Live data from Hacker News

We have 4 days to contest KYC being required by internet services

federalregister.gov

121–130 of 395 posts

Re: We have 4 days to contest KYC being required by internet services

#121

For those who didn't know, KYC stands for "know your customer". It's a good idea to spell out abbreviations the first time they're used, especially since the abbreviation itself is not used in the linked article. It's also worth noting that the proposal is about US infrastructure as a service (IaaS) products specifically, not "internet services" in general.

Yeah this is a very industry standard term in banking and anyone in that industry is going to immediately know what you are talking about, but outside of that industry, chances are high that a layman will not

Unfortunately, KYC has been bleeding into far more commercial interactions over time. I now deal with KYC multiple times per year in unrelated contexts and I don't work in finance. It has become quite intrusive.

Re: We have 4 days to contest KYC being required by internet services

#122

- "To Address the National Emergency" A fast-moving emergency that can't be fixed by normal constitutional lawmaking processes, and must resort, exceptionally, to executive-branch emergency decrees—for expedience. Nevermind the executive order it's drawing authority from was written three years ago. It was a fast-moving emergency then, too, I suppose. https://www.federalregister.gov/documents/2021/01/25/2021-01... (…

So national security trumps democracy and freedom? What do you have left to protect when you give it all up? Might as well just elect a king and be done with it.

Don't worry--we seem to be actively working on this one, too.

Re: We have 4 days to contest KYC being required by internet services

#123

For those who didn't know, KYC stands for "know your customer". It's a good idea to spell out abbreviations the first time they're used, especially since the abbreviation itself is not used in the linked article. It's also worth noting that the proposal is about US infrastructure as a service (IaaS) products specifically, not "internet services" in general.

[dead]

Re: We have 4 days to contest KYC being required by internet services

#124

Earlier quoted context omitted.

I don't disagree with your premise that KYC enables governments to violate the 4th amendment, but in general, for certain industries this is just generally a really good idea. Banking is the first industry where I encountered KYC, and it strikes me as being obviously good there. Isn't effectively the majority of what the Snowden leaks covered essentially violating the 4th amendment?

What is being proposed here will be used as a tool of fear by the government to suppress speech it doesn't like. Comparing what one individual did in the past to a formal government policy doxxing away peoples' 4th amendment rights is a strawman argument.

I think we don't understand each other. I'm not giving a moral or legal judgement on what Snowden in particular did. I'm saying, the information he disclosed showed a vast and total violation of American's 4th amendment rights on behalf of the US government.

This KYC requirement seems to me, at a glance, as being a small erosion of our digital privacy.

Re: We have 4 days to contest KYC being required by internet services

#125
post #101

For those who didn't know, KYC stands for "know your customer". It's a good idea to spell out abbreviations the first time they're used, especially since the abbreviation itself is not used in the linked article. It's also worth noting that the proposal is about US infrastructure as a service (IaaS) products specifically, not "internet services" in general.

It also looks like it only applies to foreign peoples? That said, I don’t know how you select for only foreigners without collecting identity.

Yeah that's a clever way to avoid having the rules struck down as unconstitutional. In practice though to avoid liability and possibly jail time, providers will have to assume that every customer is a foreigner until they "prove" their US citizenship (by uploading the same ID and other documentation required by foreigners).

Re: We have 4 days to contest KYC being required by internet services

#126
post #70

Earlier quoted context omitted.

I'm going to need another intelligence to read the full text. "U.S. IaaS providers and foreign resellers of U.S. IaaS products must exercise reasonable due diligence to ascertain the true identity of any customer or beneficial owner of an Account who claims to be a U.S. person." So at a minimum, everyone's identity is verified by IaaS provider. If you claim to be a non-U.S. person, additional information is collected…

Dreamhost, Wordpress, etc

Wordpress clearly does not meet the definition of IaaS in the document.

> provides processing, storage, networks, or other fundamental computing resources, and with which the consumer is able to deploy and run software that is not predefined, including operating systems and applications

Re: We have 4 days to contest KYC being required by internet services

#127
post #71
post #13

What an absolute nightmare. I would also be surprised if iaas providers arent in vehement opposition, i will instantly migrate all cloud resources away from AWS if they start requiring KYC docs. Theres close to zero effort for doing so

Wow, what layer of abstraction do you have that allows for that? Even with typical IaC, Terraform, it's going to be a rewrite. If you're leveraging anything beyond load balancers, compute, and containers I don't see how that approaches zero. Some of the services could end up with you having to build/run your own to get any equivalence.

Why is it so hard time for some of this site to understand that some of us are principled when it comes to choosing technologies? Or you know, actually learned from past trauma and make choice to avoid getting burned in the future.

Re: We have 4 days to contest KYC being required by internet services

#128
The talking point we should be using is: if banks know their customers, we don’t have to.

The trail of knowing ones customers always leads to payments and finance.

If we are accepting payment for our services with standard bank card transactions or wire transfers, etc., then the knowing of the customer can be centralized at the banks.

Re: We have 4 days to contest KYC being required by internet services

#129
And who pays for it. Yet another compliance procedure to add to the stack.

I propose that any new regulation gets financed by the the regulators . And retro actively get all regulations to have their cost covered by the government.

Who pays the auditors. Who pays Accountants, who paid for data protections schemes, who pays for random sanctions making countless companies suddenly lose large part of their business . Regulations are great, it should be at the government charge though, so that we can continue to do business, prevent market entry costs which promotes monopolies/oligopolies, encourage compliance.

Re: We have 4 days to contest KYC being required by internet services

#130

Earlier quoted context omitted.

Dreamhost, Wordpress, etc

This is not the industry-standard or NIST definitions of these terms. Something like Google Workspace Suite is Software as a Service. Something like Heroku (or Dreamhost or Wordpress) is Platform as a Service. Something like EC2 and S3 are Intrastructure as a Service. The distinction is renting out undifferentiated server space that a customer installs their own software onto. If you rent a VPS from Linode and instal…

Well, it may not be the industry standard definition, but it is the definition used in the actual regulation:

-------

Infrastructure as a Service product

or

IaaS product

means a product or service offered to a consumer, including complimentary or “trial” offerings, that provides processing, storage, networks, or other fundamental computing resources, and with which the consumer is able to deploy and run software that is not predefined, including operating systems and applications. The consumer typically does not manage or control most of the underlying hardware but has control over the operating systems, storage, and any deployed applications. The term is inclusive of “managed” products or services, in which the provider is responsible for some aspects of system configuration or maintenance, and “unmanaged” products or services, in which the provider is only responsible for ensuring that the product is available to the consumer. The term is also inclusive of “virtualized” products and services, in which the computing resources of a physical machine are split between virtualized computers accessible over the internet (

e.g.,

“virtual private servers”), and “dedicated” products or services in which the total computing resources of a physical machine are provided to a single person (

e.g.,

“bare-metal servers”).

---

So Dreamhost counts, any web host where you can run arbitrary PHP code would count. Wordpess.com -- where you cannot actually modify the PHP code yourself -- would not count as IaaS. But any web host that allows you to install applications on your own, or run any of your own code, would count as IaaS by this regulation.

Post reply on HN