Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> The data may have also included verification selfies

Why do they even keep those?

 help



I am almost sure they don't and instead they query selfies and documents on-demand from their KYC provider.

Yep, the KYC provider keeps them.

Could they be put in what bitcoin people call "cold storage"? I can't imagine they're used every day.

They're used pretty often, so not really. The KYC providers anyway wouldn't code anything like that.

Around banking it's usually because they have to

Other banks do not require selfies, so there are other options

But they are verifying customers in person with account creation, this is an online bank

> But they are verifying customers in person with account creation, this is an online bank

Revolut could do the same as they do with ATMs: make a partnership with local banks for the verification step.


Sure, but that would be like insanely stupid on pretty much every level though, so why would they do that?

Trying to find a way to tip toe around KYC, whilst keeping their customers safe, has also turned out to only use insanely stupid methods, though. So why did they already do that?

FYI it turns out that humans are pretty bad at comparing faces to ID documents. Like, really quite bad.

Automated methods, like the ones Revolut use, are significantly more effective at KYC than a Jane Doe working a 9-5 at a bank. In no way is it “tip-toeing around KYC”, and while really unfortunate leaking a selfie is pretty low down on the list of “bad stuff a bank could leak”.

The implication that the solution to this is to somehow convince your direct competitors to do inferior in-person KYC for you is the most ridiculous thing.


>The implication that the solution to this is to somehow convince your direct competitors to do inferior in-person KYC for you is the most ridiculous thing.

People work with their competitors all the time (see Netfix vs Amazon). Whats ridiculuous is the claim that a scammer would prefer to show up physically at a bank and risk being exposed instead of operating remotely.

>leaking a selfie is pretty low down on the list of “bad stuff a bank could leak”.

don't some of them require a selfie while holding legible official documentation?


No, it’s most certainly patently ridiculous.

> Whats ridiculuous is the claim that a scammer would prefer to show up physically at a bank and risk being exposed instead of operating remotely.

Of course they wouldn’t prefer to show physically. What does that mean though? Are you saying no scammers showed up physically to banks, therefore banking fraud rates are less? Do you have a source for that?

> don't some of them require a selfie while holding legible official documentation?

You can of course do KYC as stupidly as you like (zoom calls anyone?) - Revolut (and their providers) obviously separate document presentation from the liveness check (and fyi this is a short video, not a selfie. The selfie they are talking about is just a capture from the video)


>No, it’s most certainly patently ridiculous

Is your argument supposed to be more convincing because you added the word "patently"?

>What does that mean though?

It means that when you find a way to bypass purely online identity verification checks executing fraud at scale is easier than the physical alternative. As you would say, this is patently obvious.


For security reasons, obviously! That way they wouldn't leak selfies because they wouldn't have any.

Sending your new/potential customers to your competitor doesn't sound very sensible.

Seems like a thing you should be able to do at the post office.

What does post office have to do with identity verification?

In the USA they already take passport photos. Being able to receive mail addressed to a name is the closest thing to a national ID the USA has. They're already depended on for identity verification quite a lot.

You can receive mail to any name at your address.

I didn't say it was a good national ID system, I said it's the closest thing the US has to one.

Some post offices in the US also function as a so called notary public. Basically, they can verify your identity and attest that it's you who sent/did something.

This is used quite often for important things that don't have offices themselves.


This is a 100% online bank account you typically open from an app. The typical clientele will just use the "selfie" auth.

The issue is that there is no alternative to the "selfie" auth in case of Revolut.

Most banks now require selfies, try shopping around. KYC requirements get tightened all the time.

I have accounts with 2 other banks. They never asked for a selfie.

Same, they never asked for a selfie back then.

Try opening one now. Today it's hard to get a hire purchase contract as an existing custoner (already known and verified) without photos of the ID and selfie.


Likewise, opened a couple in the past few years and never saw this. That said, bank lobbies have tons of ambient cameras anyway, so they don't really need a selfie.

At least one traditional UK bank requires a selfie and a passport scan.

CYA in case of litigation.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: