Live data from Hacker News

Stripe Identity

stripe.com

461–470 of 557 posts

Re: Stripe Identity

#461

Earlier quoted context omitted.

The fix is for the government to make it a service. Right now, the government is punting responsibility to private actors who do not have the legal tools to operate an identity service. The government already operates an identity service via passports. The only reason they do not have an electronic identity service yet is because it is beneficial for them to be able to blame private actors when things go wrong.

But at a fundamental level, why do Discord and Clubhouse need to verify my identity? I don't think the question GP is asking is whether or not Stripe is a good way to confirm someone's real-life identity, or whether it would be better for the government to do it. I think what they're asking why we're doing identity verification for chat applications. Is this a good direction overall for the Internet to be moving in?…

> Discord and Clubhouse need to verify my identity?

Discord are doing it for verifying bot ownership, because bots can do a lot of damage if they're just free to sign up to Discord and start "talking" to people. A good way of omitting bad bots from the network is by verifying and tying the bot to the (verified) identity of a real person.

I run a server with 1,200 people on it - I've never needed to verify my identity. You don't need to verify your identity for using Discord.

Re: Stripe Identity

#462
post #449

Earlier quoted context omitted.

Fully agree here - I would say that I am a bit shocked at the lack of regulation regarding access to people’s identity documents as compared to credit cards. Credit/debit cards are your money, and there’s an entire network of both regulations and intermediaries working against fraud in this space. Your identity can create new credit cards. It can take out loans. It is inherently a higher order security risk, and ther…

> I would say that I am a bit shocked at the lack of regulation regarding access to people’s identity documents as compared to credit cards. To some degree it's because there isn't much point. You can call up my home state today, pinky promise that you're me, hand over $20, and they'll ship you my birth certificate or other important documents. We don't have private keys or other kinds of unique identifiers assigned…

It's supposed to work in quite a few countries, and not all make it so easy. Given the requirement in my country for ID when obtaining any other ID, I'm actually puzzled about what happens if you lose everything.

https://stripe.com/docs/identity/verification-checks

Re: Stripe Identity

#463
post #375
post #290

Considering that Stripe was originally known for letting websites accept credit card payments without seeing your credit card number, one might assume that Stripe Identity only allows websites to see the verification result, and not your selfies and scans of your identity documents. That would be an incorrect assumption. Per https://support.stripe.com/questions/managing-your-id-verifi... customers of Stripe Identity…

(Stripe cofounder.) > Considering that Stripe was originally known for letting websites accept credit card payments without seeing your credit card number, one might assume that Stripe Identity only allows websites to see the verification result, and not your selfies and scans of your identity documents. A few points: - Fundamentally, Identity makes it possible to choose how much of this data traverses / is stored on…

One of the points brought up by privacy folks in review of Apple’s plan to have your ID in your digital wallet is that the mere convenience of allowing access to ID may create ID requirements for users where none existed before, which is a loss for privacy. Do you think that Identity is going to create such new requirements?

Re: Stripe Identity

#464
post #392
post #375

Earlier quoted context omitted.

(Stripe cofounder.) > Considering that Stripe was originally known for letting websites accept credit card payments without seeing your credit card number, one might assume that Stripe Identity only allows websites to see the verification result, and not your selfies and scans of your identity documents. A few points: - Fundamentally, Identity makes it possible to choose how much of this data traverses / is stored on…

Thanks for your reply. > Fundamentally, Identity makes it possible to choose how much of this data traverses / is stored on your servers, just as Stripe did with card numbers. There's a stark difference in how Stripe treats exports of card numbers versus exports of raw identity verification data. This makes it way easier, and more likely, for Stripe customers to choose to store raw identity verification information.…

> Ideally, businesses that want the raw data would be subject to security compliance requirements.

Isn’t that already true for businesses that store this data from any source?

Re: Stripe Identity

#465
post #450

Earlier quoted context omitted.

That's a silly stretch. It's vastly more likely that a website fetching copies of a passport image is leaking copies or leaving the files where it shouldn't by accident and has the data exfiltrated by third party identity thieves, compared with a bouncer having a secret scan-quality camera installed by identity thieves without the bouncer noticing.

Who said anything about the bouncer not noticing? I'm presuming that the bouncer is the identity thief. If you're looking to make money as an identity thief, being a bouncer is the perfect job! There was a story on Reddit a few months back, about a bouncer who, when handed real ID cards, claimed they were fakes, and proceeded to immediately "cut them up" (so that people didn't feel any need to demand them back, since…

Wow, that's impressive.

I would still assume identity theft via websites being hacked is a lot more common, and likelihood is an appropriate factor when evaluating protective actions. But you make a good point about the bouncer.

Re: Stripe Identity

#466
post #452

It really makes you wonder what kind of optics they are looking through when coming up with these things. Literally no one (at least not the majority of individuals) wants this. It's one of those things that you expect a more shady company to release. Then again (and it's all hearsay mind you) that they are not a good company to work with, and when talking to employees who left, they don't seem like a good company to…

I think it’s more “prove who you are in order to drive for Uber” and less “prove who you are in order to buy something on the internet”. The completion rates from the latter would be worse than just eating the fraud in probably most cases.

We all want Uber to verify identity because paying for a ride with a complete anon is not the best idea.

Re: Stripe Identity

#467
post #408
post #392

Earlier quoted context omitted.

Thanks for your reply. > Fundamentally, Identity makes it possible to choose how much of this data traverses / is stored on your servers, just as Stripe did with card numbers. There's a stark difference in how Stripe treats exports of card numbers versus exports of raw identity verification data. This makes it way easier, and more likely, for Stripe customers to choose to store raw identity verification information.…

Appreciate your feedback. On the first point, limitations on what the secret key can access are coming very soon. > A concrete suggestion: make it possible for businesses to choose whether they have access the raw data, and expose the choice to the end user in the Stripe Identity flow. Ideally, businesses that want the raw data would be subject to security compliance requirements. This is an opportunity for Stripe to…

+1 on being able to choose. I’m building a personal finance app right now, and where I can I’m choosing to not ingest or retain sensitive data. While the origin of this is scratching my own itch, I suspect that I’ll get better traction if I can overtly say I’m not collecting data I don’t need or holding onto it for longer than you want me to. I’d love to be able to just get a Boolean back.

Re: Stripe Identity

#468
post #408
post #392

Earlier quoted context omitted.

Thanks for your reply. > Fundamentally, Identity makes it possible to choose how much of this data traverses / is stored on your servers, just as Stripe did with card numbers. There's a stark difference in how Stripe treats exports of card numbers versus exports of raw identity verification data. This makes it way easier, and more likely, for Stripe customers to choose to store raw identity verification information.…

Appreciate your feedback. On the first point, limitations on what the secret key can access are coming very soon. > A concrete suggestion: make it possible for businesses to choose whether they have access the raw data, and expose the choice to the end user in the Stripe Identity flow. Ideally, businesses that want the raw data would be subject to security compliance requirements. This is an opportunity for Stripe to…

Here we go, online IDs. It seems inevitable that some entity will leak this data at some point. Then what?

Re: Stripe Identity

#469

This seems like a really useful service but I am concerned this is going to normalize requiring identity info for sites which do not legally need it. I imagine the pretext for most will be fraud prevention, and while this might be true, I cannot see how this wouldn’t eventually be used for ad targeting and other “consumer is the product” funding models without regulation restricting it.

This
Post reply on HN