Live data from Hacker News

We have 4 days to contest KYC being required by internet services

federalregister.gov

141–150 of 395 posts

Re: We have 4 days to contest KYC being required by internet services

#141
post #46

Earlier quoted context omitted.

Legally speaking, internet service providers are infrastructure providers.

Do you have a basis for this claim or are you just throwing it out there to see if it catches on? The document linked refers to IaaS, which as an acronym definitely does not include ISPs.

Reading the definition https://www.federalregister.gov/d/2024-01580/p-46 and the paragraph following it, it's intentionally broad and i'd say it's not that much of a stretch to say ISPs provide services that match this.

Re: We have 4 days to contest KYC being required by internet services

#142
post #111

Earlier quoted context omitted.

At a quick reading, it doesn't sound like those are requirements. It also doesn't look like any documentation is technically required. One of the methods permitted is "Verification through non-documentary methods".

Do you mind expanding on what "non-documentary methods" means?

It is all defined in TFA:

https://www.federalregister.gov/documents/2024/01/29/2024-01...

The TL;DR is that it can be whatever the provider wants, as long as it:

* includes name, address, email, phone number, IP address, and payment information,

* is written down,

* gives them a "reasonable belief that it knows the true identity of each customer"

* and "a sound basis to verify the true identity of their customer and beneficial owners and reflect reasonable due diligence efforts".

Re: We have 4 days to contest KYC being required by internet services

#143

Earlier quoted context omitted.

Skimming the regulations, this does not seem right. All IAAS providers (which is everyone who allows customers to run custom code, so it includes any web host like Dreamhost) to verify the identity of foreigners who open an account. This would seemingly entail the service provider needing to verify everyone's identity, in order to figure out who is a foreigner and who is not. In other words, if you want to run your o…

Aren't you basically revealing yourself anyway because you need to pay them?

There are IaaS services out there that accept bitcoin, monero, or anonymous prepaid charge cards. They aren't an IaaS but Mullvad even accepts cash mailed to them in an envelope.

Re: We have 4 days to contest KYC being required by internet services

#144
post #111

Earlier quoted context omitted.

At a quick reading, it doesn't sound like those are requirements. It also doesn't look like any documentation is technically required. One of the methods permitted is "Verification through non-documentary methods".

Do you mind expanding on what "non-documentary methods" means?

[deleted]

Re: We have 4 days to contest KYC being required by internet services

#145

Earlier quoted context omitted.

KYC in the context of internet services stands for "violating the 4th Amendment".

I don't disagree with your premise that KYC enables governments to violate the 4th amendment, but in general, for certain industries this is just generally a really good idea. Banking is the first industry where I encountered KYC, and it strikes me as being obviously good there. Isn't effectively the majority of what the Snowden leaks covered essentially violating the 4th amendment?

>Banking is the first industry where I encountered KYC, and it strikes me as being obviously good there.

This is not obvious to me as my experience has been largely negative post-KYC/9-11 vs pre-KYC/9-11. I am a legal law abiding citizen [and voter!] and it's just added extra hassle on various occasions and then the background anxiety of knowing an institution with crappy security track records hold a photocopy of my ID. And yet all the things KYC was supposed to prevent still continue unabated: money laundering, terrorist financing, identity theft, and financial fraud.

I'm curious to hear why you think it's obviously good and if you were using these services before KYC.

Re: We have 4 days to contest KYC being required by internet services

#147
post #21

Skimming through the article, it seems like the extent of this is to require IAAS (Infrastructure) providers to verify the identity of those who are using their services to train AI. It's an attempt to stymie sanctioned or malicious actors, from training AI and especially from hopping between services or using aliases to continue training on their model. It seems a bit benign and I don't understand the parallels othe…

This won't work. Foreign nations have enough skill and resources to pass KYC as a citizen (steal someone's documents, pay a homeless for verification etc). And as I understand, US doesn't have a central citizen database so it is difficult to verify a document.

Re: We have 4 days to contest KYC being required by internet services

#148

Earlier quoted context omitted.

This doesn't seem to affect users of internet services, though. It's just IaaS, so things like AWS. With that limited scope, what is the adverse affect of KYC laws on freedom of speech?

It affects all web hosts, so if you want to lease a server in order to install Wordpress or Mastodon you would need to submit your identification to the provider.

I think it effectively affects all web hosts… Certainly how we expect them to work in 2024…

But remember that you can have a perfectly effective web host that simply accepts HTML uploads.

Certainly a tremendous loss of convenience and features but speech itself could still be available under this regime…

Re: We have 4 days to contest KYC being required by internet services

#149

Earlier quoted context omitted.

Dreamhost, Wordpress, etc

Wordpress clearly does not meet the definition of IaaS in the document. > provides processing, storage, networks, or other fundamental computing resources, and with which the consumer is able to deploy and run software that is not predefined, including operating systems and applications

Can you not add plugins to Wordpress?
Post reply on HN