Stripe has lost it's way.
Stripe Identity
341–350 of 557 posts
Re: Stripe Identity
#342Earlier quoted context omitted.
That's not my point , here my point is very clear and straightforward. Some people at Discord now have access at the pictures of my Passport that I uploaded during the verification process because they use "Stripe Identity". The FAQ is very clear , Stripe give you full access to those documents. It should NEVER do so. Now the very smart people have Discord have access to my passport they can now take a 50K Loan using…
I know it's not your point, but it's mine. Why would you upload a copy of your passport to Discord, via a third-party or not? The issue here is just trusting people you shouldn't be trusting with things you shouldn't be trusting them with. The alternative isn't WhizzBangApp doesn't request you upload documents, the alternative is they roll their own WhizBang ID service, or use a Stripe Identity competitor. I know my…
I let my Congressperson know policy is needed about online identity service providers needing better governance over identity data, as businesses aren’t going to do it voluntarily unless the law requires. This should probably be overseen by the CFPB, even though identity is a bit of a walk from finance (while Stripe is still primarily a financial services provider).
Re: Stripe Identity
#343Earlier quoted context omitted.
Are you going to pay me? If not, good luck!
Probably not the answer you expect, but the I18N team is hiring :) https://stripe.com/jobs/listing/internationalization-enginee... Otherwise, if you're a trained linguist and have demonstrable consulting experience QA'ing technical documentation then we'll be happy to arrange something. In either case, we appreciate your feedback, and my emails are open!
Re: Stripe Identity
#344Considering that Stripe was originally known for letting websites accept credit card payments without seeing your credit card number, one might assume that Stripe Identity only allows websites to see the verification result, and not your selfies and scans of your identity documents. That would be an incorrect assumption. Per https://support.stripe.com/questions/managing-your-id-verifi... customers of Stripe Identity…
It's unfortunate , I'm an Enterprise Architect in Banking and honestly I wouldn't have let that feature go in production. Businesses that do not have a legitimate reason to view my sensitive document like Passport , should not be allowed to do so. Only authorized institutions like Licensed Payment Institution / Banks / Insurances etc... should be allowed to do so and AFTER they've been approved. It's sad because you…
I get parent comment's totally legitimate security concerns. And businesses that have no business having my identity should surely not be asking for it. But I don't honestly understand how this has anything to do with Stripe. These businesses (which for whatever reason are asking for ID verification before doing business with you) are just using Stripes API to verify identity instead of just taking your info themselves.
Any customer giving their information presumably knows they are giving said business their identity documents, the customers might not even know that the business is using Stripe's API.
Furthermore, Stripe is ostensibly coming in here to streamline the process for business taking identity info from customers. Why - in your opinion - is it worse for consumers when these-type businesses (which ask for identity), use their own-rolled id verification than using Stripe's?
Re: Stripe Identity
#345Considering that Stripe was originally known for letting websites accept credit card payments without seeing your credit card number, one might assume that Stripe Identity only allows websites to see the verification result, and not your selfies and scans of your identity documents. That would be an incorrect assumption. Per https://support.stripe.com/questions/managing-your-id-verifi... customers of Stripe Identity…
Edwin from Stripe here. The two cases are actually very similar. If you want to avoid ID documents ever being stored on your servers, Identity makes it easy to do that. (Just as Elements/Stripe.js makes that easy for card numbers.) On the other hand, if you want to score card numbers or ID documents (and there are sometimes good reasons for doing this!), Stripe makes that straightforward.
When a hotel copies my passport, they get a jpg. If they use Stripe, now I know they have my biometrics serialized to JSON. That feels way riskier and scarier to me, especially now that it's all centralized by Stripe.
We hear about our personal data getting leaked and hacked every day, and here is Stripe making themselves an enormous target and serializing all the data for malicious actors.
This feels like a really tone deaf misstep by the company.
Re: Stripe Identity
#346Earlier quoted context omitted.
The fix is for the government to make it a service. Right now, the government is punting responsibility to private actors who do not have the legal tools to operate an identity service. The government already operates an identity service via passports. The only reason they do not have an electronic identity service yet is because it is beneficial for them to be able to blame private actors when things go wrong.
This is The Correct Answer™. Misc governments already operate 1,000s of identity, credentialing, and licensing services. Wouldn't it be great if profiles on DoorDash, Yelp, Hotels, etc. were required to be linked to IRL identities and licenses?
Re: Stripe Identity
#347There's definitely a market for this. Back when I worked in porn (in the camming sphere), we had a team of moderators whose main job was verifying the identity (especially age) of performers. With over 10k performers, this was a lot of work. And you can't just do it once. You have to do it every time a performer starts a performance. People would try all sorts of tricks, like taking a picture of themselves with an ol…
How would Stripe solve something like this?
Re: Stripe Identity
#348Earlier quoted context omitted.
Is this a discussion about the architecture of the web? Or about specific websites? If Costco wants me to login to their website to buy things, or Facebook wants me to use real identity, that does not stop me from using alternatives that do not. Am I entitled to alternatives that do not verify identity? Maybe the operating costs are too high?
Your proposal is for a government-run identity verification system. The "we" in this context (ordinary users) also comprise the majority of voters and regulators who will ultimately decide how the system you propose is built and what restrictions it will have; and that is a group that is not solely motivated by your business interests -- so it is kind of important for you to be able to convince them that your system…
Re: Stripe Identity
#349I gave up on Stripe because they clearly are a US-focused company, and do not have a global outlook. I find it disappointing that after so many years of being in business, their payment processing services are still only available to a few dozen countries. This for example makes it impossible to rely on them to build a global marketplace with Stripe Connect accepting merchants from all over the world. Stripe is not f…
My angle is in Brazil. Even after all these years, they still don't support monthly installments, which is literally a single line API param that, honestly, I don't know any other payment gateway in Brazil that doesn't support it. Monthly installments is a huge deal in Brazil.
They also only now started the private beta of Boletos, which is unfortunate since Boletos are being phased out in Brazil due to the new PIX, which allow for instant payments 24/7. So they are basically releasing just now a feature that nobody really wants anymore.
Stripe connect also isn't available (AFAIK only the "standard" account is available, which mandates for Stripe onboarding and can't accommodate any white label marketplace integration).
The lack of focus is noticeable even from their marketing pages. Notice how in https://stripe.com/br/connect the explanation for "Cobranças diretas" and "Cobranças de destino" are exactly the same (the text "Os compradores fazem transações diretamente com os vendedores, mas quase nunca notam a existência da plataforma, que pode cobrar tarifas de transação" appears in both), making it impossible to understand the difference, while if you visit https://stripe.com/us/connect you see two different texts for each option.
Their support team has always responded quickly and politely, but we've had an impossible time trying to understand how they could allow us collect payments from abroad as a marketplace operating in Brazil, and that's even pointing out we didn't rule out opening a US-based company via Stripe Atlas if that was necessary. Lots of contradictory information and when we pressed on, they always end with them noticing that Brazil is still in preview and they still can't operate properly with Connect in Brazil.
Which is weird, considering it's LATAM's biggest market. This release of Stripe Identity missing out Brazil on launch, even tough it's a country that badly needs antifraud solutions, is only one more evidence of this.
Re: Stripe Identity
#350Earlier quoted context omitted.
But, also as an Enterprise Architect in Banking, if you were considering Stripe Identity wouldn't you rely on it for KYC compliance? You can't just say Oh we outsource that to a third-party called Stripe, can you?
That's not my point , here my point is very clear and straightforward. Some people at Discord now have access at the pictures of my Passport that I uploaded during the verification process because they use "Stripe Identity". The FAQ is very clear , Stripe give you full access to those documents. It should NEVER do so. Now the very smart people have Discord have access to my passport they can now take a 50K Loan using…
This is a good policy when ALL first parties meet a certain (regulatory) bar. For banks, I assume that bar is "don't become insolvent" and more recently "don't lend money to terrorists."
The problem is that, as we've seen from the countless hacks in recent years, the first parties are NOT all meeting the bar when it comes to security, namely "don't leak (or abuse) users' private personal info."
And that's unfortunate, because a lot of the time, all a company really needs to know is a "does the registered account correspond (uniquely) to a real human (with certain legal characteristics)." Sometimes they need to know for compliance reasons ("our users are adults" or "aren't terrorists") and other times for uniqueness/fraud reasons ("We want to reduce spam accounts" or "we're paying users $10 to sign up and so need to make sure users aren't signing up multiple times.") It'd be great to be able to answer those questions without having to protect all that personal data that goes into answering it, similar to credit cards.
But your main point stands: if Stripe is allowing companies access to the collected data, then from a security point of view it's little better than having the companies collect and store it themselves. Hopefully Stripe explains their reasoning, or even better, course-corrects early in this launch.