Login.gov Implements Persistent Browser ID, Raising Privacy Concerns Amid Push for Universal Federal Sign-On
Login.gov, the U.S. federal government's identity platform, has introduced a persistent browser identifier, `nds_experiment_uuid`, stored as a long-lived browser cookie. This identifier is linked to analytics data, including IP addresses, browser information, and other device data. The implementation is part of an experiment with the National Design Studio (NDS), a White House organization, to test versions of Login.gov's redesigned interface. While a Login.gov developer approved the implementation, a GitHub issue questioning the identifier's apparent 20-year lifespan and the privacy review process remains unanswered. This development raises concerns about how the practice aligns with Login.gov's public statement that its website analytics are anonymized and that no personally identifying user information is tied to this data. The Office of Management and Budget (OMB) has directed agencies to offer Login.gov as a sign-on option for public-facing services, aiming for a universal federal sign-on.