Independent newsroom The Wyre News Network OpEd desk

Analysis 6 min read

The Memo That Picks The Gatekeeper

A draft OMB memo would require federal agencies to use Login.gov, the General Services Administration's sign-in service, as the standard identity check across government websites. This piece argues that turning one login system into the default door for every citizen interaction with the federal government trades away competition and redundancy for convenience, and that the trade is being made without much visible scrutiny of who audits the resulting chokepoint. It points to recent churn inside the agencies that would run and rely on that chokepoint, including the reinstatement of GSA's FedRAMP director after weeks of leave, a lawsuit accusing HUD and DHS of stonewalling FOIA requests about their data-sharing, and the departure of DHS's chief information officer, as reasons the mandate deserves more oversight than a routine IT decision usually gets.

Listen to this piece 8 min

A draft memo from the Office of Management and Budget would make Login.gov the default sign-in system across federal websites, according to FedScoop's reporting. That sounds like housekeeping, the sort of thing that gets one paragraph in a trade newsletter and no attention anywhere else. It is not housekeeping. It is a decision about who stands between citizens and the government they are trying to reach, and it deserves to be treated as one.

One login, every door

Login.gov is a General Services Administration product. It already handles identity verification for a range of federal services, and agencies that want it can already use it. The draft memo would change that voluntary arrangement into something closer to a requirement, pushing agencies toward Login.gov as the standard way people sign in to government websites rather than leaving agencies free to run their own systems or contract with private identity providers.

Centralising sign-in has an obvious appeal. One account, one password, one set of security controls to maintain instead of dozens scattered across agencies with wildly different budgets and technical competence. A citizen who has already verified their identity once should not, in theory, need to do it again every time a different corner of government wants to know who they are. That is a genuine convenience, and it is the entire argument for the mandate. It is also being asked to carry the whole policy on its own.

Nowhere in the reporting is there a parallel discussion of what happens if Login.gov itself fails, is compromised, or is simply mismanaged for a stretch of time. A single point of entry is efficient right up until the point it is not, and then it is not efficient for anyone, it is a government-wide outage with a single point of blame and, potentially, nowhere else for citizens to turn.

Redundancy is not waste

The case against mandating one system is not that competition among identity providers is inherently virtuous, or that GSA has done a poor job building Login.gov. It is that redundancy is a form of insurance, and insurance looks wasteful only until the thing it was insuring against actually happens. If every federal website checks identity through the same gate, a fault in that gate is not an inconvenience at one agency. It is a fault at all of them, simultaneously, for however long it takes to fix.

Private markets solve this problem, imperfectly, by letting multiple identity providers compete and by letting institutions choose among them based on price, service, and trust. Banks do not all rely on one login vendor. Neither do universities, hospital systems, or large retailers. The federal government, by contrast, is proposing to remove that choice in the name of consistency across every agency at once. Consistency is a fine goal for a form, a font, or a style guide. It is a more troubling goal when applied to the mechanism that decides whether a citizen can get into a government website at all, because a font choice that goes wrong is embarrassing; an identity system that goes wrong locks people out of benefits, tax accounts, and services they are legally entitled to.

There is also a slower cost to killing redundancy, one that does not show up until years later. Agencies that build or maintain their own identity systems keep in-house expertise about how identity verification actually works. Retire that expertise across the entire federal government in favour of one central team, and the government becomes dependent not just on one piece of software but on one relatively small group of people who understand it. That is a fragile arrangement to build permanent policy on.

Who audits the gatekeeper

This is where the memo runs into a problem that has nothing to do with technology and everything to do with governance. The agencies that would run and rely on a mandatory Login.gov system are not, on the current evidence, models of stable oversight.

GSA's own FedRAMP director, Pete Waterman, was reinstated after weeks of leave, according to FedScoop. FedRAMP is the programme that authorises cloud and identity systems as secure enough for federal use, precisely the kind of function a mandatory login system depends on being run steadily and transparently. Weeks of unexplained absence at the top of that programme is not, by itself, evidence of a scandal. But it is evidence that the institution asking the rest of government to trust it has had its own leadership wobble recently, at more or less the moment its responsibilities were about to grow. If the agency in charge of vetting the security of federal systems cannot keep its own director in place without a gap, that is a fair thing to notice before handing that agency a bigger job.

Separately, a lawsuit reported by FedScoop alleges that HUD and DHS have been ducking FOIA requests about how the two departments share data. Whatever the merits of that specific case, it points at a pattern worth naming plainly: agencies asked to explain their data-sharing arrangements do not always answer, and sometimes have to be sued before they try. A mandatory identity system is, among other things, a data-sharing arrangement, one that would eventually touch every agency that adopts it and every citizen who uses one of those agencies' websites. If HUD and DHS can be accused of stonewalling requests about their existing, narrower arrangements, there is no obvious reason to assume a much larger, government-wide identity system will be more forthcoming about its own workings by default. The public should not have to sue to find out how their sign-in data moves between agencies.

Add to that DHS's chief information officer, Antoine McCord, exiting the agency, and the picture is one of turnover in exactly the technical leadership roles that would need to hold steady for a single sign-in system to be trusted at scale. None of these three facts on its own proves the mandate is a bad idea. Together, they are a reasonable basis for asking who, specifically, is accountable for Login.gov's security, its uptime, and its handling of the data it collects, and what happens when that person leaves, as people in these roles evidently do with some regularity.

Convenience is not the same as accountability

It is worth being precise about what the memo actually trades away. It is not trading security for convenience; Login.gov may well be a perfectly secure piece of software on its own technical merits, and nothing in the reporting suggests otherwise. What it trades away is diversity of failure modes. When agencies run their own systems, a breach or an outage at one agency is contained, painful for that agency's users, but not a national event. When one system serves every agency, there is no such containment. The blast radius of any future failure, whether technical, human, or a mix of both, becomes the entire federal government's public-facing presence at once.

That is a decision worth making deliberately, with public debate about who audits Login.gov, how often, and with what power to compel changes, rather than a decision that arrives as a single line in a draft memo and gets treated as a technical footnote. The people writing OMB memos are not wrong that a patchwork of agency login systems is inefficient. They should not assume that efficiency is the only value at stake, or that taxpayers will simply accept a single chokepoint on the strength of convenience alone. Before Login.gov becomes the one door everyone has to use, someone in Congress or elsewhere with real oversight power ought to ask, plainly and on the record, who is watching the door, and what happens to the public when the door itself is the thing that breaks.

Wyre's opinion bylines are editorial personas of Floof Digital LLC, not separate members of staff. Essays are produced with AI assistance under human editorial direction. How Wyre works.

More Opinion

From the same desk

Analysis

Eighty-Two, Then Fifty-Three

In July, Bank of America's global fund manager survey recorded 82 percent of respondents naming long global semiconductors the most crowded trade, the highest reading it has produced for any position. In August the same question returned 53 percent. Between those two surveys nothing material changed in the industry the trade was about. What changed was who was holding it. Situational Awareness, a 45 billion dollar fund named after the essay that popularised the AI scaling thesis, lost roughly two thirds of its value in July and sold its leveraged public positions to Citadel at a discount, on a thesis that the available evidence says was not wrong. Why crowding is a risk factor that standard frameworks barely measure, what a four-week collapse in a survey reading says about how much of that capital was conviction, the two shock absorbers that stopped this unwind transmitting and why neither is guaranteed next time, and what the episode does not license anyone to conclude.

5 min

Perspective

The Spreadsheet Becomes the Vision

When the chief financial officer becomes the chief executive, the questions asked in a creative review change shape. A campaign that once had to feel right to a marketing chief now has to model right to someone trained to trace every dollar back to a return. This piece argues that the shift from operators and marketers into the CEO chair is quietly rewriting how creative work gets approved, what gets called "brand building" versus "spend," and which kinds of ideas survive the first meeting. It is not a story about finance people being hostile to creativity. It is a story about a different set of instincts now sitting at the top of the approval chain, and what marketers and agencies need to change about how they pitch, present and prove their work as a result.

6 min

Analysis

Twelve to Twenty Points

In one benchmark study the best large language model tested, GPT-4o, answered 12.0 to 19.9 percentage points less accurately in eleven African languages than in English. AfroBench, covering 64 languages and 15 tasks, records gaps reaching 28 points against English and 19 against French. The word ordinarily attached to these models is general, and it is worth being precise about what the generality is over. Model capability is measured against a distribution inherited from training data drawn overwhelmingly from the public internet, which is not a uniform sample of human activity; performance degrades with distance from the middle of that slice, and these benchmarks put a number on a degradation that is otherwise asserted rather than measured. Lelapa AI's answer runs to 400 million parameters and no hyperscaler. Why the equity argument and the engineering argument are usually conflated to the cost of the second, what follows for procurement that has been treating model choice as a ranking exercise, and the dependency question governments have not examined.

5 min