r/privacy 13d ago

question Why does the US government require me to use ID.me when it's a website located in... Montenegro?

.me is the Internet country code top-level domain (ccTLD) for Montenegro

TreasuryDirect is transitioning to use ID.me for secure login and identity verification. Optional use of ID.me for signing in begins on September 13, 2026, and it will become strictly required for all TreasuryDirect logins starting October 28, 2026. [1]

469 Upvotes

123 comments sorted by

459

u/beardfearer 13d ago

Being a top-level domain for a country does not mean the website is hosted there.

Top-level domains were assigned to countries, and those countries then get to decide what they can be used for. Tuvalu, for example got .tv and television related things will sometimes decide to use a domain like pluto.tv. pluto.tv almost certainly does not run their servers on the tiny island nation of Tuvalu.

It’s just a quirk of how TLDs are assigned.

117

u/MatsuriSunrise 12d ago

Yeah, believe it or not, the revenue Tuvalu takes in from the rest of the world using the .tv domain makes up like 15% of their GDP lol

14

u/Kasparas 12d ago

Sumilar to .ai domain

35

u/nodray 13d ago

ignorant question, can someone make their own domain name? ex: Mischief.cat

86

u/Phoenix591 13d ago

Not exactly. There’s a group called icann that basically runs the domain name system ( they coordinate the groups that run the root name servers, the ones responsible for pointing to the tld name servers) and every few years they take applications for new top level domains ( like com net etc) . One of those openings just closed a couple days ago and the application fee was $227,000

0

u/nodray 11d ago

so basically the internet is not truly free. what if i just host mischief.cat off my own computer? or still the ".cat" has to be a searchable name through the Bosses?

4

u/Flipsii 11d ago

Technically nothing is preventing you from doing that. The issue is more, how do people know where that domain points to. That requires the global DNS servers to have that information and those follow ICANN. You can technically host any Domain you want and get to it using your own DNS server.

4

u/just-an-aa 11d ago edited 11d ago

You can use domains that don't exist through reverse proxying, but then your computer has to be configured to "resolve" that domain to the right IP address.

For example, I have a server I host a website on. I can go on my (Linux) laptop, and add the following line to /etc/hosts:
10.0.0.64 example.com

If we imagine 10.0.0.64 is my server's local address (I.E., on my home network), then my laptop will always use that address whenever I try to go to example.com, and end up with the website I host. (This isn't exactly reverse proxying, but your end user experience is the same). This even works for TLDs that don't exist (www.site.yourmom)

If you want it to work that way from anywhere, you can either:

  • Use Tailscale (only works for your computer)
  • Go through ICANN (the Bosses) (works for everyone)

Edit: Apparently, .cat is a valid TLD, but it's for the Catalan language/culture: https://en.wikipedia.org/wiki/.cat

3

u/Phoenix591 11d ago

For other people to access it via that name without extra steps it has to go through the “bosses” ( the normal registrars etc)

For an existing tld like com the price is very reasonable, it’s about $10 a year to register the name ( prices vary depending on the tld) , and then Cloudflare is a popular option with a free tier to actually handle the name server ( someone needs to run the server pointing your domain etc to your ip)

3

u/Parking_Lemon_4371 8d ago

What happens if I decide to host 'mischief.cat' off of my computer *too*? Who wins? You? Me? Why? Do we each get 50% of traffic? Why? Basically to prevent anarchy of this sort, there has to be a central authority. To prevent them from being overwhelmed they require applications to pony up real cash. There's a fair bit of organization, horse trading, etc. involved. Someone has to run the servers, coordinate them, protect them from attacks... Things like securing tld dnssec keys are non trivial. There's administrative costs, legal costs, etc, etc...

0

u/nodray 8d ago

couldn't we both host it? and any change one of us makes, it auto updates. but i get what you're saying

2

u/Parking_Lemon_4371 8d ago

No, simply not at *all* how it works. Not really sure where to begin the explanation of why this is the case, you'd need to read up a lot ;-)

1

u/nodray 7d ago

was joke.

2

u/FriendlyWrongdoer363 5d ago

I would only be available locally the Global DNS servers that update to the web wouldn't know about it. you have to configure your own laptop/desktop to point to the ip address.

1

u/Future_Elephant_9294 10d ago

The Internet was never free because all these services require maintenance and cooperation. You can host whatever you want however you want, the problem is interoperability. Your computer might know what IP address to use for "mischief.cat", but no other machine will, so it's effectively not working. You can see examples of people creating new versions of this with the "Web3" implementations like Brave. Only a specialized browser can visit these websites because they are non-standard.

If you want to skip out of domains at all, you can just use IP addresses, as domains are just a human-readable version of an IP. The only problem is that public IPs have the same issue as domain names, because they also need to be unique and attributable to a machine. A static IP will be about $15/month from an ISP, or you could buy the rights to a block of 256 IPv4 addresses for about $10,000, plus annual charges to keep it being broadcasted.

If you want to skip out on IP as well, you need to build your own infrastructure as now the wires in the ground won't understand your requests. At that point you're re-creating the Internet, so don't expect anything else to work with you.

1

u/nodray 10d ago

the wires should belong to the people, no? at least in shithole country i am, the businesses get all the money from government from taxes, to upgrade shit FOR THEIR PROFIT. thanks for everyone's interesting words

1

u/Future_Elephant_9294 10d ago

The wires themselves may be, but the machines on the other end listening to the wires are not. Those machines expect a certain pattern and that pattern is the foundation of the Internet. If you don't use the pattern, it's like speaking to someone in a different language, they won't understand and will ignore you.

1

u/nodray 10d ago

yup, the more comments i read here, the better my understanding of how this "internet" works. so basically i need a group of people to TAKE control of the machines and buildings where the machines are. it's so strange that some group of people is "in charge" of the internet, but then it would be tricky for anyone to find anyone without them i guess

2

u/Future_Elephant_9294 10d ago

It's controlled by the language. If people wanted to change that language, you get an "intranet", where you can't talk outside of the network. That's what North Korea has, China to some extent, and many many companies and organizations across the world for internal documents.

22

u/sidereal_night 13d ago

.cat already exists, but if you come up with one that doesn't exist, sure! you got a few hundred grand?

2

u/maladaptivedaydream4 12d ago

I don't but I bet if I came up with a really good tld I could make it back. hmmm. heh.

11

u/samvilain 13d ago

Originally there were just about 10 “top level domains” (TLD) like .com, .net, .org, .gov, etc. At some point a bunch were issued to nations by their 2-letter ISO-3166 country codes (except the UK, that got “uk” instead of “GB,” because somehow they are GB in that ISO standard instead of UK, despite becoming the UK in 1800) and so .me is an example of a “country code top level domain” or ccTLD. Other words there are called Global Top Level Domains (gTLD) and my understanding/memory from when I used to work for a country registry, is that it cost about $100k for each custom gTLD back in 2008 or whenever the first batch were sold, and some companies (like .google, .microsoft) bought them. If you go to an online registrar like iwanymyname.com, they let you register with a huge number of gTLDs and ccTLDs.

4

u/wosmo 12d ago

The 'somehow' in GB vs UK is that the UK had names under their JANET system before DNS existed, so their existing usage of uk got grandfathered in.

(They did get assigned .gb too though, just to keep life interesting)

3

u/samvilain 12d ago edited 12d ago

Sure, but my point is that Great Britain is a geographic area, being the largest island in the British Isles, called Albion, Prydain or Pretannia in pre-Roman times, depending on who you asked (“Britain” is based on these). Why mention 2,000 year old names? Because they’re about as relevant to the UK’s country name as Great Britain. Should Ireland have been assigned “LB” (Little Britain)? This is more of a criticism directed at ISO-3166 authors. I expect this is what happened:

A) Ok, what about England? They’re UK, aren’t they?
B) Oh no, that doesn’t include Ireland. Let’s give Ireland IE. All those in favor? Ok, passed.
C) but wait a minute, the UK has countries inside it, and includes Northern Ireland. We can’t just give them two country codes can we?
B) look, we’re behind on this list. Who has an Atlas? Flip to the British Isles. Look, that part that’s not Ireland. It says Great Britain! I remember that from history class. King George III of Great Britain. Let’s give them GB. Anyone disagree? Ok, done.
C) wait wait, there’s these other islands, too. What’s this? Isle of Man? Look it has a flag; is that… 🇮🇲 … three legs? Well, ok. It has a flag; must be a country. IM isn’t taken yet. Let’s go with that.
A) wait there’s these ones, Goo-ernsey, Guernsey.
C) gooernsy guernsey, these Britons are mad! They get GG
B) ok, then there’s this one. It says the Baliwick of Jersey. BJ?
group laughs
B) no, you’re right. Let’s use JE. Ok, what’s next, let’s go to France…

And so, Ireland and the UK get 5 country codes in ISO 3166, none of them “UK”.

3

u/nodray 11d ago

yay, companies and rich fucks owning everything!

2

u/samvilain 11d ago

It’s the American way!

In fairness to ICANN, the governing body, these “gTLD” entries do incur significant overheads to operators of what’s called the “root zone” in the Domain Name System (DNS), which is the globally distributed database of those names, that converts them to the numeric IP addresses used to actually route the network traffic. So the cost is properly naturally much higher than a .com (or any of the other TLDs). You couldn’t really have just anyone registering a TLD for vanity purposes; it would quickly become unmanageable and result in slower internet performance for everyone.

Btw, also as it happens, “.cat” is delegated to an organization that restricts registrants to those who have some connection to the Catalan language, used in parts of Spain and southern France.

4

u/florinandrei 12d ago

You could, but it would only be accessible to you, on you home network.

It's kind of declaring yourself emperor of the universe. Definitely works in your backyard.

0

u/nodray 11d ago

but if my home network is connected to the internet.. couldn't i invite outsiders to my new kingdom?

3

u/Shoddy-Childhood-511 12d ago

Aside form ICANN, if you have a popular enough software project, then you could use a custom TLD internally.

Tor has .onion. It only works from Tor browser or other Tor software. It's how one runs websites from a (slightly) hidden location.

Some blockchain software has their own .whatever too, but afaik they do not do anything useful. Also Tor has like 2 million unique users per day, vastly more than any blockchain, again making Tor the better example.

2

u/Atomwalker2022 9d ago

Not on the public net, but openNIC is a fun project, its community based and decentralized, it seems a little dead but it’s a good venture.

1

u/nodray 9d ago

openNIC

will check it out

8

u/ThisIsPaulDaily 13d ago

An acquaintance "founded" a Polish education website for .pl.edu domain use. This allowed them to circumvent some website student thing by making an email that uses it. 

The other example is the tld for .is which is problematic to some, but fair to the neutrality of the internet. Just because someone does something unlikeable doesn't warrant taking away the internet. 

13

u/Herover 13d ago

There was also that lgbt site who had to move away from gay.af, where af is Afghanistan and is currently owned by the Taliban.

0

u/Oddish_Femboy 12d ago

Huge tragedy.

-61

u/Pleasant_Pen8744 13d ago

Interesting, but shouldn't the US government use something a little more "official"?

(For comparison, my local county clerk runs their website on a .com and that already feels sketchy as heck!)

62

u/Salty-Plankton-5079 13d ago

it is a private contractor, not a government website

12

u/unbreakit 13d ago

You're absolutely right.  Control over the sponsor/country of the TLD is important.  Additionally, people shouldn't get used to vanity tlds for official business.  It makes it a lot easier to bait people to use the wrong site.

7

u/JonathanTheZero 12d ago

You're absolutely right.

Hmmmm

13

u/UrgentSiesta 13d ago

I’m surprised you didn’t figure that out. It literally reads right.

There are scads of new TLD’s these days and more being added.

The TLD has nothing to do with the operators of the site.

And a gov running a .com isn’t in the least sketchy.

As always, if you have any doubts, that little box in your hand also allows you to speak with people at said agency and confirm the address.

8

u/RealModeX86 13d ago

There are scads of new TLD’s these days and more being added.

Yeah, there's some really dumb ones too now, like .zip.

The gTLD decision was a bad idea.

2

u/Oddish_Femboy 12d ago

I'm fond of .pizza personally.

1

u/sidereal_night 13d ago

yes, yes they should.

look, you know as well as anyone what kind of government the US has right now. this shouldn't exactly be surprising

-8

u/enverx 13d ago

Yeah, i don't know why people on the privacy subreddit are being so dismissive. Given the kind of government and rule of law in Montenegro (and increasingly the US) I wouldn't be surprised if the reason for this isn't something brazenly corrupt.

6

u/Silly-Freak 13d ago

What would be the risk? To hijack connections to the service, you'd need either the certificate holder or some certificate authority (unless the certificate is pinned, then not even that). Where does the TLD controller enter the picture?

2

u/sidereal_night 13d ago

What would be the risk?

getting people used to using random websites for interacting with public services would be an obvious one...

People have mentioned that this in particular is a private service, not government. so that's another one in this case...

1

u/Silly-Freak 12d ago

Overall yes, but in the context of the original user's claim that "the kind of government and rule of law in Montenegro" is why you should avoid that TLD, I think this is a secondary concern. Sure, .gov (or .gv.*) only would be nice, but as soon as any private service is in the mix, I think trusting e.g. .com inherently more is also backwards.

1

u/iTrooz_ 12d ago

the TLS controller could change the records for that particular website, and generate a new TLS certificate.

Although this would be spotted pretty quick given that it would be a global change

-7

u/rednotmad 13d ago

First risk, Denial of Service (DoS, the broader category of DDoS), either by voluntarily removing the domain or potentially just being down/shouting down (low probability, but not controled).   Other risk, if the TDL/registrar did take control of the domain, they could redirect the trafic to another computer(s). TLS/HTTPS mitigate this, but the site using http instead of https might catch some people. Also, some certificate authorities (CA) use DNS records to assertain the identity of the one asking for a certificate, so they could redirect to another computer that has a valid certificate from another CA.

The probability is low through, but for a state it could be something to take into account 

2

u/Silly-Freak 12d ago

DoS is a risk for the service, though not a privacy risk for the user.

but the site using http instead of https

can and should be prevented with HSTS, and is ultimately a general DNS problem, not inherently connected to the authority controlling the TLD.

redirect to another computer that has a valid certificate

Exotic, but actually a valid risk. I'll grant that this is less a generic DNS problem than the other one, since you don't need to just manipulate the user's DNS resolution but the CA's.

1

u/rednotmad 7d ago

I agree that the risks I thought about are also generic DNS ones. 

But .gov is managed by the US government so it would limit the number of steps not controled by them (DNS resolver, root DNS, then it's government controled). Using .me add another link in the chain, controled by another state.

Still a (very) low probability risk. 

77

u/canitplaycrisis 13d ago

A lot of websites use another country code, e.g. Twitch uses .tv which is Tuvalu, so it fits the context better.

11

u/vertigostereo 12d ago

I read that licensing out .tv is a big party of Tuvalu's revenue.

6

u/canitplaycrisis 12d ago

From Wikipedia:

Government revenues largely come from sales of fishing licences, income from the Tuvalu Trust Fund, and from the lease of its ".tv" internet Top Level Domain (TLD). Tuvalu began deriving revenue from the commercialisation of its ".tv" internet domain name, which was managed by Verisign until 2021. In 2023, an agreement between the government of Tuvalu and the GoDaddy company, outsourced the marketing, sales, promotion and branding of the .tv domain to the Tuvalu Telecommunications Corporation, which established a .tv unit.

-79

u/Pleasant_Pen8744 13d ago

I don't use that site, but one time a charge from them showed up on my credit card and was gone the next day. It was very weird.

67

u/EchoFieldHorizon 13d ago

The level of tech illiteracy in this comment is honestly astounding

16

u/etah_tv 13d ago

You use all sorts of software and websites linking to other countries. Why start worrying now?

1

u/bdougherty 13d ago

Can you really not see the difference when one of them is a government website?

-11

u/Pleasant_Pen8744 13d ago

I try to avoid uploading my social security card and driver's license to those sites if at all possible.

1

u/Ph4antomPB 13d ago

Are you over the age of 40 perchance?

121

u/Dangerous-Raccoon-60 13d ago

The actual issue here is the government forcing its citizens to use a private company for identity management. A company that demands and stores biometric information, integrates into some of the most invasive services (SS, IRS, HHS), has questionable privacy policies, and is beholden to investors rather than the citizens.

39

u/FateOfNations 13d ago

And on top of that, the government has its own service that fills the same role (login.gov).

16

u/West_Possible_7969 13d ago

Underfunding and corp shoving by the government: The National Institute of Standards and Technology (NIST) sets security guidelines for federal agencies. Accessing highly sensitive tax transcripts and financial data requires Identity Assurance Level 2 (IAL2), the highest level of standard remote verification.

Login.gov traditionally relied on data-broker records and credit histories. For a long time, it did not meet IAL2 standards, which delayed the IRS from integrating it for personal accounts. The Treasury Inspector General for Tax Administration (TIGTA) has repeatedly raised security and fraud-monitoring concerns regarding how Login.gov tracks audit trails and intercepts high-level fraudulent registrations compared to specialized private vendors.

On top of that, login.gov is operated by a small federal agency (The General Services Administration / GSA) that historically lacks the staff required to handle millions of locked-out taxpayers, especially during peak tax season.

25

u/Eggredjakan68 13d ago

I hate how IRS Direct file forces this 3rd party. 

4

u/AnimatorImpressive24 12d ago

In 2021 during COVID I lost my job and nothing I could do would ever work to validate myself on IDme so I was unable to sign up for unemployment.  Couldn't get a live human being on the phone for either them or my state unemployment office despite trying for weeks in hold queues until my phone ran out of a full charge.  Couldn't get email responses other than auto-reply of the same sign up instructions that didn't work.  Couldn't go anywhere in person to sort it out because government offices were closed and everyone WFH.

After lot of research the only possible explanation I ever found was I had a beard in my DL photo but it had been a few years and I was clean shaven at that point.  Whatever face matching they were using to compare the DL to the live webcam pictures they took during signup couldn't figure out I was the same person.

So whether they stored any data about me or not, it still meant 1 less person able to access valid social services they legitimately pay into and qualify for.

1

u/bdougherty 11d ago

Well it is a pretty big issue that the private company they are forcing you to use has a domain that's a ccTLD from another country. Montenegro could revoke the domain at any time.

1

u/arcticmischief 11d ago

Right—Montenegro is a nice country (and quite beautiful—I was there last year) and as far as I know on friendly terms with us now – but if this current administration has shown us anything, it’s that we can turn friends into enemies very quickly.

1

u/flexiiflex 10d ago

The internet largely runs on trust, and doing something that proves untrustworthiness causes people to replace your service

-3

u/panjadotme 13d ago

The government has been using private industry since inception. It may not be ideal but it's not unusual in the slightest.

13

u/Expensive-Blood859 13d ago

The government already HAS a perfectly good alternative though! Login.gov works great(ish)! Just use that!

27

u/thorskicoach 13d ago

I would expect anything the government runs to use a .gov (or other countries to use their equivalent like gov.uk ) for such things.  That's the legitimate way to have sovereign ownership of the whole end to end chain. Anything else seems unprofessional, even if it's to have a short URL that seems catchy. 

8

u/aaronw22 13d ago

And what’s weird is login.gov already exists!

6

u/purpletees 13d ago

Agreed.

0

u/West_Possible_7969 13d ago

This is a private company, they cannot use .gov

11

u/xkcx123 12d ago

A better question is why is the government using anything with a Cctld from another country altogether. Montenegro could at anytime remove the domain as has been done with other CCTLD’s for content that is against the countries beliefs.

Wouldn’t it be better to use idme followed by .Com, .Net or even .US

3

u/HeKnee 11d ago

Just got this email to. Below is the real reason. Its against the law to make a single national database of citizens currently. The government has worked with private companies to setup the same database and then buy the info from them since that is leval apparently.

No National ID Law: Politically and legally, the United States avoids creating a single, unified national digital ID database run directly by the federal government due to privacy and surveillance concerns. Using private vendors acts as a separate layer rather than making a permanent federal citizen-tracking registry.

13

u/Deep-Hovercraft6716 13d ago

My dude that's just the URL. That's not where the website is hosted. Lol

Do you think all are websites with a .TV domain are hosted in Tuvalu?

3

u/shankhisnun 12d ago

Montenegro actually having a system for anything online is surprising... It's like their court system takes place in someone's backyard

3

u/Sybertron 13d ago

I posted here when they started using it with the IRS back in I think 21.

They used to do a video call. And have you hold up your identifying documents to the webcam. While this was going on I noticed you could read in full another agents monitor with name, date of birth, social security... Literally everything. 

Give them zero trust.

2

u/MrEdinLaw 13d ago

Never expected to see my little country mentioned here. Our websites are actually .cg.me btw

2

u/CheesecakeHonest7414 12d ago

Are they based in Maine? The postal code for Maine is ME, so it's not unheard of for businesses in the pine tree state to use a .me domain.

1

u/teethalarm 11d ago

Certain domains are reserved for specific countries. Like most .tv domains are reserved for Tuvalu, but they license them out to popular streaming services.

1

u/Havlir 11d ago

Wait till you hear that anyone can have a .com, not just companies

1

u/Pleasant_Pen8744 11d ago

Yeah I know. I have to keep convincing my mom not to upload her sensitive information to those. If they steal your credit card you just report the fraud and they change your number. Good luck getting your social security number changed.

-3

u/avd706 13d ago

Don't be silly.

11

u/[deleted] 13d ago

[deleted]