8 ms·
Ask HN: How do I stop card testing attacks on my Stripe account?
For the past several months I have been getting hit with several card testing attacks. I sell a product with a subscription (which is processed via Stripe). The problem is that everytime this occurs I have to manually go into my account and determine if it is a card testing attack and then if it is then I have to refund and block the payment. Not a big deal if it happens once or twice but has been happening very frequently on my account. I've tried everything I can on my end but it's very limited what I can do since they don't even go through my website (I use Stripe Checkout, which they say is excellent protection against card attacks - which seems untrue to me). They simply get my public key (which I've rotated) and create their own checkout session. I've reached out to Stripe SEVERAL times and it is really annoying that they are unable to stop it.
What can I do, short of switching to PayPal or another provider?
Thanks!
- anenefan 3y agoVouched as this seems like a question others who use Stripe could sort out. As little as I know about check outs, (I know nothing,) I'm unsure why a public key would be used to pipe the request to Stripe? Surely any request to a third party needs an additional security measure apart from being merely being logged into the site. https://stripe.com/en-au/newsroom/news/card-testing-surge https://stripe.com/en-au/newsroom/news/card-testing-surge https://stripe.com/docs/disputes/prevention/card-testing#prevent-card-testing https://stripe.com/docs/disputes/prevention/card-testing#pre...
- weird-eye-issue 3y agoYeah, a secret key is used to create a Stripe checkout session
- deleted 3y ago[deleted]
- imtu80 3y agoMost of the time these testing card attacks are automated. If so, You can implement code and use Stripe element. Additionally, add logic if you get request from same IP in, let say 5 per within 1 minutes then block them for 15 minutes or so. Add Captcha and use CloudFlare to block IP ranges.
- tempaccount3333 3y agoUnfortunately, the attacks are happening completely outside of my website. The attacker is generating a Stripe Checkout page using my public key - which I have rotated several times. Implementing a captcha on my end won't work and I have no control over blocking IP addresses.
- magundu 3y agoNow more people know how to do the card testing. There must be an option to allow stripe script only in specific domains and sub domains. All other domains should be blocked.
- tehbeard 3y agoDoesn't work as that kind of info is in the http headers sent by the client..
- harg 3y agoAre you sure this is how it’s being done? My understanding of stripe checkout is that you need the secret key to create a checkout session.
- tibbon 3y agoUsing a fraud check service like Sift can help.
- ThePowerOfFuet 3y agoAt $5K a month last time I looked at them, Sift is a nonstarter for small businesses.
- Temporary_31337 3y agoSound like the kind of thing you’re paying Stripe to deal with? Open a support case every time it happens.
- perfmode 3y agowhat’s a card testing attack? how does it work? seems odd that this is your problem. seems like something stripe should be on the hook for.
- nibbleshifter 3y agoIt's where attackers use your sites payment method / card processing method to make a shitload of small transactions to verify the stolen credit cards they have are valid. Transaction succeeds? Cards valid.
- quickthrower2 3y agoThat raises more questions. My product is $29 say. How come they are allowed to make a small transaction at all?
- withinboredom 3y agoBecause they generate their own links using the checkout api for clients (thus all they need is your public key)
- stef25 3y agoOP says they're using his public key to create their own checkout page so they can set whatever price you want. Kind of doubtful that all you need to test cards is a public key scraped off any site that's implemented Stripe.
- tempaccount3333 3y agoThey are using my subscriptions. They don't set their own price
- chrisdkemper 3y agoThe attacker unfortunately doesn't have to use any aspect of the products that the site implements. In my situation I have different subscription levels, but the card attacker disregards all of it. Stripe really shouldn't allow for a card to be referenced without a predefined product also being referenced. It's almost as is Stripe doesn't want to stop the attacks because they're making so much from fees
- a_simm 3y agoWe had the exact same issue. Turns out cycling (all) the keys stopped it immediately. This was after looking through docs and many emails with stripe that never mentioned this as a solution.
- newusertoday 3y agocan you elaborate what do you mean cycling all keys?
- dinkleberg 3y agoCycling keys means replacing all of your API keys. So if you go into stripe and generate new keys and then update those in your app (it sounds like you need to make sure to replace all of the stripe related ones), you’ll have “cycled” them (then once your new keys are running, you should invalidate the old keys if they aren’t in use).
- chrisdkemper 3y agoHow long did this work for you? I've cycled my keys multiple times and it goes any time from 6 weeks to less than a week till the attacks start again.
- tinyprojects 3y agoI was on Stripe Radar's free trial, but it wasn't as effective as I liked - it also turned out to be very pricey paying £0.04/screened transaction. I've now rolled my own combination of IP-based bans on creating checkout links + notifications if a purchase has many failed attempts using diff cards (you can do this for free through Stripe's API). I refund suspected fraudulent transactions religiously without question as the $20 dispute fee is crippling, and have systems that will auto-generate and submit evidence to banks whenever I receive a dispute. I wish Stripe would do more to help!
- rgavuliak 3y agoAlmost feels like you could provide this to other merchants in some way/shape/form.
- danpalmer 3y agoOut of interest, how effective do you find challenging the chargebacks is in practice? I always thought about automating this (or for lost delivery claims with shipping companies) but the numbers never worked out for it to be worth it because the success rate seemed like it would be so low.
- tinyprojects 3y agoI've only trialled this system recently, but my current results are: 1 Win 2 Partial Wins (basically a loss with how much you get back) 3 Losses All these payments were fraudulent (a user doing credit card testing) and disputed by foreign banks (Thailand, Malaysia, Brazil). I think these cases are much harder to win, because the actual card holder is technically in the right to request the money back on their stolen card for a transaction they didn't do. Much better than my previous results of just accepting each dispute though :)
- danpalmer 3y agoThanks. Are your charges much more than the chargeback processing fee? One of the issues for us was that while the chargeback processing fee was ~£20, the order values were only ~£100-300, so even in the worst case of ~£320 lost, multiplied by roughly 1 in 10 non-fraud mistaken chargebacks, and 50% win rate, the value is only £16. At that amount it would take a lot to recoup the development costs. These are all very rough numbers, but illustrative I think.
- ookblah 3y agoI don't get it, you have to generate the session server side before redirect so you can do all your checks there, from rate limiting, etc. pass a nonce or something that you can check for before creating the redirect to make sure it's being generated from your own site.
- louwhopley 3y agoThere's a client-side only implementation of Stripe Checkout, which is what the OP might be using. [tutorial example](https://designcode.io/advanced-react-hooks-handbook-stripe-checkout-client-only https://designcode.io/advanced-react-hooks-handbook-stripe-c...)
- ookblah 3y agothat's probably a legacy version then. had a similar issue with the old checkout flow where card testers could just generate tokens using ur public key and feed it to whatever endpoint. they need to move to payment intents.
- nibbleshifter 3y agoI thought the whole point of using Stripe was they handle thia shit for you.
- MagicMoonlight 3y agoYeah why would you pay them a huge fee if you then have to manually deal with fraud
- frankreyes 3y agoCan you add a custom field to your payments flow, readable from Stripe? Use JWT or some other cryptography signature to tag good transactions.
- weird-eye-issue 3y agoCould add metadata to the customer when you create them as part of the create checkout flow
- codegeek 3y agoAre you using the latest Payments Intent ? That shouldn't allow attackers to use your Public key and create their own checkout page.
- gt565k 3y agoDepending on where your customer base is, the fraudulent transactions usually come from like the middle east, eastern europe, and other countries. See if you can track where those transactions are originating from HTTP request wise. You might be able to just block traffic from those regions if it does not impact your business and customer base. Not the best or cleanest solution, but when Stripe fails to handle fraud for you, you've got to get creative and hit the problem from all angles.
- 0xbkt 3y agoIf possible, collect fingerprint information through a side channel such as WebRTC or WebTransport, and use the info to correlate payments. Or, if the attack is executed from a non-browser environment, you can pattern match the order of TLS cipher suite to that sent by the attacker and block them straight away.
- edwinwee 3y agoHey — I work at Stripe. Sorry you got hit by card testing. Could you email me at edwin@stripe.com and we can take a closer look?
- dulse 3y agoHi! I work on card testing at Stripe and would love to help. Sorry to hear about this experience, would be great to dig in and see how we can fix it and improve our system. If you could, shoot me an email and we can dig in? I'm at wmegson [at] stripe.com (will DM you as well).
- monsterofcookie 3y agoCrypto payments only