The FCC wants KYC on your ham radio. Devs should care.

4 min read 1 source clear_take
├── "The FCC's KYC proposal imports a financial-surveillance model into radio infrastructure and must be fought during the comment period"
│  ├── Jameson Lopp (blog.lopp.net) → read

Lopp argues the FCC is wholesale importing the financial-system threat model into spectrum regulation — treating every endpoint as a potential bad actor and forcing custodians to vouch for identity. He frames the post as an explicit rallying document, urging readers to file comments naming specific paragraphs they object to before the short docket window closes.

│  └── @FergusArgyll (Hacker News, 290 pts) → view

By submitting Lopp's call-to-action to HN and driving it to 290 points, FergusArgyll amplifies the position that this rulemaking deserves urgent developer attention. The submission frames KYC creep into spectrum as a fight worth mobilizing the technical community around.

├── "This is an infrastructure story, not a crypto story — KYC is metastasizing from payments into the substrate of IoT and mesh networking"
│  └── top10.dev editorial (top10.dev) → read below

The editorial argues the stale crypto-versus-state framing causes developers to tune out, but this proposal marks the moment KYC stops being a payments story and becomes an infrastructure story. Radio spectrum underlies every IoT device, LPWAN deployment, and off-grid mesh — meaning the collateral damage hits experimental networking, Part 15 vendors, and university labs, not just hams.

└── "The amateur radio community has beaten FCC overreach before but is exhausted and may not muster the same fight"
  └── @Top HN reply (30-year extra-class ham) (Hacker News) → view

A veteran ham operator notes that the community successfully defeated comparable overreach in 2003 with Broadband over Power Line, demonstrating that organized opposition during comment periods works. But the blunt admission — 'We're older and tireder now' — warns that the institutional energy to repeat that victory may not be there.

What happened

Jameson Lopp — Casa CTO, long-time Bitcoin self-custody advocate, and one of the more reliable canaries for surveillance creep — published a call to action this week against an FCC Notice of Proposed Rulemaking that would extend Know-Your-Customer style identity requirements deep into the radio spectrum. The proposal, framed as an anti-fraud and national-security measure, would require operators and equipment vendors to collect, retain, and on demand surrender verified identity information tied to specific transmissions and devices.

The scope is what makes it remarkable. This isn't about licensed commercial carriers; it's about the long tail — amateur radio operators, Part 15 unlicensed device makers, LoRa deployers, mesh network experimenters, and the small vendors who ship the radios inside everything from soil sensors to security cameras. Lopp's read, echoed across the Hacker News thread that pushed the post to 290 points, is that the FCC is importing the financial-system threat model wholesale: treat every endpoint as a potential bad actor, force a custodian to vouch for identity, and accept whatever collateral damage falls on legitimate users as the cost of doing business.

The comment period is open and short. Lopp's post is explicitly a rallying document: file comments, name the specific paragraphs you object to, and do it before the docket closes. The top reply on HN, from a 30-year extra-class ham, was blunt: "They tried this in 2003 with BPL and we beat it. We're older and tireder now."

Why it matters

The usual framing of KYC fights is crypto-versus-state, and that framing has gotten stale enough that most developers tune it out. This proposal is the moment KYC stops being a payments story and becomes an infrastructure story. Radio spectrum is the substrate underneath every IoT device, every LPWAN deployment, every off-grid mesh project, and an increasing share of the experimental networking work happening in university labs and hacker spaces. Putting an identity layer underneath the physical layer of the OSI model is a categorical change, not a tuning of existing rules.

The practical mechanics are where it gets ugly for builders. If you ship a LoRa gateway, are you the custodian of identity for everyone who pairs a sensor to it? If you maintain a Meshtastic node, does relaying a neighbor's traffic make you a money-services-business equivalent for spectrum? The NPRM is vague enough that the answer is "maybe, and you'll find out when the enforcement letter arrives." Vagueness in spectrum rules historically resolves in favor of the largest incumbents, because they're the only ones who can afford to litigate the ambiguity. Small vendors comply by exiting the market or geofencing US customers out — the same pattern we've watched play out in EU AI Act compliance and California's age-verification laws.

The comparison to BPL (Broadband over Power Line) that the HN commenter invoked is worth taking seriously. In 2003-2004, the amateur radio community mobilized against an FCC push to allow BPL deployments that would have created massive HF interference. The ARRL won, but only because thousands of operators filed technical comments showing measurable harm. The KYC NPRM is harder to fight on technical grounds because the harm is structural rather than electromagnetic — and structural harms don't show up on a spectrum analyzer.

The defense and research angles compound the problem. DARPA, NSF, and a long list of university programs depend on cheap, identity-free experimental radios to do everything from spectrum-sensing research to disaster-response mesh prototypes. A KYC regime that forces every transmitter to be tied to a verified human at provisioning time doesn't just inconvenience hobbyists; it makes a whole class of research impractical. Lopp's post doesn't dwell on this, but it's the angle that should get DARPA program managers writing comments alongside the hams.

What this means for your stack

If you're building anything that touches unlicensed spectrum — and that's a much bigger surface than most web developers realize — start treating regulatory risk as a first-class architectural concern. The specific actions are unglamorous but matter: read the NPRM (Docket details are in Lopp's post), file a comment that names a concrete technical or commercial harm, and get your employer's regulatory affairs person involved if you work somewhere that has one. Generic "this is bad" comments get pattern-matched and discarded. Comments that say "our soil-moisture sensor product line has 14,000 deployed units and the proposed §X.YYZ identity-binding requirement would require a hardware revision costing $N" get read.

For protocol designers, this is a forcing function on a design question that's been quietly festering: how do you build identity-optional networks that can still satisfy abuse-mitigation requirements without a central custodian? The mesh networking community has been circling this for a decade. If KYC lands on spectrum, the next-generation protocols — Reticulum, Meshtastic's successors, whatever Helium pivots into next — will have to ship with a coherent answer or get regulated out of existence. That's a real engineering opportunity, not just a policy fight.

For the open-source firmware crowd, the threat model is more direct. Projects like OpenWrt, Tasmota, and the various ESP32 LoRa stacks operate on the assumption that anyone can flash a radio and put it on the air within the legal power and frequency limits. A KYC regime that requires hardware-level attestation of identity at transmit time is fundamentally incompatible with that model. It's the spectrum equivalent of mandatory Secure Boot — technically possible, ecosystem-destroying in practice.

Looking ahead

The near-term outcome depends almost entirely on comment volume and quality before the docket closes. The medium-term outcome — whether this becomes a template the FCC reuses, or a one-off the agency quietly walks back — depends on whether the developer community treats it as their fight or as somebody else's. The crypto community will show up; they always do. The question is whether the people building the next decade of physical-layer infrastructure recognize that the rules being written now will define what's buildable in 2030.

Hacker News 290 pts 189 comments

A Call to Action: Stop the FCC's KYC Regime

→ read on Hacker News
dec0dedab0de · Hacker News

We really just need telcos to stop allowing caller id spoofing. Doesn’t even need your name, but with a real number we could actually report these scams.You can still allow people to hide it, but then by default every non-business phone should block calls with hidden numbers.

phyzome · Hacker News

It's even worse: Since cell phones broadcast your location at all times, this means telling hundreds of companies (and a number of governments) your location at basically all times.That's already an issue with most cell phones. Making this apply to prepaid phones is even worse.

rib3ye · Hacker News

> Note: By checking this box, I acknowledge that I am filing a document into an official FCC proceeding. All information submitted, including names and addresses, will be publicly available via the web.Is there really not a way to submit an express FCC comment that avoids all my personal info bei

br0ceph · Hacker News

Im USA based use prepaid service because I dont want to provide information for a credit check to obtain postpay service. Theres absolutely no reason for a US based telephony provider to retain the most sensitive PII on their customers. Every large provider has a history of breaches and selling cust

troyvit · Hacker News

They would do well to make a better CTA for their call to action. Here's the link from the article:https://www.federalregister.gov/documents/2026/05/26/2026-10...I think that gets you most of the way to a link that somebody on HN dropped a few days ago:https:&

// share this

// get daily digest

Top 10 dev stories every morning at 8am UTC. AI-curated. Retro terminal HTML email.