Live data from Hacker News

Stripe Identity

stripe.com

371–380 of 557 posts

Re: Stripe Identity

#371

Earlier quoted context omitted.

> Businesses that do not have a legitimate reason to view my sensitive document like Passport , should not be allowed to do so. I get parent comment's totally legitimate security concerns. And businesses that have no business having my identity should surely not be asking for it. But I don't honestly understand how this has anything to do with Stripe. These businesses (which for whatever reason are asking for ID veri…

You seem to be contradicting yourself. Businesses are asking for Stripe to verify identity. These businesses just need verification, not copies of documents, but Stripe makes them available anyway. That's the whole contention. As a consumer, I would expect Stripe would do the verification and give the business partner the result, but not all the data they used to get the results themselves.

I actually disagree with this as well. The Hacker News user is not the average user. The average user has no idea what Stripe is, they assume that the business requesting a verification will have access to anything they submit.

I know this because we use Stripe Identity ourselves (in beta) and user's have no idea that Stripe and us are different companies.

Re: Stripe Identity

#372

I really despise this trend of uploading your ID and a selfie for verification. I know it makes sense in some legal frameworks, but beyond that I find it invasive and risky (and rude.)

I recently had, twice, to do stuff WAY more intrusive. Video/conf call, need to hold my passport, need to have my phone on hand... People on the other side would call me on my phone to verify it's my number and they'd also send me a SMS with a code to verify on that phone. After that they have: my face, copy of my passport, my voice, my phone number, my IP (unless I'm really going out of my way to obfuscate it), my e…

You said it happened twice. I haven't yet had to face this level of intrusiveness, but I fear that it's coming for all of us. May I ask what companies these were? If you don't want to name the exact companies, could you say the general purpose (opening a bank account, buying or selling real estate, incorporating a business, etc.)? Also, which country (I'm assuming the U.S.)?

Re: Stripe Identity

#373

Does Stripe intend to make a giant online database of international identity documents? Why should we trust Stripe to secure these? It could be Equifax levels of problematic if there would be a intrusion, but I also can't tell how Stripe plans to use this information.

I don't think they are going to beat Facebook in this race.

Re: Stripe Identity

#374
post #290

Considering that Stripe was originally known for letting websites accept credit card payments without seeing your credit card number, one might assume that Stripe Identity only allows websites to see the verification result, and not your selfies and scans of your identity documents. That would be an incorrect assumption. Per https://support.stripe.com/questions/managing-your-id-verifi... customers of Stripe Identity…

It's unfortunate , I'm an Enterprise Architect in Banking and honestly I wouldn't have let that feature go in production. Businesses that do not have a legitimate reason to view my sensitive document like Passport , should not be allowed to do so. Only authorized institutions like Licensed Payment Institution / Banks / Insurances etc... should be allowed to do so and AFTER they've been approved. It's sad because you…

As a person that still is trying to recover from identity fraud that happened many years ago. I am always very weary of companies that demand ID papers. Most of the time I will avoid them.

Most companies aren't even supposed to ask for identity papers is Stripe verifying with the passport issuer whether the country allows given their passport to some identity?

I think there should be some sort of consent system built in were when the API consumer wants to download a passport the customer gets an email with the question if they consent in them fetching a copy.

Re: Stripe Identity

#375
post #290

Considering that Stripe was originally known for letting websites accept credit card payments without seeing your credit card number, one might assume that Stripe Identity only allows websites to see the verification result, and not your selfies and scans of your identity documents. That would be an incorrect assumption. Per https://support.stripe.com/questions/managing-your-id-verifi... customers of Stripe Identity…

(Stripe cofounder.)

> Considering that Stripe was originally known for letting websites accept credit card payments without seeing your credit card number, one might assume that Stripe Identity only allows websites to see the verification result, and not your selfies and scans of your identity documents.

A few points:

- Fundamentally, Identity makes it possible to choose how much of this data traverses / is stored on your servers, just as Stripe did with card numbers.

- There's a basic difference between card numbers and identity verification. With card numbers, you (generally) don't really care about the number -- you just want the payment. With ID verification, however, many businesses have good reason to want more than just the verification result. For example, they are often subject to compliance requirements that mandate that they themselves possess or have access to the raw information. They may need or wish to perform additional checks on their side. Etc.

- The relevant UI in Identity is deliberately very clear on this points in order to avoid the assumption you're stating. The flow explicitly says "Stripe and [Business] may each use your data." Even though an end user might consider it suboptimal for the business to have their data, we still view it as an improvement to the usual status quo, where this data is frequently stored in very ad hoc fashion and without rigorous security protections.

- While many of the businesses initially building on Identity wanted access to the raw information, it may well make sense for us to enable them to restrict themselves in the future. In this world, Stripe could tell their customers that the business doesn't have access to the raw details. (This might even make sense for Stripe payments in the future.) As a philosophical matter, we consider ourselves to serve the business, which means that limiting access to what we consider to be the business's own information feels a bit strange. That said, it might sometimes be in the interests of the business to allow them to limit themselves in this fashion (especially as Stripe's brand recognition among consumers grows).

- There's a separate concern about compromise of the business's credentials leading to inadvertent disclosure of this information (a situation analogous to an S3 bucket key getting leaked). This is of general concern to us in lots of situations, not just with Identity. We have some new functionality on the way here.

Re: Stripe Identity

#376
post #287
post #11

Earlier quoted context omitted.

It's actually pretty cool (IMO; I'm biased). Drop-in browser-based user authentication that: * Uses various sophisticated heuristics to detect real vs fake IDs. * Matches the ID to the human face. * Detects whether the human face is live or not. * Dynamically requests more or less information depending on the confidence level. It also gets better over time based on the attacks and fraud attempts that Stripe itself se…

pc how are you biased? Do you work at Stripe or something?

[deleted]

Re: Stripe Identity

#377

Earlier quoted context omitted.

It is trivially easy to key-in identity info from a JPG scan They are both toxic, IMO. Businesses need to stop relying on this stuff.

Right but -- the attack vector is different. Scan/parse 10000s of JPG, and all that jazz -- to get identites. Not Trivial. Or if the hotel stored the copy as a physical photo copy -- you're not bulk scanning 10k pieces of parchment at super speed for your identity-theft ring. But download JSON blobs? From 10k records the hotel didn't store properly (cause they are not IT experts, or don't have experts at close hand)…

But like one of the Identity team folks said, the hotel would only have the OPTION to download and store those blobs. They aren't required to, and I'm assuming they would not. They'd be happy with the verification result and letting Stripe handle storing the PII.

Speaking from experience as we use Stripe Identity, and love not having to store the PII.

Re: Stripe Identity

#378
post #270

There's definitely a market for this. Back when I worked in porn (in the camming sphere), we had a team of moderators whose main job was verifying the identity (especially age) of performers. With over 10k performers, this was a lot of work. And you can't just do it once. You have to do it every time a performer starts a performance. People would try all sorts of tricks, like taking a picture of themselves with an ol…

> like taking a picture of themselves with an older sister's ID, all kinds of fake IDs How would Stripe solve something like this?

Oh I'm not saying Stripe has a magic way of solving this. I'm merely stating that this is a hard and annoying problem, that many businesses would gladly let someone else handle.

Re: Stripe Identity

#379
Curiously, they support validating identities from Costa Rica but so far they don't support processing payments there. I wonder if the payments service is in-the-works for this country.

Re: Stripe Identity

#380
post #290

Considering that Stripe was originally known for letting websites accept credit card payments without seeing your credit card number, one might assume that Stripe Identity only allows websites to see the verification result, and not your selfies and scans of your identity documents. That would be an incorrect assumption. Per https://support.stripe.com/questions/managing-your-id-verifi... customers of Stripe Identity…

I suspect most (if not all) KYC regulations require you to keep the evidence you used to verify the identity - even landlords in the UK are required to keep the evidence they saw of your right to live in the UK, let alone any institution that actually needs to prevent fraud etc. I suspect it's just a basic requirement of selling such a service to most medium-large businesses.

You're probably right about KYC, but KYC is just one of the four use cases presented by Stripe, and their customer logos include Clubhouse and Discord, which I highly doubt have KYC requirements or any need to access the underlying evidence.

Stripe could do this differently:

1. Allow the customer to choose whether or not they need access to the evidence.

2. If customer has chosen to receive access to the evidence, the Stripe Identity UI should clearly disclose this. (And they shouldn't try to deceive users by talking about deleting biometric identifiers.)

3. Require customers with access to evidence to adhere to certain security standards, similar to how they treat exports of credit card numbers: https://stripe.com/docs/security/data-migrations/exports#whe...

Stripe could have been a leader in setting high standards on how this type of information is handled. Instead they've opted to go the easy route and maximize profits while the rest of us pay the negative externalities from identity theft.

Post reply on HN