Live data from Hacker News

We have 4 days to contest KYC being required by internet services

federalregister.gov

281–290 of 395 posts

Re: We have 4 days to contest KYC being required by internet services

#281
post #177

Earlier quoted context omitted.

Aren't you basically revealing yourself anyway because you need to pay them?

AWS has my name and my credit card number. But they have never asked for a photocopy of my passport, my history of international travel, which nationalities I have and so on. Something tells me that for the goal of this law to be achieved, all those details would need to enter the database.

If you rent a VPS in supposedly privacy-conscious Germany they need photo id too :(

Luckily there's other cheap options in Europe like in France.

Re: We have 4 days to contest KYC being required by internet services

#282
post #272

Earlier quoted context omitted.

Have you travelled between the UK and Ireland? You most definitely do not need a passport and do not need "equivalent ID". You can travel (by boat) with a student card, driving license, photographic travel pass (ie over-60s pass, young person rail pass), or photographic id from your work. The check is very much "don't stop walking but hold your ID-looking thing in your hand so a nonchalant man can glance at it". You…

> You need more than this to get on an aeroplane, but that also applies to domestic flights in the UK. Can you clarify what you mean by "more than this"? I've travelled on many domestic flights within the UK, and ID is not routinely checked. > If this was your best example of governments lying and changing the rules Ouch. The common travel area has its origins way back in 1923, the rules are clear, no-one is lying. I…

When did you last travel on a UK domestic flight? You definitely need government issued ID.

You are suggesting that having to show any photographic ID is the same as having to show a passport. That's obviously silly.

No one has to prove that "they are entitled to not show a passport" by showing British or Irish ID. This is a fantasy.

On the boat everyone, British, Irish or other, has to show ID of some kind. No one has to show a passport. At the land border no one has to show anything.

Re: We have 4 days to contest KYC being required by internet services

#283
post #276

Earlier quoted context omitted.

There is no right to anonymously express political opinions. There is a right to express political opinions, but anonymity is a privilege, not a right.

Then how do you explain these? https://cs.stanford.edu/people/eroberts/cs181/projects/anony...

I see controversy and a lot of dissent among Justices, but no decisions that explicitly declare a Constitutional right to anonymity.

And the modern Court explicitly declared that a Constitutional right to privacy does not exist, and one cannot have anonymity without privacy, so no.

Re: We have 4 days to contest KYC being required by internet services

#284
post #21

Skimming through the article, it seems like the extent of this is to require IAAS (Infrastructure) providers to verify the identity of those who are using their services to train AI. It's an attempt to stymie sanctioned or malicious actors, from training AI and especially from hopping between services or using aliases to continue training on their model. It seems a bit benign and I don't understand the parallels othe…

This won't work. Foreign nations have enough skill and resources to pass KYC as a citizen (steal someone's documents, pay a homeless for verification etc). And as I understand, US doesn't have a central citizen database so it is difficult to verify a document.

It's not meant to work.

Re: We have 4 days to contest KYC being required by internet services

#285
This will pass regardless of comments and KYC will only get more strict from here on out. What other end result could there have been when the combined gov-corp-tech behemoth is incredibly data-hungry, obsessed with draconian surveillance, and about to be deluged with malicious AI across the internet? It starts with "suspected" foreign actors and ends with everyone needing to prove their humanity for every little thing on the web. This is why we can't have nice things..

Re: We have 4 days to contest KYC being required by internet services

#286
post #70
post #27

Earlier quoted context omitted.

AI is mentioned, but the scope is significantly larger if you read the fulltext.

I'm going to need another intelligence to read the full text. "U.S. IaaS providers and foreign resellers of U.S. IaaS products must exercise reasonable due diligence to ascertain the true identity of any customer or beneficial owner of an Account who claims to be a U.S. person." So at a minimum, everyone's identity is verified by IaaS provider. If you claim to be a non-U.S. person, additional information is collected…

edit: Vultr info is wrong. They don't have anonymous use anymore.

Vultr, for example.

There are high-quality IaaS providers that accept bitcoin for payment, allowing someone to host a server on their platform without revealing their identity.

Re: We have 4 days to contest KYC being required by internet services

#287
post #70

Earlier quoted context omitted.

I'm going to need another intelligence to read the full text. "U.S. IaaS providers and foreign resellers of U.S. IaaS products must exercise reasonable due diligence to ascertain the true identity of any customer or beneficial owner of an Account who claims to be a U.S. person." So at a minimum, everyone's identity is verified by IaaS provider. If you claim to be a non-U.S. person, additional information is collected…

edit: Vultr info is wrong. They don't have anonymous use anymore. Vultr, for example. There are high-quality IaaS providers that accept bitcoin for payment, allowing someone to host a server on their platform without revealing their identity.

Vultur requires a card linked for ID verification even if paying for BTC. Or at least they did in the past when I tried.

Re: We have 4 days to contest KYC being required by internet services

#288
post #175

Earlier quoted context omitted.

It applies to any "software that is not predefined". An OS is just an non-exhaustive example of one type of software that applies.

The next sentence is: > The consumer [...] has control over the operating systems, storage, and any deployed applications. That was just a snippet of the full definition here: https://www.federalregister.gov/d/2024-01580/p-46

There are two possibilities here.

First, the rule applies to WordPress and all that kind of thing, and then providers would have to KYC WordPress users. Which is a reason not to pass it.

Second, the rule is completely pointless, because it doesn't, and then anyone could create an AI training WordPress plugin that uses whatever arbitrarily fast hardware the server has and thereby easily bypass the rule. Which is a reason not to pass it.

Re: We have 4 days to contest KYC being required by internet services

#289

Earlier quoted context omitted.

I think that the biggest argument in favour is that it would remove anonymity on the internet, at least from governments, and that could enable law enforcement to more easily find people committing real crimes. CSAM, scams, etc. I think the biggest argument against it is that this removes anonymity on the internet, at least from governments, and that would remove people's ability to freely voice their opinions withou…

Does this actually remove anonymity on the internet? It seems to de-anonymize a set of IaaS customers, sure; but that's not nearly the same thing as removing anonymity completely. I've only just scanned this but it seems at first glance to mean that a foreign company can't anonymously spin up an AWS instance, that's all. Am I reading this incorrectly?

The only away for US citizens to prove that they are such would be for them to also submit their IDs. So it affects everyone.

Basically, it forces providers of a very wide variety of tech related services to collect identifying info on anyone who uses their services, and then store that info to either eventually be exposed in a breach, subpoenaed by the government, or sold to the highest bidder (might as well monetize it if you're forced to collect it )

Re: We have 4 days to contest KYC being required by internet services

#290
post #21

Skimming through the article, it seems like the extent of this is to require IAAS (Infrastructure) providers to verify the identity of those who are using their services to train AI. It's an attempt to stymie sanctioned or malicious actors, from training AI and especially from hopping between services or using aliases to continue training on their model. It seems a bit benign and I don't understand the parallels othe…

Skimming the regulations, this does not seem right. All IAAS providers (which is everyone who allows customers to run custom code, so it includes any web host like Dreamhost) to verify the identity of foreigners who open an account. This would seemingly entail the service provider needing to verify everyone's identity, in order to figure out who is a foreigner and who is not. In other words, if you want to run your o…

Good. It’s not 1999.

There are so many malicious actors putting human life at risk in some scenarios it should be possible to figure out who owns what.

Now, I would start with corporate ownership and focus on anonymous entities controlling things like Delaware and Nevada corporations. But that’s me.

Post reply on HN