Run instant authentication checks on any government issued ID
confirm.io
confirm.io
Their privacy policy looks like a standard web site privacy policy. It says nothing about how they handle ID data. That's a big deal, because Confirm is handling personal data that isn't about Confirm's own customers. This can create liability for Confirm or Confirm's customers under various identity theft laws.
Here's their founder: [1]
They claim to be approved by the German Federal Financial Supervisory Agency. Big banks use their services to authenticate account holders.
The one I had when I moved was printed on a very low quality inkjet printer... it looks more fake than a fake ID, but it is a legal, US government issued ID.
The best route to a fake ID was previously to bribe a DMV clerk to use the printer after hours. Those fakes were basically undetectable by physical inspection.
Very few convincing fakes (that are caught) are built to modern standards. Fake ID makers almost always imitate designs from before the institution of Real ID.
Most organizations would rather see your slightly expired card, demand a second factor, or just refuse service rather than trust a piece of printer paper. You're definitely not getting into a bar with a temporary ID if you look plausibly underage, or the kids would be doing that already.
See also: https://en.wikipedia.org/wiki/ADE_651, Theranos, etc.
So what?
Airbnb is exactly that, violating countless zoning laws throughout the known universe. And yet, at a recent $30 billion, it's one of the most richly valued unicorns.
We're living in a world that has little use for "honest" business practices.
Source: I went to high school
These photos could be stolen and reused for fraud and identity theft.
Electronic IDs provide a much safer and more reliable way to check the identity of a user. Eg: every citizen in Belgium can authenticate HTTPS connections with his ID card.
See Wikipedia for more info: https://en.wikipedia.org/wiki/Electronic_identification
When someone solves a problem in a particular technology stack in a suboptimal way, it is generally considered unhelpful to tell them they should have just used a totally different stack. "Why bother working around that registry issue in Windows, when you could have just used a superior operating system, such as OS X?", etc.
1. The US does not have a compulsory national ID. No, Social Security is in fact opt-in, it's just that these days most people are opted in without their consent. Passports are clearly optional.
2. The US is unique in the states/federal struggle, which has been ongoing since before 1776. One of the reasons REAL ID will never get adopted is because many states fight strongly against it.
3. There is a real question of jurisdiction. Does the Constitution grant the right for the federal government to force citizens to have an ID? If you invoke the supremacy clause, the states will invoke the 10th amendment right back at you :)
4. Do you really want the US to have a federal ID database? Between the Hillary emails, the OPM hack, and the general spirit in which the federal government seems to be operating, the last thing I'd want is for them to have more power.
EXCEPT AS EXPRESSLY SET FORTH HEREIN, THE LICENSED TECHNOLOGY IS PROVIDED ON AN “AS-IS” BASIS AND CONFIRM DISCLAIMS ANY AND ALL WARRANTIES. CONFIRM DOES NOT WARRANT THAT THE LICENSED TECHNOLOGY IS ERROR-FREE OR THAT OPERATION OF THE LICENSED TECHNOLOGY WILL BE UNINTERRUPTED. EXCEPT AS OTHERWISE EXPRESSLY PROVIDED IN THIS AGREEMENT, NEITHER PARTY MAKES ANY ADDITIONAL REPRESENTATION OR WARRANTY OF ANY KIND, WHETHER EXPRESS, IMPLIED (EITHER IN FACT OR BY OPERATION OF LAW), OR STATUTORY, AS TO ANY MATTER WHATSOEVER. ... EACH PARTY EXPRESSLY DISCLAIMS ALL IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, QUALITY, ACCURACY, TITLE, AND NON-INFRINGEMENT.
7 LIMITATIONS OF LIABILITY7.1 Disclaimer of Consequential Damages. THE PARTIES HERETO AGREE THAT, NOTWITHSTANDING ANY OTHER PROVISION IN THIS AGREEMENT, EXCEPT FOR (A) CUSTOMER’S BREACH OF SECTION 1 OR 6.2, (B) EITHER PARTY’S BREACH OF SECTION 5 , AND (C) LIABILITY ARISING FROM A PARTY’S INDEMNIFICATION OBLIGATIONS SET FORTH IN SECTION 8.1 AND 8.2 BELOW, IN NO EVENT SHALL EITHER PARTY BE LIABLE TO THE OTHER FOR ANY SPECIAL, INDIRECT, RELIANCE, INCIDENTAL OR CONSEQUENTIAL DAMAGES OF ANY KIND, LOST OR DAMAGED DATA, LOST PROFITS OR LOST REVENUE, WHETHER ARISING IN CONTRACT, TORT (INCLUDING NEGLIGENCE), OR OTHERWISE, EVEN IF A PARTY HAS BEEN NOTIFIED OF THE POSSIBILITY THEREOF.
Which is to say, it could tell you that Lovin McSpoonful is a totally valid CA driver's license, and you have no remedy if you rely on that to sell the 18 year old alcohol.
Non-authoritative answer: api.confirm.io canonical name = midentssl-861843077.us-west-2.elb.amazonaws.com. Name: midentssl-861843077.us-west-2.elb.amazonaws.com Address: 54.149.15.14 Name: midentssl-861843077.us-west-2.elb.amazonaws.com Address: 52.25.246.175
Hosted in the US on Amazon. That makes it immediately a no-go for European customers.
So, what's the data retention policy? Who has access to it? Is any PII contained in the webserver logs? If the answer is "no", how do you define PII?
Have you had a third party security audit done? If so, can we see the report?
Those are just a few of my initial questions :)
I want transparent pricing right on the page, instant SDK access for self evaluation, instant purchase if I want more, and no slimy sales process that depends on my region or what I negotiate.
Companies can make money in lots of ways. "Contact Sales" is not an invalid way to do so, just an unpopular one.
Also I don't see any data or information about any guarantees, no case studies, etc. A service like this is worthless unless they are willing to provide something for when fraud does occur, or provide a guarantee that the service actually works and the results can be trusted.
Reading through their terms of service, there is no warranty what so ever. Their technology could be completely bogus, or do nothing for all you know. It's a black box.
You're basically opening yourself up to liability for questionable benefit.
They say they used machine learning, so the reality is that usually means they don't even know what their technology does either.
I'm sure they can tell you that statistically, it will probably not validate an image of a cat as an ID.
Reminiscent of IDnow ( https://www.idnow.eu/ ), which has been around for a while now. IDnow claims that it "is available worldwide. IDnow supports identification documents (passports and personal ID cards) in accordance with the common ICAO standard, which is valid in more than 190 countries."
This is hacker-honey.
I think the company I work for could benefit from a service like this for two reasons, but neither of them have anything to do with the authenticity of the ID itself. Basically, we just need a reliable OCR system to capture the name and address to avoid manual entry, and an automated OFAC list[0] check would be nice as well (for the regulatory requirements, as you say).
[0] https://www.treasury.gov/resource-center/sanctions/SDN-List/...
Combine that with a "partnership" six months after that, and it really seems like there is zero proprietary technology that was built by this company in the first place.
I don't think this necessarily means that there's something shady going on. Could be just a way to structure the deal, compensate the founders for their work so far and get money to focus on sales and expanding the business.
The question becomes, who takes on the liability for the identity asserted by the user who has presented the card? They could compare it to all previous images of the card, but again, was that original?
All eID solutions have a bootstrapping problem related to the "fons honoram" that creates the legitimate "original."
The use cases for ID are all law enforcement related, and the integrity of these processes does not withstand even basic scrutiny.
What is the problem they need to solve? Limited liability broker for proof of legal identity over a communications channel.
Here are the things that matter:
- "liability" - "broker" - "proof" - "legal" - "identity"
Here is what other companies in that space do:
"ah takez teh picturez of teh cardz and ah sendz to tehm."
This company may have solved these other problems. If they have, I would be yelling it from the rooftops because the technology doesn't matter, they would literally have been given the right to print money.
"You are running an outdated version of Internet Explorer."
I'm on an Android phone.
I've yet to find an API based solution that can reliably verify information solely based on the picture of someones drivers license.
That name, DOB, address, and license number is easily discernible from the video.
I bet he wouldn't be happy if he realized that is date of birth, driver license number, and address were publicly on his company's homepage...
Edit: Also, the new (ugly, pastel-ey) NC drivers licenses also appear to have a 1-D barcode on them as well
I haven't seen a new ID, haven't bothered getting a new one since I turned 21 a few years back so I have no idea what the newer ones have or don't have.
The magnetic strip varies by state but the PDF417 barcode is supposed to follow DL/ID Card Design Standard (CDS) as defined by the AAMVA.
Unfortunately, there isn't a national system for encoding the data as described in the specification and some states still maintain different fields than others. As a result, it's a real pain to try and use the standard without accounting for each state's unique set of quirks which tend to change from year to year.
I assume they've built a system to handle all of these unique cases and use some type of OCR to verify everything matches up with both the encoded barcode data as well as the Driver's License number which is partially derived from the demographic data. The facial image comparison is nice but it's not the most reliable test (especially when it depends on the phone's camera and a 2cm x 2cm photo.
Combining that process with a background check of some type will guarantee that the person actually exists but the whole system system can still be duped by a good enough fake ID if the data checks out.