Advanced
In reply to @osama
Chris Carella@ccarella
2/6/2023

I once had a dapp that KYC’d people through https://cognitohq.com and I didn’t have any of the data, just relied on cognito to tell me if the user passed or not. Are you saying that’s not ok in the current reg environment?

In reply to @ccarella
Tayyab@tayyab
2/6/2023

Is it because they need a known throat to choke? I worked in KYC for two years, and that seemed to be the primary reason. Assuming the fear is that people can KYC a wallet, then sell the wallet/pass the private keys to someone? Can't you do that with usernames and passwords as well though?

In reply to @ccarella
osama@osama
2/6/2023

If you got subpoenaed for information, you must probably had a term with cognito wgich allowed you to ask them to provide info against given identifier. You cannot say “oh no, we don’t hold pii but we kyc everyone”

In reply to @ccarella
osama@osama
2/6/2023

bottom line: there’s no clear reg requirement for kyc’ed defi rn. if there was, uni and aave would be doing it. they’re fighting the good fight. MiiCA is ~year to enforcement. when reg comes hopefully it will be aligned with progress in ZK. but vendors like this (and some) are creating fud

In reply to @ccarella
shoni.eth@alexpaden
2/6/2023

You could login and view the data, right? That part shouldn’t exist. The baseline need is upon subpoena