Live data from Hacker News

Stripe Identity

stripe.com

271–280 of 557 posts

Re: Stripe Identity

#271
I’ve been saying for years that identity services will be a huge deal. In a world where captcha is less and less reliable and where fake posts are cheaper, faster and more convincing (GTP), there are almost no websites that can function without using an identity service. I’ve been screaming from the rooftops and nobody listened.

Re: Stripe Identity

#272

Earlier quoted context omitted.

Said it in another thread -- SMS's are a tangibly better user experience. You get to say stop in the moment, instead of searching through opaque settings... you can set DND to certain numbers for certain times... The whole ecosystem is there and very few are playing with it.

SMS aren’t encrypted. I don’t want my mobile carrier knowing whatever sensitive data is being sent as a push notification.

This is the biggest drawback and requires creativity - but yes, the central issue.

Re: Stripe Identity

#273

Earlier quoted context omitted.

> We will typically store the rest of your submitted identity information for 3 years. This includes all images captured, extracted data from your ID document including name, date of birth, and ID number, and any information submitted via forms such as name, date of birth, SSN, email, and phone number, and the verification response. That doesn't make me feel a lot better. :( The images are enough to generate biometri…

We are very specific about collecting consent before doing anything with your data. We ask for permissions before beginning the verification process, and if you consent, we will only use your biometric identifiers for the verification itself. (And again, those identifiers—which contain the most sensitive info—aren't stored.) Specifically, we ask for an additional level of permissions before conducting any additional…

> We are very specific about collecting consent before doing anything with your data.

How do you foresee that consent working if your product is used in account recovery flows?

For example, imagine if Steam adopted Stripe Identity as their only way to allow people with $$$$ worth of games to recover hacked accounts. If the user's only choice is to "consent" or lose their valuable account, that makes the "consent" something of a joke.

I'd be interested to hear how you plan to square that circle!

Re: Stripe Identity

#274
post #254

Earlier quoted context omitted.

Stripe hires elite Stanford grads unlike Equifax is the simplest answer they probably wouldn’t say publicly. But the pedigree and engineering talent is miles better.

Being a Stanford grad myself, I wouldn’t put too much trust into Stanford grads, or grads.

In what sense? Looking at incoming classes it’s apparent you people are objectively superior to people like me before college than I am several years after. It’s almost definitely innate too, all the more depressing for strivers-turned-failures/underachievers like myself.

The Stanford thing was really the basis for Palantirs competitive advantage in the consulting space over companies like Booz Allen Hamilton etc.

Re: Stripe Identity

#275

Earlier quoted context omitted.

Just what I was thinking. Can Stripe hurry up and go public so I can buy some shares?

You can buy it by proxy through funds or similar. I've been eyeing Scottish Mortgage which despite the name is actually a high-tech fund packaged as a stock publicly traded in the London Stock Exchange. They hold Stripe among many other interesting investments.

Stripe is 0.9% of their holdings so they are of limited value of you sell exposure to Stripe specifically.

Re: Stripe Identity

#277
post #128

Earlier quoted context omitted.

It’s not really a “trend”—if you think about it, ID verification is already required when checking into hotels, buying alcohol, or when visiting a bank teller. As more commerce moves online, Stripe Identity was built to significantly reduce the number of organizations and humans that would touch your ID—in a faster, secure way that’s hosted by Stripe ( https://support.stripe.com/questions/common-questions-about-... )…

In very few of those use-cases does the entity 1) _retain_ any of that data, 2) posses an internet-scale database of identities. And as we've all come to know the distinction between "able to surveil" and "collect it all" crosses a threshold to make it of a different kind. If one's mindset is that in general, tech companies, unlike those other entities store it all, then there actually is a recent "trend" to migrate…

[deleted]

Re: Stripe Identity

#278

Earlier quoted context omitted.

This is only about the specific image processing Stripe does to match your selfie with your ID document. The rest of the information on the document—which is what the GP comment was asking about—is retained for 3 years. Referencing the 48 hour retention period instead of the 3 year one is very misleading in this case.

Since we are storing these IDs on behalf of businesses using Identity, we need to retain non-biometric information for a period of time to support their use cases. For example: KYC is a core use case for identity, which requires us to retain ID information for audit purposes. For businesses who don’t need to keep the ID for as long, we provide a deletion API that lets them automatically delete the IDs from our system…

Yes, I agree that Stripe's policy makes sense here. But your original comment was misleading, in that it implied the information contained on your ID card was deleted after 48 hours. (It looks like you may have since edited it to clarify that you were talking about biometric signals? Maybe you haven't edited it, but it was definitely unclear enough that I, like the other responders, was confused.)

Re: Stripe Identity

#279

Earlier quoted context omitted.

I honestly find it weird having all of these things suddenly want a copy of my passport in the cloud just sitting there waiting to be hacked in years to come when the security measures drop. At this point there is giant databases containing everything people need to take complete control of your identity sitting there just waiting to be hacked. I have no idea how to change it/fix it. But it seems weird to me.

You've nailed the complexity of this. On privacy, people are rightfully spooked about this for all the reasons you've mentioned. On safety, people are really happy about these initiatives as accounts backed by user identity are less likely to be used for harm. On security, leaks of these databases create issues to other sites and companies (eg: if Company X is compromised, then identity documents could be used to dis…

> Specifically for Stripe, I trust them. So if I see that a new start-up is using them rather than rolling their own solution, that increases my trust

Note that Stripe allows their customers access to the "captured images of the ID document, selfies, extracted data from the ID document, keyed-in information"[1]. So you still have to trust any company using Stripe not to download, store, and later leak your personal information, and you also have to trust them not to let their Stripe API token be compromised and exploited by identity thieves.

[1] https://support.stripe.com/questions/managing-your-id-verifi...

Post reply on HN