Live data from Hacker News

Stripe Identity

stripe.com

521–530 of 557 posts

Re: Stripe Identity

#521
post #170

Earlier quoted context omitted.

> Chat apps use Identity to verify bots and prevent bad bots from spamming real users. Is bot spam rampant on discord or something? Are less invasive forms of verification (eg. SMS, credit card, or requiring a deposit) not enough? Can it not be solved via technical means? eg. requiring users to opt-in before receiving messages from a bot? > And shipping services use Identity when a user is suspected as a fraudster—to…

>Is bot spam rampant on discord or something? It definitely is. If you don't turn off DMs from all the public servers you're in you'll inevitably be hit with the crypto spam bots. There's also the issue of bots silently sitting on servers and logging all chats, user statuses, etc.

> If you don't turn off DMs from all the public servers you're in you'll inevitably be hit with the crypto spam bots.

The ones that aren't marked as bots and wouldn't have their identify verified anyway?

Re: Stripe Identity

#522

Smart. Banks haven't been allowed to monetize their KYC data, but this new non-bank class of payments companies have this opportunity. Interac has been trying to do this for many years. Some years ago I worked on a system let banks do identity assertions with proofs via SAML attributes instead of sharing customer PII. It is now a federation of banks in wide use for govt services in Canada. The use cases were really l…

Do banks want to monetise their KYC data? In the UK, the government launched a similar system in 2014 called Verify, a platform for banks and other firms with existing customer relationships to offer identity verification as a service to the government, and eventually, third party sites. Users would choose a participating bank they has a relationship with and login to their account as verification. But despite paying…

The scheme is still running - https://www.gov.uk/government/publications/introducing-govuk... - DWP pretty much forced me to use it when I applied for Universal Credit last year.

Re: Stripe Identity

#523

Earlier quoted context omitted.

I get it. No need to say I don't. Streamlined means more companies will ask you for such identification. Eventually stripe will be part of a news story about a data leak. I imagine they've already factored this in and decided it's worth it, due to requests they've been getting from customers. Essentially, if they don't do it, someone else will. Personally I think they should let someone else do it, or break it into a…

I disagree a bit on this. Looking at previous data breaches, when something like an s3 bucket gets hacked, the news is not going to be about on how Amazon is responsible for company X's data breach but on how company X's servers got hacked. Stripe, like AWS, is the infrastructure, the onus is on a company to ensure their infrastructure security as it can be an existential risk. A philosophy of Stripe's is that that t…

You may be right about how breaches are received in the news by people. It may depend on how they roll it out. I'm sure Stripe will do their best to help clients secure their customers' data. At the end of the day, though, it seems inevitable that breaches will occur.

Re: Stripe Identity

#524
post #492

Earlier quoted context omitted.

I sure hope so! Anonynimity is not a fundamental human right, it is a tool that should be used sparingly and only when the situation is appropriate (whistleblower, for example). The internet would be a better place if there were more identity requirements SO LONG AS companies are not legally allowed to sell or transmit that information to advertisers or other third parties without explicit opt-in consent ideally on a…

What a terrible, broad statement to make, and on an anonymous forum of all places. There are plenty of places where default anonymity makes a lot sense and it is important to a good societal structure. History has shown time and again that those in positions of advantage will abuse their access to information for their own gains. Increasing the surface of your online activity trail can and will be used against you by…

> There are plenty of places where default anonymity makes a lot sense and it is important to a good societal structure.

Can you list some examples of the types of places where you think this property holds true and explain what you mean by "good social structure"?

> History has shown time and again that those in positions of advantage will abuse their access to information for their own gains.

What are some examples of scenarios where this has happened in relation to online identity where there have been legal restrictions in place that would have otherwise prevented it? The healthcare industry and credit card industry seem to do a pretty good job of protecting sensitive information, for example.

> Increasing the surface of your online activity trail can and will be used against you by a bad actor when the opportunity arises.

How anonymous do you think you are online? If you're not deliberately taking steps to conceal your identity, your trail is thick and clear for the people who know how to track it. And that's an actual problem: people track you even if you think you're anonymous and we have no legal protection in place to prevent abuse of data that can identify you online. If you are in a position where you need to *depend* on anonymity, you simply can't because nobody will respect your wish. So the internet operates in this grey zone where because we have no rules governing abuse of PII, everyone throws on the cloak and turns to anonymity as the answer. This degrades our ability to fight spam and makes things like strong mutual authentication very very hard to do because platform vendors can't ever expose any sort of fixed identifier because privacy. Look at the insane things Apple does: zero out your mac address when scanning for wifi networks and recently issue a new certificate for every single use so that a persistent identifier does not show up. And look at IPv6, we invented "privacy extensions" where you generate a random IP every few minutes. These hacks break functional systems because we don't understand how to regulate the internet as a society.

All that is somewhat irrelevant, though. We're talking about the identity relationship between you and a service, not necessarily "the features of interacting with the internet that can be recorded and tracked either on purpose or incidentally". Do you think your email address makes you anonymous? Again, unless you're deliberately taking steps to maintain pristine op sec with your online browsing, you identify yourself to service providers one way or another. And again, the problem is people think they're anonymous when they really aren't so they misinterpret what it means to be anonymous and its importance in good societal structure. I honestly don't see a difference between providing a service your email address or your physical address or telephone number. What's so bad about having a third party say "yeah, this person is who they say they are" and optionally "and here's the list of verified fields"? The internet is the only place where people get weirded out when someone asks for an ID. Do you not show the bar tender your ID when asked because you need to be anonymous at a restaurant? How about at the gas station, the liquor store, the axe throwing range, the DMV, the hospital, when making a purchase on a credit card, taking out a loan, etc. What real world interactions do you have that are primarily anonymous? It's not normal.

Strong identity combats spam and abuse. I would choose strong identity over spam almost every single time. I do not disagree that there are some online communities that are respectfully anonymous. But do you think e.g. Reddit is one of those? Because I do not. Regardless, you can still both a) identity check and b) run an anonymous community (and c. not store identity information). You don't have to expose the identity data in the product/community/forum itself, so nothing about making identity easier to use and more streamlined defeats the ability to operate pseudonymous services in the least. I really don't understand the "anonymity by default is good for a wholesome society" angle whatsoever.

Re: Stripe Identity

#525
post #492

Earlier quoted context omitted.

I sure hope so! Anonynimity is not a fundamental human right, it is a tool that should be used sparingly and only when the situation is appropriate (whistleblower, for example). The internet would be a better place if there were more identity requirements SO LONG AS companies are not legally allowed to sell or transmit that information to advertisers or other third parties without explicit opt-in consent ideally on a…

> The internet would be a better place if there were more identity requirements This is a completely baseless claim, as most arguments against weak (ie pseudo) anonymity seem to be. Outside of banks, healthcare providers, and payment processors, I see little of benefit. Before bringing up any arguments that involve poor behavior or misinformation, please refresh yourself on the current state of Facebook (where nearly…

I'm curious, do you take this same stance in meat space? Would you rather not know who your friends are and address them by a changing handle? Would you rather be given a pseudonymous name to use for the duration of your trip to the grocery store? Would you prefer to be delivered a new car every time you need to go somewhere so people can't associate you with a vehicle? Do you really have these anonymity requirements.

The claim is not baseless. There are strong technical reasons why identifying the components in your system is a good thing. and there are practical social reasons.

Re: Stripe Identity

#526

Earlier quoted context omitted.

Are you seriously Internet Archiving me right now. Okay, where do I start… One, Discord is still primarily used by underage people. Two, most Discord guilds are not public, this was a case of malicious bots. If you install an app on your phone, is your expectation automatically that it will skirt all App Store rules and dump the contents of your phone on the internet? I hate people that obsessively archive everything…

> are also the ones doing it. Stop doing it. Many of them, perhaps. Certainly not all of them. That's irrelevant because there are a great many more who aren't necessarily saying much of anything but are logging everything. There are clear business and governmental (ie surveillance) use cases for such data so it's more or less guaranteed to happen en masse. > most Discord guilds are not public, this was a case of mal…

> have realized that the term "bot" is being used in a very nonstandard manner.

For some additional context, Discord bots aren't that far off from IRC bots.

You invite a bot to your server, you give the permissions and channel access you want it to have, and it receives various events over the web gateway such as "Message Received" of which the bot developer can use to build elaborate command systems and various other features.

Prior to the must-be-verified limit of 100 guilds, Discord had a serious issue with scam bots that would mass-message users promising free bitcoin or "insert free thing here", and usually one the "steps" was adding the bot to an additional guild. This resulted in the bot quickly cascading past 100 guilds within a matter of hours before Discord support had even noticed the problem.

Once joined to the additional guild, it would scrape as much of the server content as it could and usually dump it on some sort of "discord user tracker" platform.

On top of preventing joins past 100 guilds, verification is also required for some sensitive capabilities such as querying the entire member list.

Re: Stripe Identity

#527

Earlier quoted context omitted.

I recently had, twice, to do stuff WAY more intrusive. Video/conf call, need to hold my passport, need to have my phone on hand... People on the other side would call me on my phone to verify it's my number and they'd also send me a SMS with a code to verify on that phone. After that they have: my face, copy of my passport, my voice, my phone number, my IP (unless I'm really going out of my way to obfuscate it), my e…

You said it happened twice. I haven't yet had to face this level of intrusiveness, but I fear that it's coming for all of us. May I ask what companies these were? If you don't want to name the exact companies, could you say the general purpose (opening a bank account, buying or selling real estate, incorporating a business, etc.)? Also, which country (I'm assuming the U.S.)?

Not the OP but I had to do this when opening a bank account in Germany.

Re: Stripe Identity

#528
post #525

Earlier quoted context omitted.

> The internet would be a better place if there were more identity requirements This is a completely baseless claim, as most arguments against weak (ie pseudo) anonymity seem to be. Outside of banks, healthcare providers, and payment processors, I see little of benefit. Before bringing up any arguments that involve poor behavior or misinformation, please refresh yourself on the current state of Facebook (where nearly…

I'm curious, do you take this same stance in meat space? Would you rather not know who your friends are and address them by a changing handle? Would you rather be given a pseudonymous name to use for the duration of your trip to the grocery store? Would you prefer to be delivered a new car every time you need to go somewhere so people can't associate you with a vehicle? Do you really have these anonymity requirements…

> I'm curious, do you take this same stance in meat space? Would you rather not know who your friends are and address them by a changing handle?

There are many people I'm friendly with that I know little about. They could very well be giving me fake information about their life. I don't see this as a problem.

> Would you rather be given a pseudonymous name to use for the duration of your trip to the grocery store?

Well in most cases I wouldn't give anyone any name at all. Why does the grocery store require my name?

> The claim is not baseless. There are strong technical reasons why identifying the components in your system is a good thing. and there are practical social reasons.

There are also strong technical reasons not to. And there are practical social reasons not to. As far as I can tell, you've provided essentially no argument supporting this general claim:

> The internet would be a better place if there were more identity requirements

Re: Stripe Identity

#529
post #392
post #375

Earlier quoted context omitted.

(Stripe cofounder.) > Considering that Stripe was originally known for letting websites accept credit card payments without seeing your credit card number, one might assume that Stripe Identity only allows websites to see the verification result, and not your selfies and scans of your identity documents. A few points: - Fundamentally, Identity makes it possible to choose how much of this data traverses / is stored on…

Thanks for your reply. > Fundamentally, Identity makes it possible to choose how much of this data traverses / is stored on your servers, just as Stripe did with card numbers. There's a stark difference in how Stripe treats exports of card numbers versus exports of raw identity verification data. This makes it way easier, and more likely, for Stripe customers to choose to store raw identity verification information.…

Just from an end user POV, would I be able to request from Stripe a logs for metadata about which type/how much of my personal data has been shared to the companies?

Re: Stripe Identity

#530
post #406

Earlier quoted context omitted.

> why do Discord [..] need to verify my identity? > the overall population of users on the web You keep arguing about a non-issue. Normal users do not need to verify with Discord. It's only for bot owners of popular bots to prevent the widespread abuse Discord saw. https://news.ycombinator.com/item?id=27505905

I disagree that bot developers should be placed in a separate category from normal users, and I disagree that 100 servers is a meaningful place to draw the line that Discord is drawing. The linked comment is incorrect to say that Discord only requires verification for specific permissions, Discord requires verification for bots who are in more than 100 servers regardless of what permissions they use. I think it's fai…

I think you're being too dogmatic about this. For me it's a perfectly valid use case for identity verification. It prevents a big problem and only affects an extremely tiny subset of users.
Post reply on HN