Live data from Hacker News

Ask HN: Would you send a photo holding your drivers license to rent a VPS?

news.ycombinator.com

1–10 of 69 posts

Ask HN: Would you send a photo holding your drivers license to rent a VPS?

#1
I wanted to try out OVHcloud and signed up and paid for a small, cheap VPS. Then I get this email:

  Please provide full-color photos of the following using the OVHcloudShare app (see instructions below):
    - A government-issued photo ID
    - A picture of the credit card used in the transaction including:
          1. The name matching the listed name in the Manager account, AND
          2. The last 4 digits of the card number
    - A photo of yourself holding the government-issued Photo ID provided above.
I absolutely will not do this - it's incredibly invasive and this is just a hosting service, not a bank. And it's a terrible idea. If every company starts doing this the security implications are far worse than whatever problem they're trying to solve.

Am I crazy? Is this just the way the world works now because of KYC or credit card scams or something? Or is it a European thing? (This is a French company and I'm in the USA.)

Re: Ask HN: Would you send a photo holding your drivers license to rent a VPS?

#2
AFAIK there's a new law requiring KYC for IaaS providers serving the US. I'm assuming it covers their butts as well regarding malicious activity, they don't want to host a DoS attack, CP site, or similar. You might be hard pressed to find a hosting provider in the US that doesn't ask for these things.

Re: Ask HN: Would you send a photo holding your drivers license to rent a VPS?

#4
post #2

AFAIK there's a new law requiring KYC for IaaS providers serving the US. I'm assuming it covers their butts as well regarding malicious activity, they don't want to host a DoS attack, CP site, or similar. You might be hard pressed to find a hosting provider in the US that doesn't ask for these things.

I’ve never seen this, maybe Im missing context? Amazon/Google/etc don’t require pictures of ID and CC?

Re: Ask HN: Would you send a photo holding your drivers license to rent a VPS?

#5
KYC is already required at banks and they have the most complete - and global - view of all transaction flows.

Therefore we should insist that KYC be solely performed by banks - no other firms should be required to perform it.

Given the extraordinary privileges that banks enjoy, this would be a reasonable contribution to society - especially given that they are doing it anyway.

Re: Ask HN: Would you send a photo holding your drivers license to rent a VPS?

#6
post #2

AFAIK there's a new law requiring KYC for IaaS providers serving the US. I'm assuming it covers their butts as well regarding malicious activity, they don't want to host a DoS attack, CP site, or similar. You might be hard pressed to find a hosting provider in the US that doesn't ask for these things.

Source? OVH has had this for years.

Re: Ask HN: Would you send a photo holding your drivers license to rent a VPS?

#9
post #5

KYC is already required at banks and they have the most complete - and global - view of all transaction flows . Therefore we should insist that KYC be solely performed by banks - no other firms should be required to perform it. Given the extraordinary privileges that banks enjoy, this would be a reasonable contribution to society - especially given that they are doing it anyway .

> we should insist that KYC be solely performed by banks

That sounds like a great way of preventing anyone who doesn’t have a bank account from being able to use services at all.

There are ~1.7 Billion people in the world that are unbanked.

Even in the US alone there are around 55 million unbanked adults. (2018 numbers)

I think we should push for the opposite. Less KYC all around.

Re: Ask HN: Would you send a photo holding your drivers license to rent a VPS?

#10
post #5

KYC is already required at banks and they have the most complete - and global - view of all transaction flows . Therefore we should insist that KYC be solely performed by banks - no other firms should be required to perform it. Given the extraordinary privileges that banks enjoy, this would be a reasonable contribution to society - especially given that they are doing it anyway .

Is this sarcasm? Most banks don't write software, and the third-party software isn't that great. I don't want my bank involved in this at all.
Post reply on HN