Live data from Hacker News

Stripe Identity

stripe.com

101–110 of 557 posts

Re: Stripe Identity

#101
post #11

Earlier quoted context omitted.

It's actually pretty cool (IMO; I'm biased). Drop-in browser-based user authentication that: * Uses various sophisticated heuristics to detect real vs fake IDs. * Matches the ID to the human face. * Detects whether the human face is live or not. * Dynamically requests more or less information depending on the confidence level. It also gets better over time based on the attacks and fraud attempts that Stripe itself se…

This is amazing. Did you build all of the scanning logic yourselves? We’re exploring different options for scanning IDs like Anyline and BlinkID right now, but this looks incredibly well suited for what we’re building and would save us a tremendous amount of time if it works.

Yes, we’ve spent a lot of time on the scanning logic—especially to help guide users through photo-taking, since that’s half the battle for a successful verification.

• Document detection

• Blur and glare detection

• Tool-tips during the user flow

Re: Stripe Identity

#102

Earlier quoted context omitted.

In their TOS and Privacy Policy it’s made clear they are also data controllers. Unless you contribute to the breach it would almost certainly fall on them.

Yep, Stripe would be the data controller in this situation (and we comply with GDPR). https://support.stripe.com/questions/managing-your-id-verifi...

As USA is no longer Safe Harbor compliant, transferring PII outside EU's jurisdiction requires a legitimate interest. Does Stripe do the assessment on behalf of its customers, or does it rely on the customer being truthful and risk exporting data without consent?

Re: Stripe Identity

#103
post #60

I was once enticed by AirBnB's promise of "we don't store your ID data after validation" Few years down the line, it requested me to submit my ID data for a booking in China. All my ID data was pre-filled.

Even though I have zero confidence in similar claims by big and small players, in this case I would give them the benefit of the doubt and blame your browser instead, because exposing themselves in this way would be extremely stupid.

Re: Stripe Identity

#104

I really despise this trend of uploading your ID and a selfie for verification. I know it makes sense in some legal frameworks, but beyond that I find it invasive and risky (and rude.)

It’s not really a “trend”—if you think about it, ID verification is already required when checking into hotels, buying alcohol, or when visiting a bank teller.

As more commerce moves online, Stripe Identity was built to significantly reduce the number of organizations and humans that would touch your ID—in a faster, secure way that’s hosted by Stripe (https://support.stripe.com/questions/common-questions-about-...).

We are also very direct about collecting consent: https://support.stripe.com/questions/common-questions-about-....

Re: Stripe Identity

#105
post #68

Earlier quoted context omitted.

Google is certainly trying. On Chrome for Android you can do both of those. Whether that's a good thing is debatable though. https://developer.mozilla.org/en-US/docs/Web/API/Notificatio... https://developer.mozilla.org/en-US/docs/Web/API/Web_Bluetoo...

Nobody forces you to use PWAs. I’m tired of this constant PWA bashing on HN.

The problem with having those APIs in the browser is that it increases the attacker surface area, which makes the browser less secure for everyone, including those who do not use PWAs.

The only saving grace is that you have to accept the permission box (I hope so at least...), which, for the average user, may not be much protection.

Re: Stripe Identity

#106

Does Stripe intend to make a giant online database of international identity documents? Why should we trust Stripe to secure these? It could be Equifax levels of problematic if there would be a intrusion, but I also can't tell how Stripe plans to use this information.

Stripe hires elite Stanford grads unlike Equifax is the simplest answer they probably wouldn’t say publicly. But the pedigree and engineering talent is miles better.

Re: Stripe Identity

#108
post #99

The landing page contains logos for clubhouse, discord, and shippo, which are presumably companies use the service. Does anyone find those usages to be unnecessarily intrusive? Maybe it's just me, but a chat app or shipping site asking me for a drivers license scan + selfie would make me never want to use the service again. It's appalling how this sort of stuff is getting normalized, eg. google asking for id scans fo…

What's the difference between filling out your address in text versus scanning? Is your face not on the internet yet? Just curious what specifically would make you never want to use it?

Re: Stripe Identity

#109

After reading the HN below comments. It seems a sizeable portion of those comments are "incredible products from stripe" "amazing news" with very little backing content. Did they pay bots to post on HN???

Please don't post insinuations about astroturfing, shilling, brigading, foreign agents and the like. It degrades discussion and is usually mistaken. If you're worried about abuse, email hn@ycombinator.com and we'll look at the data.

https://news.ycombinator.com/newsguidelines.html

Re: Stripe Identity

#110
post #60

I was once enticed by AirBnB's promise of "we don't store your ID data after validation" Few years down the line, it requested me to submit my ID data for a booking in China. All my ID data was pre-filled.

All identity services we use keep all the data.
Post reply on HN