The General Services Administration (GSA) has been advised to take further action to safeguard sensitive information processed through Login.gov, an identity verification platform used by numerous federal agencies. Although the platform has generally adhered to recommended data protection practices, a federal review highlighted a critical gap: GSA has not yet shown that it is effectively testing the integrity of Login.gov’s backup data.
Continues after this brief message…
Did you know? Paid supporters get a reduced ad experience!
Thank you for supporting Radio Free Hub City!
Launched in 2017, Login.gov offers services such as multi-factor authentication and identity proofing to help verify users accessing government websites. However, from 2020 through 2023, it provided fewer features than some commercial solutions, particularly in areas like biometric verification. It wasn’t until late 2024 that Login.gov aligned its identity-proofing capabilities with federal standards. During the same period, federal agencies spent around $209 million on commercial identity solutions compared to $32.5 million on Login.gov, though a full cost comparison was not possible due to limited vendor pricing disclosures.
Article continues after these messages…
While other outlets focus on getting quotes from politicians who don't even live in our congressional district, we're focused on providing the hard-hitting truths and facts without political spin. We don't lock our news behind a paywall, will you help us keep it that way? If you're tired of news sweetened with confirmation bias, consider becoming a monthly supporter. But if you're not, that's fine too—we're confident in our mission and will be here if you decide you're ready for the truth. Just $5/month helps fund our local reporting, live election night coverage, and more.
Become a paid supporter for reduced ad experience!
In its audit, the Government Accountability Office (GAO) found that while Login.gov met most privacy practice guidelines outlined by the National Institute of Standards and Technology (NIST), it lacked full implementation of backup data testing policies. GSA attributed this shortfall to staffing shortages in its security engineering team, which were not resolved until early 2024. Although GSA has since established a data protection policy, it has yet to provide evidence that its backup testing procedures are operational and effective.
The GAO’s recommendation called on GSA’s Technology Transformation Services to ensure that Login.gov demonstrates full implementation of its backup testing policy. GSA agreed with the recommendation and is expected to report on its progress as corrective actions are completed.
Article by multiple RFHC contributors, based upon information from the U.S. Government Accountability Office press release.
Do you believe we got something wrong? Please read our publishing standards and corrections policy.
Did you know? Supporters get a reduced ad experience!
Sponsored Articles
Get daily and breaking news for Washington County, MD area from Radio Free Hub City. Sign up with your email today!
Paid supporters have a reduced ad experience!
Discover more from Radio Free Hub City
Subscribe to get the latest posts sent to your email.




