4 ms·
Right but -- the attack vector is different. Scan/parse 10000s of JPG, and all that jazz -- to get identites. Not Trivial. Or if the hotel stored the copy as
by openthc 5y ago
Right but -- the attack vector is different. Scan/parse 10000s of JPG, and all that jazz -- to get identites. Not Trivial. Or if the hotel stored the copy as a physical photo copy -- you're not bulk scanning 10k pieces of parchment at super speed for your identity-theft ring.
But download JSON blobs? From 10k records the hotel didn't store properly (cause they are not IT experts, or don't have experts at close hand) -- if you get in to their system the JSON is loads easier to parse than the JPEG.
Methods for KYC could(should!) be improved.
- tevonsb96 5y agoBut like one of the Identity team folks said, the hotel would only have the OPTION to download and store those blobs. They aren't required to, and I'm assuming they would not. They'd be happy with the verification result and letting Stripe handle storing the PII. Speaking from experience as we use Stripe Identity, and love not having to store the PII.