Live data from Hacker News

Stripe Identity

stripe.com

431–440 of 557 posts

Re: Stripe Identity

#431

This is a refreshingly affordable and beneficial offering. I did a deep-dive on KYC providers last year. The more well-known folks commanded 5 figure setup fees, wanted 1 to 2 year commitments, and sought to have you pre-pay for verifications. It reminded me of internet credit card processing pre-Stripe.

FWIW there are waaaay cheaper and yet decent options.

Re: Stripe Identity

#432
post #349

Earlier quoted context omitted.

I haven't given up on them, but LATAM is definitely not their focus and we've moved 95% of our payment volume to a local payment processor, even tough we were one of the first private beta testers back in 2015 (wow, it's been 6 years already). My angle is in Brazil. Even after all these years, they still don't support monthly installments, which is literally a single line API param that, honestly, I don't know any ot…

We're making up for lost time in Brazil and hope to change your mind in the next 6 months. I'd love your feedback on installments, Pix, and Custom Connect. Can you reach out to Marcio@Stripe? Thanks for the marketing typo, on it.

That's great to hear Marcio. I've emailed you. Cheers.

Re: Stripe Identity

#433

Earlier quoted context omitted.

You are right but frameworks help with long term maintainability of code and also being able to build out features quickly which is what the comment was referring to originally. If they use Go lang of some other tech stack without framework it can help them achieve their goal but not at the same speed.

Stripe does not use Ruby on Rails

https://www.quora.com/What-programming-languages-does-Stripe...

Re: Stripe Identity

#434

Earlier quoted context omitted.

It's unfortunate , I'm an Enterprise Architect in Banking and honestly I wouldn't have let that feature go in production. Businesses that do not have a legitimate reason to view my sensitive document like Passport , should not be allowed to do so. Only authorized institutions like Licensed Payment Institution / Banks / Insurances etc... should be allowed to do so and AFTER they've been approved. It's sad because you…

My take is that if you need it, Stripe will be better and more secure than rolling your own

More data concentration makes for a more worthwhile target, thus wiping out at least some of the potential upside. The net effect may very well be negative.

Given the regular stream of extremely large data leaks even from providers who should have size, motivation and competency to protect that data, I find it incredibly hard to believe anyone who tries to assure me, that they won't be breached.

Re: Stripe Identity

#435

Earlier quoted context omitted.

For anyone looking for the answer, in the US it's $1.50 / ID verification and $0.50 for Social Security Number lookup (an American tax number that is officially not for identity purposes but used that way all the time).

I'll give my SSN to a healthcare provider, and maybe a bank. Random vendor using Stripe? Probably not. Edit: to be a little less flippant, what is an example of a Stripe user to whom you would be comfortable giving your SSN?

You know you don't actually have to give your SSN to healthcare providers, right?

I leave it blank and tell them (in vaguely more polite terms) to fuck off if they probe me about not providing it.

Re: Stripe Identity

#436

I really despise this trend of uploading your ID and a selfie for verification. I know it makes sense in some legal frameworks, but beyond that I find it invasive and risky (and rude.)

It’s not really a “trend”—if you think about it, ID verification is already required when checking into hotels, buying alcohol, or when visiting a bank teller. As more commerce moves online, Stripe Identity was built to significantly reduce the number of organizations and humans that would touch your ID—in a faster, secure way that’s hosted by Stripe ( https://support.stripe.com/questions/common-questions-about-... )…

It's not a good trend though. I actually prioritize doing business with vendors that don't do this (I only shop at stores that don't generally card for alcohol for instance)

Re: Stripe Identity

#437
post #427

Earlier quoted context omitted.

> Why - in your opinion - is it worse for consumers when these-type businesses (which ask for identity), use their own-rolled id verification than using Stripe's? The point isn't so much using third party , we use a third party on prem. My point is very simple : Why on earth would you let discord view my passport ? JUST WHY ?! Those documents are very sensitive and no one should have access to them unless they have a…

If you've ever been carded at a bar/liquor store in a foreign country, then that random small business has seen your passport, no? How do you feel about that?

Presumably they aren’t taking photographs of the passport and viewing them at some later date from personal computers.

Re: Stripe Identity

#438
post #427

Earlier quoted context omitted.

> Why - in your opinion - is it worse for consumers when these-type businesses (which ask for identity), use their own-rolled id verification than using Stripe's? The point isn't so much using third party , we use a third party on prem. My point is very simple : Why on earth would you let discord view my passport ? JUST WHY ?! Those documents are very sensitive and no one should have access to them unless they have a…

If you've ever been carded at a bar/liquor store in a foreign country, then that random small business has seen your passport, no? How do you feel about that?

Being human to human, unless they're wearing tech that would allow them to scan/archive it, normally they just verify (eyeball it) and you get it back.

Here, with this system, they could verify and keep the data regardless of what I think is going on.

Re: Stripe Identity

#439
post #427

Earlier quoted context omitted.

If you've ever been carded at a bar/liquor store in a foreign country, then that random small business has seen your passport, no? How do you feel about that?

Being human to human, unless they're wearing tech that would allow them to scan/archive it, normally they just verify (eyeball it) and you get it back. Here, with this system, they could verify and keep the data regardless of what I think is going on.

If you can't assume that a website you upload a scan of your ID to isn't capturing details about it, then you can't assume that a bouncer checking your ID isn't wearing a surreptitious HMD, no? In both cases, you're submitting your PII to an unknown process that seems like it should be safe, but with no previous experience or brand-image there to tell you whether there's actually any proof that it's safe.

Re: Stripe Identity

#440
This seems like a really useful service but I am concerned this is going to normalize requiring identity info for sites which do not legally need it. I imagine the pretext for most will be fraud prevention, and while this might be true, I cannot see how this wouldn’t eventually be used for ad targeting and other “consumer is the product” funding models without regulation restricting it.
Post reply on HN