Live data from Hacker News

Stripe Identity

stripe.com

511–520 of 557 posts

Re: Stripe Identity

#511
post #170

Earlier quoted context omitted.

> Chat apps use Identity to verify bots and prevent bad bots from spamming real users. Is bot spam rampant on discord or something? Are less invasive forms of verification (eg. SMS, credit card, or requiring a deposit) not enough? Can it not be solved via technical means? eg. requiring users to opt-in before receiving messages from a bot? > And shipping services use Identity when a user is suspected as a fraudster—to…

>Is bot spam rampant on discord or something? It definitely is. If you don't turn off DMs from all the public servers you're in you'll inevitably be hit with the crypto spam bots. There's also the issue of bots silently sitting on servers and logging all chats, user statuses, etc.

And yet other websites (ex HN, Stack Exchange) manage to combat such spam without ID.

> bots silently sitting on servers and logging all chats

Anyone who thinks this isn't happening in every public communication channel is hopelessly naive.

Re: Stripe Identity

#512

Earlier quoted context omitted.

More a requirement at this point. Discord had to crack down on malicious bot developers after some decided to log essentially every bit of information ever sent to them to be put on the internet, including information from private channels. Some scopes require this verification outright now.

> decided to log essentially every bit of information ever sent to them Kind of like IRC? Which is basically what Discord is. Why would you assume anything you put on the internet isn't part of the permanent public record? (Wait until you find out about mailing lists, Reddit mirrors, the Internet Archive, ...) (Aside: The only halfway sane solution to this is having separate disconnected identities for each service y…

Are you seriously Internet Archiving me right now. Okay, where do I start…

One, Discord is still primarily used by underage people.

Two, most Discord guilds are not public, this was a case of malicious bots. If you install an app on your phone, is your expectation automatically that it will skirt all App Store rules and dump the contents of your phone on the internet? I hate people that obsessively archive everything, but even I can see the case for IRC being expected to be public. Especially without SSL enforcement on a channel. Discord does not work like that at all. You are advocating for a treasure trove for the likes of Kiwifarms. (Which is exactly how dis.cool ended up being used, as a stalking tool)

Three, the people who say “every litte piece of info on the internet becomes part of the public record, be careful” are also the ones doing the archiving. Nobody else cares enough. Stop doing it. Not everything is worth preserving only because you are a data hoarder. I’m happy you think you’re building the library of alexandria, just make sure it’s not built out of piles of shit and PII.

If it was technically feasible to permanently record every public place outside the internet and make the recordings available to everyone, would you be in favor of that too? Just because the internet makes that technically feasible doesn't mean it's a good idea.

Re: Stripe Identity

#513
post #510

Earlier quoted context omitted.

Do please enlighten me. I've never provided more to HN than a user name and password. There's no third party JS (I just double checked). I suppose the first party JS could be performing aggressive fingerprinting but I doubt it. (Of course they also have my entire post, view, and vote histories. Those are arguably far more sensitive than any PII I could possibly provide, but I seem to have developed a habit of repeate…

You've provided them with a username, under which you post, comment and view content. This is enough to identify you as an entity in the system and what it is you're doing. If what you're doing, based on heuristics and what you publish is having a bad effect on "the network", you can be blocked/stopped/warned. I'm saying HN do anything of this, but I doubt they only look at your IP when you're interacting with the se…

If you reread the comment chain the original context had to do with collection of PII. HN has only my IP address (no email, phone number, credit card, or ID). I am well aware that data regarding user interactions can be highly sensitive but it's not what was being discussed.

Re: Stripe Identity

#514
post #495

Earlier quoted context omitted.

I'm not sure you understand. When a business needs your ID to do business, they ask you for it and store it in their infrastructure. This already happens today. Nothing Stripe is doing necessarily changes this. Stripe is simply providing a streamlined mechanism by which business can fulfill their KYC requirements and obtain this information. And now they have the choice to continue to store it in their infrastructure…

I get it. No need to say I don't. Streamlined means more companies will ask you for such identification. Eventually stripe will be part of a news story about a data leak. I imagine they've already factored this in and decided it's worth it, due to requests they've been getting from customers. Essentially, if they don't do it, someone else will. Personally I think they should let someone else do it, or break it into a…

I disagree a bit on this. Looking at previous data breaches, when something like an s3 bucket gets hacked, the news is not going to be about on how Amazon is responsible for company X's data breach but on how company X's servers got hacked. Stripe, like AWS, is the infrastructure, the onus is on a company to ensure their infrastructure security as it can be an existential risk. A philosophy of Stripe's is that that they succeed when their customers succeed, I'd like to think that they have a shared interest in try to prevent their customers being breached as much as possible.

Re: Stripe Identity

#515

Earlier quoted context omitted.

> decided to log essentially every bit of information ever sent to them Kind of like IRC? Which is basically what Discord is. Why would you assume anything you put on the internet isn't part of the permanent public record? (Wait until you find out about mailing lists, Reddit mirrors, the Internet Archive, ...) (Aside: The only halfway sane solution to this is having separate disconnected identities for each service y…

Are you seriously Internet Archiving me right now. Okay, where do I start… One, Discord is still primarily used by underage people. Two, most Discord guilds are not public, this was a case of malicious bots. If you install an app on your phone, is your expectation automatically that it will skirt all App Store rules and dump the contents of your phone on the internet? I hate people that obsessively archive everything…

> are also the ones doing it. Stop doing it.

Many of them, perhaps. Certainly not all of them. That's irrelevant because there are a great many more who aren't necessarily saying much of anything but are logging everything. There are clear business and governmental (ie surveillance) use cases for such data so it's more or less guaranteed to happen en masse.

> most Discord guilds are not public, this was a case of malicious bots

Apologies, I don't actually use Discord and (based on this and a few other comments here) have realized that the term "bot" is being used in a very nonstandard manner. It seems that Discord "bots" are server side apps that can be launched (ie used) by other people. Using such bots to scrape private channels that the author doesn't otherwise have access to is indeed highly malicious and not to be expected or tolerated. (Of course one could wonder why such bots were permitted unrestricted communication with the outside world in the first place. Does Discord lack even a basic permission system?!)

Still, if you choose to run unverified code provided by an unknown party you should fully expect to be exploited to the maximum extent possible. It's really no different than installing arbitrary browser extensions or running arbitrary binaries that you found on the internet.

Re: Stripe Identity

#516
I'm making a dating app. After sending a potentially-fraudulent user to a Stripe VerificationSession, I would like to send Stripe their other photos and find out how well they match the ID. Does Stripe have any plan to support that?

Also, how long does the VerificationSession verified_outputs field remain accessible?

Re: Stripe Identity

#517

Does Stripe intend to make a giant online database of international identity documents? Why should we trust Stripe to secure these? It could be Equifax levels of problematic if there would be a intrusion, but I also can't tell how Stripe plans to use this information.

These databases already exist. For example, all driver's licenses issued in a state are part of the public record, and many companies already maintain databases of them. For example, you can sign up for an account with the NY DMV that allows you to search all DMV records, as long as your use falls within one of a dozen permissible use-cases (including "To verify the accuracy of information submitted by the individual…

> These databases already exist.

That doesn't matter.

Re: Stripe Identity

#518

Earlier quoted context omitted.

Are you seriously Internet Archiving me right now. Okay, where do I start… One, Discord is still primarily used by underage people. Two, most Discord guilds are not public, this was a case of malicious bots. If you install an app on your phone, is your expectation automatically that it will skirt all App Store rules and dump the contents of your phone on the internet? I hate people that obsessively archive everything…

> are also the ones doing it. Stop doing it. Many of them, perhaps. Certainly not all of them. That's irrelevant because there are a great many more who aren't necessarily saying much of anything but are logging everything. There are clear business and governmental (ie surveillance) use cases for such data so it's more or less guaranteed to happen en masse. > most Discord guilds are not public, this was a case of mal…

Discord is a product, not a protocol, so it should be in their best interest to communicate the extent to which a third party application might misuse their data. This is the case with the new scopes that require ID verification now, backed by the promise that Discord will sue you if you break their conditions of using the data provided to you.

This has some other unfortunate side effects (user tokens can't be used for bots, third party clients are a risk), but unfortunately the only way to really curtail this behavior. Privacy is not something easily understood, especially for people outside tech that just want to be around their friends during the pandemic, do not be blind for this. Technology can't be the sole component of solving this issue, so I'm glad Discord is committed to legally perusing those that misuse their API.

Re: Stripe Identity

#519

Earlier quoted context omitted.

> are also the ones doing it. Stop doing it. Many of them, perhaps. Certainly not all of them. That's irrelevant because there are a great many more who aren't necessarily saying much of anything but are logging everything. There are clear business and governmental (ie surveillance) use cases for such data so it's more or less guaranteed to happen en masse. > most Discord guilds are not public, this was a case of mal…

Discord is a product, not a protocol, so it should be in their best interest to communicate the extent to which a third party application might misuse their data. This is the case with the new scopes that require ID verification now, backed by the promise that Discord will sue you if you break their conditions of using the data provided to you. This has some other unfortunate side effects (user tokens can't be used f…

That's a pretty weak solution in my opinion. Mobile OSes and browsers use a model based on permissions. There's zero reason for a Discord "bot" to be able to send information to arbitrary endpoints without informing the user about them up front. Collecting ID and threatening to sue is a half assed response. Or more cynically ...

> (user tokens can't be used for bots, third party clients are a risk)

... how convenient. So sorry, but we need to restrict what you can do for your own protection. Where have I heard that one before?

> Privacy is not something easily understood

"Privacy" isn't what needs to be understood here. "Don't run arbitrary code" is what applies; it applies everywhere whether you like it or not.

Re: Stripe Identity

#520
post #502

Earlier quoted context omitted.

> A good way of omitting bad bots from the network is by verifying and tying the bot to the (verified) identity of a real person. Is it? I am much less charitable than you about whether Discord's bot verification is intended purely for user safety or whether it's a combination of laziness and a way of slowly clamping down control over how users access the service, how it can be extended, and what services/clients can…

> ... slowly clamping down control over how users access the service, how it can be extended, and what services/clients can interop So what? It's a private network and a private service. They can have it function however they like. That's why free market economies work - people will go find something else, or demand something else, should what's available not fit their needs or they feel too restrictive. Something li…

> So what? It's a private network and a private service. They can have it function however they like. That's why free market economies work

You're commenting under a thread that proposes creating a government service to reduce the implementation costs of identity verification. When we start talking about essentially subsidizing a business practice, then this isn't really about the free market anymore.

But even if it was, criticism is a fundamental part of how the free market works. People are free to advocate against a company's policy, to publicly criticize them, to encourage people not to use them, to argue for an industry to move in a certain direction... the free market has never been a shield against the kind of criticism happening on this thread. The invisible hand of the free market isn't actually invisible, when you see people complaining about companies and making arguments about the overall direction of the market, that is the free market at work.

> Is requiring people to validate their identity before introducing something that has the potential to directly address millions of people all at once really that invasive?

In this context, yes. In a different context, maybe not. But the Internet has different social norms surrounding anonymity, and most people online aren't thrown off by the fact that they might not know the physical identity of someone who makes a website or runs a Twitter account or releases a piece of code/bot.

I think that Discord's policy runs counter to how people expect to consume content online, and I think it's reasonable to describe their request as invasive in the context of Internet norms. You're on HN right now. Does it bother you that the site hasn't asked you for your drivers license yet?

And just as a quick side note on this point, Facebook has been around for long enough that I feel like we should drop the argument that tying accounts to real-world identities inherently prevents abuse or curbs misinformation. Heck, talk radio and cable news has been around long enough that we should probably drop the argument that vetting guests in traditional settings inherently means we'll have less misinformation.

> If a bot can join 100 servers, and they have an average of 10,000 users, then that's literally 100,000[1,000,000] people that can attached with malware, scams, and more. Are you saying that's not a problem?

I think the much more interesting question in your scenario is why Discord thinks it's OK for a malicious bot to target 990,000 people. I don't think 100 servers is a particularly high limit for a popular bot or a meaningful line for when abuse becomes a problem. I don't see how identity verification solves the abuse problem overall when hackers/spammers can just create multiple bots that can target smaller numbers of servers. I think it's really weird to act like this becomes a problem at 100 servers.

> What is it about these tools that you feel could be better?

The ability to create private invites that can only be used by a single person, the ability to require users to be approved before they join your server. The ability to ban words, the ability to block links (or better, the ability to only allow links to certain domains), the ability to block bots outright from joining (what seems to be the entire reason this verification process exists), the ability to easily share blocklists between servers, the ability to hold comments from new accounts in limbo until they're approved.

Some of this can be replicated by setting up your own bots and figuring out some kind of custom role where new users jump through hoops; and that's basically what a lot of servers I run into on Discord have to do. But it's really awful and it's a bad experience and it makes moderation unnecessarily complicated for non-technical users. As a result, most servers don't really set anything up because it's time consuming, so we end up with bad defaults on most servers. And that situation doesn't have to exist. Why do I need to find a bot to ban certain words on a server? That's something that belongs in the settings in a text input. Why do I have to go through this weird song-and-dance with invite codes, why can't I add people by their account ID? Why is there no one-click setting to just block new bots from joining my server unless I specifically grant them permission?

I've joined Discord servers that have these complicated house-of-cards setups where you're entering passwords into dedicated rooms to get granted access to other rooms by moderator bots. It's really bad, moderators shouldn't have to spend hours building custom rube goldberg machine to handle new users. This is stuff that should be configurable within 30 seconds from the settings page.

You mention that you "don't believe they can" block bots from abusing servers this way. But I just do not understand what the technical problem is. If the problem is that bots are joining random servers, and if bots can join my server without my permission, give me a single checkbox somewhere in settings to turn that off.

Post reply on HN