A new federal gateway, America.gov, is being rolled out as an AI-driven single entry point to federal information and services and is explicitly paired with Login.gov as its authentication layer. The portal’s public privacy materials promise no advertising cookies or third-party trackers, no retained chat histories, and only approximate location use, and an executive order directs the General Services Administration to integrate Login.gov and connect agency services and APIs. That integration positions America.gov as the visible presentation and transaction surface while Login.gov becomes the reusable identity and sign‑in infrastructure for multiple agencies, including planned passport and benefits workflows.
Login.gov’s public source code, however, includes recently merged National Design Studio (NDS) experiment code that creates an nds_experiment_uuid cookie as a before_action in the base controller, generating a UUID on first page load and storing it with Ruby on Rails’ cookies.permanent mechanism (documented to expire in 20 years). The UUID determines A/B interface assignment, records opt-outs, and was added to analytics events. The identifier can be created before authentication, persists after opt-out, and is attached to analytics, prompting open GitHub questions about why it’s issued at zero-percent rollout, why it lasts two decades, what privacy assessment covers it, how long analytics records persist, and whether authentication or agency context could be correlated with it - risks that gain weight as America.gov moves toward authenticated transactions.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.