21 ms·
How Candy Japan got credit card fraud somewhat under control
- seivan 11y agohttp://d.pr/i/x0JD+ http://d.pr/i/x0JD+ vs http://d.pr/i/16wJh+ http://d.pr/i/16wJh+ Not sure what the rules are, but I thought it might help.
- mikejarema 11y agoSo it appears that a combination of (1) removing instant feedback (not alerting fraudsters as to the success/failure of their charge) and (2) giving a grace period to review and cancel charges has given Candy Japan some breathing room. Though it does seem that this requires a manual step (2) before sending charges through, does anyone have experience using a fraud detection API, like Maxmind's minFraud [1] or any other, in an attempt to avoid having to review each charge? [1] https://www.maxmind.com/en/minfraud-services https://www.maxmind.com/en/minfraud-services
- bemmu 11y agoMy friend runs a similar candy subscription box called https://boxfromjapan.com/ https://boxfromjapan.com/ and reported having a good experience with Signifyd. I might try integrating something like that next.
- fweespee_ch 11y agoThis can be largely automated using something like minFraud, Signify, etc. However, you still need to use the same basic process: Step #1 - No instant feedback Step #2 - Your antifraud SaaS provider / process / whatever Step #3 - Reject anyone who fails step #2 after ~24 hours.
- mrweasel 11y ago>does anyone have experience using a fraud detection API, like Maxmind's minFraud We tried MaxMind, for our use case it was pretty useless. The feature that sort of worked which we considered using was the geo-location stuff. Our idea was to see how close a customer was to where the goods where to be sent. Sadly the countries we operate in are to small, and IP location is to inaccurate. As a test we ran a couple of months worth of fraudulent order data through MaxMind, with a success rate of 100%. The best solutions we found is: - Block cards not issued in the country where you operate. This shield us from poor credit card security in countries like the US. - Enabled 3D Secure. This blocks all the amateurs - Manually call customers ordering for large amounts. Generally speaking it's very difficult to tell the difference between a fraudulent order and a first time customer.
- 77pt77 11y ago> Block cards not issued in the country where you operate Please, don't do this. It's so annoying. > Enabled 3D Secure Yes, this is a really good idea.
- talawahdotnet 11y agoI currently use Maxmind's midfraud service. It is useful for identifying KNOWN fraudulent email addresses and proxy servers but not much else. It is just one of the signals that I currently use as a part of a fairly manual fraud review process. I have evaluated a number of different options and I am about to start using Sift Science[1]. In addition to using standard ip address/email based information they also use social data and machine learning to identify fraud. Their API/data model is the most well thought out and comprehensive one that I have come across and they allow you to back-fill up to 12 months of historical data for free to help improve your detection rates. They also have a console to assist with optional manual review workflows and store integration apis to allow full automation. On top of all that they offer scalable pricing that works for both large and small business at 6c per transaction. Obviously I can't vouch for their results yet, but what I have seen so far looks pretty good. If you have a fraud issue you should at least check them out. [1]https://siftscience.com/ https://siftscience.com/
- joshmn 11y agoI'll say that I like Sift better than MaxMind, but it still doesn't cover a lot of things that it should. I won't go into details, as I'm in the middle of building a platform to solve this issue myself, but as someone who used to be on the other end of credit card fraud, it's really laughable how many things these companies don't see.
- jasontan 11y agoHi Josh, Jason here, CEO of Sift Science. Would love to hear your feedback on what we could do better, whether publicly or privately - jason at siftscience dot com. We want to do better.
- cheeze 11y agoI'm guessing this has been asked before, but why not just use a credit card processor that handles all of that stuff for you. Seems like they are in the business of selling Japanese candy, not preventing CC fraud. Am I being naive here?
- fweespee_ch 11y agoYes. At $DayJob we have a similar process [e.g. Accept any card that passes the checksum, hand out rejections on a 24 hour delay after we've handled our fraud signals and processed the charge with the gateway] The credit card processors aren't particularly interested in handling this for you and you [the merchant] pay the price if you gave the processor stolen card numbers. Services like these: https://www.signifyd.com/pricing/ https://www.signifyd.com/pricing/ [1% per transaction] https://www.maxmind.com/en/minfraud-services https://www.maxmind.com/en/minfraud-services [ $0.005 ] would have no customers if you could get a reliable partner to handle this all for you for free-ish.
- kyle6884 11y agoCompletely agree with fweespee_ch. Major CC processors such as Authorize.net, Braintree, etc. offer fraud protection measures but in our experience they do very little to prevent even a remotely-capable fraudster. Typical features offered are IP Velocity & regional IP (useless when the fraudsters spin up thousands of amazon servers), # of transactions per hour (not too helpful when your business already does hundreds/thousands of transactions a day), CVV and AVS credit-card response codes (ends up blocking more legitimate orders than fakes and the fraudsters typically already have this information anyway), etc.
- bjano 11y agoThere seems to be a huge conflict of interest here: as card processors slap you with an extra chargeback fee for the fraudulent transactions (in addition to the amount they take back anyway) it's difficult to believe that they would work very hard to help you avoid this.
- 3dfan 11y agoIs there no service that does CC processing and fraud detection already? I would think it does not make sense for every ecommerce merchant out there to build their own solution. Bemmu, you say you use PayPal - isn't PayPal also accepting Credit Cards? Don't they do the fraud detection in this case? I would expect them to have a huge advantage. You only see the IPs and other metadata from a few customers. They see millions and should be able to do way better fraud protection.
- bemmu 11y agoYep, PayPal is awesome at this. I originally intended to go on a long tirade about how PayPal had dealt with this, but cut it out as the post was starting to get a bit long. --- Peter Thiel on PayPal: "In mid-2000, we had survived the dot-com crash and we were growing fast, but we faced one huge problem: we were losing upwards of $10 million to credit card fraud every month. Since we were processing hundreds or even thousands of transactions per minute, we couldn't possibly review each one - no human quality control team could work that fast. So we did what any group of engineers would do: we tried to automate a solution. First, Max Levchin assembled an elite team of mathematicians to study the fraudulent transfers in detail. Then we took what we learned and wrote software to automatically identify and cancel bogus transactions in real time. But it quickly became clear that this approach wouldn't work either: after an hour or two, the thieves would catch on and change their tactics. We were dealing with an adaptive enemy, and our software couldn't adapt in response." They ended up going with a hybrid approach where their algorithm would flag suspicious transactions, which would then be manually reviewed.
- michaelbuckbee 11y agoI've heard Max Levchin describe Paypal as a "credit card fraud detection system that also accepts payments".
- bemmu 11y agoAlso this quote from the book Zero to One: 'Max was able to boast, grandiously but truthfully, that he was "the Sherlock Holmes of the Internet Underground"'.
- nowarninglabel 11y agoWe exclusively use PayPal as they kindly cover all of our transaction fees. However, we still experience fraud which creates work for accounting and Customer Service. A rules-based approach has helped, but we've also been playing around with SiftScience[1] and I've seen it do wonders for some sites, so we'll likely be implementing it. The key problem is keeping the false positive rate down, as we don't want to inadvertently block our legitimate users. [1] https://siftscience.com/ https://siftscience.com/
- stcredzero 11y agoIf you suspect an order is fraud, don't go out and say to the criminal "hey, I declined your super suspicious order!". Instead, play dead. Pretend they got you. Tell them "thank you for your order", behaving exactly the same way as if it really was a successful order. The name of the game is to make things cost more for your enemies than they cost for you. Removing instant feedback is key. Instant feedback is great. Delayed feedback is costly. This is in large part why most DRM and anti-cheat failures happened. Companies and developers need to think about the economics of what's going on. It's not the side with the trickiest mechanism that wins. It's the team with economics on their side. (Amateurs: tactics, pros: logistics)
- SilasX 11y agoYeah I was just talking to an employee of a CC fraud prevention company and that was my thought: they proudly talk about how they can identify fraud and refuse the transaction, when my question was, why not just look like you're approving the order and then follow it right to the fraudster? Better to reliably catch the humans behind this and impose stringent legal penalties than allow them to keep guessing without a cost for being wrong.
- fweespee_ch 11y ago> Yeah I was just talking to an employee of a CC fraud prevention company and that was my thought: they proudly talk about how they can identify fraud and refuse the transaction, when my question was, why not just look like you're approving the order and then follow it right to the fraudster? You can get disposable physical addresses as well. It is part of why some companies flag a mailing address I use as a fraudulent order. I primarily use it to avoid handing out my RL address on domains that don't allow whois protection.
- kyle6884 11y agoThis may work nicely for a subscription business where you have 2 weeks to identify problematic orders. But what about everyone else? Should we silently fail on orders where a customer accidentally mistyped their CC#? Imagine all the extra work involved when you could have had them fix it on the spot.
- robertelder 11y agoMy understanding is that Stripe is pretty much the de facto solution to get started with credit card payments on your site, and if you're relatively low volume you can review for fraud and manually reject it yourself. I've set up stripe before, so I have a casual understanding of how it works, but I'm curious what an attacker would be able to do (worst case) if a server I have Stripe payments on gets rooted. Are they only able to charge legitimate customers' cards for the period of time that a payment token is active? Or I suppose they could re-direct the payment page to their own payment page. If they steal the Stripe secret key is there a way they can steal money using it? (other than just bulk testing if they can charge cards)
- hackuser 11y agoEliminating immediate feedback about failed transactions makes things harder for everyone the fraud detection system identifies, both fraudsters and the many false-positives. And the false-positive rates seem very high, IME; it seems like I and everyone I know has encountered that problem multiple times. Imagine that you place a legitimate order and they don't tell you it failed; how do you find out? Days later when the order never arrives? That would result in very angry customers.
- erikpukinskis 11y agoThere's nothing inherently bad about very angry customers. It's more about how you handle them and whether you are continuously looking for ways to decrease them in number. In this case, the idea is these are people who tripped red flags for you, and upon investigation didn't give you any reason to believe they were legitimate orders. If you're really worried, you can contact them and ask.
- Bluestrike2 11y agoI remember building a subscription system back around 2009-10. Very few of the tools available now existed back then, and things were much less efficient. Or at least that what it seems like looking back. The service targeted competitive gamers (teenagers, early 20s) and I've always suspected that we had to deal with a higher incident of attempted fraud than would be the case with other audiences. If I never again have to deal with a situation where some kid 'borrowed' mommy or daddy's credit card, I'll die happy. No amount of fraud detection can prevent that situation.
- ape4 11y agoWhat if a real users mistypes their credit card number... your order was successful.
- devicenull 11y agoYou check the card number via the Luhn algorithm, and tell them about it? That's not giving any data to fraudsters.
- mrweasel 11y agoIf you at any point have access to the customers credit card number, then your doing something horribly wrong. Unless you're the payment processor.
- nanofortnight 11y agoYou can do that client-side, easy.
- ThrustVectoring 11y agoLuhn algorithm can be done client-side - all it needs is the number.
- mrweasel 11y agoLetting a customer enter a credit card and then parsing it on to the credit card processor means that you would need to be some level PCI complainant. You really really don't want to be close enough to the credit card numbers to do something with them, especially client side. Having the credit card field, where you can access it, means that you become a target for people wanting to inject javascript into your site. Perhaps you're safe, but what about all the third party javascript libraries or tracking/remarketing/tracking script most sites have? Sorry, it's a really bad idea. Let you credit card processor deal with the that hassle.
- ape4 11y agoLuhn doesn't catch everything. (It will not detect transposition of the two-digit sequence 09 to 90 (or vice versa) - Wikipedia). But, ok, what about an innocent CCV typo. You need to give real users errors when they make mistakes.
- thaeli 11y agoWhat's the best way to do "no immediate feedback" when you're selling something that is instantly delivered? (Site paywalls, for instance.)
- awesomerobot 11y agoDo paywalls face as much fraud? My understanding is that industries that provide digital goods or services see a much lower rate of fraud because there's little resale value involved (and the cost of stolen/returned goods is much lower).
- GauntletWizard 11y agoHe's not concerned about fraud where he is out goods, he's concerned about fraud where he's being used as a card verification tool. Checking the validity of credit cards is expensive and hard for carders; They need to do so fast and in bulk, but without setting off the fraud detection on the other side and killing the card.
- awesomerobot 11y agoAh ok, that makes sense. A paywall would be perfect for that.
- Guvante 11y agoIt sounds like the biggest problem that OP is talking about is people using his service to validate credit card numbers. They don't particularly care about the candy, they just want to know if a number has been cancelled yet.
- deleted 11y ago[deleted]
- mjevans 11y agoMy initial solution would be a restricted trial that is mandatory and lifts when the scheduled subscription date hits and is successful. The 'trial' period is advertising.
- Osiris 11y agoI have a website that processes a fairly small number of monthly credit card transactions, 1-4 per day. However, it didn't take long for the website to be used as a place for requests, mostly from Vietnam, to check the validity of CC numbers. It cost me a lot of money in chargeback fees. I ended up implementing a system using Braintree to do 1) Request an AUTHORIZATION for the amount 2) If the AUTHORIZATION fails, return the error (sounds like I need to change this part, but how to do it without hurting legitimate users?) 3) Send information, including IP and email address, to minFraud 4) If the minFraud riskScore is >= 20, request a VOID on the authorization request 4b) If the riskScore is low, submit a REQUEST SETTLEMENT on the AUTHORIZATION This has worked extremely well, but a few still slip through the minFraud check. Even though Braintree offers it's own fraud checking, I still feel more comfortable with minFraud. I really wish that processors like Braintree would put more effort into fraud detection. I NEVER have this issue with PayPal transactions. Even if it's fraud, they just reverse the transaction and there's no chargeback fee.
- TylerE 11y agoWhy not just refuse to do business with Vietnam, Nigeria, Russia, and other fraud havens entirely?
- epa 11y agoFor some simple companies, this may be the right answer. However this grows in complexity as your business scales so don't forget about that.
- bduerst 11y agoA simple situational cost/benefit analysis can answer that. If combating CC fraud is leading to negative profits in those countries then cut them. If not, continue the war.
- siberianbear 11y agoI am a native-born American citizen living in Russia. The amount of grief that your solution causes me is significant. I'm a legitimate customer who does nothing fraudulent. However, whole swaths of the internet treat me as if I have leprosy just because my IP address is in Russia.
- landryraccoon 11y agoWhen I worked on an e-commerce website shipping physical goods we would only ship to the customer's billing address for credit card payments. Anyone shipping to a different address needed to call their credit card company to add the address (every credit card company I've dealt with would allow customers to have multiple valid addresses on file), or use a different payment method. We never had big issues with fraud and I don't recall a customer ever complaining about it. I think in 3 years we had 2 chargebacks due to fraud.
- Giorgi 11y agoYou do know that some cards allow any billing address right?
- landryraccoon 10y agoIf it's a source of fraud we never ran into it.
- aandon 11y agoPM from a fraud detection company here. One thing I didn't see mentioned on this thread is Device ID, which is very common on fraud detection platforms. When a user comes to your website or mobile app, you have access to hundreds of signals from their device. Some like IP address are easy to spoof. Others like whether the user has changed their phone alarm from the default settings are often ignored by fraudsters but surprisingly telling signals (fraudsters don't bother to change from default settings). We wrote an article on some interesting findings recently here: https://simility.com/device-recon-results/ https://simility.com/device-recon-results/. A good device ID product can not only tell if the same fraudster is accessing your app repeatedly while pretending to be different users, it can detect risky user profiles when they land on your app. Before they even make a payment.
- adrr 11y agoYou can use Valve's browser fingerprinting library. Its good enough to detect basic guys who are jumping through proxies. Combine that with MaxMind's proxy detection service and its a decent starting block.
- dw23 11y agoInteresting ... If u have a device id running on ur site , how do u tie a 'suspicious user' it flags with the orders made by that user ? I read abit about ur product and it's not clear how a web shop like candy Japan would integrate quick and dirty with this
- aandon 11y agoNormally an order on your back-end is linked to our device ID with a session ID. However our device ID can also accept user-generated data within fields on your website/mobile app. So if your customers enter their email address during your checkout process, that email will be tied to device ID and you can then look up suspicious orders by their email address.
- deusofnull 11y agoJust a thought: have you ever considered that by publishing such red flags for fraud, fraudsters will adopt these "organic" behaviors in order to appear more legitimate? I understand that the idea is to make illicit transactions more difficult and that adopting these "organic" behaviors is more difficult, but automated fraud tools (ie - what most 'script-kiddies' use) also become more sophisticated over time. Regardless, I bet you don't publish ~all~ your fraud detection vectors for that exact reason.
- xiaoma 11y agoI really love how open Candy Japan has been with the business on HN, since the beginning. Thanks!
- Matt3o12_ 11y agoIn the article, PayPal it's often mentioned that PayPal is generally disliked. As an international customer, I prefer PayPal over giving them my credit card details. When entering my CC, there is a big risk that my data gets stolen (is the data truly securely transmitted, stored, and processed?). I know I can request a refund that any time with my bank but that is a big hassle. I have to write them a physical letter, and wait for a couple of days. During that period, my CC is blocked and I they will likely issue me a new credit card (which costs 10€). When paying with PayPal, I can report a fraud online or call them and they have been really quickly in responding (I have once not gotten a product and they were very quick in issuing a refund). Also, I feel way more comfortable using PayPal because I can see that the site I'm entering my information to is actually PayPal, and I have two factor authentication. Before I didn't have a CC, PayPal was the best solution because they would just withdraw the money from my bank account and they merchant would get their money immediately. I can understand why PayPal is not a good choice for sellers (I've heard stories where PayPal blocked merchant accounts for a few months without giving them their money they had on PayPal, and refusing any new transactions). So, can you explain to me why PayPal is a bad/unpopular choice as a customer.
- eps 11y agoKeep in mind that PayPal leaks lots of your personal information to the sellers, including full street address. Merchants don't even need to opt-in to get it, it's all provided by default for all purchases, even when there are no physical goods involved.
- Matt3o12_ 11y agoAnd yet 95% of all my purchases require a billing address, even if they we'll never ever send me a letter. Even better, some even check if the billing address is correct (they send it along with my CC# to my bank and my bank will decide what to do).
- adwf 11y agoIn Europe it's the law that you need to record the billing address (for 10 years) otherwise you can't obey the VAT laws.
- ivthreadp110 11y agoI wrote a similar system for an ecommerce site- attached session data, "remora data", tracked IP's, (in fact trace routed all IP's looking for suspicious proxy flags like going through Ghana), browser meta data- etc etc. I'm proud of how robust it ended up being. Constantly recursively crunching shipping addresses, CC numbers, IPs, all that jazz and accounts- so if someone tried several different cards their account would be flag, which would flag their IP which would then trickle down the system. Of course never letting an attempted scammer know the system was on to them- in fact encourage them to keep using more cards and try different combinations so the flagging system would grow over time. Sure we got some false positives, but drastically cut down on repeat scammers. :) In which case we just encouraged a phone call and solid proof of information for an account override. It was war! Good article!
- j_lev 11y agoThanks for the insights. I've been fighting this fight for over 17 years now. The landscape has changed a lot - mostly for the better IMHO. In particular, issuers are taking more responsibility for checking the validity of the cards but some of them are hopeless and there is still a way to go. Criticise me all you like but I still have a blacklist of countries where I will never send physical goods to (unless they direct deposit the money, for one of my sites). Not sure if it's relevant for "subscription" model businesses but Stripe and a couple of other providers have an option to charge the card immediately or just get authorisation for the amount. The authorisation is only held for seven days, but I have found that this has often been enough for the owner of the card to notice and cancel the authorisation before the charge happens. I haven't checked but this could also solve the "instant feedback" problem for providers that give it as "authorsied" is less conclusive than "charged" for the scammer.
- peterwwillis 11y agoNot sure if the author tried this, but there are many experts on carding around the internet (the most famous being Brian Krebs) who might give advice for free on credit card fraud countermeasures. The simplest way to find them is to google for presentations at hacker conferences about carding, cyber criminals, credit card theft, etc.
- danbolt 11y agoHey bemmu, your presentation last year at Hacker News Kansai was really interesting, and I learned a lot. Thanks for putting the time into following up!
- silliconeheart 11y agothe problem is credit cards. the should be depricated
- Giorgi 11y agoThis article does not solve anything. Only thing I have found working is 3D security request for VISA cards.
- homero 11y agoI use chargebee so much better and cheaper than recurly