Considering that Stripe was originally known for letting websites accept credit card payments without seeing your credit card number, one might assume that Stripe Identity only allows websites to see the verification result, and not your selfies and scans of your identity documents. That would be an incorrect assumption. Per https://support.stripe.com/questions/managing-your-id-verifi... customers of Stripe Identity…
(Stripe cofounder.) > Considering that Stripe was originally known for letting websites accept credit card payments without seeing your credit card number, one might assume that Stripe Identity only allows websites to see the verification result, and not your selfies and scans of your identity documents. A few points: - Fundamentally, Identity makes it possible to choose how much of this data traverses / is stored on…
Stripe Identity
451–460 of 557 posts
Re: Stripe Identity
#452It's one of those things that you expect a more shady company to release. Then again (and it's all hearsay mind you) that they are not a good company to work with, and when talking to employees who left, they don't seem like a good company to work for.
Stick to CCs, that's intrusive enough.
Re: Stripe Identity
#453I'm surprised that they are not providing PAdES signatures here at the same time, do you think this is a direction they will be moving in? Also surprised they are not leaning more heavily into the existing identity solutions in the countries they are already operating in, like the Netherlands and the Nordics. Maybe hard to differantiate from existing competitors?
Re: Stripe Identity
#454This seems like a really useful service but I am concerned this is going to normalize requiring identity info for sites which do not legally need it. I imagine the pretext for most will be fraud prevention, and while this might be true, I cannot see how this wouldn’t eventually be used for ad targeting and other “consumer is the product” funding models without regulation restricting it.
Is knowing who the customer is with more certainty really useful though for targeting beyond just having their info they provide on sign up?
Techniques such as using different email addresses and other first party data would no longer be effective for limiting cross linking of user data (fingerprinting is an issue as well) if a legal ID is required and that data is shared with the service.
I’m on the fence about a service only using ID verification even from a fully trustworthy third party and not gaining any additional info (save for maybe a random unlinkable ID to prevent multiple accounts or perhaps just a flag indicating whether the ID is eligible for an account on that service). Even that bothers me. I would have to think about it some more. But I kind of do get it and see how that could enable better online communities. I’d like to think there is a better way though.
Re: Stripe Identity
#455The Stripe Identity product is fantastic. Some of the most impressive things: 1. If you are at a desktop, there is an easy transition to using your phone to take a picture of your ID (or a selfie if that's the use case - it will match selfies with ID photos), and then complete verification on the desktop. 2. It does all the image analysis (i.e. is the ID in focus, etc.) in browser without the need for a native app.
Just be aware that, no matter how seamless it is, you still getting crazy bounce rates for it. You would need a really good reason to use it (basically, be a bank and need KYC or something).
Re: Stripe Identity
#456Earlier quoted context omitted.
The fix is for the government to make it a service. Right now, the government is punting responsibility to private actors who do not have the legal tools to operate an identity service. The government already operates an identity service via passports. The only reason they do not have an electronic identity service yet is because it is beneficial for them to be able to blame private actors when things go wrong.
This isn't a problem to fix. Internet businesses don't have an absolute right to your identity. The government (in the US at least) does offer some form of identity services like everify for employment.
The government is using 2FA SMS as your identity (for government services themselves), effectively offloading their liability into the mobile operators. But not really, because the mobile operators are not liable either. So as a little person, you are screwed all around.
If the government were to make an electronic identity, which it needs to for its own services, it might as well be accessible for all so you do not have to trust private businesses with it.
Re: Stripe Identity
#457Earlier quoted context omitted.
We are very specific about collecting consent before doing anything with your data. We ask for permissions before beginning the verification process, and if you consent, we will only use your biometric identifiers for the verification itself. (And again, those identifiers—which contain the most sensitive info—aren't stored.) Specifically, we ask for an additional level of permissions before conducting any additional…
> We are very specific about collecting consent before doing anything with your data. How do you foresee that consent working if your product is used in account recovery flows? For example, imagine if Steam adopted Stripe Identity as their only way to allow people with $$$$ worth of games to recover hacked accounts. If the user's only choice is to "consent" or lose their valuable account, that makes the "consent" som…
Re: Stripe Identity
#458Earlier quoted context omitted.
Stripe hires elite Stanford grads unlike Equifax is the simplest answer they probably wouldn’t say publicly. But the pedigree and engineering talent is miles better.
There isn’t a correlation between graduating from Stanford and being able to write secure code. If there was, all black-hats would be coming from Ivy League schools. They’re not.
Nor is there a correlation between Stanford degrees and wanting to write secure code.
Re: Stripe Identity
#459The Stripe Identity product is fantastic. Some of the most impressive things: 1. If you are at a desktop, there is an easy transition to using your phone to take a picture of your ID (or a selfie if that's the use case - it will match selfies with ID photos), and then complete verification on the desktop. 2. It does all the image analysis (i.e. is the ID in focus, etc.) in browser without the need for a native app.
Meaning they can identify my laptop and phone as belonging to the same person. I prefer they don't.
Re: Stripe Identity
#460Considering that Stripe was originally known for letting websites accept credit card payments without seeing your credit card number, one might assume that Stripe Identity only allows websites to see the verification result, and not your selfies and scans of your identity documents. That would be an incorrect assumption. Per https://support.stripe.com/questions/managing-your-id-verifi... customers of Stripe Identity…
(Stripe cofounder.) > Considering that Stripe was originally known for letting websites accept credit card payments without seeing your credit card number, one might assume that Stripe Identity only allows websites to see the verification result, and not your selfies and scans of your identity documents. A few points: - Fundamentally, Identity makes it possible to choose how much of this data traverses / is stored on…