Live data from Hacker News

We have 4 days to contest KYC being required by internet services

federalregister.gov

201–210 of 395 posts

Re: We have 4 days to contest KYC being required by internet services

#201
post #176
post #156

Earlier quoted context omitted.

We're in a permanent emergency now. Which is no surprise - if a mere voluntary act of declaring emergency lets the government do what they otherwise can't - why not declare it over and over? Check this out: https://en.wikipedia.org/wiki/List_of_national_emergencies_i... In the US we have 42 (!) ongoing national emergencies. The oldest dating back to 1979. I think most of US-based HN readers never lived in non-emergen…

They are declared in an emergency (most of them are sanctions to freeze money and freedoms of foreigners). That does not mean you live in an emergency. That they are still active means only that the Parlament was too lazy or too blocked to put them in a law.

Legally, it means exactly that - the government wasn't allowed to do X, but they said the magic word "emergency", and now they are allowed to do X as much as they want, until they decide they are done. Of course, this means they were always allowed to do X, it's just that the public will eat it more easily if instead of saying "the government can take your freedoms anytime" they'd say "the government can't take you freedom ever - except if there's a real dangerous emergency". Functionally, those are exactly the same, but the latter sounds much more "reasonable".

Re: We have 4 days to contest KYC being required by internet services

#203
post #183

Earlier quoted context omitted.

There are IaaS services out there that accept bitcoin, monero, or anonymous prepaid charge cards. They aren't an IaaS but Mullvad even accepts cash mailed to them in an envelope.

Is it fair to assume, that one can engage in a business relationship with these services outside the US? I'm not sure I see the effect that you are implying. AWS, GCP, Azure don't accept crypto. Mullvad is as you point out not an IaaS provider.

Namecheap, Vultr, BuyVm all operate in the U.S. and at times in the past (I don't know if they still do) have either accepted crypto or anonymous charge cards (available for cash at a convenience store), thus making it possible to get a dedicated server or VM totally anonymously. This new regulation would seem to prevent this.

Re: We have 4 days to contest KYC being required by internet services

#204
Controversial point: if you run a Internet presence of any kind, this is like a property of land on which you run business. The property needs also a legal owner. For real businesses, this is normal. It is unregulated IT who does not understand this and is still in the wild West.

Obviously, modern data processing creates the rightful fear of surveillance. What we lack is a culture of privacy. In other countries if the state or anyone else wants to access the land registry or any other: good luck without a lawful reason.

Re: We have 4 days to contest KYC being required by internet services

#205
post #172
post #156

Earlier quoted context omitted.

We're in a permanent emergency now. Which is no surprise - if a mere voluntary act of declaring emergency lets the government do what they otherwise can't - why not declare it over and over? Check this out: https://en.wikipedia.org/wiki/List_of_national_emergencies_i... In the US we have 42 (!) ongoing national emergencies. The oldest dating back to 1979. I think most of US-based HN readers never lived in non-emergen…

That’d be September 1978 – November 1979 and before then during the roaring twenties if I read this right. Maybe POTUS should declare an emergency to reduce the number of emergencies?

Looks like that's exactly how they got a full non-emergency year: https://en.wikipedia.org/wiki/Report_of_the_Special_Committe...

Of course, it didn't last long - as soon as the focus moved on, emergencies started popping back up.

Re: We have 4 days to contest KYC being required by internet services

#206

Earlier quoted context omitted.

Yeah that's a clever way to avoid having the rules struck down as unconstitutional. In practice though to avoid liability and possibly jail time, providers will have to assume that every customer is a foreigner until they "prove" their US citizenship (by uploading the same ID and other documentation required by foreigners).

Resulting in AT&T 2.0 data breach. Already dealing with the consequences of our SSN#s being leaked in AT&T 1.0 breach.

Can you name some of those consequences?

Re: We have 4 days to contest KYC being required by internet services

#207

Earlier quoted context omitted.

You cannot install Debian or Windows 11 on Wordpress.

I think it’s most reasonable to read that as “includes [all of these examples]” not “excludes if it can’t [any of these examples]” AWS Lambda would clearly (IMO) be in-scope as IaaS by this definition, as an example, even though I can’t install another OS.

AWS Lambda qualifies because it is part of AWS and an AWS account gives you access to EC2 which definitely qualifies.

Re: We have 4 days to contest KYC being required by internet services

#208
post #163

Earlier quoted context omitted.

It seems the definition of IaaS Products could very well extend to ISPs: https://www.federalregister.gov/d/2024-01580/p-46 > This proposed definition adopts the E.O. 13984 definition for “Infrastructure as a Service product”, which is any product or service offered to a consumer, including complimentary or “trial” offerings, that provides processing, storage, networks , or other fundamental computing resources, and w…

I can't see how an ISP (or VPN for that matter) would qualify for the second half " and with which the consumer is able to deploy and run software that is not predefined, including operating systems and applications." This would apply to all hosting providers, which is bad enough.

Internet connections can be used to SSH into a box to deploy and run software. IANAL, but I could see that catching ISP's and VPN's.

Re: We have 4 days to contest KYC being required by internet services

#209
post #177

Earlier quoted context omitted.

AWS has my name and my credit card number. But they have never asked for a photocopy of my passport, my history of international travel, which nationalities I have and so on. Something tells me that for the goal of this law to be achieved, all those details would need to enter the database.

Amazon is certainly supposed to ensure that you are not a sanctioned person or a citizen of a sanctioned country. This was a concern decades ago when I was in shared web hosting.. don't know why it would have changed?

When has big tech had a good history of proactive compliance?

Re: We have 4 days to contest KYC being required by internet services

#210
post #187

Earlier quoted context omitted.

So national security trumps democracy and freedom? What do you have left to protect when you give it all up? Might as well just elect a king and be done with it.

Its long been this way. Even in the 1950s the were fed justices commenting that if a nuclear bomb were to be stolen, its retrieval would be a reasonable predicate justifying suspension of the bill of rights until the warhead's retrieval.

Ironically enough, we’d already lost one by then: https://nationalinterest.org/blog/reboot/us-military-missing...
Post reply on HN