Live data from Hacker News

Stripe Identity

stripe.com

441–450 of 557 posts

Re: Stripe Identity

#441

Earlier quoted context omitted.

I honestly find it weird having all of these things suddenly want a copy of my passport in the cloud just sitting there waiting to be hacked in years to come when the security measures drop. At this point there is giant databases containing everything people need to take complete control of your identity sitting there just waiting to be hacked. I have no idea how to change it/fix it. But it seems weird to me.

The fix is for the government to make it a service. Right now, the government is punting responsibility to private actors who do not have the legal tools to operate an identity service. The government already operates an identity service via passports. The only reason they do not have an electronic identity service yet is because it is beneficial for them to be able to blame private actors when things go wrong.

This isn't a problem to fix. Internet businesses don't have an absolute right to your identity.

The government (in the US at least) does offer some form of identity services like everify for employment.

Re: Stripe Identity

#442
post #427

Earlier quoted context omitted.

> Why - in your opinion - is it worse for consumers when these-type businesses (which ask for identity), use their own-rolled id verification than using Stripe's? The point isn't so much using third party , we use a third party on prem. My point is very simple : Why on earth would you let discord view my passport ? JUST WHY ?! Those documents are very sensitive and no one should have access to them unless they have a…

If you've ever been carded at a bar/liquor store in a foreign country, then that random small business has seen your passport, no? How do you feel about that?

In EU, you don't hand over ID/passport like credit card in US. You show it while keeping it in your hand. Second party can verify your age, while being unable to copy stuff like machine readable zone.

Re: Stripe Identity

#444

This seems like a really useful service but I am concerned this is going to normalize requiring identity info for sites which do not legally need it. I imagine the pretext for most will be fraud prevention, and while this might be true, I cannot see how this wouldn’t eventually be used for ad targeting and other “consumer is the product” funding models without regulation restricting it.

Is knowing who the customer is with more certainty really useful though for targeting beyond just having their info they provide on sign up?

Re: Stripe Identity

#445
Unfortunately for this demo, they will successfully verify everyone. I was hoping for a real demo, in the past I had some interesting problems with selfie KYC checks because the photo in my passeport and my actual look are quite different …

Re: Stripe Identity

#446
I used this for an online car rental service recently. My only main complaint was that it didn't work with FF for Android. Once I switched to Chrome, everything was great, but I'm disappointed in how often sites expect to be ran in a Chromium-based browser these days.

Still appreciate seeing Stripe's name when taking a pic of my ID rather than just the rather small startup I was using. No offense to small startups, but I might've balked at it otherwise.

Re: Stripe Identity

#447
post #439

Earlier quoted context omitted.

Being human to human, unless they're wearing tech that would allow them to scan/archive it, normally they just verify (eyeball it) and you get it back. Here, with this system, they could verify and keep the data regardless of what I think is going on.

If you can't assume that a website you upload a scan of your ID to isn't capturing details about it, then you can't assume that a bouncer checking your ID isn't wearing a surreptitious HMD, no? In both cases, you're submitting your PII to an unknown process that seems like it should be safe, but with no previous experience or brand-image there to tell you whether there's actually any proof that it's safe.

That's a silly stretch. It's vastly more likely that a website fetching copies of a passport image is leaking copies or leaving the files where it shouldn't by accident and has the data exfiltrated by third party identity thieves, compared with a bouncer having a secret scan-quality camera installed by identity thieves without the bouncer noticing.

Re: Stripe Identity

#448

I used this for an online car rental service recently. My only main complaint was that it didn't work with FF for Android. Once I switched to Chrome, everything was great, but I'm disappointed in how often sites expect to be ran in a Chromium-based browser these days. Still appreciate seeing Stripe's name when taking a pic of my ID rather than just the rather small startup I was using. No offense to small startups, b…

Hm! Could you email me with more on the device and browser versions? edwin@stripe.com

Re: Stripe Identity

#449
post #392

Earlier quoted context omitted.

Thanks for your reply. > Fundamentally, Identity makes it possible to choose how much of this data traverses / is stored on your servers, just as Stripe did with card numbers. There's a stark difference in how Stripe treats exports of card numbers versus exports of raw identity verification data. This makes it way easier, and more likely, for Stripe customers to choose to store raw identity verification information.…

Fully agree here - I would say that I am a bit shocked at the lack of regulation regarding access to people’s identity documents as compared to credit cards. Credit/debit cards are your money, and there’s an entire network of both regulations and intermediaries working against fraud in this space. Your identity can create new credit cards. It can take out loans. It is inherently a higher order security risk, and ther…

> I would say that I am a bit shocked at the lack of regulation regarding access to people’s identity documents as compared to credit cards.

To some degree it's because there isn't much point. You can call up my home state today, pinky promise that you're me, hand over $20, and they'll ship you my birth certificate or other important documents. We don't have private keys or other kinds of unique identifiers assigned at birth, so attempts to lock it down further would lock people out of their own identities.

Scale does matter, and a breached database of identity documents is definitely worse than having to pay a nominal fee and wait a few days, but given the context of other manual labor like securing loans I'm not sure the extra ease would result in much more fraud.

Re: Stripe Identity

#450
post #439

Earlier quoted context omitted.

If you can't assume that a website you upload a scan of your ID to isn't capturing details about it, then you can't assume that a bouncer checking your ID isn't wearing a surreptitious HMD, no? In both cases, you're submitting your PII to an unknown process that seems like it should be safe, but with no previous experience or brand-image there to tell you whether there's actually any proof that it's safe.

That's a silly stretch. It's vastly more likely that a website fetching copies of a passport image is leaking copies or leaving the files where it shouldn't by accident and has the data exfiltrated by third party identity thieves, compared with a bouncer having a secret scan-quality camera installed by identity thieves without the bouncer noticing.

Who said anything about the bouncer not noticing? I'm presuming that the bouncer is the identity thief. If you're looking to make money as an identity thief, being a bouncer is the perfect job!

There was a story on Reddit a few months back, about a bouncer who, when handed real ID cards, claimed they were fakes, and proceeded to immediately "cut them up" (so that people didn't feel any need to demand them back, since what are you going to do with scraps of an ID card?) The bouncer was actually palming the real ID and cutting up a random piece of plastic instead, and then later handing the real ID card off to the owner, who sold them on the black market. One victim of this scheme figured it out after being a victim of identity theft, as they traced back a submitted capture of the photo ID that some third-party had retained, to the one that got "cut up." The police raided the establishment, and a whole ring of people were caught up in it. It was a whole thing.

There's nothing that leads me to believe that this isn't a simple, obvious, repeatable, low-stakes, high-margin criminal business model. As such, it probably happens a lot.

Post reply on HN