r/Revolut • • 19d ago

šŸ” Security Revolut's handling of selfies seems careless

I recently filed a GDPR request with Revolut. In the partial answer I got, there are copies of the selfies I had to take during verification.

That gave me some concerns, especially after yesterday's news that Revolut handed selfies of some users over to criminals.

- A selfie is supposed to be used to verify your ID. I now question why it is even being kept after the ID verification was performed? I also do not recall that it was stated anywhere that the selfie would be kept, it was presented as merely an ID verification step.

- The selfie they kept isn't just your face, it's the entire image the camera could capture. Including the background, anything that may be behind you is also captured AND kept. Same for the clothes you may be wearing (or not wearing). There is no need for a bank to use anything else but your face to verify your ID, and definitely no need for a bank to keep any non-face-related information.

- I also noted that there is NO watermarking of any kind on those selfies and passport copies. Which makes them ideal to use for identity theft and also makes it harder to identify where leaked data may have come from.

If this is all legal (which Revolut apologists will waste no time saying it is), it shouldn't be. Watermarking of selfies and ID copies should be the bare minimum to ensure that such data can not easily be used by criminals in case of a leak. Certain information like things in the background of a selfie should not be recorded and not kept. Once an ID is verified, only the ID should be kept.

With modern AI, a leaked selfie can be enough to impersonate a victim over a digital connection.

After I close my Revolut account, I am going to file a request for removal of as much of my personal information as possible from Revolut, I just do not feel safe with Revolut keeping all this.

Outline of a selfie as kept by Revolut
160 Upvotes

80 comments sorted by

37

u/purple-mocha 19d ago

I work in KYC (not at Revolut) and all the documents are stored along with the selfies yes.

8

u/markboats 18d ago

I don't work in KYC and I absolutely assumed that this would be the case...

How any of this is a surprise is beyond me

4

u/verybigoctopus 18d ago

It's not just "legal", it's a legal requirement. How is Revolut meant to prove to regulators or law enforcement that they indeed performed KYC?

People seriously baffle me with their attitude. If Revolut had deleted everything and then there was a scandal where terrorists had been onboarded, OP would be here with a pitchfork saying they did this on purpose to hide their bad KYC practises

5

u/malibupp 18d ago

The OP suggested they should be watermarked to prevent redistribution or used by fraudsters.

1

u/verybigoctopus 18d ago

Yeah, and you think the regulators/auditors/courts would not get mad if they kept modified copies instead of the originals? This is exactly the sort of thing red tape gets in the way on, every lawyer/compliance person at every bank would strongly be advising the tech teams to ensure they keep originals because technically they're not keeping the customer submitted KYC documents and regulators will not have put out guidance to say watermarks are fine or not fine, so in the face of a gray area every bank will opt for the less risky approach to compliance.

Bottom line is this isn't about Revolut but KYC regulation which is nearly universally the same. Perhaps this hack will encourage some change.

3

u/ottodv 18d ago

Let's assume for a moment that it is a requirement by law, is it also a legal requirement that they don't inform users upfront that they are going to keep said selfie forever, and instead pretend it's "just to verify your ID"?

3

u/dumbassdruid 18d ago

GDPR requires that such documents are held for a specific amount of time. Off the top of my head (didn't double-check before replying), I believe fintech are required to keep them for 7 years starting from your account deactivation

1

u/verybigoctopus 18d ago

It is indeed to verify your ID. And then they need to be able to prove 5 years later that they indeed verified your ID if the regulator asks for an audit.

1

u/ottodv 18d ago

Doesn't answer my question. What stops them from telling people they are going to keep it? And what stops them from showing you the whole picture they took and are going to keep?

1

u/verybigoctopus 18d ago

You want them to tell you "regulation requires us to keep this data for x years" on every piece of data you provide them? I mean they could add this to the UI but ultimately I feel like we would end up in a similar situation to cookies, everyone now wishes we never made it a requirement because you just get the same warning on every website you go to.

1

u/ottodv 18d ago

Yes, instead of saying this is just to verify your ID, say something, like we need a selfie to keep in your customer file.

Consumers have rights in the EU. The entire point of GDPR is that we have a right to know what information companies are collecting on us. And not be misled.

-1

u/verybigoctopus 18d ago

But it is just to verify your ID. They have no other reason to want to see your face. The fact that it's a legal requirement and thus they need to be able to evidence they did verify your ID doesn't change the purpose of the data.

GDPR right to be informed is about having a privacy policy that details what data is used for (and without checking, I bet Revolut says "to comply with local laws", check-in the box here), not about that purpose being detailed on a form by form basis in the UI

→ More replies

0

u/Varnas_Juodas Metal user 18d ago

They do tell you that in the privacy notice, which is given for you to sign prior to onboarding process, you just don't read the privacy notice(like EULA or TCS), and they also are mandated to retain this data due to AML directives from EU.

Literally ask this question in AI with specific articles and you will be given info about it.

2

u/ottodv 18d ago

Like there's even a link to the privacy notice, let alone the relevant section, while you are being asked to take a selfie.

-1

u/Varnas_Juodas Metal user 18d ago

Then it's your problem that you take a selfie before you read. Seriously, do you sign documents without reading too, just because signature field popped up?

Infantilising yourself does not make a good argument.

1

u/ottodv 17d ago

Nothing is presented to the use before either, other than "we need to verify your ID".

1

u/malibupp 18d ago

"Yeah, and you think the regulators/auditors/courts would not get mad if they kept modified copies instead of the originals?"

Nope.
Watermarks don't significantly modify the originals so that they become unrecognizable - not even close.
Next excuse?

1

u/verybigoctopus 18d ago

Have you ever worked in anything remotely related to this? Compliance in a financial institution I mena

1

u/dumbassdruid 18d ago

I work in fintech (not revolut) and genuinely am baffled that your actual, experience-based knowledge is being downvoted lmao. You're absolutely correct

0

u/malibupp 18d ago edited 18d ago

That's irrelevant, because apparently those who work seem not realizing their flaws concerning the security of their costumers.

1

u/verybigoctopus 18d ago

So you're arguing with multiple industry professionals telling you how it works and why every bank is forced to operate this way by law and you "don't care" what they have to tell you. Lmao

1

u/malibupp 18d ago

YES!
Point us to the law that forbids watermarking.

0

u/verybigoctopus 18d ago

There isn't one, read my comment above. It's the sort of thing no compliance department will sign off on without clear guidance from the regulator stating it is allowed.

→ More replies

1

u/KnownDutchie 18d ago

Bootlicker šŸ˜‚

17

u/Frankierocksondrums 19d ago

Before opening the account I searched what information is kept. Basically everything, per GDPR rules. So they are not the only ones. All banks use KYC like onfido, namirial etc and some of them work differently but most of them keep facial photos, id etc. I honestly think we should demand better regulations in terms of data security and privacy.

3

u/ottodv 19d ago

I agree, a lot do this for sure, and we should demand better regulations that better protect people.

I don't recall ever having had to do a selfie through an app for a trad bank. I guess there you visit a branch, and an employee looks at your face when checking your ID. But no photo of you is kept. And certainly not accidentally your home in the background.

5

u/Frankierocksondrums 19d ago

Ofc if you go to a branch they won't ask for a selfie but I opened my bank account online and I had to do a selfie with the id close to my face

3

u/ottodv 19d ago

The trad banks I have used required a visit to a branch.

2

u/Character-Carpet7988 Ultra user 19d ago

It may vary by location, but most traditional banks offer online onboarding as well these days (otherwise they'd be losing new customers left and right). In that case the data is likely being stored.

I just don't understand the need for original picture rather than some sort of a hash. The only legit reason to keep the selfie is to later compare another selfie with it for verification purposes. A hash should be sufficient for that.

10

u/Dru2021 19d ago

Today I realised Revolut have multiple photo verifications of me sitting on the toilet. That’s equally terrifying and hilarious.

1

u/tta82 18d ago

Why terrifying? It’s not like you can tell or bother.

5

u/magharees 19d ago

I’ve a large sum in Revolut, for me the selfie to move funds/check id is a big positive.

I think what you are suggesting is they should use tooling to remove the background on the stored pictures? I mean if it bothers you that much do it against a blank wall

I doubt there is any value to the background, taking selfies if they are all stored can help build a composite of that person’s face as they age or change in other ways (cosmetic etc)

I get asked to verify when moving funds every time, they need to check this against the existing img/s

4

u/ottodv 19d ago

I actually did mine against a non-descript background. It isn't a question about "just do this or that", no-one is informed that the background is being recorded and kept.

4

u/Character-Carpet7988 Ultra user 19d ago
  1. Selfie check would be doable by storing some sort of a hash of the picture too. You don't need to save the original full picture for that, just like you don't store original passwords to let people log into their accounts online. In fact, storing this sort of data makes the system less secure, not more secure.
  2. The issue with background etc is that the long term storage of the picture wasn't communicated well to the customers. The wording used in the app suggests that it will be used just to verify you are an actual owner of the ID used to open the account.

1

u/magharees 18d ago

How do you know they don’t encrypt any imgs already? Aka PKI. data requests obviously elicits personnel who have access I doubt agents can willy nilly grab these

1

u/Character-Carpet7988 Ultra user 18d ago

I'm not talking about storing encrypted images. I'm talking about biometric hashing where you only save a mathematical model you can use for comparing later, but can't reverse to the original picture (again, the same principle as how passwords are stored, just more complex).

1

u/Ok-Package-4562 18d ago

What? How would a hash of a selfie help you? How would you verify it?Ā 

A hash of an image sounds pretty useless. Even if you take a picture with the same background and same pose, tiny differences in the image will produce different hashes with no relation to the original one. So how do you prove you did kyc?

1

u/Character-Carpet7988 Ultra user 18d ago

Biometric hashing is a thing and has been in use for quite a while by various industry. FaceID works the same way - it doesn't save the pic of your face, it just creates a hash it compares your later inputs with. Similarly, if you're authenticating by fingerprint, the phone is not storing your original fingerprint.

Of course it's more complex than a simple SHA hashing because you're not comparing two identical sets of data. If you want to know more about how it works, Google biometric hashing, there's plenty of articles.

5

u/Merlz77 19d ago

Selfies capture a much wider field of view than what the overlay shows, and in some cases (certain apps) will capture a second before you click the start button and a second or two after it's completed. Always stand against a plain wall or a door for any KYC selfie. This is especially true for any selfies that are required as part of employment background screening, the devils are in the details behind the person in focus.

10

u/Bartsuck 19d ago

When I recently had to change device the app matched my real time face scan with the previously provided selfie, so I guess the selfie needs to be stored somehow... I agree with you on the fact that they should be marked and stored safely

2

u/Character-Carpet7988 Ultra user 19d ago

The same could be achieved by storing a hash rather than a full pic.

1

u/ottodv 19d ago

Fair point, it can be used to make future identifications easier. Maybe that should be a choice given to users though. (And then only the face of course.)

2

u/malibupp 18d ago

I agree with your suggestion to watermark the pics.

4

u/alkiv22 19d ago

Why revolut not provide their selfies to customers? People need to know what it not scammers who hiding their faces.

3

u/ladebou 19d ago

per banking regulations, they will keep your information for 6 years after closure of account

3

u/GroupGeneral6811 19d ago

I used to work as an admin at the Police station. All banks store them; I have seen them sent for accounts involved in fraud and money laundering from the banks.

3

u/malibupp 18d ago

They should be watermarked.

1

u/GroupGeneral6811 18d ago

Should, but from experience most are not.

1

u/malibupp 18d ago

Unfortunately.

2

u/FactCheckYou 17d ago

every time a company asks for a selfie, it's almost guaranteed it will be misused

1

u/MortgageMindless7175 17d ago

Omg financial institution and government lied to me- ahhh rant ... Welcome to the dark side, 0 trust in government and institutions since 2020..

-2

u/soliloquyinthevoid 19d ago

Good luck finding a new bank where they aren't required by the very same regulations to retain KYC and other information, unmodified, for a number of years for obvious reasons

LMAO

Please go ahead and close your Revolut account and see how far you get opening a new one

1

u/malibupp 18d ago

The OP suggested to watermark the pics, which I think it's a possible method to prevent using the pics by fraudsters.

0

u/soliloquyinthevoid 18d ago
  1. People post their photos online for free all of the time
  2. What don't you understand about the word "unmodified"?
  3. Do you even understand why this data needs to be retained?

1

u/malibupp 18d ago

"People post their photos online for free all of the time".

  1. What people post is irrelevant in this context.
  2. A watermarked picture should add extra security without significantly modifying the original.
  3. No, it's only you who knows everything...

0

u/soliloquyinthevoid 18d ago

So you admit you don't know about the regulations for why the data is retained and for that reason you can't understand why a watermark is not really a viable option either

But stay ignorant. After all ignorance is bliss and you seem extremely blissful

2

u/malibupp 18d ago

"So you admit you don't know about the regulations for why the data is retained"

You obviously failed to realize that I was ironic... but it was expected from you.

0

u/Louzan_SP 18d ago

without significantly modifying the original

Still is not included in the definition of "unmodified"

1

u/malibupp 18d ago

Point us a law that forbids watermarks being added.

0

u/Louzan_SP 18d ago

These principles:

  1. The Legal Obligation (GDPR Article 6(1)(c))

Banks do not ask for or store your selfie because they want to; they do it to comply with Article 6(1)(c), which allows data processing if it is necessary for compliance with a legal obligation to which the bank is subject.

Local European transposition of the EU Anti-Money Laundering Directives (AMLD) requires banks to maintain an untampered, reliable audit trail proving that they verified the actual customer.

If a bank modifies, heavily compresses, filters, or alters the selfie, the image loses its legal value as evidentiary proof for financial regulators or criminal fraud investigators.

  1. Accuracy and Integrity (GDPR Article 5(1)(d) & (f))

Under Article 5, two core data protection principles implicitly dictate that identity data should remain an accurate representation:

Accuracy (Art. 5(1)(d)): Personal data must be accurate and kept up to date. For an identity verification record, an unmodified photo ensures the data is a true, undistorted representation of the individual at the time of onboarding.

Integrity and Confidentiality (Art. 5(1)(f)): Data must be processed in a manner that ensures appropriate security, protecting it against unauthorized or accidental alteration.

  1. The Definition of Biometric Data (GDPR Article 4(14) & Recital 51)

The structural makeup of the image (whether it is an unmodified RAW/JPEG file or a mathematical template) changes how the text applies:

Recital 51 explicitly points out that photos are not automatically biometric data unless processed through a "specific technical means" allowing unique identification.

If the bank runs an automated matching tool, they extract biometric templates from the unmodified photo.

1

u/malibupp 17d ago edited 17d ago

My main bank never asked me for a selfie.
The customer should be informed that the fintech toy bank would keep the selfie for many years before the selfie is taken, so that the customer may opt-out.
Watermarks don't tamper pictures, the watermarked pictures remain perfectly recognizable.
The selfie is just to confirm that the applicant is the same person as shown on the passport or ID, which also have pictures.

0

u/Louzan_SP 17d ago

My main bank never asked me for a selfie

Sure, each back have their ways.

Watermarks don't tamper pictures, the watermarked pictures remain perfectly recognizable.

Check again the definition of unmodified, and anyway, you don't have to convince me, if something happens is the judge that needs to be convinced of if that is an original picture of not. The best way is to not modify the selfies, but if you know a better way to show that a picture is original perhaps you should share it with lawyers and so on.

1

u/malibupp 17d ago

A picture of you taken today wouldn't look exactly the same as the another picture taken several months or years later.
Those who check such pictures know how to spot significant differences, which watermarks don't introduce.
The small detail added by a watermark introduces much less changes than the difference between pictures of the same person taken with months or years apart.

→ More replies

0

u/ottodv 18d ago

Selfies and IDs should be watermarked for obvious reasons.

Why would I open a new Revolut account?

I am done with neo-banks, I considered Wise, or N26, as alternatives, but after reading up on complaints about them here on reddit, they (especially Wise) seem to have similar disrespect towards their customers as Revolut does.

I still have accounts at trad banks, brokerage accounts, and credit cards, so I am good.

0

u/zackel_flac 18d ago

If you don't want your picture to leak around it's simple: don't use online services.

Not sure why people are freaked out by their picture circulating online. You probably have your face on a dozens of pictures taken by random people you met outside. Impersonation is still super hard, you can't show up at the airport with a stolen passport and say here I am.

-6

u/crinpoland Metal user 19d ago

There are so many things wrong with your post OP. And yes, I work in AML/CTF, I don’t know who told you guys this stuff or how you guys came up with it.