HN user

throwaway492810

-3 karma
Posts0
Comments3
View on HN
No posts found.

Sorry, I pasted the wrong link for [1], which describes how 18F thought facial recognition was racist, so it simply did not implement it for high-security accounts despite being required by spec, and falsely assured agencies that it was in compliance anyway. It is here:

https://www.gsaig.gov/content/gsa-misled-customers-logingovs...

The executive summary says: "Our evaluation found GSA misled their customer agencies when GSA failed to communicate Login.gov’s known noncompliance with the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-63-3, Digital Identity Guidelines. Notwithstanding GSA officials’ assertions that Login.gov met SP 800-63-3 Identity Assurance Level 2 (IAL2) requirements, Login.gov has never included a physical or biometric comparison for its customer agencies. Further, GSA continued to mislead customer agencies even after GSA suspended efforts to meet SP 800-63-3. GSA knowingly billed IAL2 customer agencies over $10 million for services, including alleged IAL2 services that did not meet IAL2 standards. Furthermore, GSA used misleading language to secure additional funds for Login.gov."

Sorry, I pasted the wrong link for [1] (though you could have easily found it by googling "GSA Misled Customers on Login.gov’s Compliance with Digital Identity Standards"). It is here:

https://www.gsaig.gov/content/gsa-misled-customers-logingovs...

The executive summary says: "Our evaluation found GSA misled their customer agencies when GSA failed to communicate Login.gov’s known noncompliance with the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-63-3, Digital Identity Guidelines. Notwithstanding GSA officials’ assertions that Login.gov met SP 800-63-3 Identity Assurance Level 2 (IAL2) requirements, Login.gov has never included a physical or biometric comparison for its customer agencies. Further, GSA continued to mislead customer agencies even after GSA suspended efforts to meet SP 800-63-3. GSA knowingly billed IAL2 customer agencies over $10 million for services, including alleged IAL2 services that did not meet IAL2 standards. Furthermore, GSA used misleading language to secure additional funds for Login.gov."

18F/TTS repeatedly was cited by the Inspector General for breaking rules and making false statements, often for political reasons. E.g:

March 2023: "GSA Misled Customers on Login.gov’s Compliance with Digital Identity Standards" (refused to use mandatory facial recognition because it believed it was racist) [1]

June 2017: "Investigation of Whistleblower Reprisal Complaint" (finding that an Obama political appointee retaliated against a career official for blowing the whistle on mismanagement) [2]

April 2017: GSA acknowledges "gross mismanagement" [3]

October 2016: "Evaluation of 18F" (finding that it spent thousands of dollars on things like "inclusion bots") [4]

May 2016: "GSA Data Breach" [5]

February 2017: "Evaluation of 18F’s Information Technology Security Compliance" (misrepresented severity of breach) [6]

[1] https://www.gsaig.gov/sites/default/files/ipa-reports/Alert%...

[2] https://www.gsaig.gov/sites/default/files/foia/Investigation...

[3] https://osc.gov/Documents/Public%20Files/FY17/DI-17-0642/DI-...

[4] https://www.gsaig.gov/sites/default/files/ipa-reports/OIG%20...

[5] https://www.gsaig.gov/sites/default/files/ipa-reports/Alert%...

[6] https://www.gsaig.gov/sites/default/files/ipa-reports/OIG%20...