Earlier quoted context omitted.
I suspect most (if not all) KYC regulations require you to keep the evidence you used to verify the identity - even landlords in the UK are required to keep the evidence they saw of your right to live in the UK, let alone any institution that actually needs to prevent fraud etc. I suspect it's just a basic requirement of selling such a service to most medium-large businesses.
You're probably right about KYC, but KYC is just one of the four use cases presented by Stripe, and their customer logos include Clubhouse and Discord, which I highly doubt have KYC requirements or any need to access the underlying evidence. Stripe could do this differently: 1. Allow the customer to choose whether or not they need access to the evidence. 2. If customer has chosen to receive access to the evidence, th…
Stripe Identity
531–540 of 557 posts
Re: Stripe Identity
#532Earlier quoted context omitted.
> I would say that I am a bit shocked at the lack of regulation regarding access to people’s identity documents as compared to credit cards. To some degree it's because there isn't much point. You can call up my home state today, pinky promise that you're me, hand over $20, and they'll ship you my birth certificate or other important documents. We don't have private keys or other kinds of unique identifiers assigned…
It's supposed to work in quite a few countries, and not all make it so easy. Given the requirement in my country for ID when obtaining any other ID, I'm actually puzzled about what happens if you lose everything. https://stripe.com/docs/identity/verification-checks
Re: Stripe Identity
#533Earlier quoted context omitted.
(Stripe cofounder.) > Considering that Stripe was originally known for letting websites accept credit card payments without seeing your credit card number, one might assume that Stripe Identity only allows websites to see the verification result, and not your selfies and scans of your identity documents. A few points: - Fundamentally, Identity makes it possible to choose how much of this data traverses / is stored on…
Hey Patrick, > As a philosophical matter, we consider ourselves to serve the business, which means that limiting access to what we consider to be the business's own information feels a bit strange. Maybe I'm wrong , but once a customer upload the document on Stripe Identity they are supposed to be YOUR documents. I worked in Bank as a Service , fundamentally when a customer goes through a verification process , the d…
Discord only has access to your passport if you upload it to them. They don't have access to it by virtue ofthem being a stripe customer.
Re: Stripe Identity
#534Isn't this a privacy nightmare? All that data in Stripe data centers.
1. Stripe has strict access controls—only those working on Identity/verifications can access the data. 2. Biometric data is not stored! It’s gone from our systems within 48 hours (usually in just minutes). 3. We think this’ll actually make the state of global privacy better—rather than having individuals collect, and verify your ID, Stripe will securely handle verification.
I'm sorry but this is grade A bullshit. If your api provides access to data (extracted or raw), you are not improving anything. Quite the opposite actually, because now I not only have to trust the company that I choose to do business with but I also have to trust stripe, an american company.
Re: Stripe Identity
#535Earlier quoted context omitted.
The fix is for the government to make it a service. Right now, the government is punting responsibility to private actors who do not have the legal tools to operate an identity service. The government already operates an identity service via passports. The only reason they do not have an electronic identity service yet is because it is beneficial for them to be able to blame private actors when things go wrong.
But at a fundamental level, why do Discord and Clubhouse need to verify my identity? I don't think the question GP is asking is whether or not Stripe is a good way to confirm someone's real-life identity, or whether it would be better for the government to do it. I think what they're asking why we're doing identity verification for chat applications. Is this a good direction overall for the Internet to be moving in?…
For the same reason that Facebook required proof that you were a college student. A platform with a barrier to entry and a degree of exclusivity (but not too exclusive), will tend to have higher quality content and interactions than an anonymous forum that anybody (and anybot) can join.
Whether it's a good direction for the internet to be moving in, I have no idea. But it's certainly good business, which naturally makes me suspect it's the wrong trajectory.
Re: Stripe Identity
#536Earlier quoted context omitted.
> It could be Equifax levels of problematic if there would be a intrusion I'm sure they're not as lax as Equifax. I would hope that Stripe compartment all these documents so that a compromise of one database is not a compromise of the whole database. That's basic data storage hygiene in the information age. `Don't put all your eggs in one basket` as the saying goes.
I think the Estonian e-Card scheme is the right one despite hiccups in its implementation and ID verification should be the domain and responsibility of governments. Each ID card has an embedded private key-public key pair and you can sign to reveal your identity without having to resort to giving away anything else about yourself. There is already a zero-risk way for customers to verify themselves, so giant ID datab…
Yet I've never seen any company use it. Everyone uses slower, more expensive private services that don't ask any questions about what you're going to do with the data they collect.
Re: Stripe Identity
#537Earlier quoted context omitted.
> The internet would be a better place if there were more identity requirements This is a completely baseless claim, as most arguments against weak (ie pseudo) anonymity seem to be. Outside of banks, healthcare providers, and payment processors, I see little of benefit. Before bringing up any arguments that involve poor behavior or misinformation, please refresh yourself on the current state of Facebook (where nearly…
I'm curious, do you take this same stance in meat space? Would you rather not know who your friends are and address them by a changing handle? Would you rather be given a pseudonymous name to use for the duration of your trip to the grocery store? Would you prefer to be delivered a new car every time you need to go somewhere so people can't associate you with a vehicle? Do you really have these anonymity requirements…
Re: Stripe Identity
#538Earlier quoted context omitted.
Thanks for your reply. > Fundamentally, Identity makes it possible to choose how much of this data traverses / is stored on your servers, just as Stripe did with card numbers. There's a stark difference in how Stripe treats exports of card numbers versus exports of raw identity verification data. This makes it way easier, and more likely, for Stripe customers to choose to store raw identity verification information.…
Fully agree here - I would say that I am a bit shocked at the lack of regulation regarding access to people’s identity documents as compared to credit cards. Credit/debit cards are your money, and there’s an entire network of both regulations and intermediaries working against fraud in this space. Your identity can create new credit cards. It can take out loans. It is inherently a higher order security risk, and ther…
It's a security risk because of the first couple things you listed. The problem is that identity cannot be simultaneously a secret and a public identifier. As the name should suggest, identity serves a much better use as a public identifier. So we should stop treating it like a secret and start creating real infrastructure for actual secrets.
By the way, this is completely analogous to credit cards. There's a reason the industry has moved to chip cards physically and tokenized cards virtually. And that's because the card number was serving as both identity and secret, and that doesn't work. The deviation is that, in this case, we've decided to make the credit card numbers a secret which is cryptographically protected (chips) or at the very least stored in an opaque manner (tokens).
Re: Stripe Identity
#539Earlier quoted context omitted.
Authenticity and anonymous speech are not mutually exclusive. Stop pretending they are.
You are the only one who mentioned speech, "online activity" is what was referred to. You specifically suggested linking profiles to government identification. "Linking" wouldn't seem to leave much room for anonymity regardless of activity.
If DoorDash has a fake profile for D111af5ccf's Divine Donuts, is that not a crime? Impersonation, fraud, theft of IP, etc.
Again, how does authenticity conflict with free speech?
Examples, please.
Re: Stripe Identity
#540Earlier quoted context omitted.
What a terrible, broad statement to make, and on an anonymous forum of all places. There are plenty of places where default anonymity makes a lot sense and it is important to a good societal structure. History has shown time and again that those in positions of advantage will abuse their access to information for their own gains. Increasing the surface of your online activity trail can and will be used against you by…
> There are plenty of places where default anonymity makes a lot sense and it is important to a good societal structure. Can you list some examples of the types of places where you think this property holds true and explain what you mean by "good social structure"? > History has shown time and again that those in positions of advantage will abuse their access to information for their own gains. What are some examples…