Remix.run Logo
joshfraser 3 days ago

KYC = kill your customer

It's time for us to stop pretending that YC checks do anything except provide an illusion of security while putting people's living in danger.

AI makes it trivial to generate fake documents, so most KYC checks can't actually be trusted to verify your identity. As an example of how ridiculous things have gotten, Anthropic launched their verification program for granting access to their Mythos models. North Korea are experts at bypassing KYC checks and were granted early access while the rest of us were locked out.

These leaks are constant and largely unavoidable. Even the largest, most trusted companies in the world get regularly hacked. My passport was leaked and I've received multiple blackmail attempts from people demanding I pay a ransom. There have been multiple kidnappings that have been related to home addresses and private information being leaked.

The situation is really bad, and there are no easy solutions. The correct answer is probably a new government ID system based on public key encryption with some sort of multi-sig between the individual, the government, and your parents (until you're 18). This won't be easy to roll out, but our current system is broken beyond repair. Unfortunately, things probably need to get way worse before anyone cares enough to fix it.

disgruntledphd2 2 days ago | parent | next [-]

> Even the largest, most trusted companies in the world get regularly hacked

Yes, they do. Fundamentally this is because they don't spend enough money on security (like basically everybody else).

Some form of personal liability for executives is one (relatively simple) way to ensure that this becomes a priority, like SOX did for financial reporting.

There are other ways, but I do like the personal liability approach as its targeted, and has been used successfully in the past.

mitxela 2 days ago | parent | prev | next [-]

So if I steal someone's private key I can be them and nobody can refute that I'm them? And the government retains a record of everything you ever do? How's that any better than the present state of things?

aucisson_masque 3 days ago | parent | prev [-]

> The correct answer is probably a new government ID system based on public key encryptio

Check out Estonia

joshfraser 3 days ago | parent [-]

The interesting question is how to verify who someone is before issuing them a digital ID. Estonia verifies people using their Estonian ID cards, their mobile devices, or biometric data if they have it recorded.

The system is only as strong as its weakest link. ID cards can be faked and mobile devices can be stolen. Biometrics can't be easily faked, but they're horrible to have leaked because you can't change your fingerprints or eyeballs if compromised.