8 ms·
Interestingly enough I found this subthread from an HN Post earlier today to be very relevant: https://news.ycombinator.com/item?id=10234561 https://news.ycombi
by nchelluri 11y ago
Interestingly enough I found this subthread from an HN Post earlier today to be very relevant: https://news.ycombinator.com/item?id=10234561 https://news.ycombinator.com/item?id=10234561
> Regarding his fraud issue, I found that my website was being used in the same way when I added a credit card payment form. I implemented a system that first does an "Auth". If that passes, then I pass details to MaxMind and get back a response with a "riskScore". If the score is too high, I void the auth and decline the transaction. This has saved me a lot of chargeback fees, though it's still not perfect. I prefer PayPal because a "not authorized" just reverses the transaction; there is no chargeback fee.
- Osiris (HN user)
IMO, there's more worth reading in that subthread. It's an interesting topic, at least to me. I feel sympathy for any merchant that has to go through this kind of pain.
- Osiris 11y agoThis issue is so costly and prevalent that I feel its a huge disservice for companies that offer credit card services to merchants to not either 1) mention this issue and recommend a fraud check service, or 2) include fraud protection in their service. I actually ran into an issue a little while ago in that I allowed my MaxMind account to run out of queries. Not realizing this, I saw a few days of higher than normal sales but just assumed it was a good day. When the first chargeback came through, I immediately noticed the problem, bought more credits, then began to go through each transaction one and a time and noticed a pattern in the email addresses (all two words followed by 3 numbers @hotmail.com) and individually refunded each and every one of them. I still got chargebacks but I was able to dispute them by showing that the transaction had already been refunded. My ideal credit card would be on where the physical card has e-paper on it with a 6-digit PIN that changes periodically, like 2-factor auth, and that PIN could be required for purchases to be authenticated. The new smart-chip cards don't help at all with online purchases, only point of sale. On a side note, I found that nearly all of my fraudulent purchases came from Vietnam to the point that at one time I put in an IPTABLES rule to block the entire country.
- bemmu 11y agoAll of mine seemed to come from Mexico. Either IP being in Mexico or the shipping address being there. Still many orders originating from Mexico seemed like they might be genuine, as the customers had filled in the questionnaire with their favorite animes etc. valid looking answers, so I didn't want to block the entire country. My theory is that there really was some kind of media mention there, which resulted in some real orders but also some fraudster happened to hear about the service that way as well. it seemed possible that I had been mentioned in some local
- lifeisstillgood 11y agoSince pro accounts initially cost £6 for month, it turns out that this is low enough that it won't send red flags to stolen cards That's interesting (scary). What is the minimum transaction that Visa actually gives a monkeys about? And why, if a card is stolen, does not any activity flag up? Edit: more importantly I never even thought Inwoukd need to implement fraud detection - is there a primer on "things you never thought of when selling on line - from VATMOSS to Vampires"?
- EwanToo 11y agoIt's not normally a single transaction that triggers the fraud detection, but a small initial transaction (say <$20) then one that's much larger - the first transaction validates the card works, the second one is the money grab. So if you sell something small, you'll be used to validate newly bought cards before they go off and buy $1000 of something else.
- mootothemax 11y ago>all of my fraudulent purchases came from Vietnam to the point that at one time I put in an IPTABLES rule to block the entire country. I can never work this out; it seems that scammers from different countries (or using hacked servers / proxies?) are attracted to different sites or types of ecommerce sites. For example: - One of my sites has huge fraud from Ukraine and Russia - Another from Indonesia - Another's problem country is Pakistan I typically use https://siftscience.com https://siftscience.com to identify fraud, plus country-level blocks where it makes sense. Damned shame that all the legitimate users from a given country get blocked thanks to the fraudsters!
- bemmu 11y agoOsiris' info was useful. I really also need to put in some fraud detection like that. But there are so many companies providing that service, I'm not sure which one to go with. How involved is it to integrate these? It's not my idea of fun to try look at these transactions manually, so until I get a motivation boost to go through with the integration it'll probably be PayPal-only.
- mootothemax 11y ago>I'm not sure which one to go with. How involved is it to integrate these? I really like https://siftscience.com https://siftscience.com. The important thing is to not over-think things; it's rarely that case that you truly, honestly, really need real-time automated fraud detection. Start with implementing the absolute bare minimum. You'll then receive emails from e.g. Sift when a bad user is identified, and you can manually refund the transaction, cancel the order, and block the user.
- benmmurphy 11y agoI'm thinking about integrating with siftscience. How trustworthy are they? It looks like you need to send them information about your users and give them script access on your page in order to help identify fraudulent transactions. (which is completely reasonable but still requires a lot of trust on our part)
- jasontan 11y agoHi Ben, CEO of Sift Science here. Happy to share what we do to secure and protect your data - jason at siftscience dot com
- blackice 11y agoSomething like a simple proxy / VPN IP detection should be used because I assume most of the "carders" don't use their home IPs. There are decent free solutions online like W I T C H and GetIPIntel.
- WalterBright 11y agoI was using VeriSign for years. Then my site got hit with a "carding" [1] attack. VeriSign was simply not interested in helping with it, the merchant bank I had coupled it with was not interested either. So I cancelled VeriSign and the merchant account, and use paypal and Amazon Payments instead. I did make the rounds of a few banks, all were eager to set me up with a new merchant account. All gave me blank stares when I asked if they had any means of preventing carding attacks or other frauds. [1] A carding attack is when there's an attempt to buy something for $0.00, just to see if it is rejected or not. I was getting one every minute or so. I got charged for every one of those, and so soon had racked up a grand in charges.