Live data from Hacker News

Stripe Identity

stripe.com

401–410 of 557 posts

Re: Stripe Identity

#401
post #375
post #290

Considering that Stripe was originally known for letting websites accept credit card payments without seeing your credit card number, one might assume that Stripe Identity only allows websites to see the verification result, and not your selfies and scans of your identity documents. That would be an incorrect assumption. Per https://support.stripe.com/questions/managing-your-id-verifi... customers of Stripe Identity…

(Stripe cofounder.) > Considering that Stripe was originally known for letting websites accept credit card payments without seeing your credit card number, one might assume that Stripe Identity only allows websites to see the verification result, and not your selfies and scans of your identity documents. A few points: - Fundamentally, Identity makes it possible to choose how much of this data traverses / is stored on…

Do you verify when a business downloads our identity documents from your servers that they're only doing so to meet regulatory requirements? What promise do we have you're not just making it as easy as possible to obtain drivers licenses, passports, birth certificates, etc. so that every little monster who has something we want will start making it a requirement? Have you considered how your service might impact trans people or undocumented citizens?

Re: Stripe Identity

#402

I really despise this trend of uploading your ID and a selfie for verification. I know it makes sense in some legal frameworks, but beyond that I find it invasive and risky (and rude.)

I recently had, twice, to do stuff WAY more intrusive. Video/conf call, need to hold my passport, need to have my phone on hand... People on the other side would call me on my phone to verify it's my number and they'd also send me a SMS with a code to verify on that phone. After that they have: my face, copy of my passport, my voice, my phone number, my IP (unless I'm really going out of my way to obfuscate it), my e…

Until these people are breached and someone takes out a mortgage in your name using all these lovely personal details.

Re: Stripe Identity

#403
post #95

Earlier quoted context omitted.

I'm not familiar with Stripe's situation, but there are non-public markets available for this kind of stock sale. You just can't buy from them unless you're already rich. I'd guess that long-term employees do have an amount of flexibility in that regard.

Can you form a mutual fund/ETF that invests into those kind of companies via the non-public markets and then sell shares publicly for the fund?

Scottish Mortgage (SMT) in the UK does this and has a stake in Stripe (https://citywire.co.uk/investment-trust-insider/news/boost-f...)

Re: Stripe Identity

#404
I've worked in risk & fraud for some time now. As online platforms become mainstreams and are easier to build I think Trust and Safety is going to become the key differientiator. Stripe Indentity will no doubt play a big role and benefit the whole internet.

Are any accuracy numbers for Stripe Identity currently available? I'm working with a merchant in Europe who is struggling due to fraud. Would be cool to figure out if Stripe Identity will improve over their current solution.

Re: Stripe Identity

#405
post #392
post #375

Earlier quoted context omitted.

(Stripe cofounder.) > Considering that Stripe was originally known for letting websites accept credit card payments without seeing your credit card number, one might assume that Stripe Identity only allows websites to see the verification result, and not your selfies and scans of your identity documents. A few points: - Fundamentally, Identity makes it possible to choose how much of this data traverses / is stored on…

Thanks for your reply. > Fundamentally, Identity makes it possible to choose how much of this data traverses / is stored on your servers, just as Stripe did with card numbers. There's a stark difference in how Stripe treats exports of card numbers versus exports of raw identity verification data. This makes it way easier, and more likely, for Stripe customers to choose to store raw identity verification information.…

Depending on where you're located, there is a responsibility to only take information you require.

I get your point, but you seem to be implying this data is captured without the customer being aware. That will not be the case, surely.

Re: Stripe Identity

#406

Earlier quoted context omitted.

Who is “we”? Maybe the people operating the chat app have determined that it is in their businesses’ best interest to verify identity. I can certainly see it reducing costs for the business. I am not suggesting all businesses be required to do it. But I do not see why businesses should be prohibited from doing it. If you do not want an identity linked service, then buy a website name, and start a business and do not…

"We" in this context means the overall population of users on the web, including non-corporate users and individuals who are exercising their freedoms online. We can't justify every architecture decision about the web via only business costs, if that was the case we'd make adblockers illegal and deprecate HTML. You need a stronger argument if you want me as a user to care about or support your business interests. If…

> why do Discord [..] need to verify my identity?

> the overall population of users on the web

You keep arguing about a non-issue. Normal users do not need to verify with Discord. It's only for bot owners of popular bots to prevent the widespread abuse Discord saw.

https://news.ycombinator.com/item?id=27505905

Re: Stripe Identity

#407
post #375
post #290

Considering that Stripe was originally known for letting websites accept credit card payments without seeing your credit card number, one might assume that Stripe Identity only allows websites to see the verification result, and not your selfies and scans of your identity documents. That would be an incorrect assumption. Per https://support.stripe.com/questions/managing-your-id-verifi... customers of Stripe Identity…

(Stripe cofounder.) > Considering that Stripe was originally known for letting websites accept credit card payments without seeing your credit card number, one might assume that Stripe Identity only allows websites to see the verification result, and not your selfies and scans of your identity documents. A few points: - Fundamentally, Identity makes it possible to choose how much of this data traverses / is stored on…

Do you feel in doing this that you're making the web worse? As a business, you certainly have no obligation to be ethical, but doesn't it feel a bit strange as a person who presumably grew up with the web to be playing such a big role in harming the people who use it?

Re: Stripe Identity

#408
post #392
post #375

Earlier quoted context omitted.

(Stripe cofounder.) > Considering that Stripe was originally known for letting websites accept credit card payments without seeing your credit card number, one might assume that Stripe Identity only allows websites to see the verification result, and not your selfies and scans of your identity documents. A few points: - Fundamentally, Identity makes it possible to choose how much of this data traverses / is stored on…

Thanks for your reply. > Fundamentally, Identity makes it possible to choose how much of this data traverses / is stored on your servers, just as Stripe did with card numbers. There's a stark difference in how Stripe treats exports of card numbers versus exports of raw identity verification data. This makes it way easier, and more likely, for Stripe customers to choose to store raw identity verification information.…

Appreciate your feedback. On the first point, limitations on what the secret key can access are coming very soon.

> A concrete suggestion: make it possible for businesses to choose whether they have access the raw data, and expose the choice to the end user in the Stripe Identity flow. Ideally, businesses that want the raw data would be subject to security compliance requirements. This is an opportunity for Stripe to be a leader in setting high standards on how this type of data should be handled.

Yes, per GP comment, I think this is a good idea. I suspect we'll do it.

Re: Stripe Identity

#409

Yeah, let's make a for-profit corporation an identity management entity. What could go wrong. - Did you say something politically incorrect? Banned. - Stripe employees don't like you? Banned. - They just feel like it. Banned. Yeah. No.

There's a tendency to conflate identification with endorsement. Twitter muddied the two together instead of keeping it as anti-spoofing measure. Users are trained to see HTTPS as a sign a website is legitimate or secure and not just a way to confirm the public key. Democrats want to use the unconstitutional no fly list to ban individuals from buying guns. After the Boston Marathon bomb attack some senators wanted to require KYC on all cellphones and encourage the police to not read suspects their defendant rights. The reflexive opposition to COVID-19 vaccine verification is because people don't trust the government.

Re: Stripe Identity

#410
post #140

Earlier quoted context omitted.

Discord uses it to verify the identity of bot makers - my understanding is that bots have been abused for a long time for data collection (think logging when users come online, go offline, change status, etc).

I don't get it. They're concerned about people abusing the system, and their solution is... requiring KYC? How does that solve the issue? It sounds like bot makes can still passively collect the info, it's just that when it gets discovered they can point to a real person to blame. Moreover, why do bots even need to know the online/offline status of users? Why not add a permission system so users can opt in/out of pro…

> I'm not a discord bot maker

You don't say. Go to a random Discord server and you will see how bots are used. Your solution makes no sense and would kill most of the current use cases.

Post reply on HN