18 ms·
We have 4 days to contest KYC being required by internet services
- chadsix 2y agoSubmission Statement: We have exactly 4 days to leave comments to the Federal Government of the United States of America contesting the requirement of KYC by internet service providers. This law is not conducive to a free internet/society.
- plus 2y agoI ask this 100% genuinely, since this isn't a subject I've ever given any mind to. Why should we oppose this? What are the potential negative outcomes if this goes through? Can you steelman the argument for why people support this, and explain why you find the arguments unconvincing?
- Takennickname 2y agoProvides the prerequisites for an authoritarian regime when they inevitable coopt the internet
- IfOnlyYouKnew 2y agoWell some authoritarian regime would otherwise just do it whenever it got started, and it would require maybe a week?
- Takennickname 2y agoMaybe this is what's happening right now
- mistrial9 2y agowhy recreate this important argument with coffee? The Berkman Center at Harvard or one hundred other places has decades of written policy work and case studies on these topics ..
- plus 2y agoI would also find a link to those arguments to be satisfactory.
- tomalpha 2y agoI too would have asked the same question as GP, and also meant it genuinely. It feels like HN is a place where someone could summarise the (presumably strong) arguments against this? Or links to a good source as suggested by a sibling comment.
- CalRobert 2y agoI think that the biggest argument in favour is that it would remove anonymity on the internet, at least from governments, and that could enable law enforcement to more easily find people committing real crimes. CSAM, scams, etc. I think the biggest argument against it is that this removes anonymity on the internet, at least from governments, and that would remove people's ability to freely voice their opinions without fears of repercussions (will the first amendment ever be modified? Will people who discuss what it's like to be an illegal immigrant/drug user/etc. be persecuted)? Also, it raises the question of what happens to users of VPN's, public internet, etc.
- ameister14 2y agoDoes this actually remove anonymity on the internet? It seems to de-anonymize a set of IaaS customers, sure; but that's not nearly the same thing as removing anonymity completely. I've only just scanned this but it seems at first glance to mean that a foreign company can't anonymously spin up an AWS instance, that's all. Am I reading this incorrectly?
- generalizations 2y agoIt establishes the principle, so that later it can be expanded by degrees. The trick is to oppose the principle so that it can't be expanded later.
- kjkjadksj 2y agoThis can’t be the only way to de anonymize an internet user today
- RAM-bunctious 2y agoA set? Only US customers are unaffected, i.e. 96% of the planet would no longer be able to use AWS (or anything similar based in the US, all the way down to simple web hosting or e-mail services) without going through KYC. There are so many things that can fall under the IaaS bracket. Think anything 'cloud'. Maybe that's not how they'll apply it, but legally they are free to do so. It's a huge reach.
- chadsix 2y agoIt is great that you ask a question, because we live in a world with the freedom to opine on things. What could be considered a massive issue to me may not be a massive issue to another; and if we feel the world will be better by debating our positions, we have the right to do so. Today, anonymity and pseudonymity exist and allow people to speak freely without risk of backlash for having a different opinion as often times the right opinion may differ with that of social consensus. If KYC is introduced, the ability to maintain freedom of speech, online, will likely diminish. This is of negative consequence to the people of the world. Further, with internet 'forever data', LLM NLP and so forth, character profiles are too easy to develop for people which can cause further harm as we begin segregating based on said profiles. I believe this KYC requirement can even extend to blockchain node operators and so forth as well. These are just a few reasons but there are many more.
- EGG_CREAM 2y agoThis doesn't seem to affect users of internet services, though. It's just IaaS, so things like AWS. With that limited scope, what is the adverse affect of KYC laws on freedom of speech?
- zamubafoo 2y agoHow much longer before IaaS platforms require their customers to also have similar KYC policies in their ToS to be able to shift liability downward in case anything goes down?
- carl_dr 2y agoThis law already includes platforms that resell IaaS. So about 4 days.
- chlodwig 2y agoIt affects all web hosts, so if you want to lease a server in order to install Wordpress or Mastodon you would need to submit your identification to the provider.
- switch007 2y agoIt's on the parties sponsoring and proposing the law to rigorously explain the benefits (and to discuss any negatives). Maybe go ask them?
- chlodwig 2y agoThis would make it illegal to anonymously run your own Wordpress install or Mattermost/groupchat server, you would have to reveal your identity to the web host. Do you trust the powers-that-be to never use this information to find and punish dissidents?
- yamazakiwi 2y agoOne example I've seen is a less-than-savory company make a purposefully confusing KYC process after purchase of their service/product to prevent users from realizing they're being scammed and are kept in KYC hell hoping to get verified when they never will. Time to start an ISP...
- webspinner 2y agoI know for me I'll have to stop using the internet. I can't take any chances. I can't upload government Ids everywhere I go, especially if the systems are not accessible with screen readers.
- drakythe 2y agoThis is not about Internet Service Providers. This is about Infrastructure as a Service providers, e.g. AWS, Linode, Azure, GoDaddy, etc. See https://www.federalregister.gov/d/2024-01580/p-46 https://www.federalregister.gov/d/2024-01580/p-46 for their definition. Misrepresenting what this is about is not helpful.
- spxneo 2y agoim not sure i understand are customers of AWS/Linode/Digitalocean now required to submit passport/drivers license to host a blog or website?
- Sleepful 2y agoThis is my question too. IDGI. If I am a foreigner how do they verify that my ID is real? just because it looks "real enough"? This discriminates people from other countries from having tech resources, possibly increasing poverty by limiting opportunities, at the same time it exposes people to have their data leaked. I don't see how this is a good idea.
- webspinner 2y agoYes please do! I did.
- CalRobert 2y agoI suppose VPN's will become illegal next?
- deleted 2y ago[deleted]
- webdoodle 2y agoThose in authority don't want us sharing information with anyone they can't track. So many of the websites I use are already blocking VPN access, and it's only getting worse. Codifying it as law will just be the last step to protect the censors from prosecution for violating the 1st Amendment.
- systemvoltage 2y agoUnconstitutional.
- freeone3000 2y agoIs it? How? Which bit of KYC for SaaS violates which right?
- kolanos 2y agoIsn't this a clear violation of the 4th amendment? > “The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no Warrants shall issue, but upon probable cause, supported by Oath or affirmation, and particularly describing the place to be searched, and the persons or things ... Note it says "the people" and not "citizens of the United States". Everyone has this protection within U.S. borders, SCOTUS has ruled to this effect. So the government forcing yet more private companies to do their unconstitutional bidding seems like something that should b opposed. I believe banks being required to collect KYC came about through The Patriot Act. If this trend continues, you'll need to verify your identity to use any service.
- freeone3000 2y agoThat isn’t just a trend, that’s actually this proposed rule change! Banks collecting KYC actually started with the Banking Secrecy Act of 1970. This was tried in the Supreme Court case California Bankers Association v Schultz (1974). It holds that recordkeeping requirements do not constitute a privacy violation under the 4th amendment absent reporting requirements. Since this new rule (2024) applies only to foreign entities and OFAC controls provide penalties for domestic companies, there’s no fifth amendment issue either (which is a shame imo, the 5th amendment argument in Bankers v Schultz seems incredibly shaky). There’s no reporting requirements or new crime being created here; the intention is to “”aid”” IaaS providers in complying with OFAC requirements, and, when a warrant is issued, the actual identities of the customers to be known.
- pessimizer 2y ago
- ChikkaChiChi 2y agoThis does not appear to affect domestic customers.
- Izkata 2y agoHow would they know a customer is domestic or foreign without some level of identification on everyone?
- beaeglebeachh 2y agoBingo. They'll have to KYC everyone to avoid liability of missing a faking foreigner.
- noodlesUK 2y agoThen surely all the good actors have to do KYC, and all the bad actors can just pretend to be American entities. I don't agree with this on principle, but even just from a practical perspective it seems like they are leaving the door completely open by doing that. What's even the point?
- deleted 2y ago[deleted]
- charlie0 2y agoYet.
- waihtis 2y agoWhat an absolute nightmare. I would also be surprised if iaas providers arent in vehement opposition, i will instantly migrate all cloud resources away from AWS if they start requiring KYC docs. Theres close to zero effort for doing so
- viknod 2y agoWow, what layer of abstraction do you have that allows for that? Even with typical IaC, Terraform, it's going to be a rewrite. If you're leveraging anything beyond load balancers, compute, and containers I don't see how that approaches zero. Some of the services could end up with you having to build/run your own to get any equivalence.
- k8svet 2y agoWhy is it so hard time for some of this site to understand that some of us are principled when it comes to choosing technologies? Or you know, actually learned from past trauma and make choice to avoid getting burned in the future.
- Sxubas 2y agoNot all of us are enlightened. Wouldn't you mind telling us what those technologies are?
- nadermx 2y agoAnsible comes to mind. Used it to orchestrate hundreds of servers with migrations. Could also simply set up proxmox services beforehand if you're truly motivated, then just replicate the server to another instance.
- thedaly 2y agoAnd all networking configuration and everything else is transferred with close to zero effort?
- AdamH12113 2y agoFor those who didn't know, KYC stands for "know your customer". It's a good idea to spell out abbreviations the first time they're used, especially since the abbreviation itself is not used in the linked article. It's also worth noting that the proposal is about US infrastructure as a service (IaaS) products specifically, not "internet services" in general.
- probably_jesus 2y ago[dead]
- SOLAR_FIELDS 2y agoYeah this is a very industry standard term in banking and anyone in that industry is going to immediately know what you are talking about, but outside of that industry, chances are high that a layman will not
- gdcbe 2y agoIn the past that would be true. But given most blockchain platforms require it, I imagine it is more widely known in the tech-savy hn-like realms? Then again I worked on blockchain tech around half a decade ago, so I might be knowledge biased here?
- rangerelf 2y agoDefinitely biased. I had no idea what KYC means. I don't think typing it out fully once at the beginning is too much to ask, is it?
- IfOnlyYouKnew 2y agoThis is about foreign customers only, so as an attempt to abolish the constitution, it is severely flawed in respecting it enough to keep its distance. I can't think of any US service I am using that doesn't already require KYC? None of the large providers will let you get far without a credit card, as far as I remember? Since the discussion here will consider itself mostly with upright revolutionaries being disenfranchised by such insult to their liberties, it is worth noting that when the revolutionaries are foreigners, the US often doesn't have the same incentive to disenfranchise them as it might have for domestic troublemakers. In fact the US has quite a track record of granting rights to foreigners in excess of what they find at home, and even when it concerns allies: request by European courts and law enforcement are regularly rejected based on US norms when, for example, someone hosts their hat speech blog with an US-only provider.
- axus 2y agoAnd FISA was only about surveilling non-US persons.
- IfOnlyYouKnew 2y agoNo. With a court order, FISA always allowed surveillance of "agents of foreign powers", even if they were US citizens: https://en.wikipedia.org/wiki/Foreign_Intelligence_Surveillance_Act#With_a_court_order https://en.wikipedia.org/wiki/Foreign_Intelligence_Surveilla....
- loeg 2y agoProviding a credit card is a far cry from KYC. But it also highlights that we probably don't need IAAS businesses to implement KYC as long as the payment providers already do.
- eks391 2y ago> I can't think of any US service I am using that doesn't already require KYC? None of the large providers will let you get far without a credit card, as far as I remember? There are several credit card vendors that do not require KYC that are easily available. I don't know of any banks that don't require KYC that you would use to pay those CC bills, but I wouldn't be surprised if they exist.
- oshout 2y agoSkimming through the article, it seems like the extent of this is to require IAAS (Infrastructure) providers to verify the identity of those who are using their services to train AI. It's an attempt to stymie sanctioned or malicious actors, from training AI and especially from hopping between services or using aliases to continue training on their model. It seems a bit benign and I don't understand the parallels others on this HN discussion are making. Is it that it's a slippery slope or perhaps I'm being naïve in regards to the scope?
- chadsix 2y agoAI is mentioned, but the scope is significantly larger if you read the fulltext.
- kube-system 2y agoGiven that top GPUs are sanctioned, I'm sure preventing access to them remotely is a part of this. But just generally speaking, doing any malicious crap out of an EC2 instance is an easy way for a foreign actor in China/Russia/Iran to look more legit.
- Repulsion9513 2y agoAs if they won't just use a stolen identity. And like usual the victim will never even find out because it won't show up on their credit report.
- kube-system 2y agoOf course, people who want to circumvent laws will always attempt to do so. That doesn't mean all legal mitigations are useless.
- Repulsion9513 2y agoIndeed it does not. But that also doesn't mean this legal mitigation is either useful or worthwhile.
- Izkata 2y agoFor those of us who don't know what this is, an explanation is a bit down the page: > To address these threats, the President issued E.O. 13984, “Taking Additional Steps To Address the National Emergency With Respect to Significant Malicious Cyber-Enabled Activities,” which provides the Department with authority to require U.S. IaaS providers to verify the identity of foreign users of U.S. IaaS products, to issue standards and procedures that the Department may use to make a finding to exempt IaaS providers from such a requirement, to impose recordkeeping obligations with respect to foreign users of U.S. IaaS products, and to limit certain foreign actors' access to U.S. IaaS products in appropriate circumstances. The President subsequently issued E.O. 14110, “Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence,” which calls for the Department to require U.S. IaaS providers to ensure that their foreign resellers verify the identity of foreign users. E.O. 14110 also provides the Department with authority to require U.S. IaaS providers submit a report to the Department whenever a foreign person transacts with them to train a large AI model with potential capabilities that could be used in malicious cyber-enabled activity.
- blackeyeblitzar 2y agoWhat can we do to actually contest it? I see this website lets you submit a “formal comment”. But is that enough? Who is in charge of the decision and who else can be pressured to stop it (certain legislators)?
- oldpersonintx 2y ago[dead]
- deleted 2y ago[deleted]
- martingalex2 2y agoThis is a good overview https://www.akingump.com/en/insights/alerts/commerce-issues-proposed-rule-on-malicious-cyber-enabled-activities-and-artificial-intelligence https://www.akingump.com/en/insights/alerts/commerce-issues-...
- perihelions 2y ago- "To Address the National Emergency" A fast-moving emergency that can't be fixed by normal constitutional lawmaking processes, and must resort, exceptionally, to executive-branch emergency decrees—for expedience. Nevermind the executive order it's drawing authority from was written three years ago. It was a fast-moving emergency then, too, I suppose. https://www.federalregister.gov/documents/2021/01/25/2021-01714/taking-additional-steps-to-address-the-national-emergency-with-respect-to-significant-malicious https://www.federalregister.gov/documents/2021/01/25/2021-01... ("Taking Additional Steps To Address the National Emergency [sic] With Respect to Significant Malicious Cyber-Enabled Activities" (2021))
- sschueller 2y agoSo national security trumps democracy and freedom? What do you have left to protect when you give it all up? Might as well just elect a king and be done with it.
- ryandrake 2y agoDon't worry--we seem to be actively working on this one, too.
- unboxingelf 2y agoWhy elect a king when you already have a private group of bankers running the show
- robocat 2y agoSystems run the show, not people. "What important truth do very few people agree with you on?": I believe that nobody is running the show. The systems we have created are more complex than we understand. I think a few people individually understand a few aspects of the different systems (we are not at the complete mercy to these systems). I also believe that we have a psycological need to know our social heirachies therefore we create stories about who we think is in control. That need creates conspiracy theories! That need creates narratives that certain people are running the world (but when you look closy at those people they are not running things - they don't understand how everything works even though they put much effort into trying to).
- oldpersonintx 2y agoif you are all just going to vote for Biden again anyway, stop complaining
- DonHopkins 2y agoYou're suffering from Biden Derangement Syndrome.
- megous 2y agoSo this is just to make it easier to ban non-US citizens from using US IaaS (or track them). Just don't use American IaaS in the first place. It's not like computers are available only in the US.
- patricklorio 2y agoComputers outside of the US sure, but the latest chips used for AI training have export controls so not so much.
- djoldman 2y ago> (e) The term “Infrastructure as a Service Product” means any product or service offered to a consumer, including complimentary or “trial” offerings, that provides processing, storage, networks, or other fundamental computing resources, and with which the consumer is able to deploy and run software that is not predefined, including operating systems and applications. The consumer typically does not manage or control most of the underlying hardware but has control over the operating systems, storage, and any deployed applications. The term is inclusive of “managed” products or services, in which the provider is responsible for some aspects of system configuration or maintenance, and “unmanaged” products or services, in which the provider is only responsible for ensuring that the product is available to the consumer. The term is also inclusive of “virtualized” products and services, in which the computing resources of a physical machine are split between virtualized computers accessible over the internet (e.g., “virtual private servers”), and “dedicated” products or services in which the total computing resources of a physical machine are provided to a single person (e.g., “bare-metal” servers);
- spiralpolitik 2y agoI would argue that for most use cases Internet Services are already collecting sufficient KYC data that it won't make a difference. Try signing up for anything infrastructure related without providing a credit card and/or billing address and/or cell phone number and see how far you get. That said the system is only as strong as the weakest link in the chain, and while getting a credit card/cell phone number in the US requires a certain standard of identity verification, the same might not be true for other countries (or in cases of deliberate fraud). I think that is what the legislation seems to be targeting. That doesn't mean it is good legislation or won't have unforeseen side effects.
- jofla_net 2y agoThis totally depends on what is collected, if the requirements are some form of national id submission, ie. licenses or passports, then it opens all handlers up to tremendous abuse possibilities. Or at the very least paints a big sign on their backs that they handle mass quantities of offical government forms of biometric id, something I think would do much more harm than good in the long run as each company would need to be bulletproof to avoid.
- patricklorio 2y agoI read the document a bit, it seems like this is essentially saying that services like AWS need to know the identity of their customer if they suspect they are a foreign entity. I don't think this would cover VPNs or internet access, mainly just people spending lots of $$ on compute. Is that correct? If so it seems reasonable. If a non US group is spending lots of money using US technology to develop an AI model I do think that falls under foreign trade and should be documented.
- boppo1 2y agoWhat can I do as a broke guy to stop this? Write a comment? Will it be read or considered?
- greenavocado 2y agoThere is literally nothing you can do. The intelligence agencies are building the top of the funnel for the gulags to host us in the near future.
- int_19h 2y agoIt will be read and considered - you can safely assume that it will affect your social credit score accordingly.
- chrisjj 2y ago> verify the identity of their foreign customers Makes you wonder how they are going to first determine which are foriegn...
- 2OEH8eoCRo0 2y agoThanks. Just commented in support.
- rsync 2y agoThe talking point we should be using is: if banks know their customers, we don’t have to. The trail of knowing ones customers always leads to payments and finance. If we are accepting payment for our services with standard bank card transactions or wire transfers, etc., then the knowing of the customer can be centralized at the banks.
- MmmKayWhySee 2y agoExactly. What is the point of repeating KYC across every industry? I work on the KYC team of a banking/finance company. It takes a significant amount of resources. Unless we create global governing initiatives similar to FATF for IaaS products, American IaaS offering will become less competitive.
- hakfoo 2y agoAlso, the banks have proven themselves fairly inept at it. The problem is that KYC, being a cost centre with no upside other than "it's imposed on us by law", immediately turns into a box-checking exercise. The industry will barf up some terrible "compliance in a box" solution, everyone will use it, it will eventually get databreached, and the people who brought us Bulletproof Hosting back in the Viagra Spam era will come back with Bulletproof Rack Full Of Quadros.
- hirako2000 2y agoAnd who pays for it. Yet another compliance procedure to add to the stack. I propose that any new regulation gets financed by the the regulators . And retro actively get all regulations to have their cost covered by the government. Who pays the auditors. Who pays Accountants, who paid for data protections schemes, who pays for random sanctions making countless companies suddenly lose large part of their business . Regulations are great, it should be at the government charge though, so that we can continue to do business, prevent market entry costs which promotes monopolies/oligopolies, encourage compliance.
- deleted 2y ago[deleted]
- wumeow 2y agoThis seems like the key section people should read through and where they should focus their submitted comments: https://www.federalregister.gov/d/2024-01580/p-70 https://www.federalregister.gov/d/2024-01580/p-70
- justin66 2y agoIs this more onerous than verifying the name of the person or company you're serving does not appear on the OFAC list? This is generally not difficult for anyone concerned, unless they happen to share a name with somebody on that list.
- 0xPrimal 2y ago[dead]
- LivenessModel 2y agoSimple ID scans are already on their way out. "Liveness checks" where we have to turn on our webcam and let some stranger make a full biometric model of our head to use basic internet infrastructure is the dystopia we deserve, and it's the one we're gonna get. I hope the "AI" was worth it. Let's see if you can fix this problem you created.
- pessimizer 2y agoAlready happening at the IRS. There's a reason government was so reticent in regulating facial recognition in any meaningful way: The government database of everyone's faces, purchased and cobbled together from private partners, isn't complete enough yet. This has nothing to do with AI, but an out-of-control executive branch and intelligence agencies. AI is just another tool that will make it cheaper.
- rangestransform 2y agoare they going to start requiring an ID to buy a GPU too
- elzbardico 2y agoAs if KYC for bank accounts was an astounding success on international crime, corruption and terrorism financing.
- monksy 2y agoNo it wasn't. The terrorism and cartels just got their aunts to register account.
- andybak 2y agoIf you're going to editoralize the title, could you possibly tell us what KYC stands for?
- kiernanmcgowan 2y agoKnow Your Customer - it’s a term describing how organizations like banks want to know what you’re doing so they can avoid enabling criminal activity.
- oaiey 2y agoControversial point: if you run a Internet presence of any kind, this is like a property of land on which you run business. The property needs also a legal owner. For real businesses, this is normal. It is unregulated IT who does not understand this and is still in the wild West. Obviously, modern data processing creates the rightful fear of surveillance. What we lack is a culture of privacy. In other countries if the state or anyone else wants to access the land registry or any other: good luck without a lawful reason.
- whiplash451 2y agoA number of threads seem to assume that KYC (or identity check) implies that your biometrics or gov ID data is collected/stored by the provider, but it does not have to be. The identity check is typically done by a trusted 3rd party that can delete the data right after the identity check (and can be required to do so). So you basically end up guaranteeing that the name, address and D.O.B that you provided to the IaaS provider is actually correct, nothing more and nothing less.
- hakfoo 2y agoTo be frank, I'd be more comfortable with this sort of thing more if there was a full-fat government-based ID platform. Some sort of SSO-style "Sign on with identity.gov" button, where it tells you clearly exactly what information is granted to the vendor, which should be pretty much "nation of citizenship" and nothing else, before you click through. I trust a "trusted third party" far, far less. Inevitably it's a data hoarder like our credit-bureau overlords, which has commercial motivations to ask for more data than needed, and hold it longer than necessary, and will likely suffer only a slap on the wrist when they inevitably data-breach. We really needed a coherent plan for national and digital ID 20 years ago, but as they say, the second best time would be now.
- chmod600 2y agoIdea: let's make it so all emergency powers have to be re-authorized every week by Congress at midnight on Friday with a 90% quorum of physically-present representatives. If "emergency" action is needed because Congress is too slow, then let's make sure they are working through the process to create real law. Or if they aren't, I guess it wasn't an emergency, and there's no reason for administrative law to "fill in" using a non-democratic process.
- throwway120385 2y agoGreat! I'm looking forward to seeing this requirement applied to also dissolve the judicial branch entirely so that Congress is entirely responsible for both enforcment and adjudication of the law. Let's work together to end separation of powers.
- chmod600 2y agoYou seem to be suggesting that Congress making law is intruding on the power of an agency to make Administrative law? The latter is not (supposed to be) an actual branch of government. Congress has full power to rewrite all the administrative law as they see fit.
- deleted 2y ago[deleted]
- throw5345346 2y agoThere's a surprising amount of debate in this thread on the rights and wrongs of this topic. As a matter of simple efficiency, what I suggest to you all is that you imagine this was being rolled out by the British government. Because then you'd all be certain what it meant and what was necessary.
- mr_toad 2y agoI can’t tell if you’re being sarcastic or not. I didn’t think the UK even provided IaaS services. On the other hand it seems like half the business of The City is providing cover for dodgy foreign companies, which would be perfect for people trying to get around these laws.
- martinbaun 2y agoThis seems like a slippery slope.
- midi_kyc 2y ago[dead]
- gwbas1c 2y ago> We have 4 days to contest KYC being required by internet services The acronym "KYC" doesn't appear in the linked article. What is this even about?
- eks391 2y agoKnow Your Customer. It's when you are asked for legal docs so a business can verify your identity. Like what banks do
- zarzavat 2y agoCan anyone glean from this wall of text what documents Uncle Sam is going to expect me, a dirty and potentially smelly foreigner, to submit in order to keep my AWS account?
- CatWChainsaw 2y agoThis will pass regardless of comments and KYC will only get more strict from here on out. What other end result could there have been when the combined gov-corp-tech behemoth is incredibly data-hungry, obsessed with draconian surveillance, and about to be deluged with malicious AI across the internet? It starts with "suspected" foreign actors and ends with everyone needing to prove their humanity for every little thing on the web. This is why we can't have nice things..
- greenavocado 2y agoNext thing you know if you make one comment about Israel or certain coincidences you will be debanked, cut off from all Internet services, unable to make payments, blacklisted from all employers, your payment accounts frozen, ultimately resulting in eviction for non-payment, then shortly thereafter homeless, hungry, dead, or in prison. That's the logical end-game of all this in case you don't have the foresight to see where this road leads.
- CatWChainsaw 2y agoEven foresight isn't enough to avoid it if you don't have the fortitude to avoid paths of least resistance, or the ability to oppose entrenched power structures.
- xbar 2y agoIf I host a site that is vulnerable to XSS, is it inadvertant Iaas?
- MmmKayWhySee 2y agoI work on KYC systems at a medium/large sized financial institution. The trend of adding KYC requirements to more and more online services is troubling. KYC adds a huge burden to anyone trying to offer a service. Implementing KYC imposes significant burdens on service providers due to the complexity of identifying users across different countries and understanding varied regional regulations. You end up outsourcing your KYC to another company. But most KYC vendors don't support all the countries you want to support, so you either end up limiting your service to the service area of your KYC vendor. Or you end up integrating multiple vendors together, which is challenging since vendors generally prefer exclusivity. If you didn't have an engineering team working on KYC before, you will now. You will likely need to add to or expand your compliance team. Your company will shift either slightly or significantly from being an engineering or product driven company to being a compliance driven company. KYC raises barriers and entrenches incumbents. Look at financial institutions and porn. KYC is generally not evidence based policy either [1, 2]. Bad actors get around your KYC requirements, and your KYC system ends up being a hurdle for innocent users. A lot of KYC systems rely on data aggregators (aka the people who buy your personal data), and if you aren't "in the system" either because you are young, poor, or privacy conscious, you are faced with suspicion. My experience is that anti-fraud systems tend to weed out bad actors better than KYC systems that are mandated in a governmental top down manner. 1) https://www.economist.com/finance-and-economics/2021/04/12/the-war-against-money-laundering-is-being-lost https://www.economist.com/finance-and-economics/2021/04/12/t... 2) https://www.tandfonline.com/doi/full/10.1080/25741292.2020.1725366 https://www.tandfonline.com/doi/full/10.1080/25741292.2020.1...
- webspinner 2y agoI know i'll be done with the internet completely if this rule goes through. I will not want to upload government IDs with inaccessible systems.
- webspinner 2y ago.This is what I wrote into the federal register. Please do not allow KYC for the entire internet. This is in fact a miserable failure of an idea. You want to hand our data to AI companies, huh? I do not want to have anything to do with that, or you, if you don't come up with better data privacy regulations. Under the fourth amendment, this would be an unconstitutional general warrant. I thought we did away with those long ago. It does not describe the particular things to be seized. KYC is a ridiculous idea in the first place. It is not designed for the entire internet infrastructure. All the department is doing, is enabling more mass surveillance. By trying to shoehorn KYC into the internet infrastructure, you will make the internet less convenient to use for blind people like me. I rely on it in my every day life. If you decide to make the worst mistake ever, I will have to stop using the internet in favor of my privacy.
- anarchy_matt 2y ago"I'm from the government, and I'm here to help"