Live data from Hacker News

Stripe Identity

stripe.com

391–400 of 557 posts

Re: Stripe Identity

#391

Does Stripe intend to make a giant online database of international identity documents? Why should we trust Stripe to secure these? It could be Equifax levels of problematic if there would be a intrusion, but I also can't tell how Stripe plans to use this information.

Seriously.

The only way i would trust such a thing is if i have complete control over my data and how it's used (that's probably never gonna happen from a for-profit imo)

Re: Stripe Identity

#392
post #375
post #290

Considering that Stripe was originally known for letting websites accept credit card payments without seeing your credit card number, one might assume that Stripe Identity only allows websites to see the verification result, and not your selfies and scans of your identity documents. That would be an incorrect assumption. Per https://support.stripe.com/questions/managing-your-id-verifi... customers of Stripe Identity…

(Stripe cofounder.) > Considering that Stripe was originally known for letting websites accept credit card payments without seeing your credit card number, one might assume that Stripe Identity only allows websites to see the verification result, and not your selfies and scans of your identity documents. A few points: - Fundamentally, Identity makes it possible to choose how much of this data traverses / is stored on…

Thanks for your reply.

> Fundamentally, Identity makes it possible to choose how much of this data traverses / is stored on your servers, just as Stripe did with card numbers.

There's a stark difference in how Stripe treats exports of card numbers versus exports of raw identity verification data. This makes it way easier, and more likely, for Stripe customers to choose to store raw identity verification information.

> With ID verification, however, many businesses have good reason to want more than just the verification result. For example, they may be subject to compliance requirements that mandate that they themselves possess or have access to the raw information. They may need or wish to perform additional checks on their side. Etc.

I acknowledge that some businesses have a need for this. But I see Discord and Clubhouse among your customer logos, and your product page talks about non-KYC use cases. Many of your customers will have access to identity documents without really needing it. That sucks for the end users of Stripe Identity, because it makes it more likely their data will be misused.

A concrete suggestion: make it possible for businesses to choose whether they have access the raw data, and expose the choice to the end user in the Stripe Identity flow. Ideally, businesses that want the raw data would be subject to security compliance requirements. This is an opportunity for Stripe to be a leader in setting high standards on how this type of data should be handled.

Re: Stripe Identity

#393
post #108
post #99

The landing page contains logos for clubhouse, discord, and shippo, which are presumably companies use the service. Does anyone find those usages to be unnecessarily intrusive? Maybe it's just me, but a chat app or shipping site asking me for a drivers license scan + selfie would make me never want to use the service again. It's appalling how this sort of stuff is getting normalized, eg. google asking for id scans fo…

What's the difference between filling out your address in text versus scanning? Is your face not on the internet yet? Just curious what specifically would make you never want to use it?

> Is your face not on the internet yet?

Careful there, mate. This is just another form of the infamous "Nothing to hide" fallacy.

https://en.wikipedia.org/wiki/Nothing_to_hide_argument

Re: Stripe Identity

#394

Earlier quoted context omitted.

Probably not the answer you expect, but the I18N team is hiring :) https://stripe.com/jobs/listing/internationalization-enginee... Otherwise, if you're a trained linguist and have demonstrable consulting experience QA'ing technical documentation then we'll be happy to arrange something. In either case, we appreciate your feedback, and my emails are open!

What a quality answer! I get very poor quality support from Stripe's live chat, but the professionalism and helpfulness on HN from Stripe people like you and Edwin is beyond reproach, that's for sure.

That is an interesting data point. In my case the support I got from Stripe over the years (email, chat, IRC, ...) has been consistently stellar. Are you in the US?

Re: Stripe Identity

#395

Earlier quoted context omitted.

Conflating credit card #'s and personal biometrics/SSNs is your first mistake. You think they are the same, they feel the same, but the risk to the customer is so much bigger. When a hotel copies my passport, they get a jpg. If they use Stripe, now I know they have my biometrics serialized to JSON. That feels way riskier and scarier to me, especially now that it's all centralized by Stripe. We hear about our personal…

I’m an engineer on the Identity team. There are two somewhat separate questions here. (1) Whether the business should ever have access to this data. And (2) how exactly the business should access that data and the security properties around it. On (1) this data is fundamentally the user’s, and there are often important compliance reasons as to why the user needs access to the raw data because of obligations that they…

> On (2) we’re working on a way to restrict access via secret keys very soon.

Hmm, this doesn't really seem to me like the sort of area where you bring out a MVP and then work out basic fundamentals like this afterwards.

Re: Stripe Identity

#396
post #2

I've never seen a company release incredible products with as high velocity as Stripe has over the last few years. Truly incredible. $1.50/user may sound outrageously expensive at first, but having seen all the engineering power it takes to build something like this at Uber...it's a totally fair price.

Just what I was thinking. Can Stripe hurry up and go public so I can buy some shares?

If you want exposure to them - go get Shopify stock - they just disclosed being in on the round of Stripe.

https://betakit.com/shopify-reportedly-invests-in-stripe-bri...

Re: Stripe Identity

#397
post #375
post #290

Considering that Stripe was originally known for letting websites accept credit card payments without seeing your credit card number, one might assume that Stripe Identity only allows websites to see the verification result, and not your selfies and scans of your identity documents. That would be an incorrect assumption. Per https://support.stripe.com/questions/managing-your-id-verifi... customers of Stripe Identity…

(Stripe cofounder.) > Considering that Stripe was originally known for letting websites accept credit card payments without seeing your credit card number, one might assume that Stripe Identity only allows websites to see the verification result, and not your selfies and scans of your identity documents. A few points: - Fundamentally, Identity makes it possible to choose how much of this data traverses / is stored on…

Hey Patrick,

> As a philosophical matter, we consider ourselves to serve the business, which means that limiting access to what we consider to be the business's own information feels a bit strange.

Maybe I'm wrong , but once a customer upload the document on Stripe Identity they are supposed to be YOUR documents.

I worked in Bank as a Service , fundamentally when a customer goes through a verification process , the documents uploaded are not the owned by the partner using our APIs. They are owned by us , the Bank.

For Stripe Identity the same should have apply. Here the goal is not "Lock the Partner" but rather to protect them.

Now that discord has access to my Passport , in case of an identity theft could you tell me EXACTLY whose liable for the leak in regards to the law ?

With BaaS it's pretty clear , the Bank carry the responsibility to keep those documents safe , thus it's safer to not give access to a basic business to the raw details.

With the current API design you are offering, it's more ambigous and more prone very large leak within a business information system like Discord or Uber etc..

Those leak will happen.

Re: Stripe Identity

#398
post #375
post #290

Considering that Stripe was originally known for letting websites accept credit card payments without seeing your credit card number, one might assume that Stripe Identity only allows websites to see the verification result, and not your selfies and scans of your identity documents. That would be an incorrect assumption. Per https://support.stripe.com/questions/managing-your-id-verifi... customers of Stripe Identity…

(Stripe cofounder.) > Considering that Stripe was originally known for letting websites accept credit card payments without seeing your credit card number, one might assume that Stripe Identity only allows websites to see the verification result, and not your selfies and scans of your identity documents. A few points: - Fundamentally, Identity makes it possible to choose how much of this data traverses / is stored on…

> With card numbers, you (generally) don't really care about the number -- you just want the payment.

I don't ever want to have a card number in my database or via a administration system (my own or my provider's).

So I care... but just perhaps not in quite the way you're thinking :)

Re: Stripe Identity

#399
post #61

Earlier quoted context omitted.

Just what I was thinking. Can Stripe hurry up and go public so I can buy some shares?

I have been thinking the same thing for some time now. Unfortunately, I wouldn't hold my breath. If they are able to stay private, they probably will. It's easier to build a business when you don't have to deal with the hassle and interference of public markets.

"In March, Stripe, which describes itself as “payments infrastructure for the internet,” became the most valuable private company in Silicon Valley, raising $600 million at a valuation of $95 billion. The Journal reported Stripe is considering going public later this year or early next year."

Re: Stripe Identity

#400

Does Stripe intend to make a giant online database of international identity documents? Why should we trust Stripe to secure these? It could be Equifax levels of problematic if there would be a intrusion, but I also can't tell how Stripe plans to use this information.

No. 1. Stripe cares tremendously about and knows the importance of security—we’ve learned a lot from securely processing hundreds of billions of dollars in payments annually, and Identity is built from those learnings. ( https://stripe.com/docs/security/stripe ). 2. Any biometric identifiers that are created to perform the verification are never stored or retained—they are fully removed from all of our systems within…

The problem is that companies evolve, ethics change, but the data and vendor lock-in remains.

No need to go any further for an example than Google and its "Don't be evil" somehow evolving into "Normalize the creepy".

Post reply on HN