Live data from Hacker News

Stripe Identity

stripe.com

471–480 of 557 posts

Re: Stripe Identity

#471
post #464
post #392

Earlier quoted context omitted.

Thanks for your reply. > Fundamentally, Identity makes it possible to choose how much of this data traverses / is stored on your servers, just as Stripe did with card numbers. There's a stark difference in how Stripe treats exports of card numbers versus exports of raw identity verification data. This makes it way easier, and more likely, for Stripe customers to choose to store raw identity verification information.…

> Ideally, businesses that want the raw data would be subject to security compliance requirements. Isn’t that already true for businesses that store this data from any source?

No. Unfortunately, most businesses in the US are not under any compliance requirements or regulations around identification. Certain states have special rules (like California I think?) but in most places US businesses can generally do anything they want with an ID card or relevant information, so long as they don't impersonate you or commit a crime with it.

Given the way Stripe has implemented this today, Stripe might as well be selling their business customers a tag for Driver's Licenses, because that's the level of security 99% of all business will be using around this. There's going to be Amazon S3 buckets filled up with Drivers Licenses JPEG's provided by Stripe Identity, in a few months time.

Re: Stripe Identity

#472
post #297

Earlier quoted context omitted.

And the difference is?

Bots are officially sanctioned as such and have an application ID in the developer console as well as a label in the client. Alternatively, nothing's stopping someone from taking a user account's authentication token and making the same calls, but that's against TOS (Discord calls them selfbots). The KYC they use won't protect against this kind of abuse.

Not to mention the possibility of a widely deployed moderation bot being used to attack the servers/channels they're running on, en masse.

Re: Stripe Identity

#473

Earlier quoted context omitted.

In their TOS and Privacy Policy it’s made clear they are also data controllers. Unless you contribute to the breach it would almost certainly fall on them.

Yep, Stripe would be the data controller in this situation (and we comply with GDPR). https://support.stripe.com/questions/managing-your-id-verifi...

To be clear, this isn't entirely true for all situations (sorry). Stripe verifies identities as a service provider (or processor) for the business that's using Identity. Stripe may be either a controller or a processor of data depending on the purpose of data processing (https://support.stripe.com/questions/managing-your-id-verifi...).

Re: Stripe Identity

#474

Earlier quoted context omitted.

Yes I'm talking from a customer point-of-view. Was trying to buy a vps and they for some reason wanted to scan my driver's lic using this before I could pay through Paypal. Yes I was trying to buy via PayPal but this was step 1 for some reason. So I have only seen this work from the customer's point-of-view and it was not a good experience for me. I am a very patient person as i scanned my dl 4 times on desktop using…

I think they mean 'was it stripe identity' (there is stripe branding during verification) or was the company using some other solution. The experiences I've heard from bot developers using Discord and thus their Stripe Identity verification haven't had any issues.

Yes it was stripe identity 100% not a custom solution. I think my experience was bad because it wanted to scan the back of my card which is just empty. Hopefully their tech will improve with time but my original point still stands. Don't do it Unless absolutely necessary. I was gonna pay with Paypal and chances of fraud with PP are very less anyway. They did lose a recurring customer that day since I couldn't pass this verification.

Re: Stripe Identity

#475

Earlier quoted context omitted.

I honestly find it weird having all of these things suddenly want a copy of my passport in the cloud just sitting there waiting to be hacked in years to come when the security measures drop. At this point there is giant databases containing everything people need to take complete control of your identity sitting there just waiting to be hacked. I have no idea how to change it/fix it. But it seems weird to me.

The fix is for the government to make it a service. Right now, the government is punting responsibility to private actors who do not have the legal tools to operate an identity service. The government already operates an identity service via passports. The only reason they do not have an electronic identity service yet is because it is beneficial for them to be able to blame private actors when things go wrong.

This is one of those suggestions where I can immediately see some downsides, and am struggling to think of upsides, though I'm sure they exist.

1. I don't trust my government to have better security than anybody else.

2. I'm worried that I would lose the ability to opt out of a government-provided IaaS. Unlike Stripe, and I can't avoid using the government even if I try really hard. They already have my identity, so my privacy is dependent upon whatever their current policy happens to be. I do not trust unknown future administrations not to sell my data to the highest bidder.

3. The U.S. government has an... uneven track record delivering services and software, especially when there is no competition.

Those are my anxieties: what are the advantages to this approach that I'm not seeing?

Re: Stripe Identity

#476
I think we'd be a perfect customer for this product, as we're in the consumer HaaS space, and one of the issues I've been made aware of by other HaaS companies is that they were getting subscriptions which would get the hardware, and then just disappear, resulting in a loss due to theft.

I had been warned that stripe just wasn't set-up for this type of environment, but I think identity could really help.

At the same time I'm VERY concerned that stripe has allowed the API to download the proof of identity. Just like I don't want to be managing customer credit cards, I don't want to manage customer identity documents either, and I don't want to upload my identity to a company that allows the documents to be downloaded.

When I'm buying something on the internet, maybe I trust the company I'm buying from, maybe not but I know if they are using stripe, they never get my credit card number, so at most, they are able to only get away with the value of my purchase.

My identity is another matter! If I trust stripe to manage my identity, that's probably ok. I don't think stripe should blanket allow their customers to download my identity. I get that perhaps some companies have this requirement, and I'd suggest that they need to be able to work with Stripe directly to enable this for them, but for every company that signs up with stripe to be able to download the identity file...it seems like a huge risk not worth taking.

Re: Stripe Identity

#477

Earlier quoted context omitted.

Conflating credit card #'s and personal biometrics/SSNs is your first mistake. You think they are the same, they feel the same, but the risk to the customer is so much bigger. When a hotel copies my passport, they get a jpg. If they use Stripe, now I know they have my biometrics serialized to JSON. That feels way riskier and scarier to me, especially now that it's all centralized by Stripe. We hear about our personal…

I’m an engineer on the Identity team. There are two somewhat separate questions here. (1) Whether the business should ever have access to this data. And (2) how exactly the business should access that data and the security properties around it. On (1) this data is fundamentally the user’s, and there are often important compliance reasons as to why the user needs access to the raw data because of obligations that they…

How large percentage of Stripe Identity customers do you foresee actually are required by legal regulation to retain all this information, as opposed to verifying certain aspects of an individual, as opposed to wanting it and likely handling it in ways violating GDPR and similar regulation?

I’d argue that before Stripe sends any PII other than validation results to a customer, it needs to verify that the business indeed is under regulatory requirements to gather this data, and only sell the required part.

Alternatively, you could invert the process, allowing integrating businesses to send documents to Stripe, who replies if they’re legit or not.

Finally, if there is a need for sharing data with customers for e.g. KYC, shouldn’t this be priced significantly higher than verification/validation, so that Discords and Clubhouses can’t justify it from a business perspective?

What is the reasoning for doing neither of the above?

Re: Stripe Identity

#478
post #464

Earlier quoted context omitted.

> Ideally, businesses that want the raw data would be subject to security compliance requirements. Isn’t that already true for businesses that store this data from any source?

No. Unfortunately, most businesses in the US are not under any compliance requirements or regulations around identification. Certain states have special rules (like California I think?) but in most places US businesses can generally do anything they want with an ID card or relevant information, so long as they don't impersonate you or commit a crime with it. Given the way Stripe has implemented this today, Stripe mig…

Putting my lazy developer hat on for a second here… I think I would choose to store the Stripe Identity token in my db and then pull the JPEG’s on demand from Stripe’s API. Saving the image to S3 would be additional work, and well, I’m a lazy developer.

Re: Stripe Identity

#479
post #375
post #290

Considering that Stripe was originally known for letting websites accept credit card payments without seeing your credit card number, one might assume that Stripe Identity only allows websites to see the verification result, and not your selfies and scans of your identity documents. That would be an incorrect assumption. Per https://support.stripe.com/questions/managing-your-id-verifi... customers of Stripe Identity…

(Stripe cofounder.) > Considering that Stripe was originally known for letting websites accept credit card payments without seeing your credit card number, one might assume that Stripe Identity only allows websites to see the verification result, and not your selfies and scans of your identity documents. A few points: - Fundamentally, Identity makes it possible to choose how much of this data traverses / is stored on…

There are many use cases where it's enough to verify that the user is an actual person, and also to prevent the same person to have multiple accounts. So, it would make sense that Stripe verifies the person, but keeps the details from the business itself.

I trust Stripe more than a random online forum, a dating app, or a social network, which might offer a higher quality service when people are verified. There's a high risk that the ID documents will leak from these services at some point if they get access to them. I don't want them to know who I am at all, if they don't need to know.

It would also offer a way for preventing sybil attacks on P2P networks, or help connecting to non-evil nodes on a P2P network (such as Bitcoin Lightning Network) without knowing the other person. In these cases there could be a some kind of signature generated by Stripe that could be used as an additional trust factor without centralizing the system.

Re: Stripe Identity

#480
post #111
post #99

The landing page contains logos for clubhouse, discord, and shippo, which are presumably companies use the service. Does anyone find those usages to be unnecessarily intrusive? Maybe it's just me, but a chat app or shipping site asking me for a drivers license scan + selfie would make me never want to use the service again. It's appalling how this sort of stuff is getting normalized, eg. google asking for id scans fo…

Clubhouse lets you collect payments to join some channels. Isn’t KYC reasonable in that case? Re: Age Verifications on Google & YouTube: this has been covered well elsewhere. Google is required to do so by EU law. Blame regulators not the companies.

They’re required to verify that users are above a certain age. There are no requirements to solicit and keep information or documents beyond that. Just because the easiest shortcut to age verification is requiring a copy of a government ID, this doesn’t mean that that’s a good idea.
Post reply on HN