I doubt that anyone running bots, and who is technically competent, will be identifiable or findable. I mean, I could do it, and I'm just a random anonymous coward.
I doubt that anyone running bots, and who is technically competent, will be identifiable or findable. I mean, I could do it, and I'm just a random anonymous coward.
> I doubt that anyone running bots, and who is technically competent, will be identifiable or findable.
Telemarketing, for example, was done a great deal by perfectly legal, traceable businesses. Once it was made illegal, it was forced underground, and volume dropped immensely.
> I could do it, and I'm just a random anonymous coward.
Could you? Hiding the flow of significant amounts of money is actually quite hard. Robot salesmen masquerading as humans would be a plague, and I think this law should keep that from becoming a legitimate business technique.
It's true that getting assets from cryptocurrencies is hard. I don't do it. I just spend my ~anonymous income on ~anonymous servers to play with.
But if you're moving enough assets, you can pay people, who know what they're doing, to move it. As we've seen in real estate markets in many cities.
[1] https://cointelegraph.com/news/bitfinex-hack-new-twist-two-a...
- Back when SR1 was starting, he got a visit from the FBI about fake ID that he had ordered, shipped to his actual address in SF. And he basically admitted that he bought them from SR1.
- He posted to at least two sites about SR1, using accounts linked to his real name.
- Logs in a SR1 server pointed to an IPv4 address that he used in SF.
- Apache in a SR1 server was misconfigured, such that errors were accessible via clearnet, instead of via Tor onion.
- He worked in public with a FDE laptop, which contained everything about SR1. Including IDs for all staff. And he didn't take steps to enable emergency shutdown.
And about Bitcoin. One of my favorite mixing services, Bitcoin Fog, has handled huge amounts of Bitcoin, from various thefts. And nothing has ever been traced, to my knowledge.
Finally, where do you get "businesses trying to be legitimate"? Maybe their customers are legitimate, but why would you say that about the bot providers? They could just have a credible cover operation.
As to the other bit: Bot providers need to be hired by somebody. If those people are legitimate businesses selling products or services, they will be traceable in the usual ways. It's those legitimate businesses that are of primary concern to lawmakers in this legislation and in most business regulation.
I've also often thought that the cheap bots are easily identifiable (tweeting every 3 minutes, 24/7/365) and that a better bot shouldn't be that hard to build, but then again, I've figured somebody to be a bot that actually wasn't, he was just very invested in the topic and had plenty of time on his hands.
Google's Duplex is an example of this, and I agree with the law that its use should be disclosed.
The law doesn't have to lead to prosecution of every little criminal. If it polices some of the large players who can't easily hide what they're doing, it'll be a helpful law.
Also, "breaking the law" is an ambiguous thing. I mean, that's one of my favorite Judas Priest cuts, and he was talking about breaking laws against homosexuality. Not that most head-bangers realized it, at the time.
Also, just about every US media company breaks Saudi laws against sinful use of sexual images. And nobody seems to worry much about it.
I'm excited to see legislation in this direction but I wish they'd focus on forcing Twitter, Facebook, etc. (which /are/ in California and can be governed) to display / disclose when they are aware a user is likely a bot, and employ some half-decent detection methods.
In practice, there's still a reason companies avoid breaking laws most of the time.