24 ms·
The optimal amount of fraud is non-zero
- fijiaarone 4y agoIf your job is fixing broken windows, then supporting vandalism just so you get to keep your job is a pretty asinine philosophy. I can see why this clown is the most famous redditor in the world.
- phoe-krk 4y agoIs this something that could be argued about other sorts of crime as well? In particular, in the ongoing fight against encryption that has been widely commented on HN multiple times, can (or should) one (safely) argue that e.g. the optimal amount of online sex trafficking and child abuse is greater than zero? What would be the consequences of taking such a stance once it inevitably reaches public discourse?
- Thiez 4y agoYou could argue that but as you expect your opponents would quickly paint you as being pro-X. Every decent person would prefer zero child abuse, but few people would support having mandatory police surveillance cameras installed in every room in their house, even if such a panopticon would be proven to reduce significantly child abuse. Us meatbags are irrational like that.
- kurupt213 4y agoGovernments do make that choice through prosecutorial discretion
- peteradio 4y agoIts not a choice of amount to leave out there, its a choice of how much defense to allocate.
- dahart 4y ago> can one argue that the optimal amount of online sex trafficking and child abuse is greater than zero? No, this fraud argument does not apply to child abuse or sex trafficking. The reason is because the fraud argument is talking only about direct financial loss of fraud compared to direct financial loss of enforcement. The fraud argument doesn’t actually work if we’re talking about individuals losing their savings, it only makes sense if you assume the cost of fraud is borne by banks, and that it’s a marginal cost and does not bankrupt anyone. There is no amount of money that makes the damage done by sex trafficking or child abuse okay, and there is no reasonable way to convert the damage done by these crimes into money. To suggest that the optimal amount is non-zero would only be an externalizing of the damage and costs of such crimes, and to essentially reduce our morals to money. And that’s exactly what this very argument does in other contexts; it externalizes non-financial damage, and sometimes financial damage too. This argument is made in other contexts, and it’s sometimes wrong and/or full of assumptions that aren’t true. We could imagine extreme hypothetical situations that might clarify the argument or how to think about it - is it equivalent if 1% of people suffer a 100mm knife wound or 100% of people suffer a 1mm knife wound? The 1% would all die. In the other case, everyone suffers a mild inconvenience they forget about by tomorrow. Despite the equal amount of flesh damage, these are not remotely equivalent, and thus can’t be compared or declared as optimal. The type of damage done matters, and the number of people affected and amount of damage done to individuals matters. Beware arguments that reduce negative outcomes to money. These tend to favor businesses (who are biased to prefer less regulation) and tend to externalize all the indirect costs and the costs to society. This is exactly what has been done with regard to pollution over the last century - it has been successfully argued that the optimal amount of pollution is non-zero, and we’re starting to see the consequences of that and pay costs for decisions made long ago. There was a pretty good paper I read [1] that re-evaluated these arguments for several specific large public works projects in the 50s through 70s, where the post-facto costs and outcome benefits calculations were shown to be different by orders of magnitude compared to when the decisions were being debated. IOW there is good historical precedent-based reason not to trust someone who claims the damage will be minimal or equivalent to the case where we put some effort into minimizing it. [1] https://scholarship.law.georgetown.edu/cgi/viewcontent.cgi?article=1326&context=facpub https://scholarship.law.georgetown.edu/cgi/viewcontent.cgi?a...
- phoe-krk 4y agoThanks for the in-depth reply - that's exactly the sort of fuel for the mind that I hoped for when posing my questions.
- souldeux 4y agoI feel like this starts with an agreeable premise. Some fraud is egregious, costly, and/or easy to detect. These low-hanging or high-impact cases are most worth pursuing. At some point you reach diminishing returns, where the amount of time / effort / capital you're putting in to eliminating fraud outstrips the losses from the fraud itself. I don't know that I agree with the ethical conclusion that the optimal amount of fraud is therefore non-zero. The leap from "anti-fraud efforts are expensive" to these sentences in the final paragraph was not, in my opinion, convincingly made here: >We should, as a society, accept non-zero amounts of benefits fraud. We should accept non-zero amounts of cheating on taxes.
- jon-wood 4y agoI don’t know if that statement is backed by the article, which I will admit to not having read, but in general I agree. Completely eradicating benefit fraud will necessarily increase the burden on legitimate claimants to prove that they are in fact legitimate. Doing that is going to place enough burden on some people who should otherwise be able to claim that it results in them not doing so, or failing to do so because they were unable to provide the required evidence. I’d much rather see a few people who didn’t need benefits manage to claim them than see people who do need them be left without. The first option costs tax payers a bit more money. The second results in people’s lives being made significantly worse, and in some cases in deaths.
- tialaramex 4y agoAlso, not means testing universal benefits means everybody appreciates them as just something their society does, so that reduces stigma for the beneficiaries and increases pride in your society. "We ensure children in this country have nutritious food" not "Why are my taxes going to feed this 10 year old whose mother has a full time job". I grew up in an area where many parents could afford (maybe if they budget carefully, maybe just anyway) to privately educate a child. But they mostly didn't, because the government funded schools were pretty good. In fact, as children it was actually a minor stigma to be privately educated, because if your parents are spending a lot of money on the fancy school, either they don't know how to spend their cash (so they're stupid) or you're really stupid and they sent you to that school in the hope of making up for it. It was seen as like easy mode. Smart kids don't go to private school, why would they waste the money?
- mooreds 4y agoHere's the Planet Money episode: https://www.npr.org/2022/08/26/1119606931/wake-up-and-smell-the-fraud https://www.npr.org/2022/08/26/1119606931/wake-up-and-smell-... I really enjoyed the whole thing.
- Kwantuum 4y agoThat's a lot of words to say "to make fraud harder you have to make buying from you harder, the optimal amount of fraud is the amount of fraud you get when any additional measure you could take against fraud would lower your revenue more from lost business than it would lower your costs from people committing less fraud"
- dqpb 4y agoThe title is wrong. The argument is actually that the optimal amount of fraud prevention is non-100-percent.
- vishnugupta 4y agoExactly. The optimum amount of fraud is really zero. But in order to achieve last 0.00001% you may end up screwing up experience for about 99% of your customers by asking them to 10-factor auth and what not.
- swid 4y agoI guess this applies to all crimes, even major ones likes murder and child abuse. We can monitor everyone all the time, or make sacrifices to live in a more free society. If you think the optimal amount of crime is greater than zero, at some point we are clearly using different applications of the word optimal. One person is talking about the level under the optimal “solution”, while the other is talking about one constraint that still must be balanced against other constraints. The optimal amount of fraud spending is zero, but then we’d be left with a ton of fraud.
- RcouF1uZ4gsC 4y agoYou could also use this reasoning to say that the optimal number of rapes is greater than zero. I would disagree with the world “optimal”. The optimal number of fraud and rapes is both zero, but unfortunately we don’t really have the realistic ability to achieve that.
- e63f67dd-065b 4y agoObviously the optimal number of rapes is 0, but the optimal amount of rapes we should try to prevent is not infinite, and thus the optimal amount of rapes we accept as a consequence of the above policy is non-zero. It's really a simple cost-benefit calculation; the cost of preventing the last 0.1% rape on earth is surveillance cameras in every home and egregious violations of privacy, obviously the cost of such a scheme is probably not worth it. The simple observation is that there are tradeoffs: in exchange of preventing <bad thing>, we have to give up <good thing>, at some sort non-linear curve. The cost of rape prevention goes up with each rape prevented, there reaches a point where the cost is no longer worth it and we should call it a day. People can (and do) argue all day about the point where the marginal cost of rape prevention is too great, but I'm fairly certain most would agree that it's not infinite.
- vishnugupta 4y agoThis is an extremely long-winded article/blog to say the following > the policy choices available to them impact the user experience of fraudsters and legitimate users alike. They want to choose policies which balance the tradeoff of lowering fraud against the ease for legitimate users to transact. You encounter well known tension pattern several places. For instance, in safety critical systems there's a tension between safety and progress. Or take IT-sec industry; tension between usability and being secure.
- righttoolforjob 4y agoIt's like a braindump of a thought-train trying to reach a simple conclusion rather than just stating the simple conclusion itself.
- datalopers 4y agopatio11 is good at many things, brevity is not one.
- cratermoon 4y agoI work in IT/AppSec, and this came to mind immediately. Implementing perfect security would be "don't connect to the internet and don't let anyone use the computer". Clearly not an option, so my job is to analyze the cost and risks against the benefits and help choose a path of balance. A specific example: we can only heuristically detect the difference between legitimate and malicious calls to the public endpoints. Is that spike in traffic trying to DDOS us, or is it close to Black Friday so customers are in go-go mode? Setting the rate limits somewhere meaningful is a tradeoff.
- LilBytes 4y agoGreat analogy re. appsec. Risk is never zero and achieving it prevents everything.
- deleted 4y ago[deleted]
- pwdisswordfish9 4y agoIs this just a blog-post-long Umeshism?
- jrootabega 4y agoWhen I worked Starbucks retail, we were subject to a "just say yes" policy. So when a couple came in and said they had forgotten some item, or never received it earlier in the day, I gave one to them without hesitation. It helped that I also recognized them as repeat customers. A co-worker said "you just got scammed" with disapproval. And I explained that I probably did, but we were required to do it even if we didn't want to. Otherwise we risked pissing off honest customers. Or maybe it just made more sense to spend the time serving the next 2 customers faster instead of being suspicious with 1 customer. Later on, though, I remember pissing one off when he had to wait in line behind people buying drinks and he declared he would not be buying the $300 espresso machine he had come in to buy. I wonder if my actions resulted in a net gain or loss to the store...
- zach_garwood 4y agoWhen I worked retail, I would give customers whatever they asked for because 1) it's not my stuff, 2) it belonged to a soulless corporation that did not need it, 3) I am not paid enough to be a store's loss prevention agent.
- jrootabega 4y agoBut Starbucks had this explicit corporate policy anyway, which lines up with the article and its principles. And it takes a while to become that realistically cynical about retail work. We were actually treated pretty well, had mostly friendly customers, and got along with management. At least at the time.
- kevinventullo 4y agoI’m fairly brand-loyal to Starbucks precisely because of their relaxed attitude towards customers. I remember a few times in grad school going there to work for a few hours, using their wifi, and leaving without buying a single item. I never intended to do so, I just got lost in my work. I don’t think the baristas even noticed.
- hoseja 4y ago
- righttoolforjob 4y agoThe conclusion/title talks about fraud without any context, which is the misleading thing here. What he means to say is that we have to accept to not fight some fraud because it would be too expensive. The most expensive option perhaps being to not run a business at all, eliminating both fraud and proper sales.
- deleted 4y ago[deleted]
- e63f67dd-065b 4y agoThere's 2 different things going on here: - The optimal amount of fraud in society is 0 - The optimal amount of fraud a business/industry should accept is non-zero The simple observation that the cost to prevent each marginal fraud attempt increases; the last 0.1% of fraud costs way too much to prevent compared to the first 99%. Obviously society would be better off if fraud didn't exist, but since it does the effort expended is only worth it up until when the marginal cost of prevention exceeds an acceptable threshold (when it starts to lose you money). The optimal amount of fraud is still 0, but the optimal amount of fraud prevention lies somewhere on the margin. This is why important transactions like banking have KYC checks, and buying a pair of sneakers don't.
- permo-w 4y agothis explains things significantly better than the article, which seems to be little more than dragging out a surprising-sounding headline with a pretty obvious concept
- patio11 4y agoThe reason I went to the trouble of writing it was that many, many people in both business and the finance industry do not agree it is obvious and a good portion do not agree it is true, and they take actions consistent with those beliefs, which harm themselves and others.
- ilaksh 4y ago
- jbuhbjlnjbn 4y agoTo be more specific, the article mimics the topic of a counter-intuitive "surprising" truth (like, for example the goat problem; or flaws in human cognition), while letting the reader down by making an obvious, easy to understand truth unnecessarily complicated. "Clickbait light"
- 4y ago
- jacobkg 4y agoThis is the thesis of the excellent book on financial fraud “Lying for Money”
- TheAceOfHearts 4y agoPotentially controversial take: this general idea also applies to other areas such as elections. Any sufficiently large election will have to contend with fraud and human error, but this is acceptable as long as the numbers aren't large enough to change the outcome. If you carefully scrutinize any large election you can almost certainly find at least one example of fraud. However, isolated cases of fraud or human error are not evidence of widescale election rigging.
- cratermoon 4y agoThis is what happens when enforcement is both overzealous and uneven: https://www.texastribune.org/2022/05/11/crystal-mason-illegal-voting-texas/ https://www.texastribune.org/2022/05/11/crystal-mason-illega...
- Vecr 4y agoA lot of the elections in the US in the last 25 years have been pretty close, that's the problem. I guess if they were less close or had some sort of proportional system, it might be less of a problem.
- tgflynn 4y agoIf it's the merchants who carry the burden of credit card fraud why is it that almost all fraud prevention efforts seem to be done by banks/card issuers rather than by merchants ? Except for a small number of cases involving pre-paid cards, I have never seen a merchant refuse to accept a valid credit card payment for an online purchase. I have however encountered and heard of cases of banks declining transactions they considered possibly fraudulent.
- jameshart 4y agoBecause the card services are in the business of selling their service to merchants in exchange for a fee, and they have competition in that space. Merchants will (in theory) refuse to work with - or pay as much to - a card service which does insufficient work to prevent fraud.
- tgflynn 4y agoThat explanation doesn't make sense because the fraud prevention/transaction denials are being done by the card holders bank, not by the merchant or payment processor and merchants don't get to decide what issuing banks they will be doing business with. For the most part they either have to accept all Visa cards or none (except maybe for some very broad categories like country of origin or pre-paid vs. non pre-paid).
- sgjohnson 4y agoI personally can't stand PSD2[0]. It has completely ruined the online shopping experience in the EU (for me at least). I loved the way American Express implemented it. They sent you a one-time passcode on your first purchase with the merchant, and then you could also choose for them to not bother you with any further purchases from the same merchant. I had this enabled by default, it made the experience a million times more enjoyable. Unfortunately not everyone took AmEx, and I no longer live in UK (or a country where AmEx has presence for that matter), and the way banks in my current country of residence have implemented it is absolutely abysmal. 1. The billing address must be a match 100% of the time, which is painful in situations where you can't specify separate billing and shipping addresses and you want the item shipped to a different address (could be 3 for me) 2. Mandatory 2FA on every transaction, depends on the exact implementation, but typically you must wait for a notification on your phone, and then type in a PIN. In some implementations you have to scan a QR code, and then type in the said PIN. Sometimes the solution they use for this is down. 3. If anything is wrong at all (billing address/mistyped CVV/whatever), the transaction just gets refused at the end of this loop. Was it something you did wrong? Is some system down? Let's try again. And sometimes this even messes up recurring subscriptions. My Microsoft 365 Business sub that's billed monthly on a credit card GETS REJECTED EVERY TIME UNTIL I MANUALLY GO THROUGH THIS STUPID PROCESS. It has made paying for things online a chore. I couldn't care one bit about all the fraud this presents, because I was never liable for it in the first place. That decision was previously up to the merchants (who could have implemented all of this if they wanted to). Now it's forced on everyone. [0] https://www.bbva.com/en/everything-need-know-psd2/ https://www.bbva.com/en/everything-need-know-psd2/
- no_identd 4y agotbf that's more an issue with incompetent software devs and more importantly (lest someone accuses me of shifting the blame on devs like a clown would) horrible business product owners. My hope is that Biden's executive order on SBOMs and whatever thing like it which the EU probably has in the works will (unfortunately only slowly) shift the way in which the way business treats software development affects software development culture. (SBOMs may sound completely tangential to this, but in the long run they have a pretty important role to play here.)
- 4y ago
- woleium 4y agoThere was a study done on a tribe of wild monkeys where mutual grooming to remove ticks/fleas/lice happened. Some monkeys 'cheated' and didn't pay forwards the grooming they received. The study concluded that as long as cheaters were less than 5% of the population then mutual grooming continued. when the number of cheats exceeded 5% the system broke down and no mutual grooming happened for some time. It seems that a society can bear a certain amount of cheating before the system breaks down, a 'tipping point' of sorts. As long as we keep the cheating below the tipping point, the game continues, which is after all the most important aspect, I think.
- sgjohnson 4y agoThere surely is a game theory model for this.
- rendall 4y agoI'm surprised the grooming monkeys didn't retaliate by refusing to groom the shirkers.
- mod 4y agoMaybe they didn't know. It seems to me like it's not "you scratch mine, I'll scratch yours" but more like "we all scratch each others." Like the whole troop owes one groom per day. But nobody can pinpoint who was the shirker.
- unmole 4y agoFrom the title, I thought it was a reference to the book Lying for Money by Dan Davis. Anyways, the book is an brilliant exploration of this premise and also makes the case for why trust is necessary.
- golemotron 4y agoI thought the article was going to go in another equally compelling direction. If there is no fraud, measures to prevent it become lax because they are unnecessary costs. With no measures in place, fraud comes back because there is no cost to the fraudster.
- Michelangelo11 4y agoWhat an extremely, needlessly elaborate way of saying "security vs. convenience is a tradeoff." Indeed it is, and that's not a particularly novel insight.
- ygjb 4y ago"security vs. convenience is a tradeoff" is an extremely glib and meaningless aphorism that is instinctively innate to almost every living organism. The statement obliterates the nuance of which tradeoffs need to be made and the cost and impact of those tradeoffs from an economic and social perspective that are foundational to being able to reason about risk.
- Michelangelo11 4y agoI wouldn't put it that way, but I would agree with anyone saying that statement omits a lot of information. Sure, it does, and it's pretty much the most general and abstract possible way of saying that. My beef with the article is that, despite its truly gargantuan word count, it hasn't added any new information on top of that statement. Once you know the thesis of the article is "The optimal amount of fraud is non-zero because security is a tradeoff and you want users to have convenience," everything in the article is pretty predictable. I would have liked to see, say, some nuts-and-bolts discussion od fraud handling in some particular industry -- that would be novel and interesting to me.
- JasonFruit 4y agoIt sounds more morally acceptable to say, "The optimum level of anti-fraud enforcement does not eliminate all fraud." It's not that there's a nonzero amount of fraud that is optimal — all fraud is bad — but rather that the return on efforts to eliminate the last bit of fraud is negative.
- no_identd 4y agoI wouldn't even go as far as saying "level of anti-fraud enforcement", because "anti-fraud enforcement" ain't exactly formally well defined
- JasonFruit 4y agoWell, I needed some noun. Any recommendations?
- solveit 4y agoThe optimal number of terms to "formally well define" is pretty damn close to zero in an HN comment. Ignore that guy.
- NicholasN 4y agoUnfortunately this is mostly an American issue. CC fraud in Europe is minimal because cards have an embedded PIN required for each transaction. In addition, when purchasing online, an instant pop-up on your mobile phone asks you to approve or decline the transaction within 2 minutes. Contactless transactions under $25 do not require PIN or pop-up verification. These options are considered inconvenient for American consumers so we eat the fraud and sign receipts like is 1989 :-)
- hedora 4y agoI'd expect fraud to rise in Europe soon, since the pin part of that protocol can be bypassed: https://www.zdnet.com/article/chip-and-pin-is-broken-say-researchers/ https://www.zdnet.com/article/chip-and-pin-is-broken-say-res... The mobile popup is a reasonable mitigation though; it seems likely to limit fraud to small purchases, or encourage sim swapping, etc.
- deleted 4y ago[deleted]
- hedora 4y agoThis sort of thinking has been prevalent in the payments industry for a long time, and I find it infuriating. The article is specifically limiting its discussion to situations where a payment credential is stolen. Those cases cost $10-20B per year. This is HN, so most people here can figure out how to secure payment credentials, especially given the assumption that each credit card contains a tamper resistant computer with durable storage (as they currently do). Instead of ending credential theft (at least in cases that don't involve violence/coercion), the payment networks pass the cost on to vendors, then advertise fraud protection as a feature to card holders. This only works because the payment processors' monopoly prevents the merchants from fixing the underlying security issue. So, the payment networks charge the merchants a large percentage of sales (imagine what your local government could implement if it increased sales taxes by 3-5%!) to supposedly pay for fraud protection. This is exactly like a classic protection racket, except that the thugs that smash up the business don't actually work for the credit card companies. (I do agree with the premise that driving crime to zero is usually not worth the cost, but that's just "Innocent until proven guilty", and not the subject of the article.)
- supertrope 4y agoMerchants are even more lax about card fraud than banks. The National Retail Federation complained about the cost of upgrading to chip readers. They asked the government to force banks to eliminate PCI DSS which would make it even easier to commit credit card fraud. PCI DSS is compliance not security but without it retailers would literally do nothing. Some retailers tried to get customers to switch to QR code payments linked directly to your bank account. One of these payment apps CurrentC was immediately breached.
- hedora 4y agoSmart cards were also breached before the US switched to them. I'd object to paying for PCI DSS if I were them, to be honest. The idea that every merchant (or credit card reader) even has access to credentials is ludicrous. The currentc was of email lists, not the payment flow. It's embarrassing, but still a better track record than the existing payment processors (which probably suffered 10,000s of payment flow breaches as I typed this.)
- aaron695 4y ago
- antman 4y agoEspecially if the burden of proof of fraud falls mostly on the consumer. This is how it works, we don't know the actual ratio of fraudulent vs ok cases so we compare accross institutions. If one institution is an outlier than arbitrarily changes the acceptance threshold pushing the cost to the grieving consumer. If on the other hand the cost of misidentifying a case fell on the institution then they would simply accept only personally identified payments e.g. sms or other 2fa at virtually no cost for them and effectively zeroing fraud In some places with more modern banking, this is pretty common
- mchusma 4y agoI think a more fascinating look at this is how the difference between "legitimized fraud" versus "illegitimate fraud". Basically, for most businesses the amount of "friendly fraud" which means customers disputing charges because they changed their mind or didn't want to talk to the company or whatever is 10x the amount of fraud from stolen charges. (Visa estimates this as 3x but my experience is different). Civil asset forfeiture is the government seizing property without trial, and it is slightly more than theft each year. So between these things, it seems pretty easy to reduce fraud by 75% without much additional friction.
- unicornporn 4y agoReminds me of Marx and his theories on the productivity of crime. The criminal moreover produces the whole of the police and of criminal justice, constables, judges, hangmen, juries, etc.; and all these different lines of business, which form equally many categories of the social division of labour, develop different capacities of the human spirit, create new needs and new ways of satisfying them. Torture alone has given rise to the most ingenious mechanical inventions, and employed many honourable craftsmen in the production of its instruments.[1] [1] https://marxengels.public-archive.net/en/ME1920en.html https://marxengels.public-archive.net/en/ME1920en.html
- robocat 4y agoThat is the broken window fallacy (https://en.m.wikipedia.org/wiki/Parable_of_the_broken_window https://en.m.wikipedia.org/wiki/Parable_of_the_broken_window) which was written in 1850, and Marx wrote the document you linked to in 1862 & 1863. Although I find Marx so impenetrable to read that I can’t even tell what his opinion or theory actually is. I would guess Marx read it, but he doesn’t respond to it, perhaps because in that linked document Marx says “For which reason all vulgar economists—like Bastiat…”. I also wonder what defines an economist as vulgar? Fraud is waste. Businesses optimise for profit, and that optimisation often leads to some level of waste. No process is perfect.
- jp57 4y agoI most of this thesis can be summarized with a few points: (1) A perfect ROC (100% AUC) on fraud detection is impossible, (2) false positives have costs in both lost revenue and customer insults, and (3) the operating point with 100% fraud capture has an unacceptable false positive cost.
- ljw1001 4y agoCouldn’t they just write the title as “businesses shouldn’t try to completely eliminate fraud” instead of trying to inflate their argument with this pseudo-academic bullshit? Seriously, “non-zero”? Is the “optimal” amount of fraud sometimes negative?
- sethev 4y agoThis is similar to the argument that you shouldn't set a service-level objective of 100% availability. It's not achievable and people who claim that's the goal don't act as if it is - so it's better to talk about what amount of downtime is acceptable given the cost.
- GnarfGnarf 4y agoTL;DR: If your fraud-prevention measures are too stringent, you will alienate your honest customers. Relax just enough so that the losses to fraud are less than what business you would lose if you were any more strict.
- LorenPechtel 4y agoTrue, but we don't always get the balance right. Take, for example, many sites asking for the CVV code when using a saved card. In many cases, why?? If I supplied the CVV once and I haven't changed anything since what's the chance a subsequent order is fraud? There's also the problem that some anti-fraud measures would have to be implemented by the credit card company but they're not the ones that eats the cost. I could see a market for a credit card with better terms but where you must approve every transaction with an app on your phone--but how do you make that work in the current marketplace? I have a credit card that supports virtual numbers--but it's a pain to use. Their benefit, but a hassle for me.
- velavar 4y ago> True, but we don't always get the balance right. Agreed :) > Take, for example, many sites asking for the CVV code when using a saved card. In many cases, why?? If I supplied the CVV once and I haven't changed anything since what's the chance a subsequent order is fraud? As a fraud risk manager, I've seen this scenario way too often: Say you have your card saved on a merchant website - fraudsters can often compromise your login on said merchant site and go on a spending spree with all your saved cards (unless you ask for a CVV from time to time, that is).
- LorenPechtel 4y agoSpending spree on what? What do they gain? You ask for the CVV again if anything changes about the delivery.
- sbierwagen 4y ago>I have a credit card that supports virtual numbers--but it's a pain to use. I just got an email from Capital One pushing me to link my card with Google Checkout because it would use a virtual card number for each transaction.
- paulcole 4y ago> This is counterintuitive and sounds like it is trying a bit too hard to be clever. We can wrap up the unintentional HN slogan contest right now.
- robbomacrae 4y agoThis whole article is one giant time sapping piece of click bait. The author makes the unexpected claim that businesses want a non zero amount of fraud. And so as a reader you are tempted to read on because you haven't heard this before. But essentially the argument is that fraud is needed as an unavoidable byproduct of allowing trust/credit in the system to facilitate transactions. However, if businesses could have the trust without the fraud of course they would. I wouldn't be so upset if the author had been more upfront about what this was about. I'm sure there are plenty of people out there who are learning about the fraud and trust/credit relationship for the first time. Just don't try and spin this in a way that it isn't.
- koheripbal 4y agoThere is an interesting thought experiment you can do. Imagine a world with 100% honest, rule-abiding people. What are the consequences of such a world? The initial things you realize are, no keys, no locks, no gates, no passwords. ...but it gets even more profound the more you think about it. No police, no military, no cashiers, no ticket collectors, no bouncers, no bartenders (for beer/wine), no security guards, no prisons, no weapons manufacturing or sales, no security cameras or systems, no cybersecurity professionals or monitoring software, no criminal judicial system, no financial enforcement agencies... ...and how many industries would function far more cheaply such as insurance, unemployment, credit cards, and healthcare, due to no fraud? It's actually staggering how much of society is structured purely around a lack of trust. It's easy to imagine that security is responsible for a huge portion or all human GDP/budgets - maybe 50%? ...and what percentage of the population is really responsible for causing this? It is 1%? 5? Or maybe it's much more? Maybe most of us are not criminals because of the enforcement? If we could program in obedience in people - what leaps and bounds we could achieve! But more realistically, there is an equilibrium that exists between dishonest behavior and efficiency. The more common dishonest people are, the more expensive the entire system becomes. ...and it's not at all linear. A change from 0.1% dishonest behavior and 1% dishonest behavior probably results in an outlandishly more complex security setup.
- akira2501 4y ago
- tomjen3 4y agoI think is an important point, but it misses things like verifying your transaction with your bank in an-easy-to-do-hard-to-fake-way. Like if you were sent to your mobile bank app after completing a purchase and had to FaceId verify that it was you, then fraud rates would essentially be zero. Yes such a system is annoying, I know because we have something kinda similar here in Europe, but because all the merchants are using it, I have no choice but to go to a retailer who doesn't use the system (I probably would if I could, because I tend to use my computer to do things).
- stevebmark 4y agoI agree with the other commenters. This is uniquely terrible writing.
- tomxor 4y agoIt's actually pretty simple and intuitive if you put the reason up front, article seems needlessly long: > the policy choices available to them impact the user experience of fraudsters and legitimate users alike. They want to choose policies which balance the tradeoff What I don't get is how policy makers can appreciate such nuances and then not see how attempting to ban encryption could possibly break modern society... different policy makers I have to assume.
- thayne 4y ago> overwhelmingly businesses simply absorb fraud costs in the same way that they absorb their office rent, staff salaries, and marketing expenses. I didn't realize that is who usually pays for fraud. I see two problems with this arrangement: 1. The credit card companies, who in some ways are probably in a better position to prevent fraud, are less incentivised to prevent fraud, because they aren't the ones paying for it. For example they could make credit credentials more difficult to steal, by making it so the raw credentials never go directly to online businesses, either by using asymmetric cryptography rather than a number or using an oauth style flow with the credit website in order to complete a transaction. But the credit company would bear the bulk of that cost and it would primarily benefit retailers. 2. Consumers that pay using a method with less fraud risk, such as cash, still have to pay a higher price to cover the cost of absorbing the fraud cost. On the other hand it does allow businesses to self select how much fraud they are willing to accept.
- Anderkent 4y agore: 1; since payments processors compete for business, ones that can convincingly claim to reduce fraud rate can charge higher fees of the merchants
- oli5679 4y agoThere is a concept in microeconomics called the Lerner equation. A monopolist maximises profits at the price where gross margin % is equal to -1/ price elasticity of demand. The intuition behind this is their uplift in sales from a small price cut must equal the revenue they lose on all existing items, and their costs of producing the extra items. So if they have a gross margin of 50%, they need price elasticity of demand to be -2, since a 1% price cut will sell 2% more, raising revenue by 1% and costs by 1%. The same applies for blocking fraudulent customers, you want your assessed likelihood of fraud to be higher than your gross margin. If I think you have a 25% chance of being fraudster, and I make a 25% margin, then selling to 4 customers I will make 25% 3 times, and lose 75% one time. If you have more complicated factors like cost of processing chargeback, different interventions like 3DS/manual review, then the threshold is different, but the overall probabilistic framework and calculating breakeven thresholds can still be used. https://en.wikipedia.org/wiki/Lerner_index https://en.wikipedia.org/wiki/Lerner_index
- velavar 4y agoI've spent most of the last decade working in fraud risk management and I love the message that this article conveys. It's great to see someone saying the exact thing I've innately understood but couldn't put into words :) This is something I now ask when I try out for jobs in Fraud teams. If my hiring manager expects me to bring fraud down to zero, I immediately know that this work relationship may not work because we would be on completely different pages on how some fraud losses are the necessary cost of running a business.
- hamzareh 4y agohttps://www.youtube.com/ https://www.youtube.com/
- v8xi 4y agothank you
- v8xi 4y agoHeard an ad for a cybersecurity company yesterday and this same thought crossed my mind - how much business (and expertise) is generated to prevent cyber crime? Since the capital companies spend on preventing fraud likely far outweighs what the criminals actually earn, it could easily stand the cyber crime is a net positive for society given the job creation and technical know-how needed to fill those jobs.
- edbaskerville 4y agoThe literature on the evolution of cooperation, focused around computational thought experiments with iterated prisoner's dilemma, seems relevant here, e.g., https://en.wikipedia.org/wiki/The_Evolution_of_Cooperation https://en.wikipedia.org/wiki/The_Evolution_of_Cooperation If you allow a population of individuals repeatedly playing prisoner's dilemma against each other to evolve their own strategies, you end up with a large percentage of the population cooperating with each other by default, but punishing cheaters after they are observed cheating. But a small percentage of cheaters will always persist, because as the number of cheaters goes down, the number of naive cooperators will go up, thus making it more advantageous to cheat. In evolutionary jargon, cheating behavior undergoes "negative frequency-dependent selection". And you end up with a low, but nonzero, equilibrium frequency of cheaters. This outcome here depends on the order of rewards/costs: the best outcome comes from cheating on a cooperator; next best is cooperating with a cooperator; then cooperating with a cheater; and worst is two cheaters cheating on each other. It's a caricature, but the evolutionary dynamics seem to map pretty well to the kind of examples people are bringing up here in the comments. (The actual "prisoner's dilemma" is rather a confusing story to use, because it's about criminals trying to decide whether to cooperate with each other or betray each other to avoid jail time. So you end up talking about the evolution of cooperation among a population of criminals.)
- jstummbillig 4y ago> The reason for this is that Directors of Fraud are aware that the policy choices available to them impact the user experience of fraudsters and legitimate users alike. I think herein lies the crux: All things interact, and if you think they don't you are just not aware of how. The game is identifying and moving the cogs that a) are either most important and isolated to get you where you want most efficiently or b) interact favorably in concert. You win relatively by understanding this better than others. You win absolutely by seeing or creating an opportunity to implement a brand new cog.
- hyperman1 4y agoI'm comparing the US credit card system with the chip+pin system common in my country. * As you need both the card and the code, and as cards are almost impossible to clone, card fraud and identity theft are almost nonexistent. * Plenty of online shops allow me to buy something without creating an account or providing a billing address. * As the whole thing runs on debet instead of credit, nobody cares about credit scores. * A common complaint from merchants is that the system is expensive. My paper merchant recently grumbled he paid around €4000/year. I don't know if this is normal or how much the credit card system costs for a merchant, but substracting these amounts would provide an upper bound to the preferrable amount of fraud. So while kalzumeus might be right, I believe the system he describes/is used to allows a lot more fraud than required.
- Animats 4y agoPapers, please. Some banks used to take a thumbprint when you cashed a check in person. Very few do that now. When they did it, it was more symbolic than useful, because they didn't have a useful checking system. Today, if banks took fingerprints, they'd find out more than they wanted to know, because immediate lookup is possible. It's not their job to filter the entire population for warrants and illegal aliens. In-person identification is getting really good. Here's HIKvision's new ID unit.[1] Face recognition, iris recognition, fingerprint recognition, and RFID card recognition in one convenient iPad-sized unit. Iris recognition now works at 70cm range, so it can be used routinely. In China, there is no right to be anonymous. Worth noting: credit card companies absorbing losses varies by country. The US is pro-consumer on credit card fraud, but not on debit card fraud. This differs by country. [1] https://www.youtube.com/watch?v=I29_WWuntxs https://www.youtube.com/watch?v=I29_WWuntxs
- pigbearpig 4y agoDo people who write these things really think these are novel concepts? The amount of arrogance and delusion required to state the obvious is hard to comprehend.
- entropicgravity 4y agoUnder this regime I would accept less than zero fraud.
- deleted 4y ago[deleted]
- LBJsPNS 4y agoTTBOMK, there is not and has never been a system built by humans that other humans haven't been able to take advantage of for their own devices. It's more an issue of minimizing it and punishing it when we find it.
- dahart 4y agoThis argument is a naïve cost-benefit analysis, which is already a red flag, but on top of that it claims the damage is done primarily to business that can afford it, ignoring the fact that a non-trivial amount of fraud affects individuals. > In the overwhelming majority of cases, that is where the waterfall ends. While insurance is available (both specialized chargeback insurance and general business insurance), overwhelmingly businesses simply absorb fraud costs in the same way that they absorb their office rent, staff salaries, and marketing expenses. That $10 to $20 billion number we threw around earlier? This is what happens to it, in the ordinary course of business. This claim of “overwhelming majority” being businesses and being a marginal insurance-covered cost does not square with the fact that millions of individual are losing billions of dollars to fraud and suffering very negative consequences. “In 2017, an estimated 3.0 million persons (1.25% of all persons age 18 or older) reported that they were victims of personal financial fraud during the prior 12 months. […] About 14% of financial fraud victims reported the incident to police. About three-quarters of financial fraud victims reported the incident to their family and friends (77%), two-fifths reported the incident to a company’s customer service (42%), and one-third reported the incident to their bank, credit card company, or other payment provider (31%). More than half of financial fraud victims said they experienced socioemotional problems as a consequence of the incident (53%). Financial fraud victims lost $1,090 on average and more than $3.2 billion in total.” https://bjs.ojp.gov/content/pub/pdf/ffus17_sum.pdf https://bjs.ojp.gov/content/pub/pdf/ffus17_sum.pdf And what about the opportunity cost & lost potential to innovating better solutions to fraud? There’s no good reason to assume the cost to solve this problem is an ongoing expense. http://frankackerman.com/publications/costbenefit/Prospering_With_Precaution.pdf http://frankackerman.com/publications/costbenefit/Prospering...
- AtNightWeCode 4y agoSome scams in my country have been ongoing for years cause the amount of the scam is one unit below what you can report to the right authorities. You can report to the police too but that is useless.
- benja123 4y agoI think some people are being a bit too harsh about how the author goes about explaining how you can't prevent all fraud without hurting good users - or in other words, some fraud is just the cost of doing business. Overall it is a good article (that could have probably been a bit shorter) that talks about a topic that is rarely talked about - risk tolerance. As someone who has worked in the industry for the past 15 years, I can see a few things that I believe are causing risk tolerance levels to increase across the industry. 1. Startups/new businesses that are in growth stage have a large appetite for risk which is pushing the more traditional/legacy companies to also take more risk. 2. High friction experiences that are designed to stop fraudsters require you to provide timely support to any good users that might be blocked by mistake. We all know the trend for most companies has been to move away from providing timely support to their customers as it is extremely expensive. This is another cost (on top of potential lost sales) of creating a high friction experience.
- 60Vhipx7b4JL 4y agoThe article seems to imply that there is a standard revenue/fraud curve. But what if there isn't such a static condition and you could jump to a less fraud (higher revenue) situation with different technical measures? So changing the revenue/fraud curve. Like: 2fa (like an app confirmation) based on heuristics? Yes, the fundamental statement is the same, but you changed the existing "rules"
- gumby 4y agoThis is true for things like welfare fraud (and other anti-help conditions) as well, but unfortunately Inna quest for headlines, taxpayer money is wasted (and injustice performed) in a quest to take the level to zero.
- c3534l 4y agoThe author seems to be doing exactly what he repeatedly claims not to be doing: being cute with his phrasing. He tells you he's going to make a case for fraud ceterus parabus, then actually argues fraud naturally arises through tradeoffs, which anyone who has ever made any kind of decision should be aware of. He wasted my time and had nothing insightful to say.
- jakzurr 4y agoLong-winded article, but an important subject for discussion. A business which has draconian policies can go downhill pretty fast. Facebook, maybe?
- richardc323 4y agoSure, there is a trade off, but they have it wrong for online fraud from stolen credit cards. The three digit CVV code should be a one time passcode (OTP). Banks have been using these since the 1990s for online logins. Using 90s technology, the card issuer would issue one of these OTP fobs along with the card. It has the card number printed on it, a button and a LCD screen where the OTP is displayed. The CVV is already sent through to the computer that authorises the transaction, the software that checks the CVV would need to be changed. So we have a trade off of the user having to have a separate thicker card, to fit the battery, for online use. I just googled, you can get batteries that are 0.4mm X 22mm x 29mm, a credit card is 0.76mm. Eink is old technology now with the right performance characteristics. I suspect in volume using this technology you could integrate the OTP device in the standard card form factor for less than a couple of dollars a card. So with a bit of innovation the friction of payment / fraud tradeoff goes away. This all strikes me as fairly obvious to someone designing these things, is there another tradeoff going on here?
- jokethrowaway 4y agoIf each card were a public/private keypair, you could sign a message authorising a payment of X amount at current time, in zero knowledge, without leaking your secret (the credit card number) in every transaction. Add two factor authentication, if you want, but fix the underlying giant issue first.
- richardc323 4y agoThis would be more secure than what I proposed, but requires changes that are out of the control of the credit card companies. For the card to sign the transaction, you need to add some kind of card interface to the users device. Maybe this is what happens with chip cards when you use it at a shop with a card terminal.
- still_grokking 4y agoBanks don't have much initiative for investments in IT security. They have insurances. That's why IT sec all around banking is just the bare minimum required by regulations. Those sec-specs are also usually at least one decade behind the state of the art… And they get updated only extremely seldom as this would cause "a lot of paper work" at the banks, so the banks are always against any changes to that regulations; and if something changes finally it takes the banks again at least half a decade to adapt to those changes; they can do it like that as the time windows to comply are usually set to be very long, because you know, it's really a lot of paper work…
- jiggawatts 4y agoSomething related that I've noticed in government projects is that they will spend $100K on a tender process to eliminate a fraud risk of 5% that amounts to at most $10K if it does occur. So if you amortise the total "value" of the fraud, it's 10,000 x 0.05 = $500! Spending $100K to avoid a loss of $500 is something most sane businesses will not do, but to government this makes perfect sense, because they have a rule that the acceptable amount of fraud is zero. Hence, they'll spend nearly infinite resources to try to bring fraud down to closer and closer to zero.[1] You see similar things with risk aversion. Some risk is inevitable, but again, government departments will cheerfully blow billions of dollars to avoid the slightest risk. Projects like ITER and the SLS are highly risk averse and their costs reflect that. Meanwhile smaller, newer, more risky projects will run circles around them. [1] At least what is perceived to be zero. In actuality fraud remains rampant, but as long as it is technically legal, it is not subject to this rule.
- 616c 4y ago> Spending $100K to avoid a loss of $500 is something most sane businesses will not do, but to government this makes perfect sense, because they have a rule that the acceptable amount of fraud is zero. In short: no. That's the perception but is not correct, at least security risks. So since you mentioned SLS (you mean CMS and healthcare.gov maybe? Hello from a friend of people who made those things) I assume you mean US government. Now I totally agree that is perceived. Few parts of risk management are mandated at least in terms of the infosec side of the fence with risk management beyond what is in law (FISMA and thus Risk Management Fraework made to address it as a req). The NIST RMF (SP 800-37 and SP 800-53) is very flexible and without even mentioning quantitative methods in those documents would inherently be at odds with your example; it is the opposite of risk management. But I do agree USG staff and contractors perpetuate this fallacy when provided the checklists of high-level recommendations and don't bother reading 800-37 at all, which explains the rationale strategy and approach that explain this example you give is bad and for good reason. They essentially document that not all systems get the same breadth and depth of security across govt in all agencies and projects equally for this reason. It doesn't scale or make sense. Sorry for the rant. I have it once a week with friends in public and private sector and the perception is true and may happen but the docs and the people who wrote them (also friends) can tell you that is very much the opposite of what's recommended by NIST and those upstream guidelines are those derived from law.
- benreesman 4y agoI think I agree with OP’s premise that driving “fraud” to “zero” is kind of a fool’s errand: some people, like Bender from Futurama, “just love crime, just love stealin’ things…da dah da”. But for me at least, it grates more than a little whenever Self-Assured Tech Person With Logic and Statistics In Hand assures you, dear reader, that if you actually crunched the numbers instead of gobbling up pablum from the Washington Post like a lemming, would in fact realize the Free Enterprise Is Going Just Great. The World Economic Forum has sufficient data to do a plausible “Social Mobility Index” on 82/195 UN-recognized sovereign states: and its just one of many data points that Capitalism Muzzled by Social Democracy is in fact what you want if “people having a shot at doing better than their parents in large numbers” is a priority. I’m old enough to have watched the effects of the Operational Research PhD’s at Megacorp “optimizing” every angstrom of human joy and dignity out of living in a Free Enterprise Zone. You can’t do anything these days that involves commerce without bumping into this. Friendly dare for US readers: try invalidating a credit card number in a way that stops every recurring auto-pay that has barnacled itself onto your economic ship is forced to get you to re-auth it. Good luck. So while driving “fraud” to “zero” might be silly, we can almost surely take a big whack out of it by making a salutary example or 1000 of companies that have “optimized” the right amount of paying OSHA fines rather than allowing bathroom breaks to “all of them”, or “optimized” the right amount of cheap and fast municipal fiber to “zero”, or the right amount of employees to force just below the “gets benefits” line to “whatever the maximum is”. I worked in butcher shops and call centers and retail in the Clinton Administration, and boy were they after you for every dime. Having been an over-privileged techie for the last decade or two I’ve personally been largely insulated from how much worse it’s gotten since then, but the kids I grew up with for the most part haven’t, and it’s a little hard to regard the significant fraction of them with some “grey at best” side hustle as doing anything other than scamming the scammers who have Corporate Backing.
- lossolo 4y agoThis is something I realized a long time ago when I was running specific site for a few years, we had some users that would abuse the system, there was a technical solution to this that would completely eliminate abuse but the systemic cost of implementing such a solution was just too high because it would affect the whole system in negative way. So you basically accept some amount of abuse/fraud/cheating until it starts to affect your business, this is optimal choice in most cases.
- tpoacher 4y agoDefine "fraud".
- anu7df 4y agoI mean optimal amount of anything is non zero. Trying to get 0% of anything, so getting anything 100% pure is next to impossible. Near hundred (99.9 repeat n) is useful but is always not cost effective or possible as n tends to inf.
- darepublic 4y agoIf security was perfect fraud attempts would plummet. If they plummeted cutting corners on security would start to make sense. If companies got too relaxed with security again fraud would be incentivized once more, etc. It's like game theory, it's the reason we can't have nice things, it's because forces more fundamental than we realize have to have their ebb and tide.
- ilaksh 4y agoThis is where it would be helpful for people (such as this famous patio blowhard) to learn what cryptocurrency actually is and why it's not a joke. Some day maybe.
- Dove 4y ago> These tradeoffs are often intensely difficult to pursue openly. Who wants to be known as the politician in favor of benefits fraud or the financial CEO who thinks they are not laundering enough money? It is very easy to explain such things, if you can hold two ideas in your head at the same time. It goes like this: "We will pursue benefits fraudsters via every method available to us that does not compromise our ability to get benefits to people who need them, which we must never forget is our primary mission." People used to talk like this. Politicians used to talk like this! Within my lifetime! Alas, I know the author is right. That thought is too complicated for us now. Monomania is the curse of the age, which is tragic. Life is complicated enough to require thoughtful tradeoffs between several competing variables, and cannot be simlified.