Live data from Hacker News

We have 4 days to contest KYC being required by internet services

federalregister.gov

231–240 of 395 posts

Re: We have 4 days to contest KYC being required by internet services

#231
post #21

Skimming through the article, it seems like the extent of this is to require IAAS (Infrastructure) providers to verify the identity of those who are using their services to train AI. It's an attempt to stymie sanctioned or malicious actors, from training AI and especially from hopping between services or using aliases to continue training on their model. It seems a bit benign and I don't understand the parallels othe…

On top of that, it is to identify FOREIGN users

>>"require U.S. IaaS providers to verify the identity of foreign users of U.S. IaaS products, ... which calls for the Department to require U.S. IaaS providers to ensure that their foreign resellers verify the identity of foreign users. E.O. 14110 also provides the Department with authority to require U.S. IaaS providers submit a report to the Department whenever a foreign person transacts with them to train a large AI model with potential capabilities that could be used in malicious cyber-enabled activity."

We damn well SHOULD be identifying foreign users of our services, particularly those which have high-powered potential to cause harm.

This knee-jerk [govt identifying anybody is bad] response prevalent here deeply undermines the cause of actually maintaining privacy. There are actually very bad actors out there, and if we fail to identify and contain them, things will be far worse. The reality is that some measures must be taken — let's focus on containing the real threats, not cry foul at every shadow of a hint that we might approach a slippery slope.

Re: We have 4 days to contest KYC being required by internet services

#232

Earlier quoted context omitted.

So national security trumps democracy and freedom? What do you have left to protect when you give it all up? Might as well just elect a king and be done with it.

There's an argument to be made that we would be far better off with a benevolent monarchy than whatever this is.

If we ever could find a Superman who would agree to be a benevolent monarch, sure. The only problem is that Superman is actually a work of fiction (and even a fictional one would refuse the role) and real people have, let's say, not so stellar record of being benevolent. It's one of those nice ideal arguments that works very well as long as you are allowed to assume magical entities that can't actually exist in the real world.

Re: We have 4 days to contest KYC being required by internet services

#233
There's a surprising amount of debate in this thread on the rights and wrongs of this topic.

As a matter of simple efficiency, what I suggest to you all is that you imagine this was being rolled out by the British government.

Because then you'd all be certain what it meant and what was necessary.

Re: We have 4 days to contest KYC being required by internet services

#234
post #21

Skimming through the article, it seems like the extent of this is to require IAAS (Infrastructure) providers to verify the identity of those who are using their services to train AI. It's an attempt to stymie sanctioned or malicious actors, from training AI and especially from hopping between services or using aliases to continue training on their model. It seems a bit benign and I don't understand the parallels othe…

> It seems a bit benign This seems, to me, an utterly malignant attack on anonymity, which is a protected constitutional right. It's the idea that every internet packet needs to be tied back to some verified identity. We're in frog-boiling territory with this garbage.

There is no absolute right to anonymity in the US constitution.

(The courts have "recognized relatively strong First Amendment presumptions on behalf of purveyors of anonymous speech, especially for those that are statements of opinions rather than obvious falsehoods, while recognizing that government sometimes has the right to identify such speakers when they have used their platforms to harass, engage in slander or sexual predation, make true threats, or allow foreign governments to influence U.S. elections")

Re: We have 4 days to contest KYC being required by internet services

#235
post #180

Earlier quoted context omitted.

> * gives them a "reasonable belief that it knows the true identity of each customer" > * and "a sound basis to verify the true identity of their customer and beneficial owners and reflect reasonable due diligence efforts". I'm reading in to that in a conservative manner where it's "internally justified" that going the full privacy abusive route is justified. "Reasonable due diligence" is respective to the organizati…

If the business is not a "trustable entity", then why are you using them for hosting?

You have no choice.

Going down the argument of "don't use anyone you don't trust" brings up the argument of.. well why are you paying Experian?

Where I'm getting to this is: We often times don't have a choice, that choice that looks like we have it is untrustable in the future, and we're being aggressively pushed into a situation where you have people of questionable interests. This rule/law encourages them to collect it, but there's no aggressive lifestyle ending punishments for crossing the line.

Re: We have 4 days to contest KYC being required by internet services

#236
post #177

Earlier quoted context omitted.

Aren't you basically revealing yourself anyway because you need to pay them?

AWS has my name and my credit card number. But they have never asked for a photocopy of my passport, my history of international travel, which nationalities I have and so on. Something tells me that for the goal of this law to be achieved, all those details would need to enter the database.

[flagged]

Re: We have 4 days to contest KYC being required by internet services

#237

Earlier quoted context omitted.

Why elect a king when you already have a private group of bankers running the show

Systems run the show, not people. "What important truth do very few people agree with you on?": I believe that nobody is running the show. The systems we have created are more complex than we understand. I think a few people individually understand a few aspects of the different systems (we are not at the complete mercy to these systems). I also believe that we have a psycological need to know our social heirachies t…

I mean, a monarchy is also a system, but I also recognize that's not what you're talking about.

I'm inclined to agree, though I do think there's a disproportionate amount of influence in some groups. I also worry that the true danger of an artificial super-intelligence is not in a SkyNet-like scenario, but a more subtle and slower influence over global societies via trade and economics. It already more or less runs the world in abstract, so a thing that can understand all the complexities and manipulate them with capital has the potential to be very dangerous.

Re: We have 4 days to contest KYC being required by internet services

#238
post #235

Earlier quoted context omitted.

If the business is not a "trustable entity", then why are you using them for hosting?

You have no choice. Going down the argument of "don't use anyone you don't trust" brings up the argument of.. well why are you paying Experian? Where I'm getting to this is: We often times don't have a choice, that choice that looks like we have it is untrustable in the future, and we're being aggressively pushed into a situation where you have people of questionable interests. This rule/law encourages them to collec…

??? There's nobody forcing you to have an account at a cloud provider. There are many other choices.

If you really do not trust someone else to operate a computer on your behalf, you can operate one yourself.

Re: We have 4 days to contest KYC being required by internet services

#239

Idea: let's make it so all emergency powers have to be re-authorized every week by Congress at midnight on Friday with a 90% quorum of physically-present representatives. If "emergency" action is needed because Congress is too slow, then let's make sure they are working through the process to create real law. Or if they aren't, I guess it wasn't an emergency, and there's no reason for administrative law to "fill in"…

Great! I'm looking forward to seeing this requirement applied to also dissolve the judicial branch entirely so that Congress is entirely responsible for both enforcment and adjudication of the law. Let's work together to end separation of powers.

Re: We have 4 days to contest KYC being required by internet services

#240
post #21

Skimming through the article, it seems like the extent of this is to require IAAS (Infrastructure) providers to verify the identity of those who are using their services to train AI. It's an attempt to stymie sanctioned or malicious actors, from training AI and especially from hopping between services or using aliases to continue training on their model. It seems a bit benign and I don't understand the parallels othe…

From the executive order (Executive Order 14110) it seems to affect only massive compute infrastructure: > (i) any model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations, or using primarily biological sequence data and using a quantity of computing power greater than 10^23 integer or floating-point operations; and > (ii) any computing cluster that has a set…

No, that is just one part of it. The proposed rules are intended to cover both EO13984, which addresses foreign entities using US IaaS for Cyber attacks, and EO14110 which addresses foreign entities using AI hardware.

They require all IaaS[1] to determine if customers are US persons, and if not to collect and retain certain identifying information[2], and provide annual reports describing their processes[3]. It grants the Secretary of Commerce extra-judicial power to force any IaaS to stop doing business with any foreign customer, or place restrictions on their use[4]. This section lists things that the Secretary should consider in doing so, but doesn't have any hard requirements. Finally, it requires the IaaS to report certain foreign use of AI[5].

[1]§7.301 https://www.federalregister.gov/d/2024-01580/p-189

[2]§7.302 https://www.federalregister.gov/d/2024-01580/p-219

[3]§7.304 https://www.federalregister.gov/d/2024-01580/p-266

[4]§7.307 https://www.federalregister.gov/d/2024-01580/p-377

[5]§7.308 https://www.federalregister.gov/d/2024-01580/p-403

Post reply on HN