Live data from Hacker News

Stripe Identity

stripe.com

191–200 of 557 posts

Re: Stripe Identity

#191
post #2

I've never seen a company release incredible products with as high velocity as Stripe has over the last few years. Truly incredible. $1.50/user may sound outrageously expensive at first, but having seen all the engineering power it takes to build something like this at Uber...it's a totally fair price.

I'd put Twilio and Cloudflare in the same category for vision (expanding product offering) and execution.

Yep, these are all examples of top engineering organizations.

Re: Stripe Identity

#192

Does Stripe intend to make a giant online database of international identity documents? Why should we trust Stripe to secure these? It could be Equifax levels of problematic if there would be a intrusion, but I also can't tell how Stripe plans to use this information.

No. 1. Stripe cares tremendously about and knows the importance of security—we’ve learned a lot from securely processing hundreds of billions of dollars in payments annually, and Identity is built from those learnings. ( https://stripe.com/docs/security/stripe ). 2. Any biometric identifiers that are created to perform the verification are never stored or retained—they are fully removed from all of our systems within…

This is only about the specific image processing Stripe does to match your selfie with your ID document. The rest of the information on the document—which is what the GP comment was asking about—is retained for 3 years. Referencing the 48 hour retention period instead of the 3 year one is very misleading in this case.

Re: Stripe Identity

#193

I really despise this trend of uploading your ID and a selfie for verification. I know it makes sense in some legal frameworks, but beyond that I find it invasive and risky (and rude.)

It also outright disincentivizes usage for some people. The biggest group is probably people without a proper ID (a very US-only issue), but I personally avoided showing or sending my ID anywhere before I was able to change my legal name to one that didn't make me want to rip my eyes out.

MasterCard and their "True Name" program did a good thing there.

Re: Stripe Identity

#194

Earlier quoted context omitted.

Yep, Stripe would be the data controller in this situation (and we comply with GDPR). https://support.stripe.com/questions/managing-your-id-verifi...

As USA is no longer Safe Harbor compliant, transferring PII outside EU's jurisdiction requires a legitimate interest. Does Stripe do the assessment on behalf of its customers, or does it rely on the customer being truthful and risk exporting data without consent?

Stripe supports the legal processing and transfer of data by our users — and EU requirements are top of mind. (Feel free to me at edwin@stripe.com if you have more questions.)

Re: Stripe Identity

#195

After reading the HN below comments. It seems a sizeable portion of those comments are "incredible products from stripe" "amazing news" with very little backing content. Did they pay bots to post on HN???

I don't think it's fair to assume that this is astroturfing in any way. Stripe just has a large following of people who like anything they release. Stripe has "fans" just like Apple does.

Re: Stripe Identity

#196

It looks like it's missing the user side of the equation. As in a user can validate they-are-who-they-say-they-are *once*, but Stripe is missing an opportunity to allow users to: validate themselves to a website regularly (OTP tied to identity), allow individuals to update their information (address change), allow individuals to revoke authentication, etc. It is a great foundation and there's huge opportunity for gro…

Neat idea and something we’ll think about.

Re: Stripe Identity

#197
post #128

Earlier quoted context omitted.

It’s not really a “trend”—if you think about it, ID verification is already required when checking into hotels, buying alcohol, or when visiting a bank teller. As more commerce moves online, Stripe Identity was built to significantly reduce the number of organizations and humans that would touch your ID—in a faster, secure way that’s hosted by Stripe ( https://support.stripe.com/questions/common-questions-about-... )…

In very few of those use-cases does the entity 1) _retain_ any of that data, 2) posses an internet-scale database of identities. And as we've all come to know the distinction between "able to surveil" and "collect it all" crosses a threshold to make it of a different kind. If one's mindset is that in general, tech companies, unlike those other entities store it all, then there actually is a recent "trend" to migrate…

It is already illegal to retain copies of ID cards or even some of the data in many countries. Just requesting a copy without redactions is wandering into a gray area in Germany.

Re: Stripe Identity

#198

Earlier quoted context omitted.

While that sounds like a great ... in all likelihood by the time it hits the public market most if not all the value will be extracted by the investors. With a branded company like this and equity markets as frothy as they are. I doubt there will be much value left for retail. Hopefully Im wrong though.

Wouldn’t the idea be that the company would continue to create value after going public?

The idea of going public is to raise another round of financing for the company while being able to get liquidity for private shareholders. It is not necessarily to create value going forward.

The best option is for the company to raise a good deal from the public markets (high valuation on limited equity) and then execute successfully without needing to raise again. If they do need to raise again they have hopefully not done a poor job on their original public IPO so that they can go back to the public markets. That said it isn't that important a factor.

Re: Stripe Identity

#199
Had to do this on a site recently and it didn't work for me at all.

It wanted to scan the back of my dl but Indian dls are totally blank at the back. Then it said my webcam wasn't good enough and showed me a QR code to use for my mobile. The link never opened. Tried it 3 times and 5 minutes later I just googled the next alternative site and bought it from there.

Lesson being use this only if it is totally necessary. You may lose paying customers in your overzealousness to be super tech savvy to KISS sites using a Paypal button.

Post reply on HN