A 20-year-long permanent cookie: America.gov and tracking
4 hours ago
- America.gov was launched as a single AI-powered federal gateway with a privacy promise of no advertising cookies, no third-party trackers, no chat history retention, and only approximate location use.
- An executive order requires America.gov to integrate Login.gov as its authentication service, positioning Login.gov as the reusable identity layer for government services.
- Login.gov's source code added an 'nds_experiment_uuid' cookie with a 20-year expiration that generates a persistent browser identifier before authentication, used for a National Design Studio experiment and attached to analytics events.
- Privacy concerns arise because the identifier persists even after users opt out of the experiment, is created on public endpoints, and lacks a documented privacy assessment covering its use and data retention.
- The identifier raises questions about how analytics records are associated with the UUID, whether they can be linked to authenticated users or agencies, and how long such data is kept.
- Future phases of America.gov will allow applying for benefits, passports, and interacting with multiple agencies, increasing the risk of creating a durable record of user interactions.