GAO: Time to move past 'knowledge-based' identity verification
- By Derek B. Johnson
- Jun 17, 2019
For years, individuals could use their name, address, date of birth or Social Security number to establish their online identity with federal agencies, but hackers have swept up so much personal data that those identifiers are practically useless.
In a new report, the Government Accountability Office says attacks like the 2017 Equifax hack have "raised concerns about the vulnerability of federal agencies that rely on information maintained by [consumer reporting agencies] to verify the identity of individuals who apply electronically for benefits and services," the report said.
Auditors examined six federal agencies with major public-facing web applications that rely on identity proofing solutions from the three major credit agencies: the General Services Administration, IRS, Social Security Administration, Department of Veterans Affairs, the U.S. Postal Service and the Centers for Medicare and Medicaid Services.
Those agencies have all used some form of "knowledge-based" verification, essentially asking applicants detailed personal questions "under the presumption that only the real person will know the answers to these questions." This type of verification can take place over the phone or through web-based questionnaires and rely on the same information collected by credit agencies like Equifax, Experian and TransUnion.
For example, CMS collects the names, dates of birth and addresses of applicants along with answers to personal and financial questions held by credit agencies before granting users access to Healthcare.gov services. Other portals like Login.gov rely on similar techniques and are used by OPM, the Department of Homeland Security, USAJobs.gov and GSA to interact with customers.
Those methods are no longer feasible over the long term, and NIST guidance in 2017 essentially prohibited knowledge-based verification for sensitive applications, citing an unacceptably high risk. Several federal agencies, including GSA and IRS, have already moved on to other forms of identity verification, while every other agency except CMS said they either have plans in place or intend to move away from the practice.
GAO consulted with NIST to develop alternatives options, most of which rely on an item most Americans constantly keep on their person: their cell phones.
Sending photos of your driver's license or other credentials via a mobile application, or going through an SMS text-based two-factor authentication process, were both listed as easy to implement, secure methods to verify identity. Failing that, agencies could also send confirmation codes through the mail to a listed place of residence, which users can put into a web app were all listed as more secure alternatives for verification.
Of the six agencies studied, only the Department of Health and Human Services -- which houses CMS -- did not concur with GAO recommendations to implement other forms of identity verification. HHS also said rural users who live too far away for in-person visits or who may lack access to cell phones would find it harder to access federal health benefits as a result.
"The alternatives to knowledge-based verification proposed by GAO in their report are not suitable for certain populations served by CMS as they would create undue burden, create barriers to accessing federal services, or may be cost prohibitive," wrote Matthew Bassett, assistant secretary for legislation at HHS.
This article was first posted on FCW, a sibling site to GCN.
Derek B. Johnson is a senior staff writer at FCW, covering governmentwide IT policy, cybersecurity and a range of other federal technology issues.
Prior to joining FCW, Johnson was a freelance technology journalist. His work has appeared in The Washington Post, GoodCall News, Foreign Policy Journal, Washington Technology, Elevation DC, Connection Newspapers and The Maryland Gazette.
Johnson has a Bachelor's degree in journalism from Hofstra University and a Master's degree in public policy from George Mason University. He can be contacted at firstname.lastname@example.org, or follow him on Twitter @derekdoestech.
Click here for previous articles by Johnson.