4 ms·
I suspect the databases useful for KYC already exist. The denylists that have to be checked against, for example. There might be a new record of inquiries or
by hakfoo 2y ago
I suspect the databases useful for KYC already exist. The denylists that have to be checked against, for example.
There might be a new record of inquiries or certificates generated, perhaps, but that doesn't really need to be logged.
Identity is always an ugly technical problem, and IMO the federal option has the least ugliness. Yeah, you have one database, but that also means you have only one place to monitor, keep up to date with state-of-the-art security norms, and one giant legal hammer to go after anyone who breaches it.
* Devolving the problem to lower-level governments just means you replace one database with dozens, and get to deal with varying security and use paradigms, and interoperability and data synch that's clumsy at best. How long can you keep a scam running using Jane Doe in Idaho's credentials until the system is synched and learns she actually moved to West Virginia?
* Using private entities to manage it would have all the worst incentives for misuse and abuse, and either gives one bid-winner the keys to the economy or creates a bunch of fiefdoms incentivized to limit interoperability.
* Any sort of bottom-up "self-attestation" or web-of-trust sort of solution would be difficult to bootstrap and require generating mountains of new legal precedent and tooling to support.