pull down to refresh

298 sats \ 3 replies \ @optimism 19h

this is crazy:

┌─────────────────────────────────────────────────────────┐
│                    the user                             │
│  (signs up for OpenAI, wants to use GPT-5)              │
└─────────────────┬───────────────────────────────────────┘
                  │
                  │ "verify your identity"
                  │
┌─────────────────▼───────────────────────────────────────┐
│  inquiry.withpersona.com                                │
│  Persona verification flow                              │
│  - government ID scan (Microblink)                      │
│  - selfie capture + LIVENESS DETECTION                  │
│  - video capture                                        │
│  - PUBLIC FIGURE FACIAL MATCHING                        │
│  - device fingerprint (FingerprintJS)                   │
│  - browser/network signals                              │
└─────────────────┬───────────────────────────────────────┘
                  │
                  │ complete identity dossier
                  │ (ID photos, selfie, video, PII, scores)
                  │
┌─────────────────▼───────────────────────────────────────┐
│  openai-watchlistdb.withpersona.com                     │
│  34.49.93.177 (dedicated GCP)                           │
│  Envoy proxy + internal service mesh                    │
│                                                         │
│  screens against:                                       │
│  - OFAC SDN list (US sanctions)                         │
│  - 200+ global sanctions/warning lists                  │
│  - PEP classes 1-4 (with FACIAL SIMILARITY scoring)     │
│  - adverse media (terrorism to cybercrime)              │
│  - crypto address watchlists (Chainalysis, TRM Labs)    │
│  - custom FinCEN screening lists                        │
│  - fitness & probity lists                              │
└─────────────────┬───────────────────────────────────────┘
                  │
                  │ result: approved / flagged / denied
                  │
┌─────────────────▼───────────────────────────────────────┐
│  OpenAI                                                 │
│  - grants or denies access                              │
│  - no explanation provided                              │
│  - no appeal mechanism                                  │
│  - data retained (1 year? 3 years? permanently?)        │
└─────────────────────────────────────────────────────────┘

meanwhile, on the government side:

┌─────────────────────────────────────────────────────────┐
│  withpersona-gov.com (FedRAMP Authorized)               │
│  34.27.15.233 (dedicated GCP, us-central1)              │
│                                                         │
│  SAME CODEBASE. same company. same data model.          │
│                                                         │
│  proven in source code:                                 │
│  - files SARs directly to FinCEN                        │
│  - files STRs directly to FINTRAC (Canada)              │
│  - STRs tagged with intelligence program codenames      │
│  - biometric face databases (3-year retention)          │
│  - 13 types of tracking lists                           │
│  - PEP facial recognition with similarity scoring       │
│  - 269 verification checks                              │
│  - Chainalysis crypto screening                         │
│  - custom FinCEN screening list uploads                 │
│  - OpenAI-powered AI copilot for operators              │
└─────────────────────────────────────────────────────────┘
reply

Proof of identity is fine but they require proof of address and this will be very bad and doesn't accept you mention you live with your parents and proof with name of your parents as proof of address like students having +18 years old. Common issue for multiple stupid KYC sites.

reply
107 sats \ 0 replies \ @optimism 11h

Proof of identity is not fine because the identity is an issue-once static identifier. It is the weakest link in any security scheme because the general population cannot roll it over. Once it is exposed, it is exposed forever, so it's a liability to the user, not an asset.

Imagine you cannot change your password.

reply

Why should proof of identity is fine??

reply
116 sats \ 1 reply \ @Scoresby 18h
reply
107 sats \ 0 replies \ @optimism 11h

I repeat. #1436114

Thinking if I really want to find out whether Claude is a real chad: @bot, plz port wasabi out of .net

reply
218 sats \ 0 replies \ @k00b 18h

This is the kind of stuff I think about when bitcoiner's are like:

I just gave them my
  1. email
  2. full name
  3. date of birth
  4. country of residence
  5. IP address (implicitly)
What could they possibly learn from that?

I'm like my brehs. Come onnnnnn.

A startup adjacent to Pleb Lab's office started doing this AI-powered ID stuff in '23. They had a poster of The Eye of Sauron on the wall. They've since quadrupled in size and moved up a few floors in the building.

reply

"knowledge is the only real currency. everything else is just access control."

Great post! Having said that this is dragnet surveillance.
None of this should surprise any of you.

reply
5 sats \ 0 replies \ @jasonb 21h

@remindme in 15 hours

reply

elementary