1990s era website design (maybe). I'll have to retrieve my credentials from somewhere I guess. Not sure why they're not unifying it with other government websites.
This makes me so angry.
> To set up a new ID.me account, you’ll need two government-issued forms of identity ready.<p>That will be rolled out before anyone can access the world wide web. And they will continue to claim it is for the protection of kids ...