5 ms·
We're anticipating having to make some changes to our fraud scoring which uses things like location vs. credit card address as signals.
by james_pm 5y ago
We're anticipating having to make some changes to our fraud scoring which uses things like location vs. credit card address as signals.
- avh02 5y agoas someone who lived abroad but had a US based account i wanted to use to buy things with - "clever" moves like this were the bane of my existence. Combine that with a bank that would freak out if you used the account from abroad it was often a multi-day operation to get a transaction to go through (between support calls to bank and merchant) Though i guess a signal vs hard lock/logic.
- wyager 5y agoGood. I’m tired of wasting my time with dumb bullshit like vendors thinking my credit card billing address is “suspicious” somehow.
- grishka 5y agoSo many companies insist I provide them a "billing address", except I don't have one, it's a uniquely North American thing. Filling that form with gibberish usually does the trick for me.
- cr1895 5y ago> it's a uniquely North American thing It’s a thing in Europe as well.
- supertrope 5y agoVendors do that because they’re left holding the bag in chargebacks. Addresses are de facto knowledge based authentication questions in lieu of dynamic credit card codes.
- wyager 5y agoHopefully this results in the elimination of credit cards. Vendors should ideally switch to lighting-based settlement or something.
- ratww 5y agoIsn’t 3d Secure a thing in the US? I have a little app in my phone from my credit card company where I confirm when I am really buying something and it looks more secure than relying on fraud detection.
- supertrope 5y ago3D Secure trains customers to type their bank login into popups! It shifts fraud loss liability onto the customer who is even less prepared to deal with it than the merchant. Only a few merchants tried it like Newegg.com. It flopped because the hit to conversion was more than the fraud prevention. It usually fails open (allows transaction to proceed). Merchant side fraud detection is inherently inferior to the bank doing fraud filtering, but banks don't care. Not their liability not their problem.
- ratww 5y agoIf that happens then it's definitely an issue, but I've had a couple cards with 3D Secure for about 6-7 years and it's always 2FA using an app ("Did you really buy X at vendor Y?") or, before that, with a keychain hardware token. I wonder if there's rules depending on which country. When I worked for a small-time credit card "vendor" we could put pretty much anything we wanted in our iFrame.
- SheinhardtWigCo 5y ago3DS1 isn't because it leads to unacceptable cart abandonment rates, but 3DS2 is designed to address that problem by using SMS or app-based authentication for only high-risk transactions, instead of username and password for every transaction. SCA is therefore likely to become a requirement in the US once it's reached maturity in Europe, as we saw with EMV. Further reading: https://www.jonesday.com/en/insights/2020/12/strong-customer-authentication-in-the-united-states-when-not-if https://www.jonesday.com/en/insights/2020/12/strong-customer...