Twenty-five years ago today, the United States entered the most frightened period in its modern history, and Americans who had spent the previous decade watching the internet pull more of their lives onto computers were suddenly being asked to reconsider how much privacy they were willing to exchange for the promise of safety.
Ten days after the September 11 attacks, Larry Ellison went on television in San Francisco and proposed a national identity system. Every American would receive a card containing a photograph and digitized thumbprint, which could be checked against a central database at airports and other places where the government needed to know that the person standing in front of them was the person they claimed to be. Oracle would write the software and give it to the federal government for free.
Ellison’s argument was that the government already possessed most of this information anyway. Our photographs, fingerprints, Social Security records, immigration files, tax histories, and encounters with law enforcement were already stored inside public databases; the problem, as he saw it, was that those databases belonged to different agencies and could not reliably communicate with one another. He was not proposing that the government collect an entirely new category of information about us. He was proposing that it connect what it already had, which was the part that made the offer sound so reasonable and the part that made it so dangerous.
The country said no, although not along the political lines you might expect. Republicans and Democrats, civil-liberties lawyers and gun owners, church groups and immigrant-rights organizations, people who agreed on almost nothing else in the world, looked at the same proposal and understood that the danger was not confined to the card in someone’s wallet. It was the creation of a system capable of recognizing a person across institutions, retrieving the records attached to them, and eventually deciding which doors that person could walk through. Four years later, when Congress created federal standards for state driver’s licenses, it wrote into the law that the new system was not to become a national identity card.
A quarter of a century later, we are standing in front of that door again, except nobody has called what sits behind it a national identity system, nobody has introduced a single bill describing everything it will do, and nobody has asked the public whether it wants one.
They called it Login.gov.
If you renewed a passport online, accessed veterans’ benefits, applied for student aid, requested a small-business loan, or signed into one of hundreds of government services, you may already have an account. Most people created theirs in a few minutes because they needed one thing from one agency, then closed the browser and never thought about it again. It looked like exactly what it claimed to be: a safer and more convenient way to sign in.
The Man Behind It
Login.gov now reports 180 million accounts spanning 700 services and 54 agencies, and the man recently placed in charge of expanding it is Greg Hogan, a former executive at the self-driving-car company comma.ai who had never worked in government before the second day of Donald Trump’s second term. That was when Hogan entered the Office of Personnel Management as its chief information officer, becoming the person responsible for deciding who could access the employment records of nearly every federal worker in the country.
Hogan barely exists online. There are no interviews, panels, or public statements explaining what he believes government technology should do, and nearly every word attributed to him in the press came from internal emails obtained by reporters. His first major contribution to the federal government, however, was difficult to miss, because he helped build the system Elon Musk used to email approximately two million public employees and demand a list of five things they had accomplished that week, with Musk threatening that failure to respond would be treated as a resignation.
FBI agents received it. Air traffic controllers received it. Cancer researchers at the National Institutes of Health received it. A man who did not work for the federal government had acquired the ability to threaten the entire federal workforce through a machine somebody inside OPM had built to reach all of them at once.
Federal employees had already sued over that machine because OPM created it without publishing the privacy assessment that would ordinarily tell the public what information a new system collects, why it collects it, and who can access it. The government had been warned about the system in federal court before Musk used it. It used it the following morning anyway.
When the employees’ lawyers sought to question the man who built it, the government fought hard enough to keep Hogan from testifying that Judge Denise Cote warned she would disregard his written statement if he did not appear. Hogan eventually testified by video from Washington, where he was asked why DOGE engineers had been given administrative access to OPM systems and whether the agency had followed the two foundational rules designed to prevent any one person from opening everybody’s file: give people only the access necessary to perform their jobs, and give them that access only when they need it.
Hogan said he considered those rules guidelines rather than requirements. As for why the engineers received the highest level of access in advance, he explained that they might eventually need to use it, which is exactly what those rules exist to prevent.
On June 9, Judge Cote found that Hogan’s sworn statement was not credible and that his written declarations had been incomplete and, as a result, misleading. She stopped short of finding perjury, and that distinction matters, but the finding that remains is extraordinary enough: a federal judge put in writing that a sitting chief information officer’s sworn account could not be believed.
It cost him nothing. Hogan left OPM that September, disappeared from public view for eight months, and returned at the General Services Administration with responsibility for Login.gov. In the email announcing his appointment, the federal chief information officer told employees that Hogan would grow the service toward becoming a “globally recognized identity platform.” When WIRED asked a GSA employee what that meant, the employee described a push toward a national ID containing the information a person might need for any interaction with government, including identity details, income, citizenship status, and dependents.
When Identity Becomes Eligibility
A national identity system is not automatically a nightmare, and it would be dishonest to pretend otherwise. Most countries have some version of one, and there are obvious advantages to proving who you are once instead of repeating the process for 40 agencies that each maintain a separate file. Benefits could follow people when they move, stolen identities could be caught earlier, and the government could stop asking the same person for the same documents every time they approach a different office.
The danger appears when identification becomes eligibility, because the system no longer confirms who you are; it decides whether the person it found is permitted to continue.
India’s Aadhaar system began in 2009 as a voluntary twelve-digit number connected to fingerprints and iris scans. It was supposed to make benefits easier to receive, but over time it became necessary to open a bank account, obtain a phone, enroll a child in school, and collect food rations. It never became mandatory through one announcement that people could challenge. It became mandatory one door at a time, until there was no practical way to live without it.
In 2017, the government of Jharkhand gave residents three weeks to connect their ration cards to their Aadhaar numbers. Linking the records sounded simple, except that internet connections failed, servers went down, operators did not appear, and portals sometimes refused to work. When the deadline passed, approximately 300,000 ration cards were reportedly voided, including the card belonging to the family of Santoshi Kumari, an eleven-year-old girl whose mother said she asked for rice before losing consciousness after days without food.
Officials disputed the cause of her death, attributing it to malaria, but nobody had reviewed the family’s circumstances and determined that they were no longer poor enough to receive assistance. A connection between two records had failed, and the system translated that technical failure into a human one. By the time a person encountered the consequence, there was no decision-maker standing in front of them, only a machine reporting that the government could not verify what the family already knew to be true.
The American system does not use fingerprints to distribute food, but code added to Login.gov shows how easily a shared identity service can move beyond helping a person sign in. Normally, someone seeking the highest level of verification photographs a driver’s license and then their face, allowing software to compare the person holding the phone with the person pictured on the document. Login.gov returns a code called IAL2, which tells the receiving agency that the user passed identity verification with a facial match.
In March, GSA added another route to the same code. Under this process, somebody else can enter a person’s name, birthday, phone number, address, license number, and Social Security number. Computers then ask a state motor-vehicle agency whether the license exists, the State Department whether the passport is real, and LexisNexis whether the name and Social Security number belong together. Each system checks a record, but none checks the person, because there is no camera and no photograph. The receiving agency nevertheless gets the same IAL2 label, with nothing in the response indicating which route produced it and an instruction not to challenge that user again.
This matters because Login.gov reported 100 million accounts last December and 180 million by August, even as its reported annual sign-ins remained unchanged. I cannot prove that the additional accounts came through this pathway; the setting that activates it sits on a private server, GSA has not disclosed whether it is enabled, and my Freedom of Information Act requests seek precisely those answers. What can be established is that the capability was built, the number increased by 80 million, and GSA has not explained either event.
The same form contains a seventh field labeled “suspected fraud,” even though that field has nothing to do with establishing identity. The form cannot be submitted without an answer, but the code supplies no standard, score, or evidence that would determine what the answer should be. Once selected, the label is stored beside the person’s Social Security number and transmitted to the state motor-vehicle system and LexisNexis, despite playing no role in whether the identity passes verification. A stranger’s suspicion can therefore become part of a federal record, travel to a private company, and remain invisible to the person it describes.
Other settings reveal how malleable the supposed verification can be. One feature allows a failed result to become a successful one after the system checks additional state records, but it applies only to a list of approved vendors, meaning the same person with the same documents can receive a different answer depending on which company the system randomly assigns. The internal name is not subtle: “get to yes.”
Meanwhile, outside contributors associated with the National Design Studio have been changing the pages that tell users their accounts are suspended, their identities cannot be verified, or their devices have failed security checks. In the same release that brought this work into the identity-verification process, Login.gov began assigning a random identifier to every visiting browser and connecting it to analytics about what that visitor does on the site. The identifier was designed to last twenty years, even though the experiment it supposedly supports is set to reach zero percent of users.
I opened a private browser, visited Login.gov without signing in or typing anything, and found the number waiting in the cookies. Six code changes built the mechanism, and none included a privacy-policy revision, cookie notice, or any other text intended to inform the person receiving it. GSA has since asked companies about technology capable of recognizing a device through a VPN, through private browsing, and after someone deletes their cookies, with the resulting information returned to the government for analysis.
The Common Gate
This is all happening as the White House orders federal agencies onto Login.gov, turning what once looked like a convenient account into the common gate through which Americans will approach their government. Right now, a rejection by one agency can remain one agency’s rejection; a person can appeal to the people who administer that program, while another office maintains its own record and reaches its own conclusion. Once identity, fraud, and access decisions are centralized, one failure can follow a person from door to door, and every agency can inherit an answer nobody inside that agency made.
There has been no bill presenting this system to the country, no hearing on what it should contain, and no vote on whether a sign-in service should become the identity layer beneath the federal government. The argument from 2001 has survived almost perfectly: the information already exists, the government already possesses it, and connecting the pieces is merely an administrative improvement.
The difference is that Larry Ellison stood in front of a camera and told us what he wanted to build. This time, the offer was never made, because by the time most Americans understand what Login.gov has become, they may already need its permission to enter.
SOURCES CITED:
Login.gov source code (repo: 18F/identity-idp)
Config defaults · config declarations · where the label is assigned · the facial-match list · the job with no biometric in it · don’t re-challenge · what the agency receives · where the cookie is minted · where it’s attached to every event · outside contributors · releases
Pull requests: 13462 (the cookie, shipped in RC 608 on Sept 8) · 13532 (the opt-out, opened Sept 9, unapproved) · 13443 (get_to_yes) · 13433 (reproofing). Contributor account: taigrr.
Login.gov’s own documentation
The IAL2 definition · docs repo · testing behavior · the two levels of service · when verification fails · the alternate path agencies must keep · VA’s in-person proofing application
Greg Hogan
His sworn declaration · full AFGE v. OPM docket · the complaint · Bloomberg Law on the injunction · Revolving Door Project · his hardwear.io bio · WIRED on his move to Login.gov
The 2023 oversight record
GSA Inspector General (report) · GAO · the hearing · Oversight’s letter to GSA · 100 million accounts
The mandate and the National Design Studio
OMB M-26-18 · the executive order creating NDS · Federal News Network · FedScoop · the draft version · ndstudio.gov · Aug 16 capture, no privacy policy · Sept 9 capture, privacy policy · trumpaccounts.gov
The device fingerprinting request (posted Aug 25, 2026, responses due Sept 11)
FedScoop · IDTechWire · Biometric Update
The fraud frame
Hearing announcement · transcript · wrap-up · Talcove’s fraud-rate claims
LexisNexis and ICE
Sam Biddle on the original contract · 1.2 million searches in seven months · the contract record · the gag clause · eighty groups ask DHS not to renew · what Accurint holds · the jail-data loophole · Colorado Law Review on the contract · the Aug 2026 Palantir bridge contract
The national ID prohibition
6 U.S.C. § 554 · the Homeland Security Act as compiled · REAL ID Act text · codified as a note · DHS making the claim administratively · Congress reusing the formula in 2023
Larry Ellison, September 2001
CNN · Computerworld · The Register · Newsweek · his own op-ed
India and Aadhaar
Santoshi Kumari · Tribune India · the Supreme Court takes up the cancelled cards · thirty million cancelled