Earlier quoted context omitted.
What is being proposed here will be used as a tool of fear by the government to suppress speech it doesn't like. Comparing what one individual did in the past to a formal government policy doxxing away peoples' 4th amendment rights is a strawman argument.
I think we don't understand each other. I'm not giving a moral or legal judgement on what Snowden in particular did. I'm saying, the information he disclosed showed a vast and total violation of American's 4th amendment rights on behalf of the US government. This KYC requirement seems to me, at a glance, as being a small erosion of our digital privacy.
We have 4 days to contest KYC being required by internet services
131–140 of 395 posts
Re: We have 4 days to contest KYC being required by internet services
#132Submission Statement: We have exactly 4 days to leave comments to the Federal Government of the United States of America contesting the requirement of KYC by internet service providers. This law is not conducive to a free internet/society.
I ask this 100% genuinely, since this isn't a subject I've ever given any mind to. Why should we oppose this? What are the potential negative outcomes if this goes through? Can you steelman the argument for why people support this, and explain why you find the arguments unconvincing?
Re: We have 4 days to contest KYC being required by internet services
#133Re: We have 4 days to contest KYC being required by internet services
#134Skimming through the article, it seems like the extent of this is to require IAAS (Infrastructure) providers to verify the identity of those who are using their services to train AI. It's an attempt to stymie sanctioned or malicious actors, from training AI and especially from hopping between services or using aliases to continue training on their model. It seems a bit benign and I don't understand the parallels othe…
Skimming the regulations, this does not seem right. All IAAS providers (which is everyone who allows customers to run custom code, so it includes any web host like Dreamhost) to verify the identity of foreigners who open an account. This would seemingly entail the service provider needing to verify everyone's identity, in order to figure out who is a foreigner and who is not. In other words, if you want to run your o…
Re: We have 4 days to contest KYC being required by internet services
#135For those who didn't know, KYC stands for "know your customer". It's a good idea to spell out abbreviations the first time they're used, especially since the abbreviation itself is not used in the linked article. It's also worth noting that the proposal is about US infrastructure as a service (IaaS) products specifically, not "internet services" in general.
In practice this often means requiring a photo ID scan.
Re: We have 4 days to contest KYC being required by internet services
#136Earlier quoted context omitted.
Is it? How? Which bit of KYC for SaaS violates which right?
Isn't this a clear violation of the 4th amendment? > “The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no Warrants shall issue, but upon probable cause, supported by Oath or affirmation, and particularly describing the place to be searched, and the persons or things ... Note it says "the people" and not "citizens…
Banks collecting KYC actually started with the Banking Secrecy Act of 1970. This was tried in the Supreme Court case California Bankers Association v Schultz (1974). It holds that recordkeeping requirements do not constitute a privacy violation under the 4th amendment absent reporting requirements. Since this new rule (2024) applies only to foreign entities and OFAC controls provide penalties for domestic companies, there’s no fifth amendment issue either (which is a shame imo, the 5th amendment argument in Bankers v Schultz seems incredibly shaky).
There’s no reporting requirements or new crime being created here; the intention is to “”aid”” IaaS providers in complying with OFAC requirements, and, when a warrant is issued, the actual identities of the customers to be known.
Re: We have 4 days to contest KYC being required by internet services
#137- "To Address the National Emergency" A fast-moving emergency that can't be fixed by normal constitutional lawmaking processes, and must resort, exceptionally, to executive-branch emergency decrees—for expedience. Nevermind the executive order it's drawing authority from was written three years ago. It was a fast-moving emergency then, too, I suppose. https://www.federalregister.gov/documents/2021/01/25/2021-01... (…
So national security trumps democracy and freedom? What do you have left to protect when you give it all up? Might as well just elect a king and be done with it.
Re: We have 4 days to contest KYC being required by internet services
#138Earlier quoted context omitted.
In the past that would be true. But given most blockchain platforms require it, I imagine it is more widely known in the tech-savy hn-like realms? Then again I worked on blockchain tech around half a decade ago, so I might be knowledge biased here?
Definitely biased. I had no idea what KYC means. I don't think typing it out fully once at the beginning is too much to ask, is it?
KYC is essentially about knowing who you are doing business with.
For individuals that's relatively easy, just the name and identification is required but typically there is the need to verify that the identification actually belongs to the person signing up. In banking that's why you typically have some video call with a verification provider.
For businesses it gets a lot more complex because it's not enough to know what business your client is, you also have to look through its corporate structure to figure out who the "ultimate beneficial owner" is. Essentially, who is actually controlling the business.
Now it got a lot easier recently as many countries now require businesses to file who their ultimate beneficial owners (UBOs) are.
The painful part is that it introduces friction in customer journeys as now you have to request the documentation.
In the financial industry you also have to run checks on those UBO's so that they are not known terrorists or sanctioned individuals but it seems this regulation is just that IaaS providers need to know who actually operates a server. Presumably for forensic analysis after a cyber attack.
Re: We have 4 days to contest KYC being required by internet services
#139Earlier quoted context omitted.
It also looks like it only applies to foreign peoples? That said, I don’t know how you select for only foreigners without collecting identity.
Yeah that's a clever way to avoid having the rules struck down as unconstitutional. In practice though to avoid liability and possibly jail time, providers will have to assume that every customer is a foreigner until they "prove" their US citizenship (by uploading the same ID and other documentation required by foreigners).