Live data from Hacker News

Stripe Identity

stripe.com

121–130 of 557 posts

Re: Stripe Identity

#121
post #111
post #99

The landing page contains logos for clubhouse, discord, and shippo, which are presumably companies use the service. Does anyone find those usages to be unnecessarily intrusive? Maybe it's just me, but a chat app or shipping site asking me for a drivers license scan + selfie would make me never want to use the service again. It's appalling how this sort of stuff is getting normalized, eg. google asking for id scans fo…

Clubhouse lets you collect payments to join some channels. Isn’t KYC reasonable in that case? Re: Age Verifications on Google & YouTube: this has been covered well elsewhere. Google is required to do so by EU law. Blame regulators not the companies.

> Clubhouse lets you collect payments to join some channels. Isn’t KYC reasonable in that case?

If it's limited to only people receiving payments, then it's far more reasonable than what I thought was happening (eg. people getting randomly asked for ID scans to use their service).

Re: Stripe Identity

#122
post #68

Earlier quoted context omitted.

Nobody forces you to use PWAs. I’m tired of this constant PWA bashing on HN.

The problem with having those APIs in the browser is that it increases the attacker surface area, which makes the browser less secure for everyone, including those who do not use PWAs. The only saving grace is that you have to accept the permission box (I hope so at least...), which, for the average user, may not be much protection.

Simply existing in the world increases your attack surface; everything is a trade off between usability and security. Given the pressures browsers are under, they have incentives built into their business model to provide very good security which is a departure from most other software where security is just a nuisance at best and totally ignored at worst.

Re: Stripe Identity

#123

After reading the HN below comments. It seems a sizeable portion of those comments are "incredible products from stripe" "amazing news" with very little backing content. Did they pay bots to post on HN???

I think many developers have used Stripe for payments after dealing with legacy payment APIs like Authorize.Net and have seen how Stripe does it right and makes the process so much less painful, I'd assume their other products like this are as equally well built due to their reputation in the payments industry.

Re: Stripe Identity

#124
post #95

Earlier quoted context omitted.

I'm not familiar with Stripe's situation, but there are non-public markets available for this kind of stock sale. You just can't buy from them unless you're already rich. I'd guess that long-term employees do have an amount of flexibility in that regard.

Can you form a mutual fund/ETF that invests into those kind of companies via the non-public markets and then sell shares publicly for the fund?

[deleted]

Re: Stripe Identity

#125

Earlier quoted context omitted.

Just what I was thinking. Can Stripe hurry up and go public so I can buy some shares?

If only Stripe would start a pre-ipo stock market. I guess only incumbent regulation prevents this, it’s not a technology problem.

I believe Carta already does this: https://cartax.com/

Re: Stripe Identity

#126
post #99

The landing page contains logos for clubhouse, discord, and shippo, which are presumably companies use the service. Does anyone find those usages to be unnecessarily intrusive? Maybe it's just me, but a chat app or shipping site asking me for a drivers license scan + selfie would make me never want to use the service again. It's appalling how this sort of stuff is getting normalized, eg. google asking for id scans fo…

Chat apps use Identity to verify bots and prevent bad bots from spamming real users. And shipping services use Identity when a user is suspected as a fraudster—to double check before creating fraudulent shipping labels.

Re: Stripe Identity

#127

Does Stripe intend to make a giant online database of international identity documents? Why should we trust Stripe to secure these? It could be Equifax levels of problematic if there would be a intrusion, but I also can't tell how Stripe plans to use this information.

I never wanted Equifax to have any of my data, and yet here we are. After the breach, I wouldn’t ever be a paying customer to them if I had a choice. (Indirectly, I am still a “customer” in the sense that they probably still have my data and get new data about me—but apart from canceling all my cards, not sure what choice I have). In comparison, Stripe seems to charge for each product it offers. I think that’s a more…

You are not a credit bureau's customer - the stores, public utilities, cell phone companies, banks, and so forth, are. They share that information to minimize their risk in extending credit (even something like billing you at the end of the month for services rendered is a form of credit) to you.

And frankly, if Stripe is offering any form of credit, it's likely working with the credit unions too.

Re: Stripe Identity

#128

I really despise this trend of uploading your ID and a selfie for verification. I know it makes sense in some legal frameworks, but beyond that I find it invasive and risky (and rude.)

It’s not really a “trend”—if you think about it, ID verification is already required when checking into hotels, buying alcohol, or when visiting a bank teller. As more commerce moves online, Stripe Identity was built to significantly reduce the number of organizations and humans that would touch your ID—in a faster, secure way that’s hosted by Stripe ( https://support.stripe.com/questions/common-questions-about-... )…

In very few of those use-cases does the entity 1) _retain_ any of that data, 2) posses an internet-scale database of identities.

And as we've all come to know the distinction between "able to surveil" and "collect it all" crosses a threshold to make it of a different kind.

If one's mindset is that in general, tech companies, unlike those other entities store it all, then there actually is a recent "trend" to migrate a normal behavior into an abnormally socially adjusted space.

Re: Stripe Identity

#129
I wish Stripe would go public so I could invest a good chunk. Who wouldnt want to invest in the backbone (or soon to be) of the entire internet payment infrastructure.

Re: Stripe Identity

#130
post #87

Earlier quoted context omitted.

No. 1. Stripe cares tremendously about and knows the importance of security—we’ve learned a lot from securely processing hundreds of billions of dollars in payments annually, and Identity is built from those learnings. ( https://stripe.com/docs/security/stripe ). 2. Any biometric identifiers that are created to perform the verification are never stored or retained—they are fully removed from all of our systems within…

Well, I don't believe what Stripe (or anyone) says; I believe what you do. Does Stripe have a legal contract with users that says something to the effect of "if it does 1 and 2 above (by mistake or by choice doesn't matter) - that they will be liable for it". If not, all the support documents and technical security documentation is moot. I want to see "skin in the game" by Stripe. If you're so sure about "security" s…

Exactly right.

Trust and goodwill is enough to get me to consider a service, not enough to sign up.

Also, data outlives management regimes. Eventually, any data set that can be used will be used.

Post reply on HN