Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Quote: "The Service’s memo suggests the crime ring is operating in much the same way as crooks who specialize in filing fraudulent income tax refund requests with the states and the U.S. Internal Revenue Service (IRS), a perennial problem that costs the states and the U.S. Treasury hundreds of millions of dollars in revenue each year."

A perennial! problem, hundreds of millions each year. It blows my mind how 80+ years later SSN is still used as identity, far beyond its original purpose. I mean with only one year of those losses US gov. could easily adopt something better.



The Dutch system to this is pretty nice. Your BSN gets attached to a digital id (DigiD).

You might give your BSN out to a company (healthcare, doctor, etc) but that is used to create the link to your DigiD. From there if you want to login to something like your healthcare company it will then bring up a form where you copy four characters from your DigiD app on your phone. This makes sure the requests match, then you just scan a QR code and type in a pin.

So if you want to login to do something related to your taxes, or healthcare online you have very strong two factor auth.

Additionally banks work similarly for making payments or purchases online. I want to order a pizza for delivery online it redirects me to a payment page on my banks website. I then take out my bank app on my phone, type in a pin, scan a QR, and approve the payment.


> it will then bring up a form where you copy four characters from your DigiD app on your phone

What happens when you don't own a phone?


Can't chime in for Netherlands, but here in Denmark you can get an actual code card you use for 2FA. It has 100 codes on it.

If you're doing online shopping/purchases chances are you have a phone though.


My guess is they will send a code to your registered address, which is a must if you live in the Netherlands. I just lost my phone and retrieved my DigiID through this way.


To set up digid, you apply via official website (or app), receive one-time code in your paper mail, then proceed back to the same website/app to register your password and phone number. App registers itself if you're using one.

Once set up, you have 3 authentication methods, selectable on login page:

1) password only (low-trust authentication, not all places accept this, certainly not your doctor's office);

2) password + 2nd factor via SMS/text (high-trust);

3) password + 2nd factor via app (high-trust).


Bicycle down to the local Gemeente office and talk to someone?


I think it's possible to "assign" someone and grant permission for them to access information, a bit like power of attorney.


Are elderly Europeans just so much better at tech than elderly Americans? Smartphone apps. QR codes. 2FA pins.

I know folks in their 60s who positively would not be able to do any of this with any level of success.


You can always do things via mail, phone, or bicycling down to the local Gemeente office. I just don't know what the authorisation methods are for mail/phone because I use the DigiD methods.

You can make the digital side of things secure while still having accessible method for non-technical people.


It's crazy that we all walk around with some secret number that, if discovered, could wreak havoc on our lives.

This is especially true in this digital age of connectedness and breaches, wherein we're encouraged to use and share the number ourselves in some scenarios, but somehow expect it to not fall victim of a single error or act of malice.


It's crazy that people use it and think of it as secret number.


I wonder, like, how much of that (and legitimate tax revenue) could be recovered or prevented each year by properly funding the IRS and other departments.

Where is the outrage compared to that of welfare queens, which don't exist in high numbers?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: