28 ms·
Skimming through the article, it seems like the extent of this is to require IAAS (Infrastructure) providers to verify the identity of those who are using their
by oshout 2y ago
Skimming through the article, it seems like the extent of this is to require IAAS (Infrastructure) providers to verify the identity of those who are using their services to train AI. It's an attempt to stymie sanctioned or malicious actors, from training AI and especially from hopping between services or using aliases to continue training on their model.
It seems a bit benign and I don't understand the parallels others on this HN discussion are making. Is it that it's a slippery slope or perhaps I'm being naïve in regards to the scope?
- chadsix 2y agoAI is mentioned, but the scope is significantly larger if you read the fulltext.
- kube-system 2y agoGiven that top GPUs are sanctioned, I'm sure preventing access to them remotely is a part of this. But just generally speaking, doing any malicious crap out of an EC2 instance is an easy way for a foreign actor in China/Russia/Iran to look more legit.
- Repulsion9513 2y agoAs if they won't just use a stolen identity. And like usual the victim will never even find out because it won't show up on their credit report.
- kube-system 2y agoOf course, people who want to circumvent laws will always attempt to do so. That doesn't mean all legal mitigations are useless.
- Repulsion9513 2y agoIndeed it does not. But that also doesn't mean this legal mitigation is either useful or worthwhile.
- lolinder 2y agoIt's still just for IaaS companies, though, right? Not that that makes this all okay, but it is a much more limited proposal than "internet services" makes it sound.
- chadsix 2y agoLegally speaking, internet service providers are infrastructure providers.
- lolinder 2y agoDo you have a basis for this claim or are you just throwing it out there to see if it catches on? The document linked refers to IaaS, which as an acronym definitely does not include ISPs.
- erie 2y agoSome AI services such as Synthesia https://www.synthesia.io https://www.synthesia.io › ethics " Your avatar can be created only with your explicit consent, following a thorough KYC-like procedure. Complete control: Our platform ensures you can decide"
- chadsix 2y agoThere are probably very few ISPs that can fall outside of this standard. For example if your provider provides e-mail, it's providing infrastructure. And yet, the slope can get much more slippery than this.
- zinekeller 2y agoPlease read EO 13894 before proceeding further. Is the user able to run custom software directly with a customary ISP (because that's in the definition)? I agree with EGreg that they can possibly twist this, but as written it's actually narrower than you think.
- EGreg 2y ago
- axus 2y agoI'm going to need another intelligence to read the full text. "U.S. IaaS providers and foreign resellers of U.S. IaaS products must exercise reasonable due diligence to ascertain the true identity of any customer or beneficial owner of an Account who claims to be a U.S. person." So at a minimum, everyone's identity is verified by IaaS provider. If you claim to be a non-U.S. person, additional information is collected. They mention looking at comments from a previous proposal in 2021, "Taking Additional Steps To Address the National Emergency With Respect to Significant Malicious Cyber-Enabled Activities" https://www.federalregister.gov/documents/2021/09/24/2021-20430/taking-additional-steps-to-address-the-national-emergency-with-respect-to-significant-malicious https://www.federalregister.gov/documents/2021/09/24/2021-20... Who counts as IaaS besides Amazon, Azure, and GCS?
- OgsyedIE 2y agoDreamhost, Wordpress, etc
- EGreg 2y agoLiterally every software that you can host. This effort will end anonymity on the internet. For everyone. Crypto was just the beginning. Next is end-to-end encryption. And it's going on worldwide, not just in USA: https://community.qbix.com/t/the-coming-war-on-end-to-end-encryption/214/ https://community.qbix.com/t/the-coming-war-on-end-to-end-en...
- nonameiguess 2y agoThis is not the industry-standard or NIST definitions of these terms. Something like Google Workspace Suite is Software as a Service. Something like Heroku (or Dreamhost or Wordpress) is Platform as a Service. Something like EC2 and S3 are Intrastructure as a Service. The distinction is renting out undifferentiated server space that a customer installs their own software onto. If you rent a VPS from Linode and install self-hosted Wordpress, that's IaaS. If you buy Wordpress's managed hosting, that's PaaS.
- chlodwig 2y ago
- monksy 2y ago[flagged]
- CodeWriter23 2y ago> propose regulations requiring U.S. Infrastructure as a Service (IaaS) providers of IaaS products to verify the identity of their foreign customers, Sounds like solid policy to me.
- monksy 2y agoAnd how do you know that one customer is a foreign one and one is not?
- kube-system 2y agoThat is outlined in §7.302 The TL;DR is that the must collect name, address, email, phone number, IP address, and payment information and use that information for "verifying the identity of each foreign customer to the extent it enables the U.S. IaaS provider or foreign reseller of U.S. IaaS products to form a reasonable belief that it knows the true identity of each customer." AWS already has all of this information on my account.
- monksy 2y agoHow does an email correspond to your location? My email goes through Switzerland and I have a domain address that ends in ".de" am I a US resident, German, or Swiss?
- kube-system 2y agoIt doesn't correspond to location any more than "name" does. But it is useful, in conjunction with other things, for determining identity, which is what those requirements are about.
- CodeWriter23 2y ago
- justaman 2y agoI think everyone has a sour taste left over from decades of half-baked laws written by politicians that don't understand the basics of the internet or technology in general. With that said, I also don't understand the issues people are having with this.
- newaccount7hhhf 2y agoWhat laws are you talking about? The Internet has grown a lot that’s largely because we have smart politicians and strong institutions. I really think the regulation of the Internet has been amazingly good.
- donbateman 2y ago[flagged]
- Kye 2y agoFor example: CAN-SPAM. If I want to send emails to a list, I have to burn $90 of my scarce dollars every year just for a PO box for the address at the bottom on the off chance someone sends a letter to unsubscribe. Unless I want to put my home address in every email, which I don't, and no one should. Unsubscribe links and highly effective spam filters were already completely standard when the law was passed in 2003. It doesn't matter if the email you send doesn't actually require it because every mailing list provider requires it.
- loeg 2y agoEh, unsubscribe links were definitely not universal in 2003 and they barely are today. But the situation has definitely improved in the last 20 years.
- AnthonyMouse 2y agoThe point is the rules are daft. A sensible rule would require a functioning unsubscribe process in the email, which every piece of software would then automate as an unsubscribe link. The actual rule requires people to be able to unsubscribe via a postal mailing address, which is unreasonable and ridiculous.
- f38zf5vdt 2y agoFrom the executive order (Executive Order 14110) it seems to affect only massive compute infrastructure: > (i) any model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations, or using primarily biological sequence data and using a quantity of computing power greater than 10^23 integer or floating-point operations; and > (ii) any computing cluster that has a set of machines physically co-located in a single datacenter, transitively connected by data center networking of over 100 Gbit/s, and having a theoretical maximum computing capacity of 10^20 integer or floating-point operations per second for training AI. Keep in mind that most consumer graphics cards are in the _teraflops_ range, which is 10^12. It's hard to imagine this affecting the average person, it seems that they are specifying KYC for people using clusters with thousands or tens of thousands of cards.
- Dylan16807 2y ago> Keep in mind that most consumer graphics cards are in the _teraflops_ range, which is 10^12. Something like 40 of them, or 100-300 if you're looking at FP16. So well over 2^14. And that's per second, give it your idle cycles for four months and that's 10^7 seconds. It gets pretty close to 10^23.
- pavon 2y agoNo, that is just one part of it. The proposed rules are intended to cover both EO13984, which addresses foreign entities using US IaaS for Cyber attacks, and EO14110 which addresses foreign entities using AI hardware. They require all IaaS[1] to determine if customers are US persons, and if not to collect and retain certain identifying information[2], and provide annual reports describing their processes[3]. It grants the Secretary of Commerce extra-judicial power to force any IaaS to stop doing business with any foreign customer, or place restrictions on their use[4]. This section lists things that the Secretary should consider in doing so, but doesn't have any hard requirements. Finally, it requires the IaaS to report certain foreign use of AI[5]. [1]§7.301 https://www.federalregister.gov/d/2024-01580/p-189 https://www.federalregister.gov/d/2024-01580/p-189 [2]§7.302 https://www.federalregister.gov/d/2024-01580/p-219 https://www.federalregister.gov/d/2024-01580/p-219 [3]§7.304 https://www.federalregister.gov/d/2024-01580/p-266 https://www.federalregister.gov/d/2024-01580/p-266 [4]§7.307 https://www.federalregister.gov/d/2024-01580/p-377 https://www.federalregister.gov/d/2024-01580/p-377 [5]§7.308 https://www.federalregister.gov/d/2024-01580/p-403 https://www.federalregister.gov/d/2024-01580/p-403
- chlodwig 2y agoSkimming the regulations, this does not seem right. All IAAS providers (which is everyone who allows customers to run custom code, so it includes any web host like Dreamhost) to verify the identity of foreigners who open an account. This would seemingly entail the service provider needing to verify everyone's identity, in order to figure out who is a foreigner and who is not. In other words, if you want to run your own Wordpress, or Mastodon node, or your own custom CMS web site or group chat or IRC or bitcoin node, you would need to reveal your identity to the hosting service that you want. This does seem quite bad and could obviously be used to identify political dissidents. On top of that, the IAAS must report to the US Commerce department about foreigners who are using services to train large AI models.
- Raidion 2y agoAren't you basically revealing yourself anyway because you need to pay them?
- chlodwig 2y agoThere are IaaS services out there that accept bitcoin, monero, or anonymous prepaid charge cards. They aren't an IaaS but Mullvad even accepts cash mailed to them in an envelope.
- _tk_ 2y agoIs it fair to assume, that one can engage in a business relationship with these services outside the US? I'm not sure I see the effect that you are implying. AWS, GCP, Azure don't accept crypto. Mullvad is as you point out not an IaaS provider.
- chlodwig 2y agoNamecheap, Vultr, BuyVm all operate in the U.S. and at times in the past (I don't know if they still do) have either accepted crypto or anonymous charge cards (available for cash at a convenience store), thus making it possible to get a dedicated server or VM totally anonymously. This new regulation would seem to prevent this.
- wetpaws 2y ago[dead]
- RAM-bunctious 2y agoIt's really not benign as far as I can see. There is an implication that its purpose is to allow providers to start writing reports on foreign users training LLMs (which, incidentally, I'm not condoning either), but in the process it requires every American IaaS has to start implementing KYC folly. No one wants to send in selfies and their passport just to start a Digital Ocean droplet.
- BenjiWiebe 2y agoI'm curious if the spammers will find a way around this. I would actually like to be ID'd by a provider if that also meant they had no un-ID'd customers. I'd expect their IP range would start to get a pretty good reputation.
- AnthonyMouse 2y agoThe spammers are criminals. They'll just use ID scans and info from data breaches of other companies. Requiring more companies to collect them makes it even worse because now there are more places to exfiltrate them and it makes it easier for criminals to commit identity theft against financial institutions etc. There are also non-"criminals" who are more than willing to use their actual ID for the sort of things that aren't strictly illegal but will still get your IP space on a bunch of block lists when they can make a buck doing it, so it wouldn't solve the problem even if it could actually identify all of the customers.
- jofla_net 2y agoAnd now more people will have thier passports pinched as they'll be opening themselves up to more opportunities to have it stolen. It'll be great to get ready for that overseas trip, or while returning, to find out you need to now visit an embassy as a forged version of it is now in use.
- webspinner 2y agoIt's absolutely folly! Foolishness by the department of commerce. What were they thinking?
- NoMoreNicksLeft 2y ago> It seems a bit benign This seems, to me, an utterly malignant attack on anonymity, which is a protected constitutional right. It's the idea that every internet packet needs to be tied back to some verified identity. We're in frog-boiling territory with this garbage.
- spiralpolitik 2y agoThere is no absolute right to anonymity in the US constitution. (The courts have "recognized relatively strong First Amendment presumptions on behalf of purveyors of anonymous speech, especially for those that are statements of opinions rather than obvious falsehoods, while recognizing that government sometimes has the right to identify such speakers when they have used their platforms to harass, engage in slander or sexual predation, make true threats, or allow foreign governments to influence U.S. elections")
- AnthonyMouse 2y agoHow is one supposed to exercise their right to anonymously express political opinions if anonymity is prohibited by law?
- krapp 2y agoThere is no right to anonymously express political opinions. There is a right to express political opinions, but anonymity is a privilege, not a right.
- AnthonyMouse 2y agoThen how do you explain these? https://cs.stanford.edu/people/eroberts/cs181/projects/anonymous-computing/history/law.php3 https://cs.stanford.edu/people/eroberts/cs181/projects/anony...
- krapp 2y agoI see controversy and a lot of dissent among Justices, but no decisions that explicitly declare a Constitutional right to anonymity. And the modern Court explicitly declared that a Constitutional right to privacy does not exist, and one cannot have anonymity without privacy, so no.
- chrisjj 2y ago> seems like the extent of this is to require IAAS (Infrastructure) providers to verify the identity of those who are using their services to train AI. Only foriegners. > It's an attempt to stymie sanctioned or malicious actors, from training AI and especially from hopping between services or using aliases to continue training on their model. Unlikely, since it exempts non-foriegn malicious actors
- codedokode 2y agoThis won't work. Foreign nations have enough skill and resources to pass KYC as a citizen (steal someone's documents, pay a homeless for verification etc). And as I understand, US doesn't have a central citizen database so it is difficult to verify a document.
- White_Wolf 2y agoIt's funny they don't need ID to vote but they'll need one for a VPS. EDIT: I know it's about IaSS.
- AnthonyMouse 2y agoThat isn't even the first reason it won't work. Computing is a global commodity. There are providers in other countries. They would just use one of those.
- atentaten 2y agoIt's not meant to work.
- webspinner 2y agoTrue that!
- toss1 2y agoOn top of that, it is to identify FOREIGN users >>"require U.S. IaaS providers to verify the identity of foreign users of U.S. IaaS products, ... which calls for the Department to require U.S. IaaS providers to ensure that their foreign resellers verify the identity of foreign users. E.O. 14110 also provides the Department with authority to require U.S. IaaS providers submit a report to the Department whenever a foreign person transacts with them to train a large AI model with potential capabilities that could be used in malicious cyber-enabled activity." We damn well SHOULD be identifying foreign users of our services, particularly those which have high-powered potential to cause harm. This knee-jerk [govt identifying anybody is bad] response prevalent here deeply undermines the cause of actually maintaining privacy. There are actually very bad actors out there, and if we fail to identify and contain them, things will be far worse. The reality is that some measures must be taken — let's focus on containing the real threats, not cry foul at every shadow of a hint that we might approach a slippery slope.
- olalonde 2y ago> Is it that it's a slippery slope or perhaps I'm being naïve in regards to the scope? This. Also, it won't stop malicious actors. Setting up a LLC to mask your true identity is cheap and easy. Not to mention that providing a fake identity or pretending your are not a "foreign person" is also cheap and easy.
- webspinner 2y agoI'll certainly get one, or two, if this goes through.
- webspinner 2y agoThis is a terrible idea!
- m463 2y agothe more information they keep, the more they will expose it in data breaches, or sell/share it with others.