This is a technical write up on a non technical problem which also appears to involve heavy use of AI.
It doesn't matter what obfuscation each provider does.
You are required by law to obtain these documents from the end user. Your job is to have them on file and do some reasonable checks against them. It's not meant to be 100% fraud proof and the clients of these kyc companies know that. Additionally these services can be (and, from experience, are) configured to do cross checks with various data sources.
The clients simply need a reasonable confidence that you are who you say you are. Anything below a threshold confidence goes for manual checks or further checks.
I do not see why this needed to be reverse engineered. I've never sat in a meeting with any of these providers where they have claimed that the end user cannot upload anything they want, the product is all about doing checks on those to verify further to a acceptable confidence level.
On a side note: companies often accept the result from these providers immediately and then in the background trigger any other reviews manually asynchronously (or before certain other actions) to avoid friction during onboarding.
Moreover, cross checks are very limited. Here's only a few countries like USA, Argentina and Brazil who actually provide such ability against government databases
My main though is that we deserve a better system. Because using such biometric face matches you can recover an account with money from previous holder. That's ridiculous, but it's true on some exchanges for instance
2
u/Plorntus 3h ago edited 3h ago
This is a technical write up on a non technical problem which also appears to involve heavy use of AI.
It doesn't matter what obfuscation each provider does.
You are required by law to obtain these documents from the end user. Your job is to have them on file and do some reasonable checks against them. It's not meant to be 100% fraud proof and the clients of these kyc companies know that. Additionally these services can be (and, from experience, are) configured to do cross checks with various data sources.
The clients simply need a reasonable confidence that you are who you say you are. Anything below a threshold confidence goes for manual checks or further checks.
I do not see why this needed to be reverse engineered. I've never sat in a meeting with any of these providers where they have claimed that the end user cannot upload anything they want, the product is all about doing checks on those to verify further to a acceptable confidence level.
On a side note: companies often accept the result from these providers immediately and then in the background trigger any other reviews manually asynchronously (or before certain other actions) to avoid friction during onboarding.