▶ 0:11:52Several hearings addressing the issue of fraud, addressing the the the things that the united states government faces, as well as the american people. And each time we have been talking about fraud, how to identify it and how to prevent it. In our discussions, we've highlighted the importance of government agencies focusing on preventing fraud before it happens.
▶ 0:12:18And as we've heard countless times before, once the money is gone out the door, it's hard to get back. This remains a very important issue. And this subcommittee, to both the ranking member and myself in this subcommittee is very important. But one critical element missing from our many conversations is what sort of fraud are we trying to prevent? How does it really work?
▶ 0:12:45What really are we doing about it? And where do we need to focus our attention to make sure that we are going to address this properly? In our past discussions, we've referenced the fraudsters in the dark room stealing our aunt sally's social security number. We've highlighted the risk posed by foreign actors applying to multiple disaster relief programs.
▶ 0:13:14We've discussed elaborate fraud rings that exploit loopholes in benefit programs in order to receive payment for services that they should not have received, but perhaps got the money. But fraud threats are changing, and they're rapidly advancing.
▶ 0:13:37Identifying fraud threats, specifically, or becoming a fraudster, actor or or booming as fraudulent actors become smarter and gain access to tools intended to make our life easier and their life easier through ai. This gives them more power. It's up to us to catch up. It's up to us to find it and to find a way that we're going to corner the market on our side of the agenda.
▶ 0:14:04Government programs rely on identify, verify identity verification to confirm that the individual applied for benefits to services are who they say they are. However, we've seen over the years the platforms used for this verification have failed to meet the expectations. In march of 2023, the subcommittee held a hearing focused on login.gov and the traveling fine.
▶ 0:14:31The troubling findings from the general service administration's inspector general report that was released that month told us point blank, we have a problem. In short, gsa misled government clients about the extent to which login.gov met certain technical standards and expressly what they said it would do.
▶ 0:14:57These standards were the backbone of what was needed to ensure that identity verification platform could prevent fraud, protect the taxpayer, and give the government the necessary information that it would need to know who they were speaking to and what the person might be eligible for for benefits.
▶ 0:15:18Over the years, many changes have been made to login.gov and federal agencies have explored other public and private sector solutions for digital identification verification.
▶ 0:15:33As we were moving to a more digital environment where individuals may no longer be asked to present a physical id card, we need to better understand what threats there are and what what the fraud landscape looks like. Today's fraud landscape landscape looks different than the one that existed when we started this investigation, and it's rapidly evolving even today.
▶ 0:16:00Fraudsters from literally anywhere in the world can now create hundreds or thousands of synthetic identities and apply for many different government beneficiaries of government benefit programs simultaneously. It's not, it's not.
▶ 0:16:18It's no longer they could they are backed at or bad actors are able to develop the use of deep fakes, mimicking the likeness of an individual to circumvent the safeguards that have been put in place to protect the taxpayer. Bad actors have made it their business to exploit vulnerabilities in government programs.
▶ 0:16:44It is necessary that we understand that they have been successful, and we need to make sure we're developing the tools that actually allow us to see the fraud before it occurs, not when it's out the door. Identity verification has long been a one time check at the beginning of an application process, but the.
▶ 0:17:08Considering the rapid evolution of identity fraud, we should start thinking about validating and constantly validating identity as. As it moves forward. Fraud should not be considered the cost of doing business because it means that someone is not getting the benefit that they were eligible for.
▶ 0:17:31And if there is one overriding principle that this subcommittee, all of our members agree on, it is that the people who we have intended the benefits to go to, they should be the ones that get it, and any diminishment of that is, is, is considered a failure on our part. Also, in january of this year, I introduced bipartisan legislation to combat identity fraud and theft.
▶ 0:18:01The stop identity fraud and identity theft act aims to strengthen the nation's digital I entity verification infrastructure and protect individuals, businesses and government programs from rising identity and fraud and theft.
▶ 0:18:19I'm hoping that this legislation is a step in the right direction, and after meeting with our panel members, I will tell you it is a step because we are going to learn more today in this rapidly evolving landscape that we call fraud, along with the verification systems that are available today, we have a great panel of witnesses who can shed light on new identity fraud threats plaguing our
▶ 0:18:51Systems, how the fraud landscape is evolving, and the what what the government should be doing and is doing to keep up with that. I look forward to a fruitful discussion, and I want to personally thank our ranking member, Mr. fumi, for his continued support. Those of you who are new to this subcommittee will learn that both both Mr.
▶ 0:19:13Mfume and I insist on making sure that we work well together, that we listen to each other, that we listen to all of our members and allow them to fully participate, adding thoughts and ideas, but perhaps more importantly, to show up and listen and learn about the landscape that is directly in front of us. Mr. mfume is a very dear friend of mine.
▶ 0:19:37Uh, he is a man who has a distinguished service service not just to the united states congress, but to the united states of america and to his district. And you will soon learn, those of you who are here, that we have many distinguished members of this subcommittee who are here because they believe in not only doing their job, but also helping us curb the appetite that fraudsters have to take advantage of our citizens.
▶ 0:20:05With that said, uh, I would like to now ask the gentleman if he would engage us with any opening statement he'd like to make. The distinguished gentleman is recognized. Speaker 2: I want to thank you, Mr.
▶ 0:20:19Chairman, for your kind and clearly overly gracious set of remarks, um, for your friendship, for your stewardship of this committee and for the ability for us on both sides of the aisle to really delve into detail on various issues, but none more important than this issue of fraud. I know I speak for all of my colleagues on my side of the aisle when I say, we welcome this hearing, as we did the previous one.
▶ 0:20:47We look forward to finding answers, quite frankly, and finding a way to get out of the situation that we're in with respect to the level and the significance of fraud within our our government.
▶ 0:21:00So we're here today to talk about fraud, particularly emerging threats and solutions related to digital identity verification, social security numbers and paper cards made sense 90 years ago, long before the current age of computers and digital technology programs have matured, scammers have adopted them and found a way to get around them.
▶ 0:21:24And so the government must also, I think, adapt its service, delivery and technology to prevent fraud and to better serve the american people. That adaptation was exactly what the federal government had in mind many years ago when it came up with the idea, and then later became the reality of something called login.gov, which we're all familiar with a single secure sign in that works across
▶ 0:21:55Agencies before login.gov. Each agency maintained its own identity verification. Good luck with that one. It wasn't just a headache for our constituents, it was also a costly overlap in functions and a critical cyber vulnerability.
▶ 0:22:16While the gsa may have stumbled out of the gate with the initial release, we finally reached a point, I think, where agencies across all levels of government have a safe, secure and verified gateway to government services that improves the customer service and helps our constituents across the services and the resources that their taxes pay for.
▶ 0:22:41The turnaround in this program serves as an important example of bipartisan congressional oversight, where once accusations of false promises dogged that program, login.gov can now effectively serve the american people.
▶ 0:22:57We first learned, however, of the issues with login.gov when the general services administration inspector general published a report finding that several individuals at gsa had misled its agency customers that the system could do higher levels of identity verification than gsa itself. Um, those sort of things created problems.
▶ 0:23:23Three years ago, we had a hearing exploring the issue and sent further follow up letters, as the chairman indicated, and briefings to ensure that gsa fixed the system that provided the service that they promised their agency clients.
▶ 0:23:40A year after our hearing, gsa announced it had fully implemented the national institute of standards and technology standard and had rolled it out to their agencies and to their partners. Today, login.gov has over 100 million users across more than 50 agencies and 500 applications across federal, state and local government.
▶ 0:24:07Now, that doesn't mean that the work to ensure digital identity verification across the entire federal government is finished. I look forward, like many of you, to hearing our witnesses today about how we can effectively implement the next generation of login.gov and identity management.
▶ 0:24:26However, we must be carefully consider the difficulties in the pitfalls of the new technologies and just not assume that they don't have any innovations like digital id can better combat fraud and electronically safeguard identity, much more so than a nine digit number on a piece of paper. Digital id sounds great. Uh. I wouldn't need to carry around a plastic license. Just a smart phone.
▶ 0:24:56If I'm the average american citizen with cutting edge technology to safeguard my personal information. The problem is, however, that that very phone provides a new vector of attack, and any computer is vulnerable to a cyber attack. As we know, regardless of its level of sophistication, digital id can also limit access for people who have trouble using technology, even for people who cannot afford a smartphone.
▶ 0:25:26Sometimes people just break their phones and can't take time out of their busy day to immediately go and get a new one. So I don't think we can afford to lock people out of government or private services because they cannot access or afford a smartphone. Anytime the government can revoke access to services, even for benevolent purposes, we must find a way to protect against abuse.
▶ 0:25:52The trump administration doge program, uh, the department of government efficiency, which many of us thought was the department of government evil, used a key social security administration identity database to mark thousands of living people as dead in order to exert financial hardship. A whistle blower recently said that he planned to expand this to millions of people.
▶ 0:26:22Now, do we really want to move to a system where the government can invalidate any id it wants to, just by sending an instruction to the phone that's in your pocket?
▶ 0:26:34I can absolutely think of places where digital id has valid uses for age verification and for fraud prevention, but every place that an american taps their phone to access services cannot be a bread crumb to the track or breadcrumb. Follow the track process in their daily lives.
▶ 0:26:58So I'm excited to have those of you who are here to discuss the new technologies to prevent fraud against the american taxpayer, we must also ensure that we keep an eye on the horizon to prevent any sort of mass surveillance and government surveillance that can literally decide if, in fact, we are considered live or dead.
▶ 0:27:22So I want to thank the chairman again, uh, for keeping his commitment on this issue, uh, for members on both sides of the aisle that continue to plow through this. It's been a couple of years now. We're going to continue to do what we have to do until we can't do it anymore. And I appreciate the opportunity to have all of you here hear what you have to say on the record. And, Mr. chairman, I yield back to you. Speaker 1: jim yields back his time. Thank you very much.
▶ 0:27:48I'd like to ask unanimous consent, if I can, to, uh, allow the distinguished gentleman who has a meeting that he has to attend to very quickly, give some brief remarks. I'd like to yield time now to distinguished gentleman, chairman gary palmer. Chairman palmer, you're recognized. Speaker 3: thank you, Mr. chairman.
▶ 0:28:08Thank you for holding this hearing, and I'd like to thank the ranking member for the bipartisanship that we've seen throughout this process and trying to address, um, the fraud and also other issues related to improper payments. Um, this is an extremely important issue.
▶ 0:28:27I just came out of a meeting with doctor phillip swagel, the director of the congressional budget office, and we estimate just the initial, uh, investigations into fraud that that will have about $168 billion in savings. Uh, I want to make certain that that people understand this is not just about the money. Uh, so much of this fraud mismanagement occurs in programs that are designed to help people who need help.
▶ 0:28:56And when, when we're losing that that much money, we're being defrauded of that much money. Those are funds that are not available for people who are truly in need. So this this is a huge issue for us. And it's not limited to domestic fraud. Uh, what we saw during the covid pandemic. Uh, the programs at the federal level were being defrauded by massive network of foreign actors.
▶ 0:29:21And, um, but we also have other issues aside from the fraud. I think one of the things that we found is that there's a tremendous need to, to modernize, uh, federal data systems, bring them into the 21st century, because a lot of the issues that we have with improper payments are directly related to antiquated data systems. So, Mr. chairman, uh, I really hate that I'm not going to be able to participate in this hearing.
▶ 0:29:50I think it's extremely important and would have benefited greatly from hearing the questions and answers, uh, the questions to our witnesses and their answers. With that, Mr. chairman, again, thank you for the privilege of being able to address the issue. I yield back. Speaker 1: gentleman yields back his time. Thank you very much. Without objection. Uh, congressman walkinshaw of virginia has waived onto the subcommittee for the purpose of questioning the witnesses at today's subcommittee hearing.
▶ 0:30:18I now would like to move to welcome our witnesses who have taken their time today to be with us. And I'm very delighted to say that I. I think that you will find. And the the the members will find their, uh, input very valuable to exactly the same things that chairman, uh, was talking about. And that is that we need to understand what's out there today.
▶ 0:30:47It's easy for us to think that we understand a lot and we're going to learn enough today. So I'm pleased to welcome our witnesses. Mr. jordan burress is vice president and head of public sector at soca soca, where he partners with government leaders to develop and implement private sector solutions for identity verification and fraud risk management. Next, we have marisol cruz.
▶ 0:31:13Cain is director of information technology and cyber security at the gao. The government accounting office has experts that provide not only expert testimony, but have an idea of the day to day activities that move across the government. She oversees federal cyber security and privacy work.
▶ 0:31:36Her portfolio includes emerging technologies, the national cyber security strategy and agency efforts to protect privacy sensitive data and critical computing infrastructure. Next, we have david maimon, and he is the head of fraud insights at citylink, a company that combines technology and expertise to stop identity fraud at the application stage.
▶ 0:32:08He is also a professor in the department of criminal justice and criminology at georgia state university, where he directs the evidence based cyber security research group group. Lastly, Mr. jay stanley is a senior policy analyst at the american civil liberties union. His work focuses on technology related privacy and civil liberties issues and that future and how it impacts public policy.
▶ 0:32:37Thank you to each of you for joining us. Uh, I would now ask that each of you rise in pursuant to committee rule nine g. The witnesses will each, as they stand to take the. You can all stand, please, to take the, uh, the oath to the witnesses. And I would ask that you please raise your right hand. I will read this and then let you affirm or choose as you would do.
▶ 0:33:06Do you solemnly swear or affirm that the testimony that you're about to give is the truth, the whole truth, and nothing but the truth, so help you god? That's a question. Please let the record reflect that the witnesses have answered in the affirmative. Thank you very much. You may all take your seat. Uh, I have had an opportunity to speak with each of you. Hopefully, uh, set. Mr. stanley. Mr.
▶ 0:33:32Stanley, I want you to know that I've advised the other witnesses here that we appreciate you being here as we do them. That I run the committee hearings, uh, differently. I'd like for you to be able to finish your sentence. I'd like for you to be able to complete your thought. I'd like for you to be able to thoughtfully respond and provide this subcommittee with the things which you have come professionally to do to us. Uh, I, I am not going to five minutes.
▶ 0:34:02I'm not going to bang the gavel. You're here. You're a professional. We need to hear from you. And I try and give that same type of, of leverage to each of our members. So I'm delighted. But with that said, if you don't take advantage of it, I will not either. We have an idea that we're trying to move our business and make our let allow our members an opportunity, uh, to, um, to come and do their business also.
▶ 0:34:34So we will now move forward with the feedback from our, uh, witnesses. And we will first move to the distinguished gentleman, Mr. burris. Mr. burris, you're recognized for five minutes. Speaker 4: chairman sessions, ranking member mfume and members of the subcommittee, thank you for your leadership on this critical topic and for the opportunity to be back here to be part of the conversation.
▶ 0:35:03For the last 15 years, I've worked on one question from inside and outside the government. How do we know with confidence that the person on the other side of a digital transaction is who they claim to be? Today? That question has become far more difficult to answer. And here's the blunt truth the way the federal government verifies identity was designed for a threat that no longer exists.
▶ 0:35:28Every day, however, we defend that old model as though it still does, and give fraud networks another opportunity to steal taxpayer dollars and undermine public trust. Gao estimates federal fraud losses at as high as $521 billion every year. Further, the pandemic exposed just how far our identity infrastructure has fallen behind. Those losses were a warning.
▶ 0:35:56Today, the gap has widened dramatically, and by the time we update the next set of estimates, it will be double or triple the size. My name is jordan burris and I lead the public sector business at soccer. Soccer was founded on a simple premise in a digital world, proving who someone is should be accurate, fast, and fair.
▶ 0:36:22Today, our ai native identity and fraud intelligence platform helps more than 3000 organizations globally, including over 150 public sector organizations, make trusted identity decisions. That broad view allows us to see how fraud evolves across the economy and increasingly targets the government.
▶ 0:36:44Before joining socure, I served as chief of staff in the white house office of the federal chief information officer, helping shape federal identity policy through the covid response and the government's transition to zero trust after solarwinds. Working inside the government and in the private sector has shown me just how rapidly this threat has evolved.
▶ 0:37:07Some of the identity industry have begun calling this moment world war fraud, and I understand why we are no longer confronting isolated fraudsters. We are facing organized, increasingly sophisticated transnational fraud rings using ai at industrial scale. One fraud ring we profiled created nearly 25,000 synthetic identities and launched more than 35,000 attacks in just 30 days. The adversary has changed.
▶ 0:37:37Our federal identity model, however, has not. And yet many in the government believe it will hold up to today or even tomorrow's fraud threat. For decades, the government has treated matching a name, date of birth and social security number validated against government authoritative records as proof of identity. That approach is no longer sufficient. Further, fraud does not stop at enrollment, and identity verification cannot either.
▶ 0:38:05It must become a continuous discipline that evaluates risk throughout the life cycle of an account. From where I sit, identity should be considered critical infrastructure. Nearly every interaction americans have with their government benefits tax administration, disaster relief, veterans services, and health care depends on getting this decision right. Done correctly, better security means better access.
▶ 0:38:34It makes it easier to say yes to legitimate americans and no to industrialized fraud rings. This year, socure supported the department of education in deploying real time risk based identity screening in the fafsa process, protecting more than $1 billion in taxpayer funds while allowing over 92% of legitimate applicants to pass automatically.
▶ 0:38:59That's the model the government should continue pursuing prevention before payment. Risk based rather than one size fits all continuous rather than point in time and outcomes, rather than checklists. To make this the federal model, I would leave the committee with five recommendations. First, measure outcomes, not compliance, requiring systems to prove that they can stop the fraud threat.
▶ 0:39:30Second, make continuous identity verification the standard across the life cycle of an account. Third, expand secure data sharing where we know it works through trusted resources like do not pay and other cross-government solutions.
▶ 0:39:46Fourth, reward fraud prevention instead of recovery, where agencies are incentivized to stop fraud before taxpayer dollars ever leave the treasury and finally treat identity verification as dynamic infrastructure that must be resourced to evolve continuously, not built once, certified once and left in place for a decade.
▶ 0:40:07To be clear, congress does not need to prescribe a specific technology, but congress can establish a new expectation that technology exists, and the evidence is clear now our policies and practices must catch up to the threat so americans can trust their government in the ai era. Thank you, and I look forward to your questions. Speaker 1: Mr. burris. Thank you very much.
▶ 0:40:37We now move to move to the gentlewoman. Miss cain. Miss cain, you're recognized for five minutes. Speaker 5: chairman, ranking member mfume and members of the subcommittee, thank you for inviting gao to contribute to this important discussion on identity related fraud threats and federal efforts to improve identity verification processes.
▶ 0:41:06As you know, federal agencies use personally identifiable information to verify the identity of individuals who access accounts on government websites. An increase in sophisticated cyber attacks has led to a greater risk of that pii being stolen and used to commit different types of fraud. Malicious actors can then use that information to fraudulently receive government benefits, commit tax or wage related fraud, or create new credit cards, or take over people's accounts.
▶ 0:41:34These attacks can harm individuals, result in financial loss or damage the reputation of federal agencies and financial institutions. Because of this, gao has long emphasized the urgent need for the federal government to improve its ability to protect against these cyber attacks. Today, I'll focus on issues related to identity related fraud threats.
▶ 0:41:58I'll also discuss the recent actions that gsa has taken to improve login.gov identity verification services and alignment with federal guidelines. Fraud has been a long standing issue within the federal government. One particular type is identity related fraud, which can include thieves opening new accounts in someone else's name or stealing pii to obtain government benefits. For example, we have reported that hundreds of billions of dollars were lost to the in the pandemic to potentially fraudulent payments.
▶ 0:42:28The harms caused by breaches of pii are. Identity theft can extend beyond tangible financial loss to include lost time, such as when those victims spend months or years even working to restore their identities. Additionally, there can be reputational harm or emotional distress to address these issues. Gsa developed login.gov as a means to verify users identities who want to create an account to access federal websites.
▶ 0:42:56Accordingly, gsa has a significant responsibility for protecting users pii that they collect during that process. In 2024 and 2025, we reported on login.gov process for identity verification, its misalignment with federal guidelines for identity verification and fraud prevention measures.
▶ 0:43:15In our reports, we identified several weaknesses in gsa's implementation of login.gov, including that the system did not meet the requirements to verify a person at the il two level, and that was because the system never included a physical or biometric comparison to link a user to a specific real life identity. As a result, we recommended that gsa take four actions to ensure that the pii is better protected and to lessen the risk of identity theft.
▶ 0:43:42To its credit, gsa has fully implemented three of those actions. Most importantly, they have completed their remote identity proofing pilot, ensuring that the system is compliant with nist il two standards. However, gsa hasn't taken important steps to collaborate with agencies to address login.gov technical challenges gsa has developed a roadmap that outlines planned and ongoing efforts to improve its system functionality.
▶ 0:44:12However, this action alone does not fully address all of the technical challenges that we identified in our report. For instance, agencies reported that they lacked visibility into authentications, that the system had a high failure rate, and also it lacked fraud controls. Gsa roadmap did not contain efforts directly aimed at addressing these challenges.
▶ 0:44:35It's important for gsa to work with agencies to solve these issues, as doing so will help ensure that login.gov delivers the functionality agencies need to effectively verify users identities, while also combating fraud threats. In summary, identity related fraud threats are pervasive and likely to continue to escalate. Protecting individuals pii is critical as the harms can be significant.
▶ 0:44:58Gsa has taken several actions to improve login.gov, but needs to continue to address fraud, address fraud, and technical challenges. This concludes my remarks, and I look forward to answering any questions you may have. Thank you. Speaker 1: Mr. cruz, thank you very much, doctor maimon. You are now recognized. Speaker 6: chairman sessions ranking member mfume and members of the subcommittee. Thank you so much for the opportunity to testify today.
▶ 0:45:23I serve as head of fraud insight at centerlink and as a professor of criminal justice and criminology at georgia state university. For nearly two decades, I have studied cybercrime by going where it happens into darknet markets, telegram channels, and encrypted platforms where fraudsters buy, sell and teach each other how to steal from government programs. I also go into the field myself to the mail, drops, virtual offices and shell addresses.
▶ 0:45:50These operation use to look legitimate. My testimony today is based on that firsthand work. The central lesson from my research is this fraud against government programs is no longer a series of isolated schemes. It is a durable, specialized criminal infrastructure, and it moves. The pandemic did not create this infrastructure, but it supercharged it.
▶ 0:46:13Criminals learned how to acquire stolen and synthetic identities, stand up shell companies open bank accounts and recruit money mules at scale. When pandemic relief programs ended, none of that capacity disappeared. It simply migrated. Today, my team is tracking that same infrastructure inside snap, medicare, medicaid, federal student aid, tax refunds, and sba backed loans.
▶ 0:46:38A few examples illustrate how we are watching criminals combine stolen identities with ai generated faces and deepfake video to defeat liveness checks at digital banks and tax preparers using nothing more exotic than face swapping software available to anyone. We are watching an ebt fraud market where one criminal criminal steal car data. A separate paid service verifies the balance before the card is even used, and the third actor cashes it out.
▶ 0:47:06And my own field investigation of a florida durable medical medical equipment company whose office I found abandoned in delray beach is now tied to a department of justice case alleging $3.76 billion in fraudulent medicare and medicaid claims. Different programs, different agencies, same playbook, the same stolen identity, the same shell company, the same bank account reused across systems that rarely talk to each other.
▶ 0:47:33That fragmentation is the vulnerability criminals exploit the seams between agencies precisely because our defenses are built program by program, while their infrastructure is built to move across all of them. Given my time today, I want to leave the subcommittee with four priorities. First, replace self-attestation with verified data wherever the risk is high.
▶ 0:47:58Too many programs still take applicants at their word on income, identity, or eligibility. That was the single biggest vulnerability exploited during the pandemic, and it remains one today. Second, expand real time cross-agency data, matching the same identity that files a fraudulent tax return can apply for a snap benefit. The same week, agencies that only compare notes in periodic batch runs weeks after the money is gone cannot see that pattern.
▶ 0:48:28They need to see it before disbursement, not after. Third, strengthen pre-payment screening and move toward risk based disbursement. Build on the model of treasury's do not pay system, but expand its authority and its reach so that suspicious payments are held before they leave the government, rather than chased afterward through recovery audits that criminals have already outrun. Fourth, give agencies the flexibility to adopt smarter tools and keep it current.
▶ 0:48:55Much of today's verification infrastructure and the policies behind them were built for an earlier threat, and procurement and roll making cycles that take years cannot keep pace with fraud. Tactics that shift in a month or less. Agencies need standing authority to test and deploy technologies to meet the current threats, not just at the next scheduled audit. None of this requires slowing down help for legitimate applicants.
▶ 0:49:23It requires distinguishing them from fraud earlier, using signals criminals cannot easily fabricate. The federal government already has some of the tools it needs, which is. What is missing is the authority, the coordination, and the sustained investment to use those tools before the money moves, not after. Every dollar we protect from fraud is a dollar that stays available for the people congress intended to help. Thank you, and I look forward to your questions.
▶ 0:49:52Speaker 1: doctor, thank you very much. Mr. stanley, welcome. We're delighted that you're with us. With us. Gentleman's recognized. Speaker 7: thank you so much. Chairman sessions, ranking member mfume and members of the subcommittee. Thank you for inviting me to testify today. And thank you for your attention to the subject of digital identification, which I don't think has received the attention it deserves. I hope to leave you with three overarching points today. First, a digital id system would be a disaster for individual liberties if it's not done right.
▶ 0:50:22If any such system is to become standardized, it must be built with great care and awareness of big potential downsides. We have to ensure america does not become a checkpoint society and that digital ids don't become virtual ankle monitors, something that tracks us, but we can't turn off or escape. Second, the digital id system that is most likely to become dominant mobile driver's licenses, or mdls issued by the states, is not being done right.
▶ 0:50:50If driver's licenses are already in most americans wallets and are by far the most likely form of digital id to become standard, login.gov itself is moving towards relying on them. Third, there are much better alternatives if we just do it right. So let me start by explaining my first two points that digital ids have the potential to be a disaster if they're not done right and that they are not being done right today. One big problem is that once this infrastructure is built, we start getting identity requests from every direction.
▶ 0:51:17We want to enter a 711 scan your id, you want to buy a cup of coffee, park your car, tap here, please. Want to watch a video? Log into social media. Look at a news site shopping site. Click here to send us your driver's license. There is already far too much tracking that takes place online, and polls show americans are very uncomfortable with it. But there's been a steady pushback, and that tracking has been getting harder for companies. In some ways, a digital id could lock it down and make it inescapable.
▶ 0:51:44You can't just run to the dmv and get a new identity. The way you can get a new username and password. Those pushing mdls in the states have done nothing to counter this easily predictable side effect. We may create a digital id to solve government fraud or identity theft or other problems, but there's a horde of others waiting in the shadows who will instantly pounce on this infrastructure to use it for their own purposes. Once it's created, the result will be a checkpoint society of constant id proofing with a digital id that will be really easy.
▶ 0:52:13Just tap, click or scan and a digital id system, if not built carefully, could send a report back to the government. Every time you show your id, a record of every beer purchase, bank and doctor's office visit, and online every website you visit. This is called phone home. This capability was built into the mdl standard as an option. There's also the issue of accessibility.
▶ 0:52:35If digital ids become mandatory, either legally or as a practical matter, that would harm the surprisingly large number of people who don't have a smartphone about 1 in 10 people in the us, according to studies, including over a fifth of people over age 65. Some may lack the resources to afford one, others the technological literacy to use them. That's why offline options for doing business are vital to protect.
▶ 0:53:00If we don't make sure that digital ids are an empowering option for people rather than an imprisoning requirement, then people without smartphones will be shut out of many necessary functions of life and often benefits that they sorely need. So these are easily foreseeable, predictable consequences of a digital id. But that brings me to my third point. If a digital id is to be created, there are alternative paths that would prevent many of these harms. In terms of alternatives, I have two quick points to make before I stop.
▶ 0:53:29First, the field of privacy enhancing cryptography is advancing fast and already can do amazing things that allow us to have our cake and eat it too. When it comes to privacy and security, one example is privacy enhancing technology called zero knowledge proofs. Using that kind of tech, digital ids can let me prove I'm over 21 without sharing my date or my identity, date of birth, or my identity. And it can do that in a way that if I prove my age multiple times to the same seller, they don't even know that I'm the same person.
▶ 0:53:56That's the kind of thing that is needed to stop ids from being this kind of ankle bracelet tracker. But that kind of technology is useless if we don't bother to build it in, and it has not been built into the mdl standard. If a system can reduce fraud and provide other benefits without enabling tracking, why would we build one that does enable tracking? There are other key protections we can build on our website, we've outlined 12 key protections that we think are necessary in a digital id system. There's more about that in my written testimony.
▶ 0:54:23And then second, there are some states that are moving in the right direction here. Some, like new jersey and illinois, have put some important protections in place into their digital id enabling legislation, and the state of utah is the most notable. It has set out a separate path, which they call state endorsed digital identity, or seti, that is emerging as a far more privacy protective alternative to the mdls that many states have adopted. Some other states are starting to work with utah to join in that effort and build that alternative path.
▶ 0:54:51The bottom line is, if we build a digital id system, it must be done right. We urge congress to ensure that it is american. Freedom is the top priority. Thank you very much, and I look forward to your questions. Speaker 1: Mr. stanley, thank you very much. I appreciate each of the witnesses being here. I'd like to move first to the distinguished gentleman, Mr. jack, for his question. Gentleman's recognized. Speaker 8: thank you very much, Mr. chairman, and I appreciate your testimony this morning. Mr.
▶ 0:55:20Burris, my first question is for you. Uh, the public increasingly relies on the internet to access government services. And I'm just curious, from your perspective, what fraud threats might my constituents be facing that they're not even aware of yet? Speaker 4: representative, thank you for the question.
▶ 0:55:37When it comes to the fraud threats in the way that they're evolving across the landscape, every single interaction, every single time that an individual is engaging both with their government and in their commercial life, uh, there is the chance, the opportunity that an adversary could be attempting to pose as them could be attempting to enroll in an account. Uh, we see this across financial services where we work. We see this across various aspects of the gig economy where we work.
▶ 0:56:00Uh, and then of course, with government organizations, the reality here is that all of the information, all the pii that exists for many folks within this room has been stolen by the adversary. And they are using that to attempt to become them, and therefore that they can access what would be either their bank accounts and help move money all across the economy.
▶ 0:56:23Speaker 8: you know, I've heard folks mention anecdotally that now with artificial intelligence, people are trying to impersonate, you know, a loved one by virtue of maybe their voice or their mannerisms, what have you. And using some of that information that may have been stolen. Have you seen that? And could you elaborate on that for us? Speaker 4: yeah, absolutely. We are in a what I would consider a national crisis. Uh, from where I've said, I've highlighted, uh, and our team has highlighted.
▶ 0:56:45So care for a number of years now that the moment that we're in is unlike any other in the sense that ai is being used as an accelerator for attacks that typically would take weeks to occur. Uh, and further, it's also becoming more cost effective for the adversary to launch those attacks. These attacks could be everything from launching deepfakes, things where we've seen an 8,000% increase year over year. Um, this can also be in terms of the velocity by which attacks are happening. This means the speed by which they are occurring.
▶ 0:57:13And in these instances, these moments we are seeing things that where attacks used to take weeks in order to be conducted, they have been broken down to under 48 hours. And this would mean that an adversary has launched an attack where they have stolen my information, or yours, or even worse, fabricated an identity attempt to open an account and or move money, take over an account that may have existed because they went through a call center and were pretending to be you, using your voice or something that was cloned, an image of yours, biometric, etcetera. And they've used all these patterns.
▶ 0:57:43And if like for, say, they were blocked in some way, shape or form, they then just adapt and iterate. Uh, and the cycle continues all over again. Speaker 8: thank you very much, doctor maimon. Um, do I understand? Are you a professor at georgia state university? So I want to acknowledge first and foremost, both my mother and father went to georgia state university. I represent many people who have degrees from georgia state university, and I also host panthers in the district from time to time to bring students up here. So I'm curious to build off that last question.
▶ 0:58:13Um, you obviously understand, you know, criminology, your professor of it help us understand, are most of these threats coming from inside our country, or are we starting to see foreign adversaries exploit some of this data to, um, to fraudulently impact some of our constituents? Speaker 6: thank you so much for the question. Really appreciate it. Um, a lot is coming from abroad. We have a lot going going on internally as well.
▶ 0:58:37It really depends on the type of fraud we're looking at in the context of the type of fraud you just mentioned with folks engaging in online romance fraud, we're seeing a lot coming from places like south asia. A lot is moving right now to africa in some of the online fraud markets that are infiltrate. Uh, I spent a lot of time sort of trying to infiltrate to yahoo boys channels as well as sakawa boys channels where actually see them using those deepfakes to swap faces while engaging with some of the victims.
▶ 0:59:04Uh, here in the united states, it's heartbreaking to see the level of conversations that, that these guys are able to get, uh, with those, those targets. And it's also heartbreaking to see the different modus operandi and different types of buckets that those criminals are engaging in. I can tell you that as of this, this morning, uh, we're seeing more and more yahoo boys and sakawa boys targeting, um, our 401 victims, 401.
▶ 0:59:31So, you know, we're seeing them convincing targets to borrow against the 401 s as well as hand over control completely on the 401 k's account. So this is where we're up against. We're seeing those deepfakes being used to swap faces, uh, lure targets to, uh, give away access to the 401 k accounts. And then unfortunately, victims funnel the money to bank accounts that the criminals create along with the with the targets, and then the money leaves the country.
▶ 1:00:00So it depends on the type of fraud, the type of fraud that you're referring to. Uh, definitely comes more from abroad. Speaker 8: I appreciate all of your testimony today. And Mr. chairman, I'm grateful you convened this hearing. I've learned a lot already in just this interchange. So thank you very much, Mr. chairman. I yield the remainder of my time. Speaker 1: the gentleman yields back his time. Thank you very much, distinguished gentleman. Mr. you're now recognized. Speaker 2: thank you, Mr. chairman. Um, Mr.
▶ 1:00:25Ferris, I want to start with you because something you said struck me and I might be the basis of why we are here and why we want to come back this way again. And that was that. You said, if I'm paraphrasing you correctly, that we are spending years and millions of dollars preparing for a threat that does not continue to exist. Can you expand on that, please?
▶ 1:00:56Speaker 4: absolutely. And in particular, the part of my testimony that was highlighted was the fact that much of how the federal government has thought about its standards for how to prevent or protect digital identity. And to be very clear, digital identity is just the makeup of how we present ourselves in cyberspace, right? Much of how the government has designed that standard today effectively was worked about a decade ago.
▶ 1:01:20And so if we're looking at today's fraud threat, how it is evolved, how the adversary moves, it no longer can keep pace with what we are seeing today. So much so, one of the efforts that, you know, our company led was as we were engaging with nist as part of their most recent update to the standard, was highlighting that fraud should become an underpinning of part of what we evaluate in digital identity and when it's established, not because we want it to be harder for people to prove who they are, but because the alternative is that we are
▶ 1:01:51Leaving a floodgate open for nation states to launch their attacks. And from where we see it today, you know, there's over 7500 fraud rings that are operating in their own different ways to attempt to attack what would be government services or even the commercial sector. Speaker 2: and Mr.
▶ 1:02:07Burris, um, as artificial intelligence advances at an alarming rate, what does the government and in particular, what does login.gov need to do to stay ahead of those scammers and to be able to identify them as we move forward? Speaker 4: it all starts with admitting that there is a problem. So we're going to begin there and say that this is a crisis moment for where we are in.
▶ 1:02:34I think it's important that we understand that as the federal government, we need to basically embrace and understand that we need to use ai to fight ai. At this point, the adversary does not care, um, about how anything is constructed. They do not care about our norms. They do not care about rules and regulations. They do not care about the ages of those who they're engaging with or their political affiliation. What they are attempting to do is to take money and resources to disrupt what would be the status quo, the norms that we hold dear.
▶ 1:03:01And what we need to do is engage aggressively to basically put in place the types of controls and measures, many of which have been adopted in other sectors for years, uh, in order to help prevent against this threat for login.gov in particular, I would say and, you know, full disclosure, again, we are one of the vendors that are now have been added in order to power what login.gov is doing. They are taking this threat absolutely seriously. Uh, this day and age and other fraud team has engaged diligently to understand what needs to evolve with the program.
▶ 1:03:31Speaker 2: and miss cruz, kayne, you mentioned at some point in your testimony, I'm trying to get back to it here, where gsa implemented 4 or 5 recommendations. What was the fifth recommendation? Is that still standing? Speaker 5: we made four. They implemented three. And the last one was the agency's. The 24 cfo act. Agencies that we talked to had technical challenges with login.gov. So as users, they were not necessarily able to use with ease.
▶ 1:04:01And they had some issues with the platform, such as they would like to know when the users are verified and authenticated, why they were not. So if they fail, the person just says, hey, I failed. They have no way of knowing why they failed, how they can remedy that. So then you just don't have access to your government account, so you can't get your benefit. You have no recourse of knowing how that happened. So either you just have to try again or you have to go to the post office. That was one of the issues.
▶ 1:04:31Another issue is at the time they had a high failure rate, so they were just getting problems of even logging into the system or being able to use it. And at that time, they were not having such strong fraud controls. And again, to their credit, they have been taking the issue very seriously and partnering with new technologies and new companies to enhance their fraud controls, but they need to partner with the users to make sure that they're also helping them with the issues that they're having with login.gov.
▶ 1:04:58Because if the users can't use it, the technologies can be great. But if your users are still having issues using the system, you're going to use that lose that user base. Speaker 2: thank you very much. Just one other quick question, Mr. stanley. I appreciated your description of a digital ankle bracelet or ankle monitor. Um, and you referenced driver ids. Are they the most vulnerable?
▶ 1:05:25Speaker 7: I think that in many ways cryptographically secured, um. Speaker 2: driver licenses. Speaker 7: digital driver's licenses, are. Speaker 2: they the most vulnerable? Speaker 7: uh, are, are less vulnerable probably than many other techniques for validating identity. Um, Mr. burris talked about use ai to fight ai.
▶ 1:05:42There are many technologists who say that that is a losing battle and that you will never it will always be a constant arms race, because any ai that can be used to identify who is real versus who is not, that ai can be used to fake somebody who's not real. Um, and so that is why a lot of people in the technology world are turning to cryptographically secured, uh, tokens or identities.
▶ 1:06:10So that basically, um, the dmv or other issuer takes the data on your driver's license digitally, signs it with encryption with a secret key, um, and then publishes a public key and a verifier can look at the public key. And if it matches, it could only have been signed by the dmv and not a single bit could have been changed. And that's cryptography.
▶ 1:06:33Um, and so somebody can prove that they, the thing they have in their phone, the file they have in their phone was issued by the dmv and signed by the dmv. Um, and, um, that is one of the reasons why we think that digital driver's licenses are poised to move to the forefront in online verification and why we worry about all the side effects of that kind of a system that I talked about. Speaker 2: thank you. Thank you very much. Yield back, Mr. chairman.
▶ 1:07:04Speaker 1: gentleman yields back his time. Miss norton, you're now recognized. Speaker 9: thank you. Speaker 10: did did did did digital identification and modernized technology systems can help verify identities and reduce fraudulent claims.
▶ 1:07:28But they should not come at the expense of access to vital social safety net programs. Mr. stanley, as more federal, state and local governments adopt digital identification systems, who risks getting left behind?
▶ 1:07:57Speaker 7: yeah, so exclusion is a big potential side effect of this kind of a system. And we will need to ensure that a digital identity is not mandatory. And we will need to pay the costs of ensuring that there are other options. Uh, lest we dial up the security dial too high and leave a lot of people who have genuine needs and are genuinely qualified for benefits being locked out.
▶ 1:08:24Um, we know in addition to what I said, about 20% of people over age 65 and 10% of americans not having smartphones. Um, studies have found that people with disabilities are 20% less likely to have smartphones, um, people with incomes under $30,000 a year, 25% don't have smartphones. 30% of rural americans lack fixed broadband and good internet access.
▶ 1:08:49Um, and many people with low incomes are on limited data plans. Um, and so basically we need to ensure that we never assume and a lot of things will of these things will improve over time. Some of these studies are a few years old, um, and probably are out of date already, but we're never going to get to the point.
▶ 1:09:10And we should never make policy based on an assumption of 100% adoption of technology, because there will always be people who can't or won't or simply don't want to and should have the freedom not to use all these advanced technological systems. Uh, so I hope that answers your question. Representative norton. Speaker 9: um. Speaker 10: stanley, which populations are most likely to own? Uh, most likely not own smartphones.
▶ 1:09:44Speaker 7: sorry, the populations most likely not to own smartphones. Speaker 9: yeah, yeah. Speaker 7: it's um, again, um, older americans, um, and low income americans, disabled americans, low income americans, of course, are disproportionately people of color. Um, and so I think those are the populations that would be most affected.
▶ 1:10:04People who are often already face a lot of, um, marginalization in life may find themselves further locked out of paths towards fully living in our society. Speaker 10: well, Mr. stanley, given the increased adoption of digital identification, are people without smartphones at risk of reduced access to government services?
▶ 1:10:33Speaker 7: well, yes, that is what we see. Is that, um, something a technology like a digital id tends to move over time from being an option that empowers people to being expected, to becoming normalized. And then people who don't have it end up as freaks and edge cases that just aren't accounted for by the systems that, that, that run our government, our benefits, and many private sector goods as well.
▶ 1:11:01Um, and so because often it is expensive to maintain offline, um, real world, uh, options for people, but it is important that, that a digital identity system do remain an option. There are post offices in every town in america where people can do things in person. Um, there, there are other offline ways of doing things.
▶ 1:11:28And we need to make a conscious policy decision to protect those ways, those alternatives, um, to protect american freedom and to protect people who are vulnerable and need the benefits that they are qualified for. Speaker 9: uh.
▶ 1:11:45Speaker 10: even, even for those who do own smartphones, a lost, stolen, damaged or nonfunctioning device could temporarily prevent them from accessing the accessing the programs they rely on. While we should embrace new technology to minimize fraud, we must ensure all americans have access to programs.
▶ 1:12:13I yield back. Speaker 1: gentleman yields back her time. Thank you very much. I now recognize myself for a u. C unanimous consent request. I'd like to enter into the record two letters that have been provided to the committee, both Mr. mfume and myself. The first is a letter from the better identity coalition.
▶ 1:12:34They highlight how digital identity credentials, like mobile driver's licenses and investments in digital identity infrastructure, could help address this emerging fraud threat that we are talking about. Secondly, the second letter is from the defense credit union council.
▶ 1:12:53It reinforces how critical it is to protect the nation's military and veteran communities against scammers who specifically look to exploit vulnerabilities created by their life in the military and to take advantage of that. So without objection, so ordered. Thank you very much.
▶ 1:13:12Uh, it is intuitively obvious to each of us that, uh, my side, the republican side, the majority side does not have many witnesses or many members here that we are in the middle of receiving a briefing on the conflict in the middle east at this time by the administration. And so I've chosen not to cancel this hearing, but rather to stay myself. And so, uh, I may take the place of several of my members. So I would yield myself my time right now. Mr.
▶ 1:13:41Stanley, thank you for being here. Mr. stanley, I'd like to ask a question that really came to me today, and I find it very interesting, not only your comments, that I find common sense, and I find myself I would have to struggle with myself to disagree with you.
▶ 1:13:58But it brought up one issue, and that is we generally see fraud as an overwhelming factor that we need to defeat, that when fraud is involved. And fraud could be something that then becomes tangible where it's been established, necessarily established as opposed to questioned, to establish whether it is fraud, where fraud is involved.
▶ 1:14:27Are there limitations, uh, at, uh, on behalf of the government to, uh, to, to, to satisfy the requirement of protecting self and the, for instance, I'd like to give is at an airport that I go to every week, uh, called reagan airport.
▶ 1:14:47There is a sign from, uh, from the government that says, if you're in this area, you are subject completely to search and seizure. In other words, you we can do by and large, within some balance what we want to do to ask you, to demand you to comply with our orders and those things. Is there a point at which we should be careful once we know fraud is involved?
▶ 1:15:16And I can give you probably several instances, but I want to ask that question to you. Speaker 8: Mr. chairman. I'm not sure I totally understand the question. My apologies. Speaker 1: so I'll I'll try and help it out. When we think that we have established the standard of fraud by a government agency, and they then are saying we are dealing with fraud, is there a limit to how far they can go?
▶ 1:15:44Within reason. But to establish something, for instance, could they pick up the phone and call a bank of know your customer and a bank would have an idea of what they're involved. And we're trying to move a lot of this, uh, these issues to, uh, professionals in law enforcement and professional.
▶ 1:16:12Otherwise, could they call a bank and say, can you please tell me I've got a customer that lives at 1515 smith avenue and this is their name, and they tell me they're 68 years old. And they told me that they do this and this and this is that is that okay? Because they've established fraud and they're trying to then run it down. What are the limits?
▶ 1:16:38What is the expectation that you have? Because you've mentioned civil liberties a few times and I respect that. But we're talking about fraud and we're talking about how would you expect the government or their parameters, the government can only go so far. Are we going to give the criminals that upper hand? So that's the question, sir. Speaker 8: okay. Yeah. So if you're talking about investigating fraud that you have, evidence has already happened.
▶ 1:17:08I think that it would become a criminal investigation like any other. And that has been that is subject to the constitution, the limits of the constitution, um, you know, presumption of innocence and the fourth amendment of the constitution prohibiting unreasonable searches and seizures. Um, uh, and other provisions of the constitution that have been well litigated over the years. Um, so I would think that a professional law enforcement officer would know what those limits are in many ways. Um, and whether.
▶ 1:17:38Speaker 1: you had a chance, Mr. stanley, to look at the piece of legislation that was passed by this committee a few weeks ago that's waiting for floor arrival, that would take these options and move them to the ig in the treasury department, in a specialized unit that are law enforcement type people. Have you looked at that? Speaker 8: I confess that I have not. I would be happy to and get back to the committee with, uh, with our with our. Speaker 1: if you could do that.
▶ 1:18:10I'm interested in your feedback because we are trying to say that we believe once a standard of fraud has been established, that there needs to be specialized. Sure. But the ability that investigators have to go and vet this. We just have to find a way. Is it truthful? How widespread is it and how are we going to handle this? Okay, I'm going to ask you another question.
▶ 1:18:36Got five seconds left, but we're kind of being a little careful. We're not as tight on this. Uh, the second one is, is there a limitation on someone if they are presently on social security?
▶ 1:18:56Uh, they, they've taken out a loan sba, something where they've in the government system and we find some instances where there might be questions that arise. And I know once again, you're very careful, and I agree with that within the law, within the bill of rights, within the constitution, within all the things that we could establish.
▶ 1:19:21Is it fair game to go back and run people back through if they think there's something that might be amiss through that's this organization. Even though a person has been on government benefits, because, you see, we think that a lot of people that presently are receiving government benefits might not be exactly as we thought they were. Is that fair game? Speaker 8: I think it is with some cautions.
▶ 1:19:51Uh, I think if if the if a government agency sees signs of fraud, there is no reason why it shouldn't. Um. Speaker 1: that has to be established. Speaker 8: um, there are cautions, especially if you are looking at, for example, using ai algorithms in order to do that, um, that may have been trained on, um, sets of preexisting data that, uh, contain biases that there was a man, it was, there was an nbc report which I could share with
▶ 1:20:21The committee about it, who, uh, paid his credit card off every month in full. And he got a letter from his credit card and they said, we're, we're reducing your credit limit. And he said, why I pay off in full? And they said, because we have found that the other store, other customers at some of the stores you shop at have been bad credit. And I think that that strikes most people as just unfair and guilt by association. Speaker 1: smell test. Speaker 8: yeah. But I think that a lot of ai algorithms do basically the same thing in a hidden way.
▶ 1:20:49Speaker 1: how about if ai discovered that there are 74 people at your home address that receive benefits? Uh, because ai discovered it. And, uh, we, I think that you might be one of them and we'd like to do some sort of a review about this. Is that fair game? Speaker 8: I think that there are good uses of ai and that flagging that kind of anomaly. As long as there's human review, um, might make sense.
▶ 1:21:15Um, but for example, for examples like that, there are other examples where we see unfortunately, um government agencies not building in the checks and balances the due process and using ai not only to figure out who it thinks is suspicious, but then to take actions against people that they have trouble, um, uh, you know, getting due process and fighting back. We've seen, for example, in the states, people losing their disability benefits based on algorithms. Okay.
▶ 1:21:45Speaker 1: so, uh, let me give you that. It would then at some point require, uh, human intervention to review data to then make some decision as opposed to a computer automatically assuming something. Speaker 8: I think that's right.
▶ 1:22:05The only other caveat I would add is that, um, some of the fraud prevention techniques are based on gathering an enormous amount of intrusive data about individuals. Speaker 1: and we spoke about this, but you had indicated earlier without human intervention, that meant that someone else, a computer or an ai modeling decided they could send you a letter and cut off your benefits.
▶ 1:22:30I'm saying that they we could use these to then go to a human who is trained, who does have this professional experience, who would be able to apply it, and then would be able to use some rational basis. Okay. So you would agree with that. Speaker 8: yeah. But what I'm saying is that, for example, there are industries that, um, that use unethical apps on people's smartphones to track their location without their knowledge or permission.
▶ 1:22:59I'm sure that many people in this room are being tracked by these companies without knowing, um, and that some of that data can be fed into these algorithms for deciding who is suspicious and a lot of other very privacy invading data. And so if the algorithm you're talking about is based on that kind of very intrusive privacy invading, um, data sources, we would have a problem with that. Speaker 1: okay. Well, I could bring up lots of examples. I'm not going to I want to thank you.
▶ 1:23:28I think this is an important question. That's why you're here today. We now like to move to the distinguished gentleman from florida, Mr. frost. Mr. frost, I yield back my time. We now move to you. The gentleman is recognized. Speaker 11: yes. Thank you so much. Um, you know, part of my concern as it relates to digital id becoming mandatory is the risk of widespread data collection and exposing millions of americans to harm, which is already an issue that this country has seeped into many different ways.
▶ 1:23:55Social media, um, online and different things like that. Mr. stanley, how could digital id systems become a barrier for americans trying to access services, benefits, or programs? Speaker 8: that could happen if, um, first of all, you are unable to get a digital identity system because you don't have a smartphone.
▶ 1:24:16There are also a lot of americans who don't have access to, uh, who don't have, currently have any kind of driver's license or non-driver id from dmvs who there are people whose birth certificates were burned in a fire in, in tennessee in 1955 and don't have access to them. Um, it is a messy world out there. And I think that digital ids seek to impose a sort of neatness and bureaucratic, uh, you know, regimentation on all of us.
▶ 1:24:45And so we in, in making policy, we have to make sure that people who don't have access to those things are not left out. So you can't get there are people who can't get a driver's license or people who. Maybe they have a driver's license, but they won't be able to get a digital driver's license because of the things that we talked about in terms of not having access to the technology or the technological literacy to use it. Um, there was one study that found that a very large proportion of people over 65, you know, weren't able to install an app on a, on a smartphone.
▶ 1:25:15Um, uh, there could be situations where, um, people's ids are abusively revoked. Um, you know, we've seen, uh, there has been mentioned that the trump administration put some people in the social security dead file. We also saw in california a democratic, uh, candidate for governor proposed that, uh, that, um, federal agents who wear masks should have their driver's licenses stripped from them.
▶ 1:25:41And whatever you think of mask wearing by federal agents, which is controversial issue that is, that is using an identity infrastructure for political purposes, which is something that we may see in the future left, right or center. Um, and, um, so, so that could be a threat. And we have called for protections against people having their, um, their, their ids yanked by abusive governors or the like. Um, so those are some of the ways in which people could find that they are left out of a digital identity infrastructure.
▶ 1:26:11Speaker 11: part of my concern too, is, I mean, when you look at this administration, um, we know they've empowered big tech companies like palantir to create databases of americans personal data for government use. We know that during the, you know, doge era, similar things were done during that as well. This data collection could make it easier for private companies to abuse our data. I know some proponents will say, well, you know, this is mainly for government use, but we know it never it's not only for government use.
▶ 1:26:38Um, and that's part of my concern with this. There's just so much collaboration between private companies, data sharing, um, how, how should we legislate on balancing the convenience and the real dangers of digital id, which also will lead to losing anonymity online? Um, which is something else I'm concerned about as well.
▶ 1:27:05Speaker 8: you know, we have a piece on our site that outlines 12 protections that we, we call for that, that we think state legislatures should enact that govern any, um, you know, mobile driver's license or digital id that's created in their state. I won't go through them all, but they include such things as protecting people against incessant demands from every quarter, if you want to, if you want to do business with us or come in our candy store, you have to tap your id and give us your driver's license.
▶ 1:27:32Speaker 11: this is part of my concern, too, that making it easier to prove who you are will lead to more services companies asking you to do so. For every service that is not expected of you right now. Speaker 8: yeah, it's an excellent point because, um, one of the things that, you know, if you're a website and it's really, really hard to prove your identity online, you have to take a photo of your id, you have to send it in, you have to get a video, you have to do proof of liveness, all this stuff. You're not going to ask your visitors, your users to do that unless you really need to. So that imposes a limit.
▶ 1:28:02But by getting rid of all the friction of proving who you are online, you get a pop up like the privacy pop up as we get today. Click here to send us your digital id. It not only become easier for me to share my digital id, that means that it makes it much easier for them to ask me to or demand that I do so. Um, and that's one of the big things, and that's one of the protections that policymakers can make, which is to say, these are super ids, they're cryptographically locked down, dmv vetted everything like that.
▶ 1:28:28This is, you know, and that you shouldn't be forced to use a super id to prove your identity unless it's legally required. We have called for, uh, maybe in certain other specific situations, but, um, people are going to need protection against this absolute, you know, waterfall of demands that, that, that we, you can easily anticipate are going to happen once this is created. And then other protections, like privacy protections to make sure that the wallet holders don't aren't spying on everybody.
▶ 1:28:51Um, and that, um, you know, that these cryptographical things that I talked about are built in to protect privacy so that, you know, you can prove things about yourself without having to, you know, create a lifelong relationship with somebody by identifying yourself to them. Speaker 11: how can I know we're over? Indulge me, Mr. chair. I just my last question is, how can digital id lead to complete loss of anonymity online? Speaker 8: yeah. So, I mean, websites are going to want everybody to identify themselves all the time.
▶ 1:29:21They're going to want to do it because their ads will be worth more if they know who you are and they can plug in you the data they have about you to other, other data they get, um, they're going to want to do it to make sure that you're of age so they can market to you under coppa, which is, you know, you can't market to people under 13 identity verification, uh, which has become a big controversial issue. Um, and, uh, bots, a lot of sites have, are having problems with ai impersonating humans.
▶ 1:29:49And they're going to want to know that you're human, um, for various reasons. And so there's going to be a lot of pressure for a lot of websites to start demanding this all the time. Speaker 11: and part of the concern, right, is the fact that this information can be weaponized against consumers, working people who are looking to purchase things online and have that information leveraged against them when they're making decisions on what they want to buy and how much those items cost. Correct. Speaker 8: yeah.
▶ 1:30:13Surveillance, pricing, um, where stores get a bunch of data about their customers and then they charge you based on what they know about you and how much they think you'll pay and whether you're desperate and so forth. That's become a very controversial issue. Um, and states, as you know, um, regulation of surveillance pricing has been attracting support in the state legislatures from both left and right.
▶ 1:30:34And digital ids will make that much easier because if you know, they're going to charge, if the store is going to charge you more like, let's say that the airline happens to know that you've just lost a close loved one and you have to fly. They can, they can up your price. Yeah. Um, and so you're going to want to see what the price is without them knowing who you are, right? But they're going to want to know who you are. And there'll be this arms race. And a digital id would sort of end that arms race. And you can't escape them knowing who you are. Speaker 11: yeah. Speaker 8: if it's done badly.
▶ 1:31:05Speaker 11: I appreciate it. Thank you for indulging me, Mr. chair. I just think, uh, you know, I'm not a luddite. And, uh, I just think, like, these conversations are important because it shows how much care and intentionality needs to be put into this. Oftentimes, we're very excited about something. We move quickly on it without thinking the next ten, 20 years into the future. And then it's an emergency for another generation to handle. I think we have to have these conversations now and legislate accordingly. Thank you, I yield back. Speaker 1: gentleman yields back his time. Thank you very much. The gentlewoman from washington is now recognized. Speaker 12: thank you.
▶ 1:31:33Um so much, Mr. chair, and thank you to our panelists for joining us. You know, login.gov gives every american a one stop portal so they can use a single username and password to log in across a variety of federal programs. Sounds like a benefit and a, you know, um, customer service improvement. This is a portal that state and local governments can use as well.
▶ 1:32:00And it saves taxpayers time and money and generally makes life easier. Mr. burris, can you briefly describe how login.gov has leveraged solskjaer's technology to help reduce identity fraud for government programs?
▶ 1:32:17Speaker 5: absolutely, and I think a lot of this comes down to trust and basically leveraging what would be considered next generation, uh, technologies to try to help balance, uh, a lot of the conversation I've heard around access and speed and confirming that the right people ultimately can access these services. So login.gov, uh, conducted a competitive procurement, uh, where they evaluated our technology, uh, against that of 17 others, uh, at the time.
▶ 1:32:40Uh, and they incorporated different components of our solutions, everything from solutions that we have around document verification. So confirming that it's legitimate government issued id and or, uh, what would be, um, facial biometric comparisons. So the idea is comparing it and confirming that it is actually the right person on the other end of the screen.
▶ 1:33:02They also incorporated, uh, what would be additional fraud models, uh, to their stack, uh, things that they're incorporating, such as identifying and understanding what's happening with the device a person may be using, because it's all too often that the adversary would do something such as, uh, take a jailbroken device that is overseas and attempt to say that they are operating within new york or D.C. for that instance. Um, also doing comparisons with things like the phone or the address and individuals using their email.
▶ 1:33:31And then some of the see flagship offerings that we have, uh, related to helping to paint a picture or prediction of whether or not it is someone who is engaging in what would be a pattern that is associated with identity theft and or synthetic identity. And far too often what we see in the industry is that kind of weaknesses in these technologies have led to this unfortunate conversation about folks who've been left out and forced down alternative paths.
▶ 1:33:56It's always been my belief that if someone is choosing to engage with a digital service in government, they should be able to do so, and the technology should adapt to meet them where they are. So the addition of software tools have been, uh, have enabled login.gov to take strides towards being able to address that and make their service more accessible while simultaneously combating fraud. Speaker 12: thank you so much.
▶ 1:34:18It's really great news that we're innovating in this way to provide access that the people want, and to smooth some of these barriers to accessing services. But like you've mentioned, and based on other testimony that we've heard today, we know that scammers and identity thieves are constantly trying to find new ways to evade id verification. And that means that login.gov has to remain alert and prepared to fight new forms of fraud. We have to keep innovating.
▶ 1:34:45Miss cruz cane in gao's assessment, will there be ever be a day when login.gov will be finished and no longer need to adapt to face new fraud tactics? Speaker 6: I don't think so. I think criminals are working every day, 24 hours a day, to get better at what they do, and largely in the federal government, we're reactive. So login.gov procured the tools because they're being reactive to what has been happening within their tools.
▶ 1:35:12So I think largely federal systems are reactive to what is going on. And rather than being proactive. Speaker 12: yeah. So would it be safe to say, um, that competent and technically capable leadership of the login.gov program is critical to, um, effectively sustain prod fraud prevention? Speaker 6: yes.
▶ 1:35:37Speaker 12: and is it critical that leadership has experience in effectively managing and protecting sensitive data programs? Speaker 6: yes. Speaker 12: would it be very concerning to you, Mr. cruz, if leadership@login.gov came from an organization that had, say, an extensive history of mismanaging private data and endangering the privacy and financial security of the american people.
▶ 1:36:05Speaker 6: without, I mean, knowing a little bit more about the situation, it'd be hard to opine. But, you know, we like to look at facts and situations. But I mean, just like I told you, we would really need to have experience with technology leadership, with good technology and knowledge of how to. Speaker 12: absolutely. But if if someone who had previously been proven to mismanage private data and endanger privacy and financial security was moved into leadership, that would be concerning. Speaker 6: yes, if it was proven. Speaker 12: yeah. Um, Mr.
▶ 1:36:35Chairman, I'd like to ask unanimous consent to submit these following articles to the record. Doge put critical social security data at risk from the new york times from npr. The trump administration admits even more ways doge access sensitive personal data. Washington post, washington post, and wired similar subject matter. Speaker 1: without objection.
▶ 1:36:55Speaker 12: and just in my remaining time, I'd like to say what these articles say that president trump took one of the doge bros who oversaw the looting of the federal government's data and endangered the privacy of every american and put him in charge of identity verification and login systems for every american. And based on our previous line of questioning, that doesn't sound like a way to safeguard the american people's information, and I yield back. Speaker 1: gentleman yields back her time.
▶ 1:37:22And now I'd like to move to the second round, uh, with with your understanding. We're doing that, sir. Uh, doctor maimon, uh, you and I spent some time yesterday. Uh, maybe it was today.
▶ 1:37:37Days run together, but you most expressly indicated that you have not only great knowledge, but work on a day to day basis with many people who are criminals and who are attempting to be fraudsters at our systems. And I did not have a chance. You did not really delve into this area very much, but I think Mr.
▶ 1:38:04Mfume and I need to hear this about not only that, it exists that they're very active, that they're on the dark web or open web, that they, uh, target certain people and that they learn, uh, areas that are vulnerable and that they openly talk about it. It's, it's no longer behind anybody's back anymore.
▶ 1:38:29Do you mind taking the time that you need to express the things that we need to understand about the attack that's against us and our, our agencies? Speaker 7: with pleasure, Mr. chairman. Um, as as you mentioned, Mr.
▶ 1:38:45Chairman, I spent my time, my day, uh, infiltrating darknet platforms, telegram groups, uh, trying to understand what fraudsters put out there and how they bypass a lot of the security solutions that, uh, we deploy on financial institutions as well as on the government side. Um, oftentimes what we find in those platforms are tutorials which will walk you through how to bypass many of the security solutions that we have out there.
▶ 1:39:13Uh, the tutorials sometimes will be offered for free. Other times you will pay for them, uh, amounts ranging from 150 to $250, uh, specific guidelines with respect to how to bypass, um, and obtain sba loans, fafsa, uh, a, we're seeing as of earlier this morning, people talking about how to, um, set targets 401, uh, accounts, which I think is a
▶ 1:39:43Major issue to our country. Um, and we simply see that on scale. We see that, as I mentioned earlier on darknet and telegram, but also more and more on facebook, on twitter, on instagram. Uh, a lot of what we see also on is available on the internet, on the clearnet, uh, websites that the criminal put together and simply offer fake driver's licenses for sale.
▶ 1:40:04Um, this is the reality that we're dealing with, uh, organized crime groups with very detailed supply chains, which will have our identities offered for sale. Uh, they will have. Services which will allow the, allow the fraudsters to build histories around the identities.
▶ 1:40:27They will walk you through how to create deep fakes, high quality deepfakes, um, both images as well as videos. They will teach you how to take those videos and images and inject them in the cameras, uh, of the computers or the smartphones that folks are using in order to apply for benefits or apply, apply for sba loans. Um, and then, uh, secure all those, uh, resources that they get from the government.
▶ 1:40:56So this is what we're up against. We're seeing that happen domestically with a lot of organized crime groups, uh, operating, uh, within the united states. But a lot is happening from abroad as well. We're infiltrating russian crime groups. Uh, we were able to infiltrate some chinese crime groups who operate the scam compounds in south asia and are explicit about the type of operations and our identity and how, uh, you know, how they essentially offer those identities for sale.
▶ 1:41:26Um, and essentially walk you through the list of steps you need to engage in in order to target, uh, our benefit program. This is what we're up against, unfortunately at this point. Speaker 1: so furthering this, uh, development that you're talking about, I spoke with you about how we had looked at during 21, 22, 23, 24, uh, numbers of agencies that did not have their workers at work.
▶ 1:41:56They were not engaging the people who were seeking services. Uh, they were not able to, even when working from home, necessarily did not have a full array of opportunities to vet who people were, know your customer to look at things. And so this huge amount of money that we were talking about today in testimony before this subcommittee that is very consistent with what we've heard a say in the past.
▶ 1:42:21Uh, it it has found a real home to where this is a cottage more than a cottage industry. It is people who literally are figuring out how to do this. And you said to me, whenever we last spoke this morning, you do believe human interaction.
▶ 1:42:42And I brought up my circumstance of talking to social security, how they vetted me, how they talked to me about things that I would know about myself that I would probably not a lot of people would understand. Is this the kind of fair game that would be used to vet people, uh, on a regular basis?
▶ 1:43:05And how can we cross get this type of information to where if you're at sba, you may or may not have that available to you. If you're at social security, you probably could ask some detailed questions about, uh, working history, about doing other things. Do we need to expand or develop some way for agencies that take a new, um, perhaps a new request from a person?
▶ 1:43:35It could be about, uh, not va because you could ask about those questions, but about someone who's recently unemployed and asking about a depth of knowledge. How do we really help those agencies to make the determination, even when speaking to a person? Speaker 7: this is a great question, Mr. chairman.
▶ 1:43:55Um, and I agree with with your statement, I think, uh, and let me go back to my career as a sociology in the ohio state university, uh, first class, uh, in, in, uh, in, in the degree we were taught about the difference between gemeinschaft and gesellschaft community and society.
▶ 1:44:16The reason why I'm bringing this important distinction is that in the past, here in the united states or any other place, when we when you went into the bank or to the irs and asked for opening a new bank account or a loan or getting some governmental benefits, the guy sitting across from you knew who you were. He knew your family. He knew where you worked. He knew your history, so to speak. And so they were able to assess the risk you pose to the organization more effectively.
▶ 1:44:45Now, you know, we're at this point in a point of a society. We have a lot of people, um, living in this great country, uh, very difficult to assess in the same way we assessed in the past folks history. But, uh, fortunately, we do have solutions out there which will allow you to tackle the signals, uh, create and look at some historical signals around identities.
▶ 1:45:10So, um, if government is, um, willing to sort of, uh, use some of those solutions to try and assess the historical evidence around those individuals who need to be verified, then I think we'll be in a better place to sort of determine whether individuals are who they say they are, who they say they are, or they're completely different individuals stealing identities or using synthetic identities.
▶ 1:45:36Um, and in that sense, I just want to refer to the conversation we had earlier about the driver licenses and mdl. One of the things that we proved already, um, you know, during the last ten years or so is that pretty much everything could be faked. Uh, that I think will go also to the mdl. I mean, criminals will be able to find ways to use this technology to their benefit. What they will not be able to fake is the historical evidence.
▶ 1:46:05And that that goes as well to the ai solutions out there, right? I mean, ai will be able to give you an amazing picture of a person who does not exist, or ai will be able to take my face and bring it to life when I'm abroad, so to speak, and, and try and authenticate me when I'm trying to get unemployment benefits. But one thing that ai tools will not be able to do at this point is to create the historical signals around, uh, around me or around anyone who is trying to identify themselves.
▶ 1:46:32And I think that is where the solution lies, being able to find solutions which will allow us to look at historical evidence around individuals, around their name, date of birth, addresses, telephone numbers, and, uh, make assessment with respect to whether they are who they say they are. Speaker 1: uh, Mrs.
▶ 1:46:50Kane, uh, furthering this discussion, I had a chance to engage you also yesterday, and part a part of this was about the viewpoint that when there was a failure, meaning a person came through login.gov, provided information, but it was not what I would call successful. So there'd be a failure then.
▶ 1:47:19Evidently, it is not unusual for someone not as a challenge, but to ask for authentication of who they are to go to a post office. You had indicated that one of the things which you have engaged government agencies on, and perhaps g. A, is data and information back about what caused that failure. The. Was it a question we asked?
▶ 1:47:48Was it the picture? Was any number of facts and factors. Following up on doctor maimon, I, I you're the cyber security person also at g.
▶ 1:48:04A and you are aware of the power of technology, the power of these things that could be used to fool people, to give false positives to to do things.
▶ 1:48:19Do you see that in this process that we need to go go with new areas that would have some more depth to where you didn't fail off one or 2 or 3, you failed off five different questions because you were looking for them.
▶ 1:48:41How do we go and and ascertain when someone falls out, whether that was fraud, whether that was someone you were openly challenging and I see you later. And so they never went to the post office and to where we then learn what they did, how they did it, where they asked the question who they were. We could move them to the organization we talked about this morning to prac.
▶ 1:49:13Speaker 6: I think it's an important question because the people who are failing and are legitimately the person that they say they are, are going to keep trying because they want that government benefit that they're entitled to. Speaker 1: and they could go to a post. Speaker 6: office, right? They could go to the post office and go take their documents and verify who they are that way. But there's also barriers to that. So if you're in a rural area, your post office may be far, you may not have a reliable transportation there. There may be lots of barriers for you to do that. So it might not be that easy.
▶ 1:49:42So a lot of the agencies reported to us that they would like to have visibility into that authentication and why it failed. So they might be able to help that person on the end and say, well, yes, it was because the name that you put in was not the name that hud had on, or there was a letter transposed, or your new address was never updated. And hud's database. And there is a privacy principle called redress.
▶ 1:50:07You know, you are supposed to be able to get the most updated or whatever information and agency has on you, so you're able to correct it if it's wrong. That process can be easy. Or gao has reported that process can take very long for you to be able to update your information.
▶ 1:50:24So if that takes me months to years to get my address updated in a government database, I'm going to fail for that whole year on every government agency that I use login.gov to try to access, which is going to be a very big barrier for me to get any government benefits that I am eligible for.
▶ 1:50:43So that was something that many agencies brought up for us, and giving those agencies that ability to insight into that and to be able to say, hey, this is why you failed, you know, here's your options. And again, some of them may not even be able to go to a post office and have that secondary option available to them. But, you know, you're going to have to do that if you want your benefits.
▶ 1:51:05That was of one thing that was really helpful to them because some people would fraudsters would probably legitimately stop if they were not able to go somewhere and prove who they say they were. Nine times out of ten, they're stopped. They'll take their other synthetic identities and keep trying to get through. But they would stop probably with that fraud name and say, okay, look, I've got 300 others that I just paid $3 for. I'm going to keep pushing those.
▶ 1:51:27So I think the difference is you really need to think about the people who are really who they say they are, who are having that false positive, that they are going to keep trying. And they need that reason why so that they can go remedy that. So they can continue to be not be found ineligible for the benefits that they are legally entitled to. Speaker 1: interesting. Thank you, Mr. mfume. Speaker 3: thank you, Mr. chairman.
▶ 1:51:56It's been an interesting hearing, to say the very least. Um, one of the things that I hope comes out of these sort of interactions are ideas that would affect and change existing law and policy. And I know all of you in your work have come across items, matters and issues that you said if this were only changed or if this could be in place.
▶ 1:52:27So I want to come back to that in just a minute, and it'll be a quick minute too. But I want you to give some thought to that because as legislators, that's very important to all of us, no matter what side of the aisle we serve on, if we're trying to deal with an issue and a problem. And certainly, uh, this is one of them. Um. I want to, if I might, doctor maimon, go back to something you said earlier, and then I'll come back and we'll try to wrap this up on this side.
▶ 1:52:54Anyway, I'm interested in your work that you have been doing, tracking russian and chinese cyber networks and their ability to infiltrate this country. More importantly, their ability to take advantage of the citizens of the united states. It sounds like fascinating work, but I'm sure it's also leading you to some ideas about how we can do things better.
▶ 1:53:22What I really want to know, though, on this matter, the evidence that you are coming up with as you track these crime syndicates and cyber networks, whether they're russian or chinese, are you or your organization sharing th<u>%</u>t information with the director of national intelligence or sharing it with the fbi, or are they about doing what they do in their own silo, developing their own intelligence and not doing a comparative analysis of
▶ 1:53:53Both? Could you speak about that for a minute? Speaker 7: of course. Thank you so much for this question. Um, I do what I do in order to make sure that the american public is aware of what's going on there. And when I investigate, uh, my investigations usually result in publications. I put together white papers, I put together news articles and let the public know about what I find.
▶ 1:54:15Um, oftentime, uh, we will reach out to law enforcement, and then we'll simply give it to them, and then they need to make a decision with respect to whether they want to pursue investigation or not. I can tell you that in the past, we had very strong relationship as a professor in georgia state university with the department of homeland security. What we've done back then, that was during the pandemic time.
▶ 1:54:36We essentially, um, had a monthly meeting with local folks in dhs, and we simply talked, what is it that we find out there? What is it that the dhs did with that information? Obviously, I have no idea. Uh, because oftentimes what happens is that law enforcement take this information and do their own thing, so to speaking. And so I can tell you that I'm doing my best to make sure that everybody is aware of what I find out there, but I have limited visibility with respect to the actions folks take.
▶ 1:55:06Uh, once I put the information out there. Speaker 3: well, if I could be the devil's advocate, if I'm the director of national intelligence or the head of the fbi, I might say, well, he's never given that information to us. So you do you forward that to them. Are you in contact? Is there a liaison that shares the information so they can match it up with their own intelligence? Speaker 7: so in the past, what I was doing, essentially having a monthly meeting with the department of homeland security, um, that was during covid time.
▶ 1:55:36We had very strong relationship at the time, uh, where we essentially provided. Speaker 3: but I'm specifically speaking about the director of national intelligence and the federal bureau of investigation. Speaker 7: yeah. I do not have relationship with the fbi. I do not stand in touch with the fbi. I'm more than happy to be in touch with them and let them know about what I know.
▶ 1:55:59Speaker 3: yeah, because it seems like you've done an extensive amount of work, and I can appreciate white papers and editorials and that sort of thing, but everybody doesn't read. And if it's something so pertinent or hot or game changing, those two agencies more than anyone else, I think needs to know. So let's pray that they're listening. They obviously are. I hope that they would take advantage of the work that you've already done just to match it up against their own intelligence. Um, this is a very serious issue, as we all agree.
▶ 1:56:26And the more we can do to be effective, the better. And now I just want to come back to all of you, just very briefly, with respect to this notion about policy changes or about proposed legislative avenues to address some of the more glaring aspects of this, or maybe just to address things that right now are not getting any attention. I'm going to start with you, Mr. barris, and I'll end up with you, Mr. stanley.
▶ 1:56:54Speaker 5: thank you, ranking member, for the opportunity to address this item. You know, there were a number of recommendations that I provided as part of my testimony as far as where we could be pursuing policy levers. I actually will leave with one that wasn't in there. And it's really around mindset shift and culture. Um, and if you indulge me for just a moment, there were it shows you the depth of my nerd.
▶ 1:57:11Uh, it goes into, I was thinking actually back to the avengers movie, the last one with captain america and how, uh, there was like the darkest moment where they were basically up against an insurmountable threat, basically took all the avengers coming together at the same time out of nowhere in order to try to combat what they were seeing or what was about to happen. I think that generally, culturally has to change within the federal government in the sense that right now, when you're talking about who is fighting fraud within an agency or an organization, they're doing it siloed.
▶ 1:57:41They are doing it without sharing intelligence. They are doing it without having the types of conversations that need to happen. Um, so much so that fema could be having an existential fraud threat. And they're not talking to the sba, they're not talking to treasury, they're not talking to gsa even. And so there's an opportunity to basically culturally shift to say that we all have to get on the same page about what we are fighting against, uh, and then change that dynamic. So that way we can actually can take some of these more proactive measures that I've outlined in my testimony. Speaker 3: thank you very much.
▶ 1:58:10Um, I'm going to, I appreciate that I didn't see the movie, but I appreciate your context. Um, but I'm talking now about policy more so than mindset. Mindset is going to take a while, but if we can implement minor or major policy changes, that'll make a difference. Right now, miss cruz can. Speaker 6: I'll go for a big one, but I think we do need to revamp the federal privacy act. So the privacy act goes back to 1974.
▶ 1:58:37Gao has plugged many times in its reports that that was created way before policy and technology has updated, and we need to revisit that. But I also think that there is a great need for a consumer privacy law as well that starts at the federal level, but also allows states to have some input into it. Because of right now, there is no federal consumer privacy law, and it's a sort of framework of mismatched state laws, local laws.
▶ 1:59:07And, you know, there's nothing really governing at a higher level of what needs to be done. Speaker 3: thank you, doctor, about doctor marmo. I appreciate the extensive nature of your written remarks. I tried to get through all 20 pages. I don't know if I did or not, but thank you very much for that. Speaker 7: thank you so much. Um, uh, I think I think in terms of, uh, policy and I really appreciate this question because I see it at georgia state university in the school of policy.
▶ 1:59:36One of the things that I would strongly, strongly recommend is an evidence based approach. I think, um, you know, we're at a point in time where science has advanced dramatically. Uh, we have evidence based medicine, evidence based policing, um, all essentially suggest that in order to make decisions with respect to policy or the implementation of tools, what we need to do is essentially test what works and what doesn't. Unfortunately, we don't have that in the context of fraud.
▶ 2:00:04So I think if we're thinking about policies and policy changes, the first thing we need to sort of have in mind is a different state of mind, and that is of evidence based what works and what doesn't in the context of fraud prevention, uh, in the context of the government operation, we're in a very difficult position, I would say, because to be honest, we don't really know how much fraud we have. Uh, we have reports on improper payments, but we don't know how much fraud we have. Uh, on the government side, we hear numbers and very large numbers.
▶ 2:00:34So it's definitely an issue, but we need to be able to quantify how much fraud we have. And then after we quantify that number, we need to try and assess how to reduce that number to the minimum possible in order to make sure that taxpayers get their money's worth in terms of benefits, in terms of programs that they should have access to. So I think if we need to sort of have something in mind when we think about a policy change, then then it is approach to fighting fraud. Speaker 3: Mr. stanley.
▶ 2:01:03Could you turn your mic on, please? Speaker 8: so sorry about that. I would agree with miss cruz kayne, that strengthening the privacy act of 1974 is sorely needed, as well as overarching consumer privacy legislation.
▶ 2:01:20I believe that the us is the only advanced industrial oecd nation that doesn't have an overarching privacy law that sets baseline expectations for both individuals and businesses about what's fair and what's not, in terms of how people's information is treated.
▶ 2:01:35And then as as I've been arguing, I think that we need to set standards for digital driver's licenses in the states and other digital ids, um, that put in place, but put in place both, um, requirements for how they are built. Technically, they should have certain encryption, um, capabilities that protect privacy while still allowing for people to authenticate themselves.
▶ 2:02:01And there should be a, an envelope of legal protections around them, um, to make sure that they remain optional and not mandatory, for example, and to limit, um, overuse. Um, and so those would be the top of the top things that I think the congress should consider. Speaker 3: thank, thank you very much. I want to thank all of you. Mr. chairman, you may recall this idea of revamping the federal privacy act continues to come up. We did the last hearing. We did like this. That same thing came up.
▶ 2:02:31So I want to commit myself, and I'm sure, you know, you and I will get together on this and figure out how, in fact, we might be able to move forward with some joint legislation that at least starts to move the ball. Regarding the federal privacy act. It's been a long time, uh, since 1972, the world has changed. And the least we can do, I think, is to try to find a way to protect the privacy of americans by updating the federal policy that we have.
▶ 2:02:58Uh, and I want to commit myself to working with you in that regard, I yield back. Speaker 1: gentleman yields back his time. Um, did was that your closing statement also? Yes. The gentleman did make a closing statement. I too want to join in with my dear friend, Mr. infamy, and thank each of you for being here. This issue is not going to go away. The question is, are we serious enough to continue the search that to look for these things?
▶ 2:03:29And I thank all four of you have proven to us today that there is not just much ground to go, but there's much to learn. And I think both Mr. mfume and I need to provide some, perhaps guidance back to inspector generals, their attention to this, uh, to, uh, help gao to reinforce the things that they're after, to have the gsa follow up.
▶ 2:03:55I, I find myself in a position where I don't want to say that they're not paying attention. I think they're trying trying to do a number of things that are important. But Mr.
▶ 2:04:07Mfume and I find ourselves on the on this end of the, uh, trying to save the taxpayer, trying to understand that the people, whether it's one of my sons or it's one of his constituents that that need government benefits and government services to work properly, to be legally bound to, to recognize these things, but that we'll, we'll bleed ourself out.
▶ 2:04:35We can bleed ourself out by people who are outside the system, uh, causing us to, to completely miss the mark. So we're going to stay after this. Uh, we're going to make sure that we approach every single angle, uh, and challenge government to do that. We're, we've, we've, by and large decided, we do understand the prac, we do understand the importance of data.
▶ 2:05:02We do understand the need to make sure that it survives, uh, in perpetuity. Yeah, probably for a lot longer, uh, that we give it the, the authority and the responsibility to evolve itself to, to meet the emerging and new threats and to provide information back. Uh, but I want to thank you for your insistence that we will continue to work together. And I want to thank each of you.
▶ 2:05:28Um, so with that said, uh, without objection, all members have five legislative days within which to submit materials and additional written questions for the witnesses, which would be forwarded to the witnesses. If there is no such further business objection. Subcommittee stands adjourned.