Live data from Hacker News

Stripe Identity

stripe.com

231–240 of 557 posts

Re: Stripe Identity

#231
The way domestic services (both public and private) in Finland verify user's identity is via bank credentials (Finnish Trust Network), via Mobile ID (Mobiilivarmenne), or via government FINeID. All these involve multi-factor authentication.

The service then gets the user's personal identity code as a return value.

Looks like that kind of flow is not supported.

Finnish users will be very hesitant of giving scans of their ID documents to foreign companies as no domestic online services require them. And of course Finnish companies cannot practically use this for now, at least for domestic users.

Re: Stripe Identity

#232
Sift has a longer list of logos on their landing page, though I’d imagine even at this point that Stripe has more data. Sift got hit hard being unprepared for CCPA, I wonder what Stripe’s position would be. I’m naive but it strikes me that if Stripe were to offer a cheaper version of this product that does not transactions but for UGC, then Sift might have trouble retaining customers.

I’m also impressed that Stripe called this “Identity” instead of something more like “Trust and Safety.” The current name makes it sound more like Okta or something but that’s not the case. At least today. Perhaps they want this to grow to overtake stuff like Experian.

Re: Stripe Identity

#233
post #140

Earlier quoted context omitted.

Discord uses it to verify the identity of bot makers - my understanding is that bots have been abused for a long time for data collection (think logging when users come online, go offline, change status, etc).

I don't get it. They're concerned about people abusing the system, and their solution is... requiring KYC? How does that solve the issue? It sounds like bot makes can still passively collect the info, it's just that when it gets discovered they can point to a real person to blame. Moreover, why do bots even need to know the online/offline status of users? Why not add a permission system so users can opt in/out of pro…

> Why not add a permission system so users can opt in/out of providing this sort of information to bots?

The bots provide a function for the "server" and the server operator. That's like saying "Why not just provide a system for users to opt out of ChanServ/NickServ".

Re: Stripe Identity

#234
post #95

Earlier quoted context omitted.

I'm not familiar with Stripe's situation, but there are non-public markets available for this kind of stock sale. You just can't buy from them unless you're already rich. I'd guess that long-term employees do have an amount of flexibility in that regard.

Can you form a mutual fund/ETF that invests into those kind of companies via the non-public markets and then sell shares publicly for the fund?

This is already a thing, large investors like Fidelity do exactly this.

e.g. Fidelity has a significant investment in SpaceX through a handful of their mutual funds, which you can then purchase and basically invest in SpaceX indirectly.

Re: Stripe Identity

#235
post #2

I've never seen a company release incredible products with as high velocity as Stripe has over the last few years. Truly incredible. $1.50/user may sound outrageously expensive at first, but having seen all the engineering power it takes to build something like this at Uber...it's a totally fair price.

The tech stack has something to do with it. Stripe has such high velocity because of Ruby on Rails.

Re: Stripe Identity

#236
post #125

Earlier quoted context omitted.

If only Stripe would start a pre-ipo stock market. I guess only incumbent regulation prevents this, it’s not a technology problem.

I believe Carta already does this: https://cartax.com/

CarTax.com? Good jerb marketing team!

Re: Stripe Identity

#237
post #163
post #62

Earlier quoted context omitted.

The fact that Apple has refused to deliver that only proves the point. If they did, many apps wouldn’t be forced to be in the App Store. It’s certainly possible, as iirc, it works on Android for years now.

They have supported it on desktop Safari for years, so it really is just a political decision for them at this point.

Financial decision, more like.

They are using it to force developers who don’t need the App Store to use the App Store. Thus, Apple can force them to pay their tax.

Re: Stripe Identity

#238
post #46

Earlier quoted context omitted.

how are mobile notifications on the web going for iOS?

Said it in another thread -- SMS's are a tangibly better user experience. You get to say stop in the moment, instead of searching through opaque settings... you can set DND to certain numbers for certain times... The whole ecosystem is there and very few are playing with it.

On Android you:

  1. Swipe the notification halfway to reveal the buttons
  2. Tap the options button
  3. Flip the switch that shows up
On SMS you:

  1. Tap reply on the notification
  2. Type STOP (4 taps or one swipe)
  3. Hit send
There's no difference in complexity, if anything SMS is more complicated and less discoverable.

Re: Stripe Identity

#239
Does anyone know if it does liveness checks for the "selfie verification"? The docs are a bit vague on that.

And do I understand "Stripe uses a combination of machine learning models, automated heuristic analysis and manual reviewers to verify the authenticity of hundreds of different document types." correctly in that I do not only upload video/images of my passport, face to stripe for automatic analysis but in some cases a human would even review it? Or is this a specific option I could choose?

Re: Stripe Identity

#240
post #121
post #111

Earlier quoted context omitted.

Clubhouse lets you collect payments to join some channels. Isn’t KYC reasonable in that case? Re: Age Verifications on Google & YouTube: this has been covered well elsewhere. Google is required to do so by EU law. Blame regulators not the companies.

> Clubhouse lets you collect payments to join some channels. Isn’t KYC reasonable in that case? If it's limited to only people receiving payments, then it's far more reasonable than what I thought was happening (eg. people getting randomly asked for ID scans to use their service).

Others have said it's limited to people who have a bot joined to more than 75 servers, or use certain sensitive scopes. So it's not quite that restrictive (only payments).

But I can say that I'm in... about 10 servers as a user and have a couple of bots I hacked together for various things operating in 3 of them and have never been asked for anything but my email. And across all the people I know using Discord, I was totally unaware that they even did that sort of identity verification because it seems like no one I know's ever run into it.

Post reply on HN