Live data from Hacker News

We have 4 days to contest KYC being required by internet services

federalregister.gov

311–320 of 395 posts

Re: We have 4 days to contest KYC being required by internet services

#311
post #209

Earlier quoted context omitted.

Amazon is certainly supposed to ensure that you are not a sanctioned person or a citizen of a sanctioned country. This was a concern decades ago when I was in shared web hosting.. don't know why it would have changed?

When has big tech had a good history of proactive compliance?

AWS has a denied party screening team and absolutely restricts access to services based on the BIS entity list and other sanctioned parties.

Re: We have 4 days to contest KYC being required by internet services

#312
I work on KYC systems at a medium/large sized financial institution. The trend of adding KYC requirements to more and more online services is troubling.

KYC adds a huge burden to anyone trying to offer a service. Implementing KYC imposes significant burdens on service providers due to the complexity of identifying users across different countries and understanding varied regional regulations. You end up outsourcing your KYC to another company. But most KYC vendors don't support all the countries you want to support, so you either end up limiting your service to the service area of your KYC vendor. Or you end up integrating multiple vendors together, which is challenging since vendors generally prefer exclusivity.

If you didn't have an engineering team working on KYC before, you will now. You will likely need to add to or expand your compliance team. Your company will shift either slightly or significantly from being an engineering or product driven company to being a compliance driven company.

KYC raises barriers and entrenches incumbents. Look at financial institutions and porn.

KYC is generally not evidence based policy either [1, 2]. Bad actors get around your KYC requirements, and your KYC system ends up being a hurdle for innocent users. A lot of KYC systems rely on data aggregators (aka the people who buy your personal data), and if you aren't "in the system" either because you are young, poor, or privacy conscious, you are faced with suspicion.

My experience is that anti-fraud systems tend to weed out bad actors better than KYC systems that are mandated in a governmental top down manner.

1) https://www.economist.com/finance-and-economics/2021/04/12/t...

2) https://www.tandfonline.com/doi/full/10.1080/25741292.2020.1...

Re: We have 4 days to contest KYC being required by internet services

#313

Earlier quoted context omitted.

> Providers will supply anything the customer is willing to pay for. I suppose every company and every service should be in scope for KYC then. /s But the reality is that Wordpress hosts are not in the business of renting people dedicated servers the price of a nice house. And if they were asked to do so, it wouldn't be a simple automated request without scrutiny.

In 2010 it wouldn't have been an automated request. Now there is plenty of demand for it to do inference and some providers are likely to start offering it if they don't already. You're also assuming the providers are interested in preventing foreigners from using their systems for AI training, rather than being interested in making as much money as possible without violating the letter of the law. The latter is one…

I don't think anyone is under the presumption that these requirements are bulletproof. The point is to just target one big glaring loophole.

> $50,000/month? That would be almost everyone

It might be almost every individual developer. But that isn't really a huge cloud spend at all for an organization.

https://www.cloudzero.com/wp-content/uploads/2023/10/flexera...

But speaking of loopholes, what do you think bad actors would do if you told them that they weren't subject to KYC under a certain dollar amount? lol

Re: We have 4 days to contest KYC being required by internet services

#314
post #308

Earlier quoted context omitted.

> I see controversy and a lot of dissent among Justices, Precedent is set by the majority, not the dissent. > but no decisions that explicitly declare a Constitutional right to anonymity. Weird then that there are several decisions striking down laws that violate the right to anonymous speech? > And the modern Court explicitly declared that a Constitutional right to privacy does not exist, and one cannot have anonymi…

>One cannot refuse to turn over one's papers and effects in the absence of probable cause without privacy either. Yes. I believe a right to privacy once existed, but it was nullified as it formed the basis of the case for Roe V. Wade. As a result even the Fourth Amendment is weakened because it must be interpreted in the light of a right to privacy no longer existing. What I'm trying to put forth is that the assumpti…

> I believe a right to privacy once existed, but it was nullified as it formed the basis of the case for Roe V. Wade.

It was kind of the other way around. There is clearly no explicit right to abortion in the constitution, so to find one it would have to be implicit, but the Court in Roe wanted to find one, so they made one up. The reasoning was something like, the constitution implies there is a general right to privacy and laws against abortion violate it. The people who liked the result were then stuck trying to defend its inconsistent reasoning for 50 years, because the same logic would cause all kinds of other laws to be a violation of the same right. Obvious example would be drug prohibition; government invading your privacy by trying to control what you put into your own body. Same logic as Roe.

But Roe was never actually extended to any of that stuff, so overturning it didn't re-enable drug prohibition after it was struck down, since it was (inconsistently) never struck down to begin with.

The cases having to do with anonymous speech are independent and use entirely different logic. The general idea is that people are deterred from speaking (chilling effects) if people can associate what they have to say with a physical person who can then be harassed for expressing an unpopular opinion. It doesn't have any of the same problems because there is no First Amendment right to morphine, which they could ban outright under the same justification as they ban heroin, so having to show your ID to get morphine isn't deterring you from exercising your right to free speech.

Re: We have 4 days to contest KYC being required by internet services

#315
post #127
post #71

Earlier quoted context omitted.

Wow, what layer of abstraction do you have that allows for that? Even with typical IaC, Terraform, it's going to be a rewrite. If you're leveraging anything beyond load balancers, compute, and containers I don't see how that approaches zero. Some of the services could end up with you having to build/run your own to get any equivalence.

Why is it so hard time for some of this site to understand that some of us are principled when it comes to choosing technologies? Or you know, actually learned from past trauma and make choice to avoid getting burned in the future.

Exactly. At the startup I work for, we built from the old methods of bare metal, and integrate cloud services as needed. At any time though, if we are not satisfied with sed service, we're able to jump ship without headache pretty easily. As simple as spinning up a new container cluster elsewhere, migrating data, and ramping down the old. The founders were very clear on never being entrenched into a singular provider.

Re: We have 4 days to contest KYC being required by internet services

#316
post #128

The talking point we should be using is: if banks know their customers, we don’t have to. The trail of knowing ones customers always leads to payments and finance. If we are accepting payment for our services with standard bank card transactions or wire transfers, etc., then the knowing of the customer can be centralized at the banks.

Exactly. What is the point of repeating KYC across every industry? I work on the KYC team of a banking/finance company. It takes a significant amount of resources.

Unless we create global governing initiatives similar to FATF for IaaS products, American IaaS offering will become less competitive.

Re: We have 4 days to contest KYC being required by internet services

#317

Earlier quoted context omitted.

In 2010 it wouldn't have been an automated request. Now there is plenty of demand for it to do inference and some providers are likely to start offering it if they don't already. You're also assuming the providers are interested in preventing foreigners from using their systems for AI training, rather than being interested in making as much money as possible without violating the letter of the law. The latter is one…

I don't think anyone is under the presumption that these requirements are bulletproof. The point is to just target one big glaring loophole. > $50,000/month? That would be almost everyone It might be almost every individual developer. But that isn't really a huge cloud spend at all for an organization. https://www.cloudzero.com/wp-content/uploads/2023/10/flexera... But speaking of loopholes, what do you think bad act…

> It might be almost every individual developer. But that isn't really a huge cloud spend at all for an organization.

That's kind of the point. It excludes all of the individuals and small businesses and makes it unambiguous that it doesn't apply to someone paying $10/month for a VPS to use as a VPN endpoint for privacy.

> But speaking of loopholes, what do you think bad actors would do if you told them that they weren't subject to KYC under a certain dollar amount?

In some hypothetical world where the rules were actually effective? Spend $49,000 and then create a new account, which would be highly suspicious and still cause them to get caught.

In practice? Use a cooperative provider (Wells Fargo as a hosting company), or one in another country, the same as they would do regardless.

Re: We have 4 days to contest KYC being required by internet services

#318
post #307

Earlier quoted context omitted.

The converse would have to be true then, that the government has the legitimate power to intimidate people to not express their opinion. This does not seem like a legitimate power for government to have, but now I need to be careful whether I express it at all.

Laws against slander, libel, intimidation, conspiracy, perjury, etc are based upon the government's power to intimidate people from expressing opinions. It is a felony in the US to express the opinion that the President should be killed. Speech in the US has never been a free for all.

Those are not opinions, they're provably false statements or threats. Conspiracy is essentially committing a crime as a group rather than an individual, and the statements are the evidence of the crime rather than the crime in itself.

The closest the government comes to prohibiting an opinion is copyright, but even then you can restate the opinion in your own words, and when an exact quote is necessary to make your point it's fair use specifically because it would otherwise violate free speech.

Re: We have 4 days to contest KYC being required by internet services

#319

Earlier quoted context omitted.

What stops them? You could have a WordPress plugin that uses Stable Diffusion to generate images, or encodes uploaded video, or provides an AI chatbot, and needs fast GPUs because there are a lot of users. Providers will supply anything the customer is willing to pay for. The expected AI plugins would be doing inference rather than training, but the user could use the same hardware for plugins that do something else.

> Providers will supply anything the customer is willing to pay for. I suppose every company and every service should be in scope for KYC then. /s But the reality is that Wordpress hosts are not in the business of renting people dedicated servers the price of a nice house. And if they were asked to do so, it wouldn't be a simple automated request without scrutiny.

The whole SUV category of vehicles was spawned as a workaround for the 1975 Energy Policy and Conservation Act of 1975. Demand blocked by laws leads to weird mutations.

I'm thinking that this will simply promote cloud providers that operate outside America, sort of like Binance and FTX were "forced to exit" the US market. Not a bad result.

Re: We have 4 days to contest KYC being required by internet services

#320
post #167
post #78

Earlier quoted context omitted.

For example: CAN-SPAM. If I want to send emails to a list, I have to burn $90 of my scarce dollars every year just for a PO box for the address at the bottom on the off chance someone sends a letter to unsubscribe. Unless I want to put my home address in every email, which I don't, and no one should. Unsubscribe links and highly effective spam filters were already completely standard when the law was passed in 2003.…

Eh, unsubscribe links were definitely not universal in 2003 and they barely are today. But the situation has definitely improved in the last 20 years.

The point is the rules are daft. A sensible rule would require a functioning unsubscribe process in the email, which every piece of software would then automate as an unsubscribe link. The actual rule requires people to be able to unsubscribe via a postal mailing address, which is unreasonable and ridiculous.
Post reply on HN