Bay Street Wire
Tech & BusinessOpinion

The Twenty-Year Tether: How the Government's New AI Portal Betrays Its Own Privacy Pledge

Portrait of Sam Whitfield
Sam Whitfieldtelecom & connectivityOct 2AI
The Twenty-Year Tether: How the Government's New AI Portal Betrays Its Own Privacy Pledge

AI-generated image · Bay Street Wire

While the Trump administration markets America.gov as a privacy-preserving gateway, hidden code in the Login.gov authentication layer reveals a persistent tracking identifier designed to last two decades.

### Opinion: The Surveillance State is No Longer Just a Corporate Monopoly

For years, I have sounded the alarm on the Big 3 telecom giants and their appetite for our data. We have grown accustomed to the corporate surveillance economy—the feeling that every click is logged, every movement mapped, and every preference sold to the highest bidder. But there is a fundamental difference between a private corporation chasing profit and a sovereign government managing the rights of its citizens. When the state adopts the tactics of a data broker, it isn't just a breach of privacy; it is a breach of trust.

The recent launch of America.gov is a masterclass in this kind of hypocrisy. As Biometrics News first reported, the Trump administration is presenting a shiny, AI-powered gateway to federal services wrapped in an unusually explicit privacy promise. But beneath the presentation layer lies a rotting foundation of surveillance logic that should terrify anyone who believes the government should be a steward of public trust, not a silent partner in the tracking industry.

### The Great Privacy Pretense

According to reporting from Biometrics News, America.gov was launched as a single digital point of entry for federal information and services. The administration has gone out of its way to signal its commitment to privacy. The portal's own materials claim it eschews third-party trackers and advertising cookies, avoids retaining chat history, and relies on approximate location data rather than precise GPS coordinates.

President Donald Trump further solidified this image via an executive order signed on Tuesday, which directs the General Services Administration (GSA) to integrate Login.gov as the authentication service for America.gov. The order explicitly mandates that these integrations occur in a "secure and privacy-preserving manner" and stipulates that no one other than an originating agency may access an individual's records unless permitted by law or the Privacy Act.

It is a comforting narrative. It suggests a government that understands the modern digital landscape and is taking active steps to shield its citizens from the predatory data practices of the private sector. But as any tech columnist worth their salt knows, the marketing copy is where the lies live. To find the truth, you have to look at the code.

### The Twenty-Year Cookie

As Biometrics News reports, the reality is hidden in the public source code of Login.gov, the reusable identity and authentication layer that powers the federal gateway. On September 4, Login.gov merged code for a "look and feel" experiment conducted by the National Design Studio (NDS). This update introduced a function called `nds_experiment_uuid` into the base application controller.

Here is how the mechanism works: the system checks for an existing `nds_experiment_uuid` cookie. In the absence of one, the system creates a random universally unique identifier (UUID) and saves it. The method used for this storage is Ruby on Rails’ `cookies.permanent` cookie jar.

For those not steeped in development, the implications are staggering. As Biometrics News notes, the framework's documentation states that the `cookies.permanent` setting assigns an expiration date of 20 years.

Twenty years.

This isn't a session cookie that expires when you close your browser. This isn't a short-term identifier used to remember your language preference for a week. This is a persistent, pseudonymous identifier designed to tether a browser to a specific ID for two decades.

### Analytics and the Illusion of Choice

If this were merely about testing which button color users prefer, it might be an overreach, but it wouldn't be a scandal. The real horror emerges on September 9, when Login.gov merged a second change. This update attached the `nds_experiment_uuid` to the attributes of analytics events generated by the service.

Because this function is placed in the base application controller, the identifier is generated before a user even signs in. Biometrics News reports that the code's own tests confirm the UUID is stored on the very first page load, regardless of whether the visitor is assigned the NDS design or the legacy interface.

This means the government is creating a persistent tracking ID for visitors before they have even authenticated their identity. Once this ID is linked to analytics events, the privacy implications explode. We are left wondering what other attributes are being associated with this ID, how long those records are kept, and whether the government is correlating this persistent ID with specific agency contexts or authenticated identities.

To make matters worse, the government has provided a hollow "opt-out" mechanism. A change merged on September 21 allows users to switch back to the legacy design. While this process deletes a `ui_test_bucket` cookie, it explicitly does not delete the `nds_experiment_uuid`. Instead, the system simply records the opt-out using that very same 20-year identifier as the discriminator.

In other words, you can opt out of the *interface*, but you cannot opt out of the *tracking*. The UUID continues to attach to analytics events even after a user has explicitly rejected the experiment.

### A Wake-Up Call

The most damning part of this saga is the silence from the architects. Biometrics News reports that an open GitHub issue filed on September 12 asked why this identifier is generated even when the NDS experiment is at a zero-percent rollout, why it exists on public endpoints, and whether a 20-year lifetime was intentional. The issue also questioned what privacy assessment covers the cookie and the resulting analytics records.

As of the reporting, that issue remains open.

There may be a technical justification for this. Developers often need to track returning browsers to calculate statistics. But there is no legitimate engineering reason why a "look and feel" experiment requires a two-decade tracking window.

This is the same playbook used by the Big 3 and the Silicon Valley giants: build the surveillance apparatus first, hide it in the technical weeds, and offer a "privacy pledge" as a distraction. When our public institutions adopt these behaviors, they aren't just failing at IT—they are signaling that they view the citizenry as data points to be harvested rather than people to be served.

If the government is willing to bake twenty-year tracking cookies into its primary digital gateway, we can no longer trust their "privacy-preserving" promises. The surveillance economy has officially moved into the halls of government, and it has brought a twenty-year lease with it.

Sources

More from Sam Whitfield