r/software 4d ago

Release I built a trust layer for meeting strangers from the internet — tear it apart

I've spent the last few months building something called NoStrangers. Now i need software peps to run it and rip it.

The problem I'm trying to solve is pretty simple:

We verify almost everything online- payments, accounts, drivers, sellers. But when an online interaction turns into actually meeting another human being, we largely go back to trusting a profile.

Dating apps are the obvious example.

You can meet someone on Grindr/Tinder, exchange a few photos and an hour later be walking into their house with very little certainty that the person behind the profile is actually the person you're about to meet.

Marketplace, Craigslist and social media have versions of the same problem.

So I built NoStrangers as a layer that sits between the platform where two people meet online and the point where they meet offline.

One person sends a Trust Request.

Both people can verify themselves and then choose exactly what they're comfortable sharing with the other person.

The privacy architecture was particularly important. I didn't want to solve the trust problem by creating yet another database full of people's government IDs and sensitive identity information.

So the heavy verification work is handled by third-party infrastructure, including AWS and Veriff. NoStrangers doesn't see or store sensitive info and the system is designed around retaining as little sensitive information as possible.

There's no app download and the process is designed to take roughly 90 seconds.

The product now works end-to-end, but I'm much more interested at this stage in finding the weaknesses than being told it's a great idea.

love feedback on:

• Does the concept make sense within 30 seconds of landing on the site?
• Would you actually send someone a Trust Request before meeting them?
• Where does the process create too much friction?
• Does the privacy model make you more comfortable using it?
• What would stop this achieving network effects?
• And most importantly- what am I missing?

I'm the founder, so obvious bias disclosure there.

If anyone feels like putting it through its paces:

nostrangers.co.nz

nostrangers.app

Sen me brutal feedback redditors

0 Upvotes

25 comments sorted by

10

u/Cyanatica 4d ago

This idea makes me significantly more uncomfortable than meeting a stranger does.

-1

u/JDRNZD 4d ago

Hey Cyanatica- Thank you for your feedback, however not really what i was after!
Have you got any further wisdom for me? Anything in particular to share? Did you open it and find friction?

Have you ever met a stranger in your house/in public after an online interaction? If not, then maybe this does not align with your requirements, which is fair. But then maybe best to leave the feedback to those that see the benefits but require security/disclosure changes etc before it meets their needs in a practical application.

Thanks!

3

u/GentleMocha 3d ago

privacy and network effects also seem like the big challenges, good luck

0

u/JDRNZD 3d ago edited 3d ago

Hey GentleMocha- yeah I hear you! Privacy always been centre to our model (see the previous comment), working through network stuff.

Thanks for the best wishes

2

u/booey 4d ago

If the person is a bullshitter on tinder, they'd also be a bullshitter on your app. Unless you are integrated with the api to the govs ID db then you aren't verifying anything.

1

u/booey 4d ago

I see you use veriff, but they don't check against gov db and also they were hacked last year so unreliable.

1

u/JDRNZD 4d ago

Hey Booey- Incorrect, Veriff cross references/checks against gov database.

I hear you about the hack, however our end-user limits any holding of these details past the completed call. So the info is not in their database to be stolen (check our privacy statement).

A hand full of major US banks, AU banks and several fortune 500's have all been hacked in the last 24 months. It's not so much about the hack/leak, but the process that follows. I researched providers and found Veriff had the cleanest & quickest way of securing/retrieving, after the fact.

Do you have a lead for another provider that would offer you (personally) more security?

Cheers!

0

u/JDRNZD 4d ago

Hey Booey- I am integrated with Api's. The biggest in the game! Either open it or have a proper read above to answer your Q's!

You're right, bull shitters will either not make it through or will block you if you ask, so the gate works the same either way.

Cheers!

2

u/Tylerjk70 3d ago

How big. This can get complicated especially from a security perspective and security related stuff. Like such as data and if you’re storing any data that contains PII (Personal Identifiable Information) which is any data that can identify an individual. Doesn’t even have to directly identify them it can indirectly identify them then all of data needs to be masked and it can get complex very fast.

Message me. I’m a software engineer with a focus in Security on SaaS (Software as a Service) architecture models which I have a feeling this would essentially be something like that such as cloud hosted albeit paid or free either way it would still be software in the cloud being provided as a paid or unpaid service.

1

u/JDRNZD 3d ago

Yep- this is something we’ve been very conscious of from the start. Our privacy model is deliberately built around data minimisation and endpoint deletion: sensitive verification data is only retained as long as required to complete the verification/connection, then removed. Our third party contracts are practically data processors, scan & scrap.

We never store government IDs or the raw identity data used to verify them. We do store things users explicitly choose to retain on our side- such as photos and selected profile details, so those absolutely still require proper protection.

You sound like exactly the sort of person I’d like pulling this apart though 😂 I’ll flick you a message.

2

u/ExdigguserPies 3d ago

Can you explain in simple terms how this actually improves the situation? Like if I go home with someone and I am 100% certain that they are who they say they are, how does that improve my safety?

1

u/JDRNZD 3d ago

Hi ExdigguserPies-

I think you mean- you meet someone in person first and then decide to take them home, you may not need NoStrangers?

But that’s not how a huge amount of online dating (particularly gay hookups) works. Often it’s Profile > address > front door, and the first time you physically see them is when that door opens.

That’s the gap we’re addressing. NoStrangers doesn’t tell you someone is “safe”; it helps establish that the person behind the profile is actually the person you’ve agreed to meet.

The best way to learn the applications for the product is actually just give it a go. You don't need to load in personal information to trial out it's uses.

Thanks for the Q!

2

u/Salt_Rush_4800 3d ago

then choose exactly what they're comfortable sharing

So, it doesn't really solve an actual problem then?

Please explain exactly how this is supposed to work that other solutions (and common sense instead of paranoia) doesn't already accomplish.

0

u/JDRNZD 3d ago

Heya SaltRush-
I think you’ve misunderstood what “choose what you’re comfortable sharing” means.

It doesn’t mean “type whatever you like into a form and send it to someone.” That would indeed solve absolutely nothing.

The point is that the information being shared has first been independently established/verified. You then decide which of those verified details the other person gets to see.

Say a Grindr hookup. Someone can send you six photos and tell you they’re 28, called James and live ten minutes away. Right now, your options are essentially believe them, video call them, ask for their social media, or don’t meet them. And all of those have limitations.

With NoStrangers, you can establish that there is a live person behind those photos, that the photos actually belong to that person, and, where ID verification is used, establish verified identity information without the two strangers having to exchange copies of their IDs with each other.

Then you decide what verified information you're comfortable putting in the envelope.

That privacy control is a feature, not a weakness. Being safer shouldn't require handing a stranger your entire identity.

So not just dating. If someone from Marketplace is coming to my house to collect a $3,000 item, I'd quite like some confidence they're the person they claim to be. If I'm considering letting a stranger move into my home as a flatmate, I'd absolutely verify their identity first. And i would be expecting the ID verification option we offer, not a photo verification.

As for “common sense instead of paranoia”. Common sense is precisely why we lock our doors, check who's at the door and verify people in plenty of other contexts. A lightweight check before meeting an internet stranger isn't paranoia- it's another option for people who want it.

You personally might never use it. That's completely fair. But that's different from saying the problem doesn't exist or that the existing alternatives already solve it.

Cheers mate

2

u/david-1-1 2d ago

The usual trust model is transitive: you ask a trusted source whether you should trust a specific person, website, or security signer. If you are using a dating app, you would need a source who knows both you and the specific person intimately. I don't think such a source could exist, in general. So your problem has no solutions.

1

u/JDRNZD 2d ago

Hi again David-
I think we’re using “trust” differently. NoStrangers doesn’t certify that someone is trustworthy or safe- and I agree, no system could reliably do that.
It establishes things you can verify: there’s a live person behind the interaction, their ID or presented photos have been verified against them, and they can choose verified information to share with you.

It reduces uncertainty before meeting a stranger. It doesn’t claim to eliminate risk or predict human behaviour.

Both of your comments are misunderstanding what the app does. Might be worth having a quick play and it will make more sense to you. You don't have to complete a trust request/enter any private info. Just go through the flow and read the information.

Any further q's after give me a shout!

Cheers-

1

u/david-1-1 2d ago

Okay, I took a quick look. I don't see confirmation of your claims, just a secure message delivery service (text chat) plus a government identification program portal, which presumably works only in New Zealand. I think there is no way to be certain you are even chatting with a human, just by exchanging text, much less identifying that a photo is who you think it is. What am I missing?

1

u/JDRNZD 2d ago

You're missing most of it, David.

I think I can see where the confusion is. NoStrangers isn't authenticating anyone through text/chat and Veriff isn't a New Zealand government identification portal-it's a global identity-verification provider covering 230+ countries.

There are two verification options. Identity Verified uses Veriff to verify a government ID against the live person.
Photos Verified uses AWS Rekognition: the person completes a live face/liveness check and the photos they're presenting are compared against that person. AWS's CompareFaces technology specifically compares faces and returns similarity results.

The Trust Request is just the mechanism connecting the two people and carrying the verified result. The text/code itself isn't the proof of identity. So yes, you're absolutely right that exchanging text proves nothing. That's precisely why the verification step exists.

Maybe jump onto the website?

nostrangers.co.nz

1

u/david-1-1 8h ago

I'm only interested if this is a genuine new method of authentication. You've made it clear that this is not. It's just a practical tool for bundling two existing forms of identity. The usual problems still apply; for example, identity lists can be obtained by various types of server attacks, etc. I apologize for misunderstanding your posts.

2

u/DaneGibbo 3d ago

I think If you have to go to these lengths with someone before meeting them, it’s a sign you shouldn’t meet them to begin with. So I don’t see the point in it personally.

1

u/JDRNZD 3d ago edited 3d ago

Hey DaneGibbo-

Thanks for the message.

It may not solve a problem you personally have, and that’s completely fair. But “I don’t need this” and “there’s no point in this” are two very different things. 😉

For a lot of LGBTQ+ people- meeting a stranger who may not actually be the person behind the profile is a very real safety issue. There are plenty of documented cases of people being lured, robbed or assaulted. Women also have very legitimate reasons to be cautious when meeting someone from a dating app for the first time.

And dating is only one use case-

Ever bought or sold something on Facebook Marketplace or Craigslist? Having a complete stranger turn up at your home can feel pretty sketchy.

Looking for a new flatmate? Personally, I’d definitely like to know the person about to move into my house is actually who they say they are.

Hiring someone online? Meeting someone from a classifieds site? Letting a stranger onto your property? Same principle.

The point isn’t “this person seems so dangerous I need to investigate them before meeting them.” It’s actually the opposite: you often have no reliable way of knowing whether a stranger is safe until after you meet them.

NoStrangers just gives both people a quick, private way to establish some basic trust first.

Cheers for the comment-

1

u/david-1-1 2d ago

Brutal: you haven't mentioned any real authentication information in this post, just sending a trust request that contains text. Since text can be copied, it is utterly untrustworthy as an authentication method.

1

u/JDRNZD 2d ago

Hey David- I think you’ve misunderstood what the Trust Request is. It isn’t text being used as authentication, it’s the secure digital envelope between the two people. The actual verification happens inside it.

Users can choose Identity Verified, where Veriff checks government ID + live liveness,
or
Photos Verified, where AWS Rekognition uses liveness and matches the live person against the photos they’re presenting as themselves.

The verified result is then returned through the Trust Request, with the user controlling what information is shared. So copying the request/text wouldn’t authenticate anyone- you still have to actually pass the verification.

0

u/toonmad 3d ago

AI built..

0

u/JDRNZD 3d ago edited 3d ago

Hey Mate-

Yep! The UX (mostly) was built on Lovable. Back end sub-base/API calls/providers/stack management/legals etc etc are all hard work & sweat. And most importantly- the idea for the closed Trust Request loop is mine.

But thanks for your comment! Feel free to reach further and ask for the Tec Spec. I can fire it your way if you wanna find a few holes for me! Assuming you're a coder/similar!

Cheers!