Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The process is hostile and the UI confusing at times, but the requirements aren't insane. They're doing what they're supposed to do: verify you are who you say you are and that you're the owner of the domain. Just sending a mail to the webmaster is weak verification (and a SPOF, if nothing else).


I stand by my original argument.

A sane version in this country is PostIdent. It's a way to verify a person & address using the post. Think postman arrives, asks you to pull out your ID and sign something, hits okay. Company knows that you are a real person with the specified name living at that place. They _might_ have access to the number on your national ID afterwards, but I'm not even sure about that one.

Have you checked what kind of documents you're to send to a random foreign company for verification?

On top of that, the process doesn't WORK internationally. I still don't understand what kind of utility bills you have in Israel (StartSSL) or the US (usually the source for.. things), but mine are different. Plus, what does a random letter in a random language prove? Sending in an ID is understandable - it's a state issued document and protected by law, forging one would be a Bad Idea. A "utility bill"... Well, as I said: Insane. And arbitrary.

For the fun of it I looked up the mail exchange.

Documents they asked for (* denoting that I sent them):

- Mobile bill

- Utility bill* (sent a cable provider's bill)

- Passport & ID *

(I think I provided my driving license as well)

The first two documents are absolutely braindead requirements. They certainly don't have the expertise to know all utility providers/mobile network providers on a global level. So I could hand in ANYTHING and it would a) be probably legal (there's no law to prevent me from 'forging' a utility bill.tell ..) and impossible to prove. That is .. unless they call your utility/mobile provider to check the information, which wouldn't work in the first place (data protection laws) unless you IMPERSONATE the person you try to check. Which would be crazy on a different level.

In the end they wanted to send me a registered letter by snail mail and I cancelled the whole ordeal. Doing that would've been an option of course, but not after they asked for random documents proving my address. EITHER send me a registered letter OR ask for crazy stuff that contains my name and address in the header.

Plus, transparency. This whole process took a while and was a lot of "Now please send this", "We really need that", "Since you have no mobile bill to offer, we fall back to snail mails". I discovered this in painful mails, after handing over enough of my data to do mostly anything in my name.

I fail to understand how this process could be acceptable and I certainly consider it broken, hostile and inefficient.

(Handing in my utility bill was difficult as well - I blacked out all but the letter head, which caused them to complain again and again. Ignoring that the letter contained the SIP credentials for my landlines, what the..? I cannot _invent_ a reason for this requirement. My creativity is too limited, it seems)


A current utility bill shows a link to an address; a lot of IDs don't, and from memory passports don't (anyway, they last for years and don't require updates...). Yes, it's not foolproof, but it raises the bar. Most people have access to this thing and are able to send it in - so it's a cheap way to raise the bar.

Possibly you raised such a fuss that you tripped their 'possibly a forger, probably not worth it' spider-sense, so you got more hoops to jump through.


That's exactly my issue. Maybe that's the case in your country of origin, but not here. The ID lists your address and you're required by law to update it whenever you move.

Plus, they got that (address/name, a header of a utility bill), but complained about blacked out passwords/details.

Plus, if your fallback is to send a registered letter to verify an address, why .. not list that from the start and just do it that way? Slower, but less crap.

We won't find some common ground here, of course. I don't think that I 'made a fuss', not before the process became utterly broken and laughable.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: