Live data from Hacker News

Stripe Identity

stripe.com

291–300 of 557 posts

Re: Stripe Identity

#291

Earlier quoted context omitted.

I honestly find it weird having all of these things suddenly want a copy of my passport in the cloud just sitting there waiting to be hacked in years to come when the security measures drop. At this point there is giant databases containing everything people need to take complete control of your identity sitting there just waiting to be hacked. I have no idea how to change it/fix it. But it seems weird to me.

You've nailed the complexity of this. On privacy, people are rightfully spooked about this for all the reasons you've mentioned. On safety, people are really happy about these initiatives as accounts backed by user identity are less likely to be used for harm. On security, leaks of these databases create issues to other sites and companies (eg: if Company X is compromised, then identity documents could be used to dis…

> Specifically for Stripe, I trust them

The problem with this is that the user isn't trusting Stripe today, they are trusting Stripe today, and all future Stripe managers and owners until the user dies and no longer cares. That's a big bet! Bad CEOs and sales happen.

Re: Stripe Identity

#292
This is funny timing. My neighbor is the CTO at a company managing identity and building out frameworks and products to help other companies do it themselves. He was trying to pitch me on joining. Sounded neat until I found out how much they focus on the blockchain. It's far too likely it's a gimmick tacked on for no reason but getting hype and investment. Blockchain just attracts all the wrong people in my experience.

This looks cool though, and no gimmicks.

Re: Stripe Identity

#295
post #230
post #164

Earlier quoted context omitted.

SMS messages are probably 1000x to 100 000x more expensive to send than push notifications.

Push is free, assuming you have network connectivity, and 100000*0 is still 0.

Edit: Totally wrong

You need to buy from apple/google if you want battery efficiency, as you want to be included in the one persistent channel the OS manages.

Even without that your own servers cost money.

Re: Stripe Identity

#296
post #201

Earlier quoted context omitted.

Was the data cached locally in your app?

That's still storing the data. Nothing says that the user typically lets this sort of information stay on their phone.

That's nice, but I'm not here to argue for one viewpoint or another, I'm just trying to explore the complaint that originated this thread.

Re: Stripe Identity

#297
post #221

Earlier quoted context omitted.

Those are usually from automated user accounts, not actual bots.

And the difference is?

Bots are officially sanctioned as such and have an application ID in the developer console as well as a label in the client. Alternatively, nothing's stopping someone from taking a user account's authentication token and making the same calls, but that's against TOS (Discord calls them selfbots). The KYC they use won't protect against this kind of abuse.

Re: Stripe Identity

#298
post #184

Earlier quoted context omitted.

I always hear this line of thinking, but there aren’t ever supporting examples presented. Stripe reminds me of Cloudflare. Cloudflare is over 5x what it was at IPO (as of 6/14/21). Maybe what you describe is the case “on average” for most IPOs, but it seems to not be the case for extraordinary companies like Cloudflare (and maybe Stripe). Obviously just an n of 1 but I’m sure others could chime in with similar exampl…

There are numerous examples on both sides for sure. I would add that performance also does well for companies operating in a bull market. In the case of cloudflare (And many tech stocks) they had a black swan event of a large portion of the global economy going online during the pandemic which has juiced their returns. Not saying it doesn't happen but rather that it isn't how people typically price their IPOs to gene…

Yep, makes sense. A little nitpick: I wouldn’t call it a Black Swan because multiple people called out the potential for such a global event to happen (Gates, Taleb, etc.), but to your point it certainly further accelerated the move to online commerce, mainstream remote work, etc. Cloudflare and Stripe are/were both well positioned for that type of world.

Re: Stripe Identity

#299
post #290

Considering that Stripe was originally known for letting websites accept credit card payments without seeing your credit card number, one might assume that Stripe Identity only allows websites to see the verification result, and not your selfies and scans of your identity documents. That would be an incorrect assumption. Per https://support.stripe.com/questions/managing-your-id-verifi... customers of Stripe Identity…

>Considering that Stripe's original selling point was that it let websites accept credit card payments without seeing your credit card number

I thought that Stripe's original selling point was that you could easily accept payments online without having to integrate with complicated bank and payment processor tech.

Re: Stripe Identity

#300

Does anyone know if it does liveness checks for the "selfie verification"? The docs are a bit vague on that. And do I understand "Stripe uses a combination of machine learning models, automated heuristic analysis and manual reviewers to verify the authenticity of hundreds of different document types." correctly in that I do not only upload video/images of my passport, face to stripe for automatic analysis but in some…

Liveness check is coming soon!

At the moment we take live photos of the individual to help confirm that there’s a real person behind the camera.

Post reply on HN