I think the biggest argument against it is that this removes anonymity on the internet, at least from governments, and that would remove people's ability to freely voice their opinions without fears of repercussions (will the first amendment ever be modified? Will people who discuss what it's like to be an illegal immigrant/drug user/etc. be persecuted)? Also, it raises the question of what happens to users of VPN's, public internet, etc.
It seems to de-anonymize a set of IaaS customers, sure; but that's not nearly the same thing as removing anonymity completely. I've only just scanned this but it seems at first glance to mean that a foreign company can't anonymously spin up an AWS instance, that's all. Am I reading this incorrectly?
There are so many things that can fall under the IaaS bracket. Think anything 'cloud'. Maybe that's not how they'll apply it, but legally they are free to do so. It's a huge reach.
Basically, it forces providers of a very wide variety of tech related services to collect identifying info on anyone who uses their services, and then store that info to either eventually be exposed in a breach, subpoenaed by the government, or sold to the highest bidder (might as well monetize it if you're forced to collect it )
This is about IaaS not “internet services”. It doesn’t remove anonymity from internet users, just foreign customers renting cloud servers and other infrastructure.
> This proposed definition adopts the E.O. 13984 definition for “Infrastructure as a Service product”, which is any product or service offered to a consumer, including complimentary or “trial” offerings, that provides processing, storage, networks, or other fundamental computing resources, and with which the consumer is able to deploy and run software that is not predefined, including operating systems and applications.
How would an ISP not be misconstrued as a "managed network"? Deploy/run software could just as easily be running some protocol over the network connection?
Sure, there are very few international ISPs which would be affected by this as physical infrastructure must be local to the user, but I wonder if this would be true always (e.g.: Starlink)
This would apply to all hosting providers, which is bad enough.
- TCP is a spec delivered by a software implementation program. Maybe you disagree that TCP is being "deployed" as opposed to "used"?
- What about peer-to-peer hosted webpages? Certainly this is deployed software served over the internet connection?
The devil is in the details... details which are not specified in the order. It wouldn't be hard to imagine a lawyer arguing the finer details of "deployed" and "software" and falling on a definition which results in a less "open" Internet.
Also, I think of the meaning of "that is not predefined" is not at all clear. Predefined at what point in time?
IANAL.
Today, anonymity and pseudonymity exist and allow people to speak freely without risk of backlash for having a different opinion as often times the right opinion may differ with that of social consensus.
If KYC is introduced, the ability to maintain freedom of speech, online, will likely diminish.
This is of negative consequence to the people of the world.
Further, with internet 'forever data', LLM NLP and so forth, character profiles are too easy to develop for people which can cause further harm as we begin segregating based on said profiles.
I believe this KYC requirement can even extend to blockchain node operators and so forth as well.
These are just a few reasons but there are many more.
But remember that you can have a perfectly effective web host that simply accepts HTML uploads.
Certainly a tremendous loss of convenience and features but speech itself could still be available under this regime…