Commerce Department Proposes Imposing "Know Your Customer" on IaaS Providers
natlawreview.com
natlawreview.com
Always for the same dubious straw men reasons of terrorism and co, they want to control everyone. Like for banks, the excuse is to ensure that no forbidden foreign actor is allowed the use of the service , but just for that the billion legitimate users will all have to provide their complete justificative info, IPs, and support documents to later be used by the org or gov for whatever reason they will want once they will have them.
Like for banks.
Imagine if the same thing was requested in the real world, like forced to prove your identity when you take gas, When you buy a computer, when you buy a condom.
Most definitely was not.
The government pushes surveillance too but in my experience it’s the secondary driver, at least in the US. Might be different in other countries.
I’m really pessimistic about privacy online given that every single incentive both public and private encourages maximum privacy invasion and centralization. I mean every single incentive. It’s almost impossible to resist.
We might have a chance if end users cared enough to pay for privacy and avoid things that invade it, but very few do. Most people care about convenience, features, and cost, and that’s it. Nothing else matters.
But make no mistake - we could, as a society, invest heavily in developing privacy-first platforms and software, and have it all. I can't even say that we choose not to; it's more that representative democracy is not particularly representative in practice, and mostly works as a form of veto.
People choose to watch youtube with ads rather than pay for youtube premium without ads.
People buy the kindle with ads on the lockscreen over paying $20 or whatever more for an ad-free one.
When given the choice of a $3 app store app with no ads vs an identical free one with ads, users pick the ads.
Picking ads is effectively the same as choosing a lower price (free) over privacy, and people seem to consistently pick in this direction.
Because of that, I don't think it's fair to say that users aren't actually making any choice here. Users are choosing free services over privacy.
Ads are orthogonal to privacy. We've had privacy-preserving ads in physical newspapers for hundreds of years.
There is no reasonable way for a normal person to consistently choose privacy these days.
The average American isn't exactly awash in cash to spend on privacy, you know.
We are not talking about a lot of money in most cases. I usually compare it to coffee shops. People will pay $10 at a coffee shop for a latte and a snack, but they refuse to pay even $5 for a software app or game that they might use every day.
Becoming?
Stalkerware, data brokers selling women's information to the Gilead apparatus, Palantir... none of this is new, and present much greater threats on a day to day basis than this.
Likewise anonymous use of shared infrastructure is a central part of the scam/spam/malware ecosystem which costs the global economy $10+ trillion a year.
At some point given the impacts to the most vulnerable in society we need to simply ask that people prove who they are.
From 2009 to 2013 only 7 new banks were formed, fewer than 2 per year.
Many industry observers have suggested that the decline is primarily due to regulatory burden, including new FDIC regulations and the 2010 Dodd‐Frank Act. But other influences could have played a role, in particular, the current weak economy.
https://www.federalreserve.gov/econresdata/feds/2014/files/2...
Due to how fractional banking works, in reality they would be earning some multiple of that return rate, but that’s a bit more abstract and hard to quantify.
Because AML processes are completely opaque, often made up on the fly and operate without any due process, banks can and routinely do delay transactions worth multiple billions of dollars for many weeks or longer by asking lots of irrelevant questions, requesting new documents or minor changes, and taking their time in getting back to you about anything, ect... In the world of high value transactions these kafkaesque processes and delays are completely routine.
This reminds me of when people say, "those stories of street crime are exaggerated." It's content-free. And "any risks related to money laundering" is rather dismissive, isn't it?
Are you denying that actual criminals have a problem with moving money around except in $100 bills and other tangible assets?
why is it a bad thing to make criminals expend more effort and money?
If you want to imprison all the murderers, you can accomplish that goal by imprisoning everyone but we don't do this and most people would recognize that the idea is mad.
So the test here for any regulating authority should be, is your regulation harming the innocent in some way? If so, the imperative is on you to find a better way to go after the guilty, if you don't you have become an enemy of the public good and your moral authority is lost. We can get into specific regulations but I think with modern KYC and AML we are absolutely at the point where they contribute to the suppression of economic growth and individual liberties and need to be dialed back.
The point being, sometimes undercutting criminal activity can be done be legalizing the activity rather than introducing more types of illegal activities to try and detect the original ones. The cure is sometimes worse than the disease.
The $10k rule by the Bank Secrecy Act wasn't indexed to inflation and would be closer to $80k today. So it should be amounts up to $80k that aren't considered worth monitoring, but instead, if you deal with, say, buying and selling cars, you get tripped up by that all the time. It's regulatory red tape overhead that costs a legitimate business extra time money that they could be better spent elsewhere.
And even you yourself answer the main question - it doesn't stop criminals. Just makes it more expensive.
As for "Criminals with LOTS of money do not have any difficulty finding an investment bank to handle money movement" what is your evidence for that? And what's the line between "petty" and "LOTS of money" ?
So customers can very easily move their money and business elsewhere if they feel like they are being somehow controlled. And as someone who has worked at two banks almost all of those restrictions derive from the government.
For retail and SME customers this is true. But for any customer that deals with large sums of money it is not. If you’ve never heard of an MT730, then you probably have good reason to think that moving money around is easy.
Sounds like exactly the sort of entities that the government should be investigating.
But your reaction of “must be a criminal, let’s investigate you” to my complaints of banks abusing your power leads me to 100% believe your claim of having worked in banks before.
Also, little barriers to entry like this are the kind of things that discourage initiative and make our economy slightly less competitive. When I was a teenager I wrote Linux tutorials on vultr.com for $50 each to be credited to my account, which I used to pay for hosting before I had a debit card. I had no drivers license so if I encountered some dialog asking for an ID I would've just clicked away and been disappointed. There are 17 year olds running hosting businesses on lowendtalk.com - should their $1000 a month in revenue business be expected to consult with a lawyer to write a 40 page customer identification plan?
People in Los Angeles get a shock when they find out the city wants it percent of global sales.
What happens with foreign financial institutions which don't implement KYC or otherwise play nice? I'm really asking; I remember when I was young that "swiss bank accounts" were famous for shielding account owners, but my understanding is that's no longer the case.
My first thought here was, what happens when the US decides that network providers doing business in the US must blackhole Hetzner or whatever because they aren't implementing KYC.
USA has a lot of experience how they can influence foreign providers by making it increasingly difficult for them to do business with any USA entities. It’s not bulletproof, but nothing is. As long as USA has dominant position in the world, their influence is huge.
> ... secret documents leaked from FinCEN, the Financial Crimes Enforcement Network, a unit of the U.S. Treasury. The documents “show that five global banks — JPMorgan, HSBC, Standard Chartered Bank, Deutsche Bank and Bank of New York Mellon — kept profiting from powerful and dangerous players even after U.S. authorities fined these financial institutions for earlier failures to stem flows of dirty money.”
https://insightcrime.org/news/chinese-money-launderers-mexic...
> While the involvement of Chinese money-laundering rings in handling drug proceeds from Mexico is nothing new, a number of recent court cases in the United States have revealed crucial information about how these schemes work ... weekly pick-ups from representatives of Mexican criminal groups, made in cash ranging between $150,000 and $1 million, with an average of $500,000. These were made in large cities including Chicago, New York and Atlanta ... network of Chinese-owned businesses in the United States and Mexico ... transfer a correspondent amount of money through Chinese banking apps. This happened entirely through the Asian country’s domestic banking system ... “It’s the most sophisticated form of money laundering that’s ever existed,” one of the US sources told Reuters.
Netflix series, "The Laundromat", https://youtube.com/watch?v=wuBRcfe4bSo
Switch to a credit union that values your business, they are much more motivated to hook you up with high ACH limits, and I've repeatedly seen them issue loans at rates well below market.
First republic bank imploded so fast because their niche was convenience in not having limits
All the banks have the same problem, they’re holding us treasuries with customer deposits at a huge loss right now. the regulations say they don’t have to disclose the current market value of government bonds like us treasuries, so as long as they never need the money they’ll get it all paid by the government over time, but if they ever do need the money sooner they’ll have to liquidate the bonds at their current market value and never have enough to pay everyone.
How many bank accounts you want depends on you, but two seems awfully few to me.
There's no need, there's fifty security cameras and phone trackers already doing it that may not even require a warrant to access.
(There’s worse stuff, like they could decide only 10% of your budget can be used on gas. Or force you to pay higher taxes as a carbon credit, etc etc)
IaaS: running your own email server, your own cloud, your own vpn.
I'm vehemently against the idea of a KYC for iaas. This just feels like another swipe at destroying internet anonymity. "Foreign actors" already route traffic over every network in the US. Preventing them from getting an ec2 isnt necessary as senators can already request aws drop customers because they dont like them (joe lieberman personally pulled the plug on wikileaks)
People get deanonymized in spite of using Tor and Monero, not because of it.
In the recent Monopoly Market case and seizures from the huge hacks, it was all chain analysis. Only the Bitfinex hackers even tried to conceal what they were doing (by using Alphabay as a mixer, which became their undoing once it was seized), the others went straight from crime -> accounts in their name. This can be obviated with Monero.
Yes, I'm aware that the US government used some sort of probabilistic attack on Monero in 2018 against North Korea, which has since been fixed.
I don't want to spend my whole life looking over my shoulder and IRL opsec is a whole other thing that I am not really familiar with. I don't use the techniques in my post because I'm not leading a double life or something like that, but I think it's entertaining to read about.
Edit: Also, is your contention that there is no Internet anonymity anymore, therefore it's fine to even further limit Internet anonymity?
"The proposed rule requires U.S. IaaS providers and their foreign resellers to report known instances of foreign persons training “large AI models with potential capabilities that could be used in malicious cyber-enabled activity” to Commerce.
Use a GPU, go to prison?
Which is to say: every language model and image generator with >100M params. In other words, IaaS providers must report nearly every transaction, since you can train a LoRA module for a small model on a few hundred ARM cores, or on nearly any datacenter GPU.
To be clear though, the rule doesn’t include prison time for you, the GPU user. The prison time and/or fines are for the noncompliant IaaS provider, which means that cloud GPUs (and possibly every other resource) will be much more expensive and harder to access.
Name; Address; Means and source of payment; Email address; Telephone number; and “IP address(es) used for access or administration and the date and time of each such access or administrative action.”
I'm pretty sure all IaaS providers already have all that (except maybe the phone number which is not mandatory
Watch the US say in a few years that they will block all international VPN connectivity for security reasons.
You can run your own infrastructure in whatever data centre is willing to host you.
"Just build your own website" has rapidly turned into "just build your own data center, domain registrar, CDN and DDoS protection shield, T1 ISP, advertising network, search engine, and defeat the VISA/MasterCard duopoly if you want any income". The pro-deplatforming crowd has shown that they'll use every possible measure to make a site they don't like impossible to operate, rather than stopping at their claim that they just don't want the content on Facebook or whatever
b) You don't just get to demand that the entire world bends to your whims.
My point is the status quo allows people for good and bad to operate networked compute anonymously, and US government organizations want to strip anonymity away from the Internet.
Judge’s Ruling Sets Back Law Meant to Fight Money Laundering
"An Alabama judge barred the government from collecting certain company ownership data to help the Treasury Department identify money launderers, and called the effort a case of congressional overreach."
[0] https://www.nytimes.com/2024/03/03/us/politics/judge-ruling-...
I don't know why there has not been more uproar over this. By the end of the year over 33 million business owners in the US will be required to give FinCen identifying info including a photo ID for owners of 25% of their business. In addition those just filling out the application must do the same.
Is there a way forward? yes, penalties for abuse, not "papers please" life for every peon on Earth.
2. I'm not engaged in any activities that warrant scrutiny, so again tf are you even on about.
In the former, there is considerably more consent, some level of flexibility in how data is disclosed and some possibility of user mitigation. In the latter, none of these things are possible. It's a straight jacket for society, with the net effect being massively less fundamental liberty and more centralization of power around the state.
Just look at mandated KYC processes in finance, and the enormous costs they impose — in time wasted and intimate private information involuntarily exposed — on hundreds of millions of law-abiding consumers and businesses, while massively constraining the space for innovation in finance, by mandating a regimented PII disclose process that precludes the development of better processes for providing safety and accountability.
This is not the same as people's voluntarily disclosed financial data being available to buy from commercial data brokers, that incurs none of these costs on society.
And miss me with that "consent" fig leaf. You damn well know ToS (what would the plural be there?) that notionally establish consent are intentionally designed to be impenetrable walls of legal verbiage designed specifically to provoke end users to click through without reading a damn thing. Furthermore, to truly opt out of all forms of digital tracking, which I think we agree most people would do if given the option, would require completely disengaging from the economy as brokerable electronic records are produced every time you use a cellphone, view anything on the internet, or perform a financial transaction with anything besides cash.
There has been no demonstrable reduction of criminal and terrorist activity since the G7 embarked on widespread financial surveillance in 1989.
As for the ToS, they provide some level of accountability, which can, for example, take the form of a mass exodus of users when a company changes its ToS to make them more invasive.
And people can ultimately choose what data they share with web services, whereas mandates like the ones being promoted by the Commerce Department eliminate that choice altogether.
There is undoubtedly a lot of space for improvement in the privacy realm but clearly we're not going to go in that direction if we institute overt mass surveillance programs that criminalize privacy.
Claiming there is no privacy, so nothing is an invasion of privacy, is apologia for mass-surveillance.
I think it's worth contacting your support rep if you don't like this and letting them know you're going looking to take your business elsewhere if this happens.
Probably this:
And really, once you start using a lot of resources at a cloud company they start asking about you and your workloads because they want to up sell you more services. I'm sure they're also thinking about what kind of credit risk you might be since the industry generally operates on a post-payment basis. They will also require further information if you're doing things that have potential to harm their services such as email sending.
There is no good reason to demand the identity of people spending 1000 bucks a month on virtual machines that nobody is complaining about, it's outright totalitarian.
This takes us down a road to a centralized internet with government agencies acting as gatekeepers. Not only is this dangerous, in making political repression orders of magnitude easier, it is inefficient, as it replaces the apolitical efficiency of the permissionless internet with a bureaucratic and friction-laden process for internet interactions.
But I'm willing to even concede that a highly controlled internet will lead to less internet crime. But it'll be a Devil's Bargain where the price of less internet crime will be less economic activity and wealth. Repression of the general population to reduce the threat posed by bad actors is counter-productive to the larger goal of a safer and more prosperous world.
Less prosperous as repression inhibits productivity and less safe because less prosperity makes people less able to reduce the risks that they face. To give a concrete example: the people of a city that has access to Uber or an Uber-like service (more prosperity) are safer than those of a city relying on older taxi technology involving flagging down cabs with no ratings (less prosperity).
The former have greater freedom of movement which has a huge number of positive second order effects, many of which improve personal safety. The emergence and rapid evolution of services like Uber is largely because of Internet Freedom giving internet projects space for deployment and iteration outside the confines of regimented safety processes.
Also, plenty of people on this forum are not OK with securing IP either, seeing it as a serious impediment to the free flow of ideas and the advancement of human knowledge. Basically the same argument the OP just described.
But that's only a small part of the AML/KYC package. The other part is the active surveillance obligations on behalf of law enforcement that a financial has to engage in. I.e., the filing of SAR (suspicious activity reports), and reports whenever large amounts of cash are withdrawn from their custody. These are the AML side of things, that basically turns the financial system into an extension of paw enforcement.
This proposed KYC program from Commerce is applying the same template of obligations to U.S. cloud providers. Maybe it'll only be them for a few years, but much like FATCA ended up expanding OFAC's influence worldwide, so to likely will this be propagated worldwide.