We have 4 days to contest KYC being required by internet services(federalregister.gov)
federalregister.gov
We have 4 days to contest KYC being required by internet services
https://www.federalregister.gov/documents/2024/01/29/2024-01580/taking-additional-steps-to-address-the-national-emergency-with-respect-to-significant-malicious
372 comments
What an absolute nightmare. I would also be surprised if iaas providers arent in vehement opposition, i will instantly migrate all cloud resources away from AWS if they start requiring KYC docs. Theres close to zero effort for doing so
I work on KYC systems at a medium/large sized financial institution. The trend of adding KYC requirements to more and more online services is troubling.
KYC adds a huge burden to anyone trying to offer a service. Implementing KYC imposes significant burdens on service providers due to the complexity of identifying users across different countries and understanding varied regional regulations. You end up outsourcing your KYC to another company. But most KYC vendors don't support all the countries you want to support, so you either end up limiting your service to the service area of your KYC vendor. Or you end up integrating multiple vendors together, which is challenging since vendors generally prefer exclusivity.
If you didn't have an engineering team working on KYC before, you will now. You will likely need to add to or expand your compliance team. Your company will shift either slightly or significantly from being an engineering or product driven company to being a compliance driven company.
KYC raises barriers and entrenches incumbents. Look at financial institutions and porn.
KYC is generally not evidence based policy either [1, 2]. Bad actors get around your KYC requirements, and your KYC system ends up being a hurdle for innocent users. A lot of KYC systems rely on data aggregators (aka the people who buy your personal data), and if you aren't "in the system" either because you are young, poor, or privacy conscious, you are faced with suspicion.
My experience is that anti-fraud systems tend to weed out bad actors better than KYC systems that are mandated in a governmental top down manner.
1) https://www.economist.com/finance-and-economics/2021/04/12/t...
2) https://www.tandfonline.com/doi/full/10.1080/25741292.2020.1...
KYC adds a huge burden to anyone trying to offer a service. Implementing KYC imposes significant burdens on service providers due to the complexity of identifying users across different countries and understanding varied regional regulations. You end up outsourcing your KYC to another company. But most KYC vendors don't support all the countries you want to support, so you either end up limiting your service to the service area of your KYC vendor. Or you end up integrating multiple vendors together, which is challenging since vendors generally prefer exclusivity.
If you didn't have an engineering team working on KYC before, you will now. You will likely need to add to or expand your compliance team. Your company will shift either slightly or significantly from being an engineering or product driven company to being a compliance driven company.
KYC raises barriers and entrenches incumbents. Look at financial institutions and porn.
KYC is generally not evidence based policy either [1, 2]. Bad actors get around your KYC requirements, and your KYC system ends up being a hurdle for innocent users. A lot of KYC systems rely on data aggregators (aka the people who buy your personal data), and if you aren't "in the system" either because you are young, poor, or privacy conscious, you are faced with suspicion.
My experience is that anti-fraud systems tend to weed out bad actors better than KYC systems that are mandated in a governmental top down manner.
1) https://www.economist.com/finance-and-economics/2021/04/12/t...
2) https://www.tandfonline.com/doi/full/10.1080/25741292.2020.1...
For those who didn't know, KYC stands for "know your customer". It's a good idea to spell out abbreviations the first time they're used, especially since the abbreviation itself is not used in the linked article. It's also worth noting that the proposal is about US infrastructure as a service (IaaS) products specifically, not "internet services" in general.
Submission Statement:
We have exactly 4 days to leave comments to the Federal Government of the United States of America contesting the requirement of KYC by internet service providers.
This law is not conducive to a free internet/society.
We have exactly 4 days to leave comments to the Federal Government of the United States of America contesting the requirement of KYC by internet service providers.
This law is not conducive to a free internet/society.
The talking point we should be using is: if banks know their customers, we don’t have to.
The trail of knowing ones customers always leads to payments and finance.
If we are accepting payment for our services with standard bank card transactions or wire transfers, etc., then the knowing of the customer can be centralized at the banks.
The trail of knowing ones customers always leads to payments and finance.
If we are accepting payment for our services with standard bank card transactions or wire transfers, etc., then the knowing of the customer can be centralized at the banks.
Simple ID scans are already on their way out.
"Liveness checks" where we have to turn on our webcam and let some stranger make a full biometric model of our head to use basic internet infrastructure is the dystopia we deserve, and it's the one we're gonna get.
I hope the "AI" was worth it. Let's see if you can fix this problem you created.
"Liveness checks" where we have to turn on our webcam and let some stranger make a full biometric model of our head to use basic internet infrastructure is the dystopia we deserve, and it's the one we're gonna get.
I hope the "AI" was worth it. Let's see if you can fix this problem you created.
For those of us who don't know what this is, an explanation is a bit down the page:
> To address these threats, the President issued E.O. 13984, “Taking Additional Steps To Address the National Emergency With Respect to Significant Malicious Cyber-Enabled Activities,” which provides the Department with authority to require U.S. IaaS providers to verify the identity of foreign users of U.S. IaaS products, to issue standards and procedures that the Department may use to make a finding to exempt IaaS providers from such a requirement, to impose recordkeeping obligations with respect to foreign users of U.S. IaaS products, and to limit certain foreign actors' access to U.S. IaaS products in appropriate circumstances. The President subsequently issued E.O. 14110, “Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence,” which calls for the Department to require U.S. IaaS providers to ensure that their foreign resellers verify the identity of foreign users. E.O. 14110 also provides the Department with authority to require U.S. IaaS providers submit a report to the Department whenever a foreign person transacts with them to train a large AI model with potential capabilities that could be used in malicious cyber-enabled activity.
> To address these threats, the President issued E.O. 13984, “Taking Additional Steps To Address the National Emergency With Respect to Significant Malicious Cyber-Enabled Activities,” which provides the Department with authority to require U.S. IaaS providers to verify the identity of foreign users of U.S. IaaS products, to issue standards and procedures that the Department may use to make a finding to exempt IaaS providers from such a requirement, to impose recordkeeping obligations with respect to foreign users of U.S. IaaS products, and to limit certain foreign actors' access to U.S. IaaS products in appropriate circumstances. The President subsequently issued E.O. 14110, “Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence,” which calls for the Department to require U.S. IaaS providers to ensure that their foreign resellers verify the identity of foreign users. E.O. 14110 also provides the Department with authority to require U.S. IaaS providers submit a report to the Department whenever a foreign person transacts with them to train a large AI model with potential capabilities that could be used in malicious cyber-enabled activity.
> (e) The term “Infrastructure as a Service Product” means any product or service offered to a consumer, including complimentary or “trial” offerings, that provides processing, storage, networks, or other fundamental computing resources, and with which the consumer is able to deploy and run software that is not predefined, including operating systems and applications. The consumer typically does not manage or control most of the underlying hardware but has control over the operating systems, storage, and any deployed applications. The term is inclusive of “managed” products or services, in which the provider is responsible for some aspects of system configuration or maintenance, and “unmanaged” products or services, in which the provider is only responsible for ensuring that the product is available to the consumer. The term is also inclusive of “virtualized” products and services, in which the computing resources of a physical machine are split between virtualized computers accessible over the internet (e.g., “virtual private servers”), and “dedicated” products or services in which the total computing resources of a physical machine are provided to a single person (e.g., “bare-metal” servers);
This is a good overview https://www.akingump.com/en/insights/alerts/commerce-issues-...
I read the document a bit, it seems like this is essentially saying that services like AWS need to know the identity of their customer if they suspect they are a foreign entity.
I don't think this would cover VPNs or internet access, mainly just people spending lots of $$ on compute. Is that correct? If so it seems reasonable. If a non US group is spending lots of money using US technology to develop an AI model I do think that falls under foreign trade and should be documented.
I don't think this would cover VPNs or internet access, mainly just people spending lots of $$ on compute. Is that correct? If so it seems reasonable. If a non US group is spending lots of money using US technology to develop an AI model I do think that falls under foreign trade and should be documented.
There's a surprising amount of debate in this thread on the rights and wrongs of this topic.
As a matter of simple efficiency, what I suggest to you all is that you imagine this was being rolled out by the British government.
Because then you'd all be certain what it meant and what was necessary.
As a matter of simple efficiency, what I suggest to you all is that you imagine this was being rolled out by the British government.
Because then you'd all be certain what it meant and what was necessary.
Can anyone glean from this wall of text what documents Uncle Sam is going to expect me, a dirty and potentially smelly foreigner, to submit in order to keep my AWS account?
I suppose VPN's will become illegal next?
As if KYC for bank accounts was an astounding success on international crime, corruption and terrorism financing.
This will pass regardless of comments and KYC will only get more strict from here on out. What other end result could there have been when the combined gov-corp-tech behemoth is incredibly data-hungry, obsessed with draconian surveillance, and about to be deluged with malicious AI across the internet? It starts with "suspected" foreign actors and ends with everyone needing to prove their humanity for every little thing on the web. This is why we can't have nice things..
This does not appear to affect domestic customers.
This is about foreign customers only, so as an attempt to abolish the constitution, it is severely flawed in respecting it enough to keep its distance.
I can't think of any US service I am using that doesn't already require KYC? None of the large providers will let you get far without a credit card, as far as I remember?
Since the discussion here will consider itself mostly with upright revolutionaries being disenfranchised by such insult to their liberties, it is worth noting that when the revolutionaries are foreigners, the US often doesn't have the same incentive to disenfranchise them as it might have for domestic troublemakers.
In fact the US has quite a track record of granting rights to foreigners in excess of what they find at home, and even when it concerns allies: request by European courts and law enforcement are regularly rejected based on US norms when, for example, someone hosts their hat speech blog with an US-only provider.
I can't think of any US service I am using that doesn't already require KYC? None of the large providers will let you get far without a credit card, as far as I remember?
Since the discussion here will consider itself mostly with upright revolutionaries being disenfranchised by such insult to their liberties, it is worth noting that when the revolutionaries are foreigners, the US often doesn't have the same incentive to disenfranchise them as it might have for domestic troublemakers.
In fact the US has quite a track record of granting rights to foreigners in excess of what they find at home, and even when it concerns allies: request by European courts and law enforcement are regularly rejected based on US norms when, for example, someone hosts their hat speech blog with an US-only provider.
> verify the identity of their foreign customers
Makes you wonder how they are going to first determine which are foriegn...
Makes you wonder how they are going to first determine which are foriegn...
This seems like the key section people should read through and where they should focus their submitted comments:
https://www.federalregister.gov/d/2024-01580/p-70
https://www.federalregister.gov/d/2024-01580/p-70
What can we do to actually contest it? I see this website lets you submit a “formal comment”. But is that enough? Who is in charge of the decision and who else can be pressured to stop it (certain legislators)?
So this is just to make it easier to ban non-US citizens from using US IaaS (or track them).
Just don't use American IaaS in the first place. It's not like computers are available only in the US.
Just don't use American IaaS in the first place. It's not like computers are available only in the US.
A number of threads seem to assume that KYC (or identity check) implies that your biometrics or gov ID data is collected/stored by the provider, but it does not have to be.
The identity check is typically done by a trusted 3rd party that can delete the data right after the identity check (and can be required to do so).
So you basically end up guaranteeing that the name, address and D.O.B that you provided to the IaaS provider is actually correct, nothing more and nothing less.
The identity check is typically done by a trusted 3rd party that can delete the data right after the identity check (and can be required to do so).
So you basically end up guaranteeing that the name, address and D.O.B that you provided to the IaaS provider is actually correct, nothing more and nothing less.
[deleted]
are they going to start requiring an ID to buy a GPU too
What can I do as a broke guy to stop this? Write a comment? Will it be read or considered?
Is this more onerous than verifying the name of the person or company you're serving does not appear on the OFAC list?
This is generally not difficult for anyone concerned, unless they happen to share a name with somebody on that list.
This is generally not difficult for anyone concerned, unless they happen to share a name with somebody on that list.
If you're going to editoralize the title, could you possibly tell us what KYC stands for?
This seems like a slippery slope.
If I host a site that is vulnerable to XSS, is it inadvertant Iaas?
It seems a bit benign and I don't understand the parallels others on this HN discussion are making. Is it that it's a slippery slope or perhaps I'm being naïve in regards to the scope?