Live data from Hacker News

Stripe Identity

stripe.com

381–390 of 557 posts

Re: Stripe Identity

#381

Earlier quoted context omitted.

You seem to be contradicting yourself. Businesses are asking for Stripe to verify identity. These businesses just need verification, not copies of documents, but Stripe makes them available anyway. That's the whole contention. As a consumer, I would expect Stripe would do the verification and give the business partner the result, but not all the data they used to get the results themselves.

I actually disagree with this as well. The Hacker News user is not the average user. The average user has no idea what Stripe is, they assume that the business requesting a verification will have access to anything they submit. I know this because we use Stripe Identity ourselves (in beta) and user's have no idea that Stripe and us are different companies.

> user's have no idea that Stripe and us are different companies.

Doesn't that imply that if there's a security breach at Stripe, that your users will blame you [too]

Re: Stripe Identity

#382

Earlier quoted context omitted.

It's unfortunate , I'm an Enterprise Architect in Banking and honestly I wouldn't have let that feature go in production. Businesses that do not have a legitimate reason to view my sensitive document like Passport , should not be allowed to do so. Only authorized institutions like Licensed Payment Institution / Banks / Insurances etc... should be allowed to do so and AFTER they've been approved. It's sad because you…

> Businesses that do not have a legitimate reason to view my sensitive document like Passport , should not be allowed to do so. I get parent comment's totally legitimate security concerns. And businesses that have no business having my identity should surely not be asking for it. But I don't honestly understand how this has anything to do with Stripe. These businesses (which for whatever reason are asking for ID veri…

> Why - in your opinion - is it worse for consumers when these-type businesses (which ask for identity), use their own-rolled id verification than using Stripe's?

The point isn't so much using third party , we use a third party on prem.

My point is very simple : Why on earth would you let discord view my passport ? JUST WHY ?!

Those documents are very sensitive and no one should have access to them unless they have a VERY good reason to do so. PCI DSS treat "card information" like hot lava, the same model should have applied here.

Stripe should have acted as a "Trusted Party" and securely store those documents without giving access to it but just let you extract the information from it.

Thus you would been able to have uniquely identified user , backed up by government id , but you can't get access to the documents and sensitive data should have been redacted .... just like Card Number...

Again unless you are a Fintech / Financial Instituion , with a VALID in effect license , you should not have access to those documents.

Re: Stripe Identity

#384
Yeah, let's make a for-profit corporation an identity management entity. What could go wrong.

- Did you say something politically incorrect? Banned. - Stripe employees don't like you? Banned. - They just feel like it. Banned.

Yeah. No.

Re: Stripe Identity

#385
post #290

Considering that Stripe was originally known for letting websites accept credit card payments without seeing your credit card number, one might assume that Stripe Identity only allows websites to see the verification result, and not your selfies and scans of your identity documents. That would be an incorrect assumption. Per https://support.stripe.com/questions/managing-your-id-verifi... customers of Stripe Identity…

Certainly a market for this sort of thing, but agree, dangerous privacy management.

Re: Stripe Identity

#386

Earlier quoted context omitted.

I honestly find it weird having all of these things suddenly want a copy of my passport in the cloud just sitting there waiting to be hacked in years to come when the security measures drop. At this point there is giant databases containing everything people need to take complete control of your identity sitting there just waiting to be hacked. I have no idea how to change it/fix it. But it seems weird to me.

The fix is for the government to make it a service. Right now, the government is punting responsibility to private actors who do not have the legal tools to operate an identity service. The government already operates an identity service via passports. The only reason they do not have an electronic identity service yet is because it is beneficial for them to be able to blame private actors when things go wrong.

> The fix is for the government to make it a service.

Agreed. An example: https://www.realme.govt.nz/

Re: Stripe Identity

#387
post #287
post #11

Earlier quoted context omitted.

It's actually pretty cool (IMO; I'm biased). Drop-in browser-based user authentication that: * Uses various sophisticated heuristics to detect real vs fake IDs. * Matches the ID to the human face. * Detects whether the human face is live or not. * Dynamically requests more or less information depending on the confidence level. It also gets better over time based on the attacks and fraud attempts that Stripe itself se…

pc how are you biased? Do you work at Stripe or something?

I think pc is one of the Stripe co-founder.

Re: Stripe Identity

#388
post #66

At work we do eIDV of customers and we tested 5 companies. One was quality but too expensive and required too large commitments; two couldn't detect badly photoshopped frauds we threw together, another couldn't detect a printed or on-screen copy of a document being captured (vs the real document - difficult to do, but important). The fifth which we're using can detect printed copies of documents around half the time,…

It is absolutely impossible to validate the authenticity of an ID document from a photo. Even if you capture a high-res photo and have it inspected by a trained document expert.

Fortunately, it is not necessary to do this. Modern passports and many identity cards contain NFC chips that allow you validate the data on an identity document with complete certainty (as in: you know that the data is correct and not tampered with). In the majority of cases (depending on the document supporting the necessary protocols) it is also possible to prove that the chip is authentic and not a clone.

Since the chip also contains a good quality color photo of the document holder, it is then possible to match this with the person holding the phone and do liveness detection.

Remote optical verification of documents is impossible, and anyone who claims they can do it isn't being honest.

Re: Stripe Identity

#389
post #99

The landing page contains logos for clubhouse, discord, and shippo, which are presumably companies use the service. Does anyone find those usages to be unnecessarily intrusive? Maybe it's just me, but a chat app or shipping site asking me for a drivers license scan + selfie would make me never want to use the service again. It's appalling how this sort of stuff is getting normalized, eg. google asking for id scans fo…

I completely agree. Also we don't know how this data is shared or used. Can't wait for new privacy laws to come in place for such data handling.

Re: Stripe Identity

#390

Earlier quoted context omitted.

> It is not necessarily to create value going forward Not sure where you are going with that thought. A business that isn't creating value is going out of business or selling to someone who has an idea of how to use its assets to create value.

Actually not all companies create value. Monopolies create profits through pricing distortions but not necessarily value. My point is that creating value is not a key component of a company going public. In this current moment I would wager that if you are suggesting that you will create value in the market going forward you will get a great return on your investor dollars but you may not actually execute that value…

Perhaps my original wording should have been "delivering value" rather than "creating value." Of course it's true that some things that companies do are at best shifting value around and at worst extracting or even stealing value from elsewhere. But my point was that people who buy public stock from a company almost certainly expect that company to somehow be more valuable in the future.
Post reply on HN