惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

MyScale Blog
MyScale Blog
MongoDB | Blog
MongoDB | Blog
The Register - Security
The Register - Security
T
The Blog of Author Tim Ferriss
A
About on SuperTechFans
Vercel News
Vercel News
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Jina AI
Jina AI
Stack Overflow Blog
Stack Overflow Blog
Cisco Talos Blog
Cisco Talos Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
W
WeLiveSecurity
S
Securelist
I
Intezer
F
Full Disclosure
WordPress大学
WordPress大学
腾讯CDC
酷 壳 – CoolShell
酷 壳 – CoolShell
Latest news
Latest news
aimingoo的专栏
aimingoo的专栏
C
Cisco Blogs
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
T
The Exploit Database - CXSecurity.com
P
Proofpoint News Feed
K
Kaspersky official blog
阮一峰的网络日志
阮一峰的网络日志
P
Proofpoint News Feed
J
Java Code Geeks
人人都是产品经理
人人都是产品经理
雷峰网
雷峰网
AWS News Blog
AWS News Blog
T
Tenable Blog
Google DeepMind News
Google DeepMind News
B
Blog RSS Feed
L
LINUX DO - 最新话题
小众软件
小众软件
T
Threat Research - Cisco Blogs
C
Cyber Attacks, Cyber Crime and Cyber Security
The GitHub Blog
The GitHub Blog
爱范儿
爱范儿
N
News and Events Feed by Topic
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
量子位
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Forbes - Security
Forbes - Security
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
U
Unit 42
O
OpenAI News
V
V2EX
T
Troy Hunt's Blog

Hacker News

Introducing Claude Opus 4.7 Qwen Studio The Future of Everything is Lies, I Guess: Where Do We Go From Here? GitHub - SeanFDZ/macmind: Single-layer transformer in HyperTalk for the classic Macintosh Show HN: Agent-cache – Multi-tier LLM/tool/session caching for Valkey and Redis Bonsai 1-bit WebGPU - a Hugging Face Space by webml-community Moving a large-scale metrics pipeline from StatsD to OpenTelemetry / Prometheus GitHub - Nightmare-Eclipse/RedSun: The Red Sun vulnerability repository GitHub - SethPyle376/hiraeth: Local AWS emulator focused on fast integration testing, with SQS support, SQLite-backed state, and a debug-friendly web UI. GitHub - macOS26/Agent: Any AI, replaces Claude Code, Cursor, OpenClaw. Over 18 LLM providers (Claude, OpenAI, Gemini, Ollama, Zai, HF, Qwen) wired into a native Mac app that writes code, builds Xcode projects, bumps versions, manages git, automates Safari, use AppleScript, JS or Accessibility, extend Agent! w/ MCP Servers, run tasks from your iPhone via Messages. YouTube now lets you turn off Shorts I Made a Terminal Pager Burgers | マクドナルド公式 Commands — HackerNews CLI documentation ChatGPT for Excel PiCore - Raspberry Pi Port of Tiny Core Linux Live Nation illegally monopolized ticketing market, jury finds Google Broke Its Promise to Me. Now ICE Has My Data. Founding Engineer at Adaptional | Y Combinator CRISPR takes important step toward silencing Down syndrome’s extra chromosome GitHub - saffron-health/libretto: The AI toolkit for building reliable browser automations US v. Heppner (S.D.N.Y. 2026) no attorney-client privilege for AI chats [pdf] Retrofitting JIT Compilers into C Interpreters IPv6 – Google The Accursèd Alphabetical Clock Cybersecurity Looks Like Proof of Work Now Fragments: April 14 Cal.com Goes Closed Source: Why AI Security Is Forcing Our Decision | Cal.com - Scheduling Software for Online Bookings Laravel raised money and now injects ads directly into your agent When moving fast, talking is the first thing to break Too much Discussion of the XOR swap trick – Heather Cafe Introduction to Spherical Harmonics for Graphics Programmers The Grand Line Building a Z-Machine in the worst possible language High-Level Rust: Getting 80% of the Benefits with 20% of the Pain GitHub - duguyue100/midnight-captain: Inspired by Midnight Commander, tailored to my taste. How to build a `git diff` driver · Jamie Tanna | Software Engineer Center for Responsible, Decentralized Intelligence at Berkeley The Local Universe’s Expansion Rate Is Clearer Than Ever, but Still Doesn’t Add Up - A new synthesis of astronomical measurements confirms a persistent mismatch that could point to physics beyond current models The air throughout our homes is infused with microplastics. But there are things you can do to breathe less of them The disturbing white paper Red Hat is trying to erase from the internet – OSnews The Future of Everything is Lies, I Guess: Annoyances ‘Abhorrent’: the inside story of the Polymarket gamblers betting millions on war Productive procrastination — Max van IJsselmuiden maps, territory and LMs 447 Terabytes per Square Centimetre at Zero Retention Energy: Non-Volatile Memory at the Atomic Scale on Fluorographane Show HN: Pardonned.com – A searchable database of US Pardons 20 Years on AWS and Never Not My Job The Seasons are Wrong Artemis II crew splashes down near San Diego after historic moon mission We gave an AI a 3 year retail lease in SF and asked it to make a profit | Andon Labs How a dancer with ALS used brainwaves to perform live On filing the corners off my MacBooks Installing every* Firefox extension OpenClaw’s memory is unreliable, and you don’t know when it will break Steve Blank Nowhere Is Safe Chimpanzees in Uganda locked in vicious 'civil war', say researchers watgo - a WebAssembly Toolkit for Go linux/Documentation/process/coding-assistants.rst at master · torvalds/linux GitHub - callumlocke/json-formatter: Makes JSON easy to read. Founding Product Engineer at Bild AI | Y Combinator A compelling title that is cryptic enough to get you to take action on it GitHub - Keychron/Keychron-Keyboards-Hardware-Design: Industrial design files for Keychron keyboards and mice. 100+ models with CAD assets in STEP, DXF, DWG, and PDF. Source-available, with commercial use allowed for original compatible accessories within the license terms. [ANNOUNCE] WireGuardNT v0.11 and WireGuard for Windows v0.6 Released 1D-Chess Helium Is Hard to Replace Cooperative Vectors Introduction | Evolve Keeping a Postgres queue healthy — PlanetScale Our response to the Axios developer tool compromise Do Americans read print books, e-books or audiobooks more? The Zettelkasten Method in Obsidian: A Practical Setup Guide Artemis II Is Competency Porn and We Are Starving For It WeakC4 Flight Viz — Cockpit View A Mexican surveillance giant you’ve never heard of is now watching the U.S. border Surelock: Deadlock-Free Mutexes for Rust RISC-V 101 – what is it and what does it mean for Canonical? | Ubuntu The Problem That Built an Industry How Much Linear Memory Access Is Enough? | Solidean Investigating Split Locks on x86-64 Simplest hash functions Sybilproof reputation mechanisms (2005) [pdf] What is a property? How Complex is my Code? Static code analysis in Kotlin — tools overview Toffoli gates are all you need PGLite evangelism dcmake: a new CMake debugger UI Clojure on Fennel part one: Persistent Data Structures Fragments: April 2 Python Release Python install manager 26.1 The Life and Death of the Book Review - Liberties Introducing Database Traffic Control — PlanetScale Bitcoin miners are losing $19,000 on every BTC produced as difficulty drops 7.8% God sleeps in the minerals Building slogbox Apple Silicon and Virtual Machines: Beating the 2 VM Limit Who was “Not Even Wrong” first? Pokemon Evolution Vs Darwinian Evolution The APL Programming Language Source Code
A Call to Action: Stop the FCC's KYC Regime
Jameson Lopp · 2026-06-12 · via Hacker News

Robocalls are really annoying. Everyone knows the misery of scam calls, spoofed numbers, fake warranty pitches, fraudulent bank alerts, and automated political spam. The FCC is correct to claim that illegal calls erode trust in the phone system and cost Americans time, money, and security. But this problem does not justify a dragnet solution. Under the guise of fighting robocallers, the FCC is now considering “Know Your Customer” rules that could force phone providers to collect identity information from ordinary people before they can acquire or renew service with a phone carrier.

The proposal is being sold as consumer protection, but the surveillance regime it would create is something else entirely.

On April 30, 2026, the FCC adopted a Further Notice of Proposed Rulemaking seeking stronger KYC rules for voice service providers. The agency says possible measures include requiring providers to verify customer identities before enabling service, including name, address, government ID, and alternate phone numbers. The item was approved by Chairman Brendan Carr and Commissioners Gomez and Trusty.

That should alarm anyone who believes phone access is basic infrastructure, not a privilege conditioned on identity verification. The danger is not that the FCC wants to punish robocall scammers. The danger is that the FCC is contemplating rules that would put millions of innocent people into telecom identity databases in the hope that criminals will be inconvenienced. We've seen this playbook before. Such measures take more privacy from lawful users while determined criminals will adapt and find ways around the "gate."

KYC rules seen stopping determined criminals

KYC does not reliably stop determined criminals. We know this to be true simply from looking at KYC requirements in the financial system. There's no shortage of money laundering that occurs through regulated venues, in part because criminals don't have much trouble providing the required documentation to pass KYC checks. Why is this easy to route around? Mainly because so much personally identifiable information gets leaked on an ongoing basis that entire markets exist to trade this information. Buying a new identity and the associated documents to go along with it is cheap.

The proposal also reaches directly into prepaid service. The FCC is asking whether KYC requirements should vary between prepaid and postpaid plans, what information wireless providers currently obtain from prepaid SIM customers, and whether KYC measures should be imposed for prepaid service purchased through third-party vendors. That is the heart of the burner-phone issue. A prepaid phone is not just a movie prop for criminals. It can be a lifeline for a domestic violence survivor, a worker reporting misconduct, a journalist protecting a source, a protester avoiding retaliation, or someone who simply does not want every communication account tied to a government ID.

ACLU senior policy analyst Jay Stanley warned that the rulemaking contemplates taking away people’s ability to get a burner phone and could harm low-income people, domestic violence victims, and anyone who values privacy. That is the point the public needs to understand: anonymous or pseudonymous communication is not suspicious by default.

I've used KYC-free phone services for many years both as a security and privacy protection tactic. I, like anyone who might be suspected of having access to significant amounts of bitcoin, need strong privacy in order to protect myself from wrench attacks. This is not a theoretical threat; hundreds of Bitcoiners have been physically attacked and I myself have been swatted and extorted.

The most chilling parts of the FCC’s proposal go beyond ordinary ID collection. In its section on risk-based KYC differences, the FCC even asks whether providers should consult lists of terrorists, terrorist organizations, and “criminal persons” maintained by law enforcement entities. We've also seen this before and such lists would surely lead to false positives, abuse of innocent people being opaquely added to said lists, and the possibility that people could be denied basic communication infrastructure without a conviction or meaningful due process. Even though the FCC frames this as a question rather than a final decision, it is a dangerous question for a communications regulator to normalize.

The proposal also contemplates long retention periods. The FCC asks about requiring providers to retain KYC information and supporting records for four years after the customer relationship ends. That means the risk does not end when someone cancels service. A person’s identifying information could remain in carrier databases for years, exposed to breach, misuse, subpoena, sale, or mission creep.

Mission creep is already visible in the FCC’s own words. The agency asks whether enhanced KYC rules could help law enforcement investigate crimes beyond illegal calls, including organized crime, trafficking, espionage, influence operations, and other national-security concerns. That is a very different pitch from “we are stopping robocalls.” Once telecom providers are required to verify, retain, re-verify, and possibly screen customers, the phone system starts looking less like an open communications network and more like a chokepoint.

The FCC also proposes a per-call enforcement structure. It asks about assessing KYC violations on a per-call basis and specifically proposes a $2,500 per-call base forfeiture. That creates an obvious incentive: providers will protect themselves by over-verifying, over-retaining, and over-denying. When the penalty for under-screening can multiply by call volume, the safest corporate choice is not the one that protects consumer privacy, but rather the one that intrudes upon it greatly.

Privacy Is Not a Crime

A free society does not require citizens to continually fight to retain their privacy. The burden should be on the government to justify eroding the rights of citizens via surveillance, data retention, and denial of access to essential communications tools.

We have seen this playbook before, oh so many times, to the point that it has become a meme. Those who seek to control the channels of communication must first be able to identify anyone who is using a network so that they can then send their thugs to silence the undesirable speaker.

There is a better path. The FCC can target high-volume commercial origination, negligent providers, spoofing infrastructure, SIM-box abuse, and repeat bad actors without forcing every ordinary person to surrender identity documents to get a phone number. It can strengthen enforcement against carriers that knowingly enable illegal call traffic. It can require narrow, risk-based due diligence for bulk callers. What it should not do is make every phone user prove who they are before they can communicate.

This is not a partisan issue. The average citizen does not want the government compiling lists of people who are conducting completely normal activities. They do not want “consumer protection” turned into surveillance. They do not want privacy treated as a loophole. And they do not want to find out later that a rule meant to stop robocalls quietly ended the last practical way to access the telephone system without government permission.

KYC Is the Real Crime

I often refer to KYC as Kill Your Customer, because the very act of collecting sensitive personally identifiable information about a customer puts them at risk. The KYC regime has made itself into a joke by resulting in massive data leaks over the years, which now undermine the reliability of KYC since criminals can easily obtain fresh documents to bypass KYC checks with stolen identities.

Specific to phone service, KYC will actively degrade the security of your phone account because tying your account to an identity means that a criminal who obtains enough of your PII becomes better positioned to impersonate you to your phone provider and attempt to transfer your number to a SIM under the criminal's control. This "SIM swapping" / "SIM jacking" issue has been a problem for over a decade now and is only getting worse as more and more of our lives are going digital and most of our important online accounts are tied to phone numbers and email addresses. The common attack vector for SIM jacking is:

  1. Take over the victim's phone number.
  2. Use the phone number to reset access to the victim's primary email account.
  3. Use the email account and phone number to reset access to financial accounts.

KYC is a laughable regime put in place under the claim of "stopping criminals" but the reality is that it is security theater that actually weakens the privacy and security of consumers rather than protecting them from bad actors. We should not double down on this broken system by implementing it in even more aspects of our lives.

It's Not Too Late

This is not yet a final rule. It is a proposed rule, which means the public still has a chance to push back. In the Federal Register, the FCC says it is seeking comment on this proposed change. That means we can give them a piece of our minds.

The comment deadline is June 25, 2026, with reply comments due July 27, 2026.

I urge you to submit a public comment to the FCC before June 25, 2026 opposing mandatory KYC identity checks for ordinary phone users. You can use the form at this link to submit a comment on this matter. Just click the link right now and submit a comment before you close this post! Yes, you, dear reader!

Remember that FCC comments are public. Assume that anything you submit, including personal information in the comment text or attachments, may become publicly viewable online. Don't include personal details you can't safely reveal to the world.

Feel free to use the following template to save yourself some time. Add / remove / edit whatever you wish to personalize it to your view.

I oppose any FCC rule that would require ordinary phone users, including prepaid users, to provide government-issued identification numbers, identity documents, physical addresses, alternate phone numbers, or similar personal information as a condition of obtaining or renewing phone service.

Robocalls and scam calls are serious problems, but mandatory identity collection for all users is overly broad, privacy-invasive, and likely to harm lawful users who need privacy, including domestic violence survivors, journalists, whistleblowers, low-income citizens, political organizers, and people facing retaliation or stalking.

The FCC should reject any requirement that voice providers consult law-enforcement watchlists or lists of “criminal persons” before granting service. Access to basic communications infrastructure should not depend on opaque lists, screening systems prone to abuse and false positives, or processes lacking transparency.

The FCC should also reject multi-year retention of KYC records for ordinary customers. Retaining identity information and supporting records after a customer leaves service creates unnecessary breach, misuse, and surveillance risks.

The Commission should instead focus on narrow, evidence-based enforcement against high-volume illegal callers, spoofing abuse, SIM-box operations, and providers that knowingly or recklessly enable illegal traffic. Any new rules should be targeted, privacy-protective, data-minimizing, and should preserve access to prepaid and privacy-protective phone service for lawful users.

Please do not turn phone service into an identity checkpoint. Reject mandatory KYC requirements for ordinary telephone users.


Now is the time for all Americans who are concerned about the constant erosion of their privacy to speak out.