Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

[flagged]


> You're calling a collection and storage of your personal information as "benign"?!

All major cloud services already collect this information. I filled in the bare minimum on AWS, and they've got my full name, address, phone number, email, and credit card details.


They collect biometric data (selfie) plus a copy of your drivers license? That's a big part of KYC/AML.

That's a huge difference from address, email, CC number.


You should really read patio11's article on KYC [0]. A relevant paragraph:

> Many people believe that the law requires a bank to see your government-issued ID in person to open a bank account. Again, this is incorrect; the law very rarely requires any particular action. The most prescriptive the US gets is that the sort of KYC information required about a customer include their true identity, including a name (not, incidentally, their “true” name because governments actually have some glimmer of understanding that that is not a thing which exists), a residential address, their date of birth, and an identifying number.

[0] https://www.bitsaboutmoney.com/archive/kyc-and-aml-beyond-th...


Looks like his argument is that randomized and client to client based rules are better. To some extent I agree.

However, it's inconsistent and we have a government that is punitive, which is why I see that these KYC approaches are reactive to that. There's not punitive measures for violating privacy concerns and storing/profiting from this data.

In practice, to buy crypto, you have to give a disreputable private entity (crypto exchanges have a terrible history of not being scummy.. is cryptobase good? only time will tell) very sensitive documents.


Your biometrics and gov ID data don't have to be collected or stored by the provider.

They can be used during the identity check and deleted right after, without ever entering the provider's infrastructure (assuming they are using a trusted 3rd party).


> They can be used during the identity check and deleted right after, without ever entering the provider's infrastructure

You trust them to delete it right after? What about the human reviewers in other countries that are working at home taking pictures of their laptops with your id on it?

> trusted 3rd party

You trust that 3rd party's intent and word? It's pretty weird to bring another company to steal your data and details.


At a quick reading, it doesn't sound like those are requirements. It also doesn't look like any documentation is technically required. One of the methods permitted is "Verification through non-documentary methods".


Do you mind expanding on what "non-documentary methods" means?


It is all defined in TFA:

https://www.federalregister.gov/documents/2024/01/29/2024-01...

The TL;DR is that it can be whatever the provider wants, as long as it:

* includes name, address, email, phone number, IP address, and payment information,

* is written down,

* gives them a "reasonable belief that it knows the true identity of each customer"

* and "a sound basis to verify the true identity of their customer and beneficial owners and reflect reasonable due diligence efforts".


> * gives them a "reasonable belief that it knows the true identity of each customer"

> * and "a sound basis to verify the true identity of their customer and beneficial owners and reflect reasonable due diligence efforts".

I'm reading in to that in a conservative manner where it's "internally justified" that going the full privacy abusive route is justified. "Reasonable due diligence" is respective to the organization that could be punished, not a public sense.

Given that it's on the company's discretion of diligent checks, I can completely see that their more aggressive requirements of: "your biometrics, copies of your official documents, 20 years of criminal background checks, a polygraph, approval by the Democratic National Party for appropriate speech, history of pornography consumption" being the standard.

We're not getting a solution from the government that's a secure "is this person a US citizen?"/"Valid for IaaS service?" data point. The business is receiving all of the data to ask that question and are not trustable entities.


If the business is not a "trustable entity", then why are you using them for hosting?


You have no choice.

Going down the argument of "don't use anyone you don't trust" brings up the argument of.. well why are you paying Experian?

Where I'm getting to this is: We often times don't have a choice, that choice that looks like we have it is untrustable in the future, and we're being aggressively pushed into a situation where you have people of questionable interests. This rule/law encourages them to collect it, but there's no aggressive lifestyle ending punishments for crossing the line.


??? There's nobody forcing you to have an account at a cloud provider. There are many other choices.

If you really do not trust someone else to operate a computer on your behalf, you can operate one yourself.


> propose regulations requiring U.S. Infrastructure as a Service (IaaS) providers of IaaS products to verify the identity of their foreign customers,

Sounds like solid policy to me.


And how do you know that one customer is a foreign one and one is not?


That is outlined in §7.302

The TL;DR is that the must collect name, address, email, phone number, IP address, and payment information and use that information for "verifying the identity of each foreign customer to the extent it enables the U.S. IaaS provider or foreign reseller of U.S. IaaS products to form a reasonable belief that it knows the true identity of each customer."

AWS already has all of this information on my account.


How does an email correspond to your location?

My email goes through Switzerland and I have a domain address that ends in ".de" am I a US resident, German, or Swiss?


It doesn't correspond to location any more than "name" does. But it is useful, in conjunction with other things, for determining identity, which is what those requirements are about.


Same way banks do. Documentation.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: