Live data from Hacker News

Launch HN: Berbix (YC S18) – Instant ID checks to fight fraud and stay compliant

news.ycombinator.com

21–30 of 57 posts

Re: Launch HN: Berbix (YC S18) – Instant ID checks to fight fraud and stay compliant

#21
post #18
post #11

Congrats on the launch! Do you verify consistency of components on a license through access to a DMV database (e.g. name matches address matches license number) or is this closer to a surface-level check of subtle visual indicators present on a license? Watermarks, holograms, etc. Curious if the core asset here is a well-trained CV model, or if there's a data/partnership moat as well.

Thanks and great question! Our patent-pending fake ID detection provides an additional layer of fraud prevention on top of the surface-level checks of visual indicators that are typical in online ID checks. This gets closer to a DMV database check without the high cost (several dollars) of checking against motor vehicle records.

Gotcha, thanks! When you say "provides an additional layer of fraud prevention", you mean you're verifying against some external service like Checkr or something?

If not, very curious how you solve for false negatives in your KYC. That itself is a meaty problem domain. I remember when Coinbase was scaling, tons of folks were complaining about being unable to access funds because they were told that they weren't providing proper identifying information, even when they were, in fact, were.

Re: Launch HN: Berbix (YC S18) – Instant ID checks to fight fraud and stay compliant

#22
post #9

Congratulations! Know your customer/online id verification sure looks like the business to be in lately. Given that there's https://veriff.com which seems to be the most advanced one and they are also YC graduate, what's the advantage/edge you guys have? Selling on the price looks like a race to the bottom. Or are you focusing on USA customers only? GDPR and all that.

Thank you! And yes, this space is definitely becoming increasingly important. Our focus has been to provide a lightweight, low-friction means by which to confidently check IDs. While we have been primarily serving North America-based customers, our product can work well for any US or Canadian IDs or ICAO compliant travel documents (which includes many European IDs).

Like Veriff, there are a lot of companies in this space. What is the differentiator other than low-friction? Most of the competitors offer ~$1 per use and are highly automated and frictionless.

Re: Launch HN: Berbix (YC S18) – Instant ID checks to fight fraud and stay compliant

#23

A few questions: 1. "images that leave our system..." Why do they at all?? -- 2. You're a startup. Meaning: 90%+ chance you die. What procedures have you put in place to make sure that ALL the data is destroyed in case your company changes hands, so that it cannot be used by somebody whose ideas and privacy are different than yours, simply by buying you (or your carcass after you are bankrupt)? -- 3. What use is wate…

Appreciate the thoughtful questions.

On the point of why images leave our system at all, we provide a way to show our work to our customers — they won’t trust our results if they can’t see that they’re accurate. When they access information on our dashboard, if we render the images, they’ve left our systems. To be clear, we’re not syndicating this information to any third parties, just showing this information directly to our customer (who is the owner and controller of this data).

As for what procedures we put in place, we enforce short retention periods for the data we store in our systems for precisely the reason you are worried about. At the expiration of that period, the data is permanently deleted. Furthermore, in the event of a change of control, the contracts we’ve put in place with our existing customers govern how the information can be used. This is super important to us as we personally take privacy extremely seriously.

The aggressive watermarking is important for several reasons. First, in the worst case scenario, we can trace how a breach happened and when. Second, it is watermarked in such a way that the images become much less functional than they would be otherwise — the intent is to ensure that the images cannot be used to verify an identity on any other service. We take security very seriously — we’ve already secured SOC 2 certification and continue to invest heavily in security using industry best practices.

Re: Launch HN: Berbix (YC S18) – Instant ID checks to fight fraud and stay compliant

#25
Oh! You're the company who -- when I was requesting the non-consensual tome of personal data that Sift keeps on me (and basically everyone else in the US and other coutries) -- refused to accept my straight-faced selfie and instead specifically insisted over and over again that I need to look "joyful or happy" and try again.

I get (in retrospect, after research) that you're asking for a real-time face pose change for better identity verification, but do you realize how dystopian it feels when someone is fighting with an opaque bureaucracy and the process demands that they smile about it?

You should try expressing a rationale up-front so it's not so Orwellian.

Re: Launch HN: Berbix (YC S18) – Instant ID checks to fight fraud and stay compliant

#26
I submitted a data request to a third party processor recently (to Sift, after they were mentioned in an NYT article) and they sent me a link to your service to submit ID and two selfie photos.

The consumer facing experience on this is not the best. Here I am filing a request to a third party processor for data that I never personally sent them. And in order to handle that, I have to send even more sensitive information to yet another third party processor. See the irony here?

Sift’s email said the ID data would be retained for no more than 14 days, while Berbix’ privacy policy says the retention period is the shorter of “until no longer needed” or for 3 years from my last interaction with your customer.

Who’s right here, and if your customer quotes end users a retention period that’s shorter than 3 years, how do you hold them to that?

Re: Launch HN: Berbix (YC S18) – Instant ID checks to fight fraud and stay compliant

#27

Oh! You're the company who -- when I was requesting the non-consensual tome of personal data that Sift keeps on me (and basically everyone else in the US and other coutries) -- refused to accept my straight-faced selfie and instead specifically insisted over and over again that I need to look "joyful or happy" and try again. I get (in retrospect, after research) that you're asking for a real-time face pose change for…

Completely understand and sympathize with that. We absolutely can (and will) do a better job of conveying the intent of the different checks here. The pose change requested is randomized, but I get that this can be frustrating.

I know you already get this, but for posterity, the idea here is to make sure the person submitting their ID is actually in front of the computer (and can react to a prompt). Attempting to use a still photo is a common way a bad actor may try to circumvent these protections. Obviously correctly identifying someone in the case you described is extremely important given the sensitivity of some of these data access requests.

Orwellian isn’t exactly the vibe we’re looking for, though, so we can do better here.

Re: Launch HN: Berbix (YC S18) – Instant ID checks to fight fraud and stay compliant

#28

Oh! You're the company who -- when I was requesting the non-consensual tome of personal data that Sift keeps on me (and basically everyone else in the US and other coutries) -- refused to accept my straight-faced selfie and instead specifically insisted over and over again that I need to look "joyful or happy" and try again. I get (in retrospect, after research) that you're asking for a real-time face pose change for…

>when I was requesting the non-consensual tome of personal data that Sift keeps on me

I hope Berbix has a plan here for the fact that when sketchy companies use their service, it will make them look sketchy by association.

Re: Launch HN: Berbix (YC S18) – Instant ID checks to fight fraud and stay compliant

#29
Nice! ID checks are so prevalent that I really wouldn't mind a stripe-esque provider mediating it.

I stumbled on Indian government's effort to address this problem via https://digilocker.gov.in/ I think they basically store photos of you, your govt IDs (driving license, social security etc), your records (educational, financial) and digitally verify it with the issuer of those records (in most cases, other govt agencies), plus, also link it with your mobile phone number and/or personal email (for MFA). Is it fair to say berbix is doing the same but addressing a global market? Or, is berbix a complementary product, that is, you'd simply build on top of a service like digilocker as requester and/or issuer of verifiable documents [0]?

With that in mind, do you also plan to expand verifiability to other forms of documents, too, other than IDs?

Congratulations on the launch.

[0] https://partners.digitallocker.gov.in/

Re: Launch HN: Berbix (YC S18) – Instant ID checks to fight fraud and stay compliant

#30
post #26

I submitted a data request to a third party processor recently (to Sift, after they were mentioned in an NYT article) and they sent me a link to your service to submit ID and two selfie photos. The consumer facing experience on this is not the best. Here I am filing a request to a third party processor for data that I never personally sent them. And in order to handle that, I have to send even more sensitive informat…

Absolutely understand where you’re coming from. It can be jarring to be asked to go through those steps by a set of companies with whom you have no direct relationship. That said, data access requests can contain some extremely sensitive information and it’s important companies responding to such requests don't share information with the wrong person.

Regarding your question on data deletion; we abide by the retention policies chosen by our customers, which are typically much shorter than 3 years. For Sift specifically, the retention policy is indeed 14 days, after which point we automatically delete all the personally identifiable information we've collected on Sift's behalf. We'll be taking in your feedback, however, as this could be made clearer in both our privacy policy and our product.

Post reply on HN