5 ms·
Conflating credit card #'s and personal biometrics/SSNs is your first mistake. You think they are the same, they feel the same, but the risk to the customer is
by prague60 5y ago
Conflating credit card #'s and personal biometrics/SSNs is your first mistake. You think they are the same, they feel the same, but the risk to the customer is so much bigger.
When a hotel copies my passport, they get a jpg. If they use Stripe, now I know they have my biometrics serialized to JSON. That feels way riskier and scarier to me, especially now that it's all centralized by Stripe.
We hear about our personal data getting leaked and hacked every day, and here is Stripe making themselves an enormous target and serializing all the data for malicious actors.
This feels like a really tone deaf misstep by the company.
- tomc1985 5y agoIt is trivially easy to key-in identity info from a JPG scan They are both toxic, IMO. Businesses need to stop relying on this stuff.
- openthc 5y agoRight but -- the attack vector is different. Scan/parse 10000s of JPG, and all that jazz -- to get identites. Not Trivial. Or if the hotel stored the copy as a physical photo copy -- you're not bulk scanning 10k pieces of parchment at super speed for your identity-theft ring. But download JSON blobs? From 10k records the hotel didn't store properly (cause they are not IT experts, or don't have experts at close hand) -- if you get in to their system the JSON is loads easier to parse than the JPEG. Methods for KYC could(should!) be improved.
- tevonsb96 5y agoBut like one of the Identity team folks said, the hotel would only have the OPTION to download and store those blobs. They aren't required to, and I'm assuming they would not. They'd be happy with the verification result and letting Stripe handle storing the PII. Speaking from experience as we use Stripe Identity, and love not having to store the PII.
- xur17 5y agoIsn't the problem that businesses are required to store this type of information (kyc verification information)? At what point are we going to have a logical system for verifying identity that doesn't require transferring the same list of data that every other 3rd party you've verified with also has?
- ibeitia 5y agoI’m an engineer on the Identity team. There are two somewhat separate questions here. (1) Whether the business should ever have access to this data. And (2) how exactly the business should access that data and the security properties around it. On (1) this data is fundamentally the user’s, and there are often important compliance reasons as to why the user needs access to the raw data because of obligations that they themselves are subject to. It’s important to remember that you should trust both Stripe and the business that’s asking you to verify your identity. They are in control of explaining to you how they are using this data and giving you an option to opt out—or lose you as a customer. On (2) we’re working on a way to restrict access via secret keys very soon.
- PuffinBlue 5y ago> On (2) we’re working on a way to restrict access via secret keys very soon. Hmm, this doesn't really seem to me like the sort of area where you bring out a MVP and then work out basic fundamentals like this afterwards.
- 3np 5y agoHow large percentage of Stripe Identity customers do you foresee actually are required by legal regulation to retain all this information, as opposed to verifying certain aspects of an individual, as opposed to wanting it and likely handling it in ways violating GDPR and similar regulation? I’d argue that before Stripe sends any PII other than validation results to a customer, it needs to verify that the business indeed is under regulatory requirements to gather this data, and only sell the required part. Alternatively, you could invert the process, allowing integrating businesses to send documents to Stripe, who replies if they’re legit or not. Finally, if there is a need for sharing data with customers for e.g. KYC, shouldn’t this be priced significantly higher than verification/validation, so that Discords and Clubhouses can’t justify it from a business perspective? What is the reasoning for doing neither of the above?
- petemyers 5y agoAs a consumer, how can I request a removal of my personal info from Stripe's Identity database?
- 5y ago
- wdb 5y agoHotels don't even get a full copy of passport but a redacted version of my passport. That's my government's guidance only select entities should get unredacted copies. If not possible, I should mark the copy to the specific user.