would have been a better title. The missing information is more easily guessed from skimming the article than the mystery acronym.
Isn't effectively the majority of what the Snowden leaks covered essentially violating the 4th amendment?
This is not obvious to me as my experience has been largely negative post-KYC/9-11 vs pre-KYC/9-11. I am a legal law abiding citizen [and voter!] and it's just added extra hassle on various occasions and then the background anxiety of knowing an institution with crappy security track records hold a photocopy of my ID. And yet all the things KYC was supposed to prevent still continue unabated: money laundering, terrorist financing, identity theft, and financial fraud.
I'm curious to hear why you think it's obviously good and if you were using these services before KYC.
The problem is that there are no checks and balances preventing banks from freezing assets because they want to or the government told them to.
Banking needs to be a right, and unless someone is convicted of a crime involving the bank account's assets, banks and governments should not be able to freeze them. There can be exceptions for fraud like FTX where there will be a significant financial harm to other individuals if the assets aren't frozen, but what we have today is unchecked government financial terrorism against individuals they do not like, and now they want to extend that terrorism to speech.
KYC helped them by deny-listing abusive clients between branches, or by allowing the bank to develop heuristics for things like allowing customers to bypass cheque clearing times.
From an end-user perspective, I've had no hangups personally but I do share your grievances about yet-another-shoddy institution holding a photocopy of my ID. My bank truncates passwords when setting them, and when logging in, without telling the user. It boggles the mind.
Comparing what one individual did in the past to a formal government policy doxxing away peoples' 4th amendment rights is a strawman argument.
This KYC requirement seems to me, at a glance, as being a small erosion of our digital privacy.
I would say "unconstitutional" (it was on its face legal), but yup.
> and was being done in secret
Do open secrets count? We all knew they were spying.
> and once exposed they had to stop
BAHAHAHAHAHAHAHAHAHAHA
Then again I worked on blockchain tech around half a decade ago, so I might be knowledge biased here?
Once you're familiar with it, your brain/eyes key onto "KYC" much more strongly than "know your customer". I might have missed the latter, but "KYC" in the title grabbed my attention instantly and reading the title made my heart jump a bit, because generally KYC means a pain in my ass, and even moreso for friends here on visa.
I have a Canadian friend visiting and staying with my girlfriend and I for a month or so. KYC causes actual headaches for her, to the point that she just decides not to get cellular service at all while she visits unless I get a pre-paid SIM under my name and hand it to her. When she pays for things like restaurants, I can't just Venmo/Paypal/Zelle/ApplePay her back on the spot, I have to withdraw cash at some point and coordinate giving it to her.
The general concept of "KYC" makes sense for some situations, but actual implementations really fucking suck for a lot of people. It's very scary to me to see it be required for more and more categories of services because of the way it's currently implemented.
But remembering the meaning of an acronym while scanning front page post titles without much context? No. My brain is pretty ruthless at evicting TLAs that are reasonably distant from my core areas of interest.
KYC is essentially about knowing who you are doing business with.
For individuals that's relatively easy, just the name and identification is required but typically there is the need to verify that the identification actually belongs to the person signing up. In banking that's why you typically have some video call with a verification provider.
For businesses it gets a lot more complex because it's not enough to know what business your client is, you also have to look through its corporate structure to figure out who the "ultimate beneficial owner" is. Essentially, who is actually controlling the business.
Now it got a lot easier recently as many countries now require businesses to file who their ultimate beneficial owners (UBOs) are.
The painful part is that it introduces friction in customer journeys as now you have to request the documentation.
In the financial industry you also have to run checks on those UBO's so that they are not known terrorists or sanctioned individuals but it seems this regulation is just that IaaS providers need to know who actually operates a server. Presumably for forensic analysis after a cyber attack.
The proposal seems to use the term Customer Identification Program (CIP) instead, mentioning KYC (spelled out) only once, in the introduction:
> Section 1 of E.O. 13984 requires the Secretary to propose, for notice and comment, regulations that mandate that U.S. IaaS providers verify the identity of foreign persons that sign up for or maintain accounts that access or utilize U.S. IaaS providers' IaaS products or services (Accounts or Account)—that is, a know-your-customer program or Customer Identification Program (CIP).