Live data from Hacker News

Stripe Identity

stripe.com

541–550 of 557 posts

Re: Stripe Identity

#541

Smart. Banks haven't been allowed to monetize their KYC data, but this new non-bank class of payments companies have this opportunity. Interac has been trying to do this for many years. Some years ago I worked on a system let banks do identity assertions with proofs via SAML attributes instead of sharing customer PII. It is now a federation of banks in wide use for govt services in Canada. The use cases were really l…

Actually, it seems that this did go into production - you can now verify identity using the service. For example, you can identify yourself for Govt. of Canada services (immigration, taxes) by logging into to your banking platform that then vouches for your identity using a service called SecureKeyConcierge / Verified.Me - note that ALL of Canada's major and quite a few minor banks are signed up to the service. See t…

I wrote an identity verification process with Verified.Me. I understand your concern regarding SecureKey's creation of a user account for its service built around identity verification sources such as the chartered banks. Your Verified.Me account is tied to your mobile device, and that it doesn't have any extra PII. You can delete your Verified.Me account from the app at any time. If you move to a new device and want to use Verified.Me, it will tell you that your account is already on another device and needs to be deleted from it before proceeding. The PII that is shared from the banks to the Verified.Me consumer is name, email, and phone number. At all times SecureKey said that it's the conduit and doesn't see that data.

Similar to Stripe, SecureKey currently offers an analysis service for photo ID that looks for anomalies and calls them out. The next version of the service integrates with provincial records to concretely confirm validity.

Re: Stripe Identity

#542

Earlier quoted context omitted.

Conflating credit card #'s and personal biometrics/SSNs is your first mistake. You think they are the same, they feel the same, but the risk to the customer is so much bigger. When a hotel copies my passport, they get a jpg. If they use Stripe, now I know they have my biometrics serialized to JSON. That feels way riskier and scarier to me, especially now that it's all centralized by Stripe. We hear about our personal…

I’m an engineer on the Identity team. There are two somewhat separate questions here. (1) Whether the business should ever have access to this data. And (2) how exactly the business should access that data and the security properties around it. On (1) this data is fundamentally the user’s, and there are often important compliance reasons as to why the user needs access to the raw data because of obligations that they…

Same as petermeyers: how can I have my personal information removed from Stripe Identity? thanks!

Re: Stripe Identity

#543
post #525

Earlier quoted context omitted.

I'm curious, do you take this same stance in meat space? Would you rather not know who your friends are and address them by a changing handle? Would you rather be given a pseudonymous name to use for the duration of your trip to the grocery store? Would you prefer to be delivered a new car every time you need to go somewhere so people can't associate you with a vehicle? Do you really have these anonymity requirements…

> I'm curious, do you take this same stance in meat space? Would you rather not know who your friends are and address them by a changing handle? There are many people I'm friendly with that I know little about. They could very well be giving me fake information about their life. I don't see this as a problem. > Would you rather be given a pseudonymous name to use for the duration of your trip to the grocery store? We…

We already have a society that identifies people when doing business. The burden of proof is on an anonymity advocate to demonstrate why that is harmful and should be changed. I may mot have convinced you that having strong identity enables strong security and reduces spam (that is my argument). But it’s also not my problem if you aren’t aware of the nuances surrounding how security, privacy and anonymity work. You haven’t made any compelling argument as to why we don't need identity in cyberspace beyond a naive axiomatic assertion that “businesses don’t need them so they shouldn’t collect them” and some FUD level fear that strong identity is an Orwellian technology hell bent on ruining your life. There is so much nuance I don't feel like we’re doing the topic justice. There is a huge spectrum between “ad tech tracking everything you do” and “everyone looks like a spam bot”. The mindshare is heavily skewed toward spam bot because ad tech is abusive. You can have strong identity and privacy without invoking anonymity. You can be anonymous and still fall victim to fishing attempts and scams. Anonymity is not synonymous with security or privacy. Security means you know who you’re communicating with online so you can establish trust. Privacy means you don't need to share invasive personal details in the regular course of existing in society. Anonymity means nobody knows who you are. I want a society where my digital communication with other people is authenticated and a baseline of trust is established. Do you use a secure messenger app that has E2E encryption? Guess what, that depends on strong identity. You are not anonymous but you are private. I would take a secure and private society every time over an anonymous one that offers weak, if any, guarantees of security and/or privacy.

I work on a product that doesn't collect any PII. We made the decision very early on not to collect any information we don’t need because that’s literally not our business. I am deeply aware of the landscape on these topics. However, as a society we cannot run in a “normal meatspace anonymous cyberspace” mode. We need to bridge civil identity in a secure and private (those are fundamental human rights) way into the online era. That is the core focus of the product I’ve been working on. In reality people have identities whether they use them offline or online. The goal is to protect those identities so they cannot be abused, not remove them altogether.

Re: Stripe Identity

#544
post #492

Earlier quoted context omitted.

I sure hope so! Anonynimity is not a fundamental human right, it is a tool that should be used sparingly and only when the situation is appropriate (whistleblower, for example). The internet would be a better place if there were more identity requirements SO LONG AS companies are not legally allowed to sell or transmit that information to advertisers or other third parties without explicit opt-in consent ideally on a…

> The internet would be a better place if there were more identity requirements SO LONG AS companies are not legally allowed to sell or transmit that information to advertisers or other third parties without explicit opt-in consent ideally on a per-use basis. Or simply at all This is a pipe dream. The online world spans the globe and we can only enforce the law in our own respective countries. And even if all countri…

A fully anonymous society is also a pipe dream. It doesn't work.

You already provide your name and phone number and email to Twitter. You already identify yourself. We're talking about making that exchange more reliable and more secure...

Re: Stripe Identity

#545
post #524

Earlier quoted context omitted.

> There are plenty of places where default anonymity makes a lot sense and it is important to a good societal structure. Can you list some examples of the types of places where you think this property holds true and explain what you mean by "good social structure"? > History has shown time and again that those in positions of advantage will abuse their access to information for their own gains. What are some examples…

Oh no, I'm not going to go down that slippery slope. We are not talking about CIA whistleblower levels of anonymity here. This is just basic sanity. You may never be able to fight abuse 100%, so it's good practice to reduce the surface of compromise as much as possible. If the information is not needed, just don't send it. It's about de-risking the possibilities. The fact that banks, healthcare institutions etc. are…

Fake identity is is not hard to create online. You’re right! That is the problem. Fake identity is orders of magnitude harder to create in meatspace. You don't solve that problem by saying “welp I guess we just have to deal with spam to realize pseudo-security via anonymity”. I don't disagree about privacy, even. I think you’d find we agree about not sending information you don't need. Where we talking past each other is on the topic of anonymity vs privacy. I want strong identity and privacy and tools and laws that protect my identity and privacy online as well as offline. Tools that let me manage who has access to my private information and for what use cases. Tools that alert me when that information is accessed or shared. Tools to allow me to verify the information provided by others is genuine. This has nothing to do with anonymity.

Re: Stripe Identity

#546
post #287
post #11

Earlier quoted context omitted.

It's actually pretty cool (IMO; I'm biased). Drop-in browser-based user authentication that: * Uses various sophisticated heuristics to detect real vs fake IDs. * Matches the ID to the human face. * Detects whether the human face is live or not. * Dynamically requests more or less information depending on the confidence level. It also gets better over time based on the attacks and fraud attempts that Stripe itself se…

pc how are you biased? Do you work at Stripe or something?

See: https://news.ycombinator.com/user?id=pc

Re: Stripe Identity

#547
post #213

EU is apparently about to design and roll out Europe-wide digital ID service: https://ec.europa.eu/commission/presscorner/detail/en/IP_21_...

"Europe-wide" meaning EU, Europe is much bigger than EU

Re: Stripe Identity

#548
post #375
post #290

Considering that Stripe was originally known for letting websites accept credit card payments without seeing your credit card number, one might assume that Stripe Identity only allows websites to see the verification result, and not your selfies and scans of your identity documents. That would be an incorrect assumption. Per https://support.stripe.com/questions/managing-your-id-verifi... customers of Stripe Identity…

(Stripe cofounder.) > Considering that Stripe was originally known for letting websites accept credit card payments without seeing your credit card number, one might assume that Stripe Identity only allows websites to see the verification result, and not your selfies and scans of your identity documents. A few points: - Fundamentally, Identity makes it possible to choose how much of this data traverses / is stored on…

How are you going to handle E.E.U. citizens? It seems that the GDPR applies here. The only real solution I see is to have a separate E.E.U.-based company.

Re: Stripe Identity

#549
post #392

Earlier quoted context omitted.

Thanks for your reply. > Fundamentally, Identity makes it possible to choose how much of this data traverses / is stored on your servers, just as Stripe did with card numbers. There's a stark difference in how Stripe treats exports of card numbers versus exports of raw identity verification data. This makes it way easier, and more likely, for Stripe customers to choose to store raw identity verification information.…

Fully agree here - I would say that I am a bit shocked at the lack of regulation regarding access to people’s identity documents as compared to credit cards. Credit/debit cards are your money, and there’s an entire network of both regulations and intermediaries working against fraud in this space. Your identity can create new credit cards. It can take out loans. It is inherently a higher order security risk, and ther…

When Stripe handles the data of residents of the European Economic Union it is subject to the General Data Protection Regulation [0].

[0] https://en.wikipedia.org/wiki/General_Data_Protection_Regula...

Re: Stripe Identity

#550
post #543

Earlier quoted context omitted.

> I'm curious, do you take this same stance in meat space? Would you rather not know who your friends are and address them by a changing handle? There are many people I'm friendly with that I know little about. They could very well be giving me fake information about their life. I don't see this as a problem. > Would you rather be given a pseudonymous name to use for the duration of your trip to the grocery store? We…

We already have a society that identifies people when doing business. The burden of proof is on an anonymity advocate to demonstrate why that is harmful and should be changed. I may mot have convinced you that having strong identity enables strong security and reduces spam (that is my argument). But it’s also not my problem if you aren’t aware of the nuances surrounding how security, privacy and anonymity work. You h…

> We already have a society that identifies people when doing business.

This is false. There are many cases in real life when this is not the case as explained in the very post you just responded to.

> The burden of proof is on an anonymity advocate to demonstrate why that is harmful and should be changed.

You are making certain claims and then saying it's up to others to disprove you? If that's your attitude why are you engaging in this discussion at all?

> But it’s also not my problem if you aren’t aware of the nuances surrounding how security, privacy and anonymity work.

Frankly I don't have the energy to engage with you. Take that as you will. You clearly think you know much more than everyone here already anyway.

Post reply on HN