3 ms·
Let's be serious for a moment. A computer that is hacked and running remote access programs poses a MUCH higher risk of account hi-jacking for ebay and paypal p
by anon102010 6y ago
Let's be serious for a moment. A computer that is hacked and running remote access programs poses a MUCH higher risk of account hi-jacking for ebay and paypal purposes than another computer.
Feed that into a system that monitors lots of other inputs, and you start to build improved fraud detection systems. Most of these systems benefit significantly from long tail / long history monitoring - all the other providers of systems in this space try to get beacons onto virtually all the pages you visit, monitor all mouse and other movements you carry out etc.
Why not this pretty simple and straightforward explanation vs something complicated about overpaid consultants? Amazon does $80B of sales or something per year. Each 1% of fraud on this platform is worth $800 million. How overpaid must a consultant be who can knock this down?
I'm curious how someone with crypt in their name would ignore obvious remote access trojan installs as a threat vector?
- crypt1d 6y agoI'm not ignoring anything. I'm simply stating that this is not an effective prevention method. I'm even going to argue that this can potentially _hurt_ whatever fraud system they have in place, as it could create a lot of false-negatives. Once the fraudsters pick up on this they'll change the ports. From then on, this script is useless. At best, the result of the data points created by this script is going to create a temporary drop in fraud, which can be used by the aforementioned 'consultant' to claim (premature) victory. Give it a month or two, and the fraud numbers are going to go back to their previous levels.
- anon102010 6y agoDo you deal with fraud issues. My guess is not. "The fraudsters may adapt" is a complaint with almost all fraud fighting approaches - and yet many even older methods STILL have value even if fraudsters could work around them. Many fraudsters are using scripts and tools they don't even know how to modify but that circulate and are used. In person use has geo checks, so easy to avoid by using cards in a local area - but fraud prevention STILL picks up out of billing zip attempts at use. So you'll be wrong here. And even a 6 month decline in fraud is highly valuable to any of these large scale players.