TechDigits

Tech news
Thursday, Apr 25, 2024

The IRS is working with a startup called ID.me that stores the 'inferred citizenship' of some users. That creates a huge new pool of personal data for police and other authorities to tap into.

The IRS is working with a startup called ID.me that stores the 'inferred citizenship' of some users. That creates a huge new pool of personal data for police and other authorities to tap into.

Observers worry how much information ID.me collects and how willing the company seems to be to share it with authorities when asked.
A possible collaboration between the Internal Revenue Service and a startup called ID.me is alarming privacy experts and civil-rights advocates who say the partnership will create a massive new pool of sensitive personal data that could be tapped by the police, immigration enforcement, and other authorities.

ID.me verifies people's identities by asking them to upload information, including their Social Security number, a selfie, and pictures of a government-issued ID. It then uses facial recognition and "liveness detection" on the pictures, and compares the submitted information to data from "telecommunications networks, credit card bureaus, financial institutions," and other sources, according to its privacy policy.

The company also stores the "inferred citizenship" of some users "based on passport information," along with facial images, voiceprints, location data, and information from documents such as postal addresses, Social Security numbers, driver's license numbers, passport-card numbers, and more, according to the policy.

Last month, the IRS said it would start requiring people logging into their accounts on the IRS website to use ID.me to verify their identities. The agency is considering alternative providers, but if the deal goes through, it would likely add millions to the company's user base, which already exceeds 60 million members. The technology is now used for identity verification to access benefits in 27 states.

What really worries observers is how much information ID.me collects and how willing the company seems to be to share that with authorities when asked.

"It feels like the IRS has integrated this service into its website without a lot of vetting or really necessarily thinking through these issues," Jeramie Scott, a senior counsel for the Electronic Privacy Information Center, told Insider.

The company states in its privacy policy that it will "access, preserve and share" personal information with law enforcement if asked. "We reserve the right to disclose your Personally Identifiable Information as required by law and when we believe that disclosure is necessary to protect you, our rights and/or comply with a judicial proceeding, court order, or legal process," ID.me writes.

Big Tech platforms, including Google, Facebook, and Apple, host billions of pieces of personal data and are regularly subpoenaed by law-enforcement agencies. These companies often comply, but they also push back sometimes. For instance, Apple has fought law-enforcement requests to unlock the iPhones of some suspects.

Samir Jain, director of policy for the Center for Democracy & Technology, told Insider that the way ID.me talks about law-enforcement compliance is broader than other companies and implies that ID.me can and will comply with police requests voluntarily, even when it's not strictly required by law or court order.

"You read a lot of privacy policies and they say, 'warning, that data we collect will be provided to law enforcement where the law requires it,'" Jain said. "Their privacy policy says, 'We will comply with this request voluntarily where the law doesn't prevent it.' Basically, putting the world on notice that they're going to voluntarily cooperate with law enforcement in sharing of people's data."

Patrick Dorton, who works for a PR firm ID.me hired, said biometric data "is not shared with the IRS or any government agencies absent the receipt of a subpoena or as part of an investigation into an identity theft or fraud case only at the specific agency where the ID.me account was involved."

He did not address several specific questions from Insider, including under what circumstances ID.me would push back against a law-enforcement request like a subpoena, how many times ID.me has complied with law-enforcement requests, and whether ID.me would push back on a hypothetical request from Customs and Border Protection for the data of all ID.me users who are inferred noncitizens.

There are US laws that limit the collection of personal data in certain circumstances. One federal law prevents the Department of Homeland Security from routinely accessing people's tax returns.

Jay Stanley, a senior policy analyst for the American Civil Liberties Union, told Insider that this law — Title 26, Section 6103 of the Internal Revenue Code — generally applies to information submitted to the IRS as part of the tax-filing process.

But ID.me technically isn't part of the tax-filing process. Rather, it would act as an identity confirmation tool for logging into an IRS.gov account. This could lead the DHS to believe that ID.me isn't subject to the law.

"Ideally, the law would cover the biometric data and other personal information collected by ID.me, and generally prevent that information from being disclosed to a law enforcement agency like DHS," Stanley said. "It's not completely clear to me that it does. And consequently, it likely means that DHS would interpret it as not covering this particular information." DHS did not respond to a request for comment on Thursday.

The IRS code has exemptions that allow DHS agencies to access people's tax-return information but only under extreme conditions, such as a person under investigation for tax fraud.

A 2018 letter from the ACLU to the Social Security Administration argued that "immigration enforcement" isn't a legal exemption that would permit sharing data with DHS. "The strict confidentiality of tax returns and related return information is critical to encourage and ensure public compliance with the federal tax laws," the letter said.

The IRS spokesperson Robert Marvin said a lack of funding for IT modernization has made it impossible for the IRS to invest in state-of-the-art technology."

"The IRS today uses third-party service providers to validate the identification of individuals attempting to improperly gain access to taxpayer accounts," Marvin added in a statement that he asked to be attributed to the US Treasury Department. "This includes ID.me, which is compliant with the National Institute of Security Technology standards and used by multiple agencies across the government."

The Treasury Department recently said it was looking into alternatives to ID.me for the IRS after a Bloomberg reported that some people have been unable to get unemployment benefits due to problems using ID.me's service. A Cyberscoop article also showed that ID.me misrepresented how it uses facial recognition. The company claimed to do one-to-one face matching, such as determining whether a selfie matches a driver's license provided by a user. In fact, it uses a method known as one-to-many matching, which compares images to a stored database of photos, but ID.me hasn't disclosed how many images it has or how it got them.

"We shouldn't be required to trust that ID.me will push back on those kinds of requests if they receive them," said Scott from the Electronic Privacy Information Center. It's critical for government agencies to evaluate any company they may work with, especially what data the company is getting, and how it can use or disclose that information, he added.

The IRS' evaluation of ID.me "really isn't being done appropriately," Scott said.
Newsletter

Related Articles

TechDigits
0:00
0:00
Close
FTX's Bankman-Fried headed for jail after judge revokes bail
America's First New Nuclear Reactor in Nearly Seven Years Begins Operations
Southeast Asia moves closer to economic unity with new regional payments system
Today Hunter Biden’s best friend and business associate, Devon Archer, testified that Joe Biden met in Georgetown with Russian Moscow Mayor's Wife Yelena Baturina who later paid Hunter Biden $3.5 million in so called “consulting fees”
Google testing journalism AI. We are doing it already 2 years, and without Google biased propoganda and manipulated censorship
Musk announces Twitter name and logo change to X.com
The future of sports
TikTok Takes On Spotify And Apple, Launches Own Music Service
Hacktivist Collective Anonymous Launches 'Project Disclosure' to Unearth Information on UFOs and ETIs
Typo sends millions of US military emails to Russian ally Mali
Server Arrested For Theft After Refusing To Pay A Table's $100 Restaurant Bill When They Dined & Dashed
Democracy not: EU's Digital Commissioner Considers Shutting Down Social Media Platforms Amid Social Unrest
Sarah Silverman and Renowned Authors Lodge Copyright Infringement Case Against OpenAI and Meta
Why Do Tech Executives Support Kennedy Jr.?
The New York Times Announces Closure of its Sports Section in Favor of The Athletic
Florida Attorney General requests Meta CEO's testimony on company's platforms' alleged facilitation of illicit activities
The Poor Man With Money, Mark Zuckerberg, Unveils Twitter Replica with Heavy-Handed Censorship: A New Low in Innovation?
The Double-Edged Sword of AI: AI is linked to layoffs in industry that created it
US Sanctions on China's Chip Industry Backfire, Prompting Self-Inflicted Blowback
Meta Copy Twitter with New App, Threads
BlackRock Bitcoin ETF Application Refiled, Naming Coinbase as ‘Surveillance-Sharing’ Partner
UK Crypto and Stablecoin Regulations Become Law as Royal Assent is Granted
A Delaware city wants to let businesses vote in its elections
Alef Aeronautics Achieves Historic Milestone with Flight Certification for World's First Flying Car
Google Blocked Access to Canadian News in Response to New Legislation
French Politicians Advocate for Pan-European Regulation on Social Media Influencers
Melinda French Gates Advocates for Increased Female Representation in AI to Prevent Bias
Snapchat+ gains 4 million paying subscribers in its first year
Apple Makes History as the First Public Company Valued at $3 Trillion
Elon Musk Implements Twitter Limits to Tackle Data Scraping, but Faces Criticism for Technical Misunderstanding
EU and UK's Slow Electric Vehicle Adoption Raises Questions About the Transition to Green Mobility
Top Companies Express Concerns Over Europe's Proposed AI Law, Citing Competitiveness and Investment Risks
Meta Unveils Insights on AI Usage in Facebook and Instagram, Amid Growing Calls for Transparency
Crypto Scams Against Seniors Soar by 78% in 2022, Experts Urge Vigilance
The End of an Era: National Geographic Dismisses Last of Its Staff Writers
Shield Your Wallet: The Perils of Wireless Credit Card Theft
Harvard Scientist Who Studies Honesty Accused Of Data Fraud, Put On Leave
Putting an End to the Subscription Snare: The Battle Against Unwitting Commitments
The Legal Perils of AI: Lawyer Faces Sanctions for Relying on Fictional Cases Generated by Chatbot
ChatGPT’s "Grandma Exploit": Ingenious Hack Exposes Loophole in AI, Generates Free Software Codes
The Disney Downturn: A Near Billion-Dollar Box Office Blow for the House of Mouse
A Digital Showdown: Canada Challenges Tech Giants with The Online News Act, Meta Strikes Back
Distress in the Depths: Submersible and Passengers Missing in Titanic Wreckage Expedition
Mark Zuckerberg stealing another idea: Twitter
European Union's AI Regulations Risk Self-Sabotage, Cautions smart and brave Venture Capitalist Joe Lonsdale
Nvidia GPUs are so hard to get that rich venture capitalists are buying them for the startups they invest in
Chinese car exports surge
Reddit Blackout: Thousands of Communities Protest "Ludicrous" Pricing Changes
Nvidia Joins Tech Giants as First Chipmaker to Reach $1 Trillion Valuation
AI ‘extinction’ should be same priority as nuclear war – experts
×