Live data from Hacker News

Stripe Identity

stripe.com

281–290 of 557 posts

Re: Stripe Identity

#281

Earlier quoted context omitted.

I work at Stripe, though not on the L10N/I18N or identity teams. It would be tremendously helpful if you could send me some feedback so that we can improve, jlh at stripe dot com. I'm a native Spanish speaker too, and nothing in this announcement strikes me as unintelligible, but that might be my own biases at play given the familiarity with Stripe's lingo.

Are you going to pay me? If not, good luck!

Probably not the answer you expect, but the I18N team is hiring :) https://stripe.com/jobs/listing/internationalization-enginee...

Otherwise, if you're a trained linguist and have demonstrable consulting experience QA'ing technical documentation then we'll be happy to arrange something.

In either case, we appreciate your feedback, and my emails are open!

Re: Stripe Identity

#282
post #88

Isn't this a privacy nightmare? All that data in Stripe data centers.

1. Stripe has strict access controls—only those working on Identity/verifications can access the data. 2. Biometric data is not stored! It’s gone from our systems within 48 hours (usually in just minutes). 3. We think this’ll actually make the state of global privacy better—rather than having individuals collect, and verify your ID, Stripe will securely handle verification.

> 1. Stripe has strict access controls—only those working on Identity/verifications can access the data.

> rather than having individuals collect and verify your ID, Stripe will securely handle verification.

The above statements are materially false. You allow customers of Stripe Identity the ability to access and retain "captured images of the ID document, selfies, extracted data from the ID document, keyed-in information, and the verification result". [https://support.stripe.com/questions/managing-your-id-verifi...]

Re: Stripe Identity

#283

Smart. Banks haven't been allowed to monetize their KYC data, but this new non-bank class of payments companies have this opportunity. Interac has been trying to do this for many years. Some years ago I worked on a system let banks do identity assertions with proofs via SAML attributes instead of sharing customer PII. It is now a federation of banks in wide use for govt services in Canada. The use cases were really l…

"Banks haven't been allowed to monetize their KYC data"?

I work for a major US Bank and they are most definitely monetizing KYC data, in fact we have made several billion dollar acquisitions just to scoop peoples data.

Re: Stripe Identity

#284

Smart. Banks haven't been allowed to monetize their KYC data, but this new non-bank class of payments companies have this opportunity. Interac has been trying to do this for many years. Some years ago I worked on a system let banks do identity assertions with proofs via SAML attributes instead of sharing customer PII. It is now a federation of banks in wide use for govt services in Canada. The use cases were really l…

Do banks want to monetise their KYC data? In the UK, the government launched a similar system in 2014 called Verify, a platform for banks and other firms with existing customer relationships to offer identity verification as a service to the government, and eventually, third party sites. Users would choose a participating bank they has a relationship with and login to their account as verification.

But despite paying over £20 a user for each verification they only got one or two banks to join, and the scheme was a disaster.

Re: Stripe Identity

#285
post #99

The landing page contains logos for clubhouse, discord, and shippo, which are presumably companies use the service. Does anyone find those usages to be unnecessarily intrusive? Maybe it's just me, but a chat app or shipping site asking me for a drivers license scan + selfie would make me never want to use the service again. It's appalling how this sort of stuff is getting normalized, eg. google asking for id scans fo…

I honestly find it weird having all of these things suddenly want a copy of my passport in the cloud just sitting there waiting to be hacked in years to come when the security measures drop. At this point there is giant databases containing everything people need to take complete control of your identity sitting there just waiting to be hacked. I have no idea how to change it/fix it. But it seems weird to me.

The fix is for the government to make it a service. Right now, the government is punting responsibility to private actors who do not have the legal tools to operate an identity service.

The government already operates an identity service via passports. The only reason they do not have an electronic identity service yet is because it is beneficial for them to be able to blame private actors when things go wrong.

Re: Stripe Identity

#287
post #11

How does this work?

It's actually pretty cool (IMO; I'm biased). Drop-in browser-based user authentication that: * Uses various sophisticated heuristics to detect real vs fake IDs. * Matches the ID to the human face. * Detects whether the human face is live or not. * Dynamically requests more or less information depending on the confidence level. It also gets better over time based on the attacks and fraud attempts that Stripe itself se…

pc how are you biased? Do you work at Stripe or something?

Re: Stripe Identity

#289

Had to do this on a site recently and it didn't work for me at all. It wanted to scan the back of my dl but Indian dls are totally blank at the back. Then it said my webcam wasn't good enough and showed me a QR code to use for my mobile. The link never opened. Tried it 3 times and 5 minutes later I just googled the next alternative site and bought it from there. Lesson being use this only if it is totally necessary.…

Another commenter on this post said that this service isn't available in India, so it seems like the real flaw is that this shouldn't have been presented to a user in India by whatever site you were using.

Re: Stripe Identity

#290
Considering that Stripe was originally known for letting websites accept credit card payments without seeing your credit card number, one might assume that Stripe Identity only allows websites to see the verification result, and not your selfies and scans of your identity documents.

That would be an incorrect assumption. Per https://support.stripe.com/questions/managing-your-id-verifi... customers of Stripe Identity have API access to "captured images of the ID document, selfies, extracted data from the ID document, keyed-in information, and the verification result".

Thus, when you use Stripe Identity to verify your identity, you have to trust that:

1. The website doesn't download, retain, and later leak your selfie and identity information.

2. The website's Stripe API token isn't compromised and exploited by identity thieves to access your selfie and identity information.

Stripe appears to be leaning heavily on their claim that they don't disclose "biometric identifiers" to websites and that these "biometric identifiers" are deleted from their systems within 48 hours. This is extremely deceptive considering that biometric identifiers can be reconstructed from the selfie.

Post reply on HN