Live data from Hacker News

We have 4 days to contest KYC being required by internet services

federalregister.gov

61–70 of 395 posts

Re: We have 4 days to contest KYC being required by internet services

#61

- "To Address the National Emergency" A fast-moving emergency that can't be fixed by normal constitutional lawmaking processes, and must resort, exceptionally, to executive-branch emergency decrees—for expedience. Nevermind the executive order it's drawing authority from was written three years ago. It was a fast-moving emergency then, too, I suppose. https://www.federalregister.gov/documents/2021/01/25/2021-01... (…

So national security trumps democracy and freedom? What do you have left to protect when you give it all up? Might as well just elect a king and be done with it.

Re: We have 4 days to contest KYC being required by internet services

#62
post #53
post #12

Earlier quoted context omitted.

What provision of the constitution does it violate? Do you know of court precedents that support that claim? I'm not writing this to argue against your position, but to help people craft effective comments to submit in response to the proposed regulation. Federal agencies are not responsive to comments about people disliking a proposed rule, but are very responsive to concrete examples of why it might be legally prob…

The fourth amendment? > “The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no Warrants shall issue, but upon probable cause, supported by Oath or affirmation, and particularly describing the place to be searched, and the persons or things ...

How does verifying your identity in any way violate that, though? You have a physical address that you live at, and the government verifies that you are the person living at that address, and that is not violating the fourth amendment. This would be pretty similar to that.

Re: We have 4 days to contest KYC being required by internet services

#63

For those who didn't know, KYC stands for "know your customer". It's a good idea to spell out abbreviations the first time they're used, especially since the abbreviation itself is not used in the linked article. It's also worth noting that the proposal is about US infrastructure as a service (IaaS) products specifically, not "internet services" in general.

synthesia requires KYC:" Your avatar can be created only with your explicit consent, following a thorough KYC-like procedure.

Re: We have 4 days to contest KYC being required by internet services

#64
post #21

Skimming through the article, it seems like the extent of this is to require IAAS (Infrastructure) providers to verify the identity of those who are using their services to train AI. It's an attempt to stymie sanctioned or malicious actors, from training AI and especially from hopping between services or using aliases to continue training on their model. It seems a bit benign and I don't understand the parallels othe…

I think everyone has a sour taste left over from decades of half-baked laws written by politicians that don't understand the basics of the internet or technology in general. With that said, I also don't understand the issues people are having with this.

What laws are you talking about? The Internet has grown a lot that’s largely because we have smart politicians and strong institutions. I really think the regulation of the Internet has been amazingly good.

Re: We have 4 days to contest KYC being required by internet services

#65
post #43

Earlier quoted context omitted.

Yeah this is a very industry standard term in banking and anyone in that industry is going to immediately know what you are talking about, but outside of that industry, chances are high that a layman will not

In the past that would be true. But given most blockchain platforms require it, I imagine it is more widely known in the tech-savy hn-like realms? Then again I worked on blockchain tech around half a decade ago, so I might be knowledge biased here?

Definitely biased. I had no idea what KYC means. I don't think typing it out fully once at the beginning is too much to ask, is it?

Re: We have 4 days to contest KYC being required by internet services

#66
> (e) The term “Infrastructure as a Service Product” means any product or service offered to a consumer, including complimentary or “trial” offerings, that provides processing, storage, networks, or other fundamental computing resources, and with which the consumer is able to deploy and run software that is not predefined, including operating systems and applications. The consumer typically does not manage or control most of the underlying hardware but has control over the operating systems, storage, and any deployed applications. The term is inclusive of “managed” products or services, in which the provider is responsible for some aspects of system configuration or maintenance, and “unmanaged” products or services, in which the provider is only responsible for ensuring that the product is available to the consumer. The term is also inclusive of “virtualized” products and services, in which the computing resources of a physical machine are split between virtualized computers accessible over the internet (e.g., “virtual private servers”), and “dedicated” products or services in which the total computing resources of a physical machine are provided to a single person (e.g., “bare-metal” servers);

Re: We have 4 days to contest KYC being required by internet services

#67
I would argue that for most use cases Internet Services are already collecting sufficient KYC data that it won't make a difference. Try signing up for anything infrastructure related without providing a credit card and/or billing address and/or cell phone number and see how far you get.

That said the system is only as strong as the weakest link in the chain, and while getting a credit card/cell phone number in the US requires a certain standard of identity verification, the same might not be true for other countries (or in cases of deliberate fraud). I think that is what the legislation seems to be targeting.

That doesn't mean it is good legislation or won't have unforeseen side effects.

Re: We have 4 days to contest KYC being required by internet services

#68
I read the document a bit, it seems like this is essentially saying that services like AWS need to know the identity of their customer if they suspect they are a foreign entity.

I don't think this would cover VPNs or internet access, mainly just people spending lots of $$ on compute. Is that correct? If so it seems reasonable. If a non US group is spending lots of money using US technology to develop an AI model I do think that falls under foreign trade and should be documented.

Re: We have 4 days to contest KYC being required by internet services

#69

For those who didn't know, KYC stands for "know your customer". It's a good idea to spell out abbreviations the first time they're used, especially since the abbreviation itself is not used in the linked article. It's also worth noting that the proposal is about US infrastructure as a service (IaaS) products specifically, not "internet services" in general.

Google is your friend

Re: We have 4 days to contest KYC being required by internet services

#70
post #27
post #21

Skimming through the article, it seems like the extent of this is to require IAAS (Infrastructure) providers to verify the identity of those who are using their services to train AI. It's an attempt to stymie sanctioned or malicious actors, from training AI and especially from hopping between services or using aliases to continue training on their model. It seems a bit benign and I don't understand the parallels othe…

AI is mentioned, but the scope is significantly larger if you read the fulltext.

I'm going to need another intelligence to read the full text.

"U.S. IaaS providers and foreign resellers of U.S. IaaS products must exercise reasonable due diligence to ascertain the true identity of any customer or beneficial owner of an Account who claims to be a U.S. person."

So at a minimum, everyone's identity is verified by IaaS provider. If you claim to be a non-U.S. person, additional information is collected.

They mention looking at comments from a previous proposal in 2021, "Taking Additional Steps To Address the National Emergency With Respect to Significant Malicious Cyber-Enabled Activities" https://www.federalregister.gov/documents/2021/09/24/2021-20...

Who counts as IaaS besides Amazon, Azure, and GCS?

Post reply on HN