5 ms·
> You can reasonably want the burden to be on retailers to prove fraud before taking action against it The issue here doesn't seem to be that they took action,
by jensensbutton 4y ago
> You can reasonably want the burden to be on retailers to prove fraud before taking action against it
The issue here doesn't seem to be that they took action, but that they won't restore the account. I think it's reasonable to expect that, upon producing evidence, the burden is back on the retailer.
- tptacek 4y agoWhat evidence? Receipts? Scammers have receipts too. People here don't seem to be considering that having meticulous documentation for 25+ gift cards doesn't make you look more like a normal person.
- alymaly 4y agoI'm not a new customer, it's not a new account. With a verified phone number. I used to add my personal credit cards in the beginning (then gave that up). I don't see any good reason to mark my account as fraudulent. Even if the automation does it, a manual check should see that everything is fine
- tptacek 4y agoYour account got marked fraudulent because you applied 25+ gift cards to it; it has nothing to do with whether you have a credit card number on file.
- logicalmonster 4y ago> having meticulous documentation for 25+ gift cards doesn't make you look more like a normal person. If gift cards are suspicious and cannot be reliably secured, then why are they even sold?
- tptacek 4y agoMy guess is that gift card usage is bimodal: 1. The large set of gift card transactions that involve just one or two gift cards being used in a long period of time by a single person, which don't set off fraud flags. 2. The other large set of bulk gift card uses, which are overwhelmingly fraudulent. So the answer would then be: they're sold for case (1), and policed for case (2). Don't do case (2).
- alymaly 4y agoIt seems to me that it is completely random in nature. The main reason I heard from tech support was that the cards were of different denominations. That is, I took only cards of 100 dollars would be all right. I just talked to a colleague, about which I wrote, she used the same denomination cards to buy a phone (she did not do it on purpose, but it just happened that all the cards were $ 100)
- pwinnski 4y agoA gift card is not suspicious. A few gift cards, all originally purchased around the same time, are also not suspicious. People do receive multiple cards for special occasions, after all. 25-40 gift cards, purchased in several different countries over an extended period of time, that is what's suspicious. In the first two cases, the most likely explanation is that the cards are gifts. I mean, it could be that I bought them myself, which would also be fine, but most likely I've just had a birthday or someone said thank you in a monetary way. In the third case, the most likely explanation is that I'm a scammer, and have exploited ignorant people, convincing them to buy me gift cards, and I'm finally cashing them all in. It isn't gift cards that are intrinsically suspicious. It's the pattern of behavior. If OP is indeed as innocent as they claims to be--and I see no reason to believe otherwise--then they are very much an edge case, with a very unusual pattern of behavior. That is the issue, not the cards themselves.
- logicalmonster 4y agoSo if 25 gift cards is suspicious, then are 24 gift cards not suspicious? And if 25 gift cards is the limit, then why can't this information be published so people understand what the rules are? A system can't work if people don't know what the rules are.
- pwinnski 4y agoLike any and all anti-fraud measures, clarity is the enemy. In any system, as soon as the rules are published, scammers will do everything they can to commit malfeasance while technically not breaking any rules. You say the system can't work if people don't know what the rules are, but in fact, any system where all of the rules are known exactly is doomed to fail because bad actors exploit the rules. It would be easy to demonstrate how publishing a rule that says "23 gift cards within 36 hours triggers our systems" would obviously and necessarily lead to scammers redeeming 22 gift cards every 36 hours, right? So in fact, there's some kind trigger, and it might change based on time of day, it might change per origin country, it might change based on account age, who knows? Anti-scam and anti-spam measures succeed primarily by being flexible and vague. In this case, and in many cases, humans who looked at the full pattern of behavior (a full pattern we have only the OP's description of part of) also decided that this was likely fraudulent. That human factor is always going to be important, because some people just do unpredictably weird things sometimes. This is not about Apple and gift cards, this is ANY system that doesn't plan to turn into a scam-filled wasteland. A system can't work if everybody knows exactly how to avoid triggering automatic fraud detection.
- alymaly 4y ago> If gift cards are suspicious and cannot be reliably secured, then why are they even sold? I just imagined for a minute - what if someone asks for a birthday present with cards and his friends bring him a pack. It's a GIFT and it's named GIFT card
- salawat 4y agoYes, but... That "GIFT" card, is a printed PAN, plus metadata that acts as close as you can get to a bearer account in the modern financial system. It's an endpoint that is incredibly difficult to really secure. KYC makes it a fraught thing to deal with, and organized crime knows and actively uses these mechanisms on a regular basis. Your activity pattern, like it or not, is mirrored by drug dealers, arms dealers, scammers, and other criminal enterprises looking to clean up ill gotten funds. We can't have nice things, because as soon as we do, some jerkwad starts running his profits from human or narco tracking through it. Further, there is something known as "structuring" which by itself, is a federal crime, and no, the feds are not too picky about who they deem to be actively structuring. Stucturing is moving money around in such a way as to avoid triggering reporting requirements. $2000 worth of gift cards is a dead giveaway. That's right on what eould normaly be reported as a CSR or SAR if done all at once if I recall. If you actively inquire about said reporting limits, that generally has to be reported or noted somewhere too. There is a right way to do things in the financial system, and there is the wrong way. You definitely hit on the wrong way. Is it annoying? Yes. So sorry. However... It is what it is. If you want to know another thing that is the same way, look at Terms of Use/Licensing agreements/EULAs... etc... If you want to redline something and negotiate something else than the canned stuff legal blessed, sorry bout it, but it is cheaper to forego your business rather than accommodate you. We cannot have nice things, because every time we try to make nice things, jerks ruin it for everyone else. Also, an additional bit: most companies do gift cards in order to either manage float (money held for a time to accrue interest before being spent), or to harvest consumer purchasing data to monetize. Often, they are trying to localize on one particular person, per account, and want to do so cheaply, and easily. You getting say 50 different cards makes 49 other people's data they are missing out on. No one wants that. It's a degenerate state for the business/surveillance capitalism model. Therefore, you're going to find organizational policies will make it hard for you to do that. Nor, mind, are they likely to try to help you remediate your errant behavior. That's a lot of clean up and paperwork, particularly for such a small amount (in their view), and also because, formalizing such a process encourages the use of it, which is non-value generating for the company/host-state. Again, and with 100% sincerity, I regret to inform you, you are currently residing in the worst timeline, second only to the ones in which you are dead, in imminent risk of dying, or on fire. If you were physically closer, I'd offer you one of those little hats you can fold out of a periodical or aluminum foil, or a paper bag to wear over your head... It wouldn't help in terms of changing the world to make your problem no longer a problem, but you'd at least be a rung up into the "free hat and not on fire" timeline. Welcome to the "life in the edge cases" club.
- jensensbutton 4y agoI get your point about pattern of behavior, but it doesn't change mine about who the onus is on. If Apple cannot verify whether gift card usage was legitimate, and takes no steps (e.g. a hard limit on how many gift cards can be used in a transaction) to prevent people from accidentally getting their account killed, that is on Apple. You're coming off like a "technically correct" guy that completely missed the user experience.