28 ms·
The optimal amount of fraud is non-zero (2022)
- karmakurtisaani 3y agoTo summarize: there is a trade-off between amount of fraud and ease of doing business. Zero fraud means doing legitimate business becomes too cumbersome. Seems like the same point we have with security in computer systems and ease of use.
- brazzy 3y agoImportant corollary: it may well be possible to reduce fraud much closer to zero (then the currently accepted rate) without negative effects on legitimate business. For example, the USA's lack of a national ID (and the resulting adoption of realldy ba substitues like SSNs, driver's licenses and "two photo IDs") has made a plethora of fraud techniques ridiculously easy. In many other countries, "identity theft" so rare there is not even an established term for it. Passkeys will hopefully turn into a similar case regarding computer security.
- andyferris 3y agoI lived in Spain and never understood how the DNI/NIE's weren't an easy vector for identity theft. You need to give the number to do the simplest things, and many people wanted to see the card (and possibly make a copy). As far as I know the smart chip on my card wasn't used once in 2.5 years. I suspect the digital certificates you could get from the government likely aren't as well protected by the general (non-technical) populace as they should be. What makes it harder for someone to steal identity via a DNI/NIE in Spain than someone could use a drivers license + SSN in the US? (For what it's worth, I actually liked the national identity card, and didn't hear too much about identity theft - I'm just curious).
- deleted 3y ago[deleted]
- fer 3y agoSpanish ID card has multiple layered security in them. The obvious and difficult to commit fraud with is the chip which is just a cryptographic one, but you also have RFID in them (with I assume appropriate FNMT signatures), but also physically the patterns in the print, the different textures in different areas of it, holograms, transparencies and the like. For most ID-requiring processes people undergo training to identify these security features, to the level of fraud that it's worth detecting for said process. When the post office asks for your ID to retrieve a package, they won't check much, but I don't think it's unusual for banks to pass your card through the RFID reader and have a high res picture of your face on screen even if only to recognize you properly (btw you have apps to read such data).
- genezeta 3y agoThings may have changed since you were here. Currently, there's additional digital systems built around the e-DNI and much of the administration -national and local- uses that for most of the things where you previously just used your DNI number and a smile. The certificates themselves in the DNI are used only occasionally, but it's mostly your decision: you can stick to using the certificates and not activate other means and then you can't access a bunch of things unless you use the certificates. But still, this is mostly for the public administrations. Private entities, such as banks or whatever, don't really make use of it and build their own systems (most of the time quite stupid ones [0]). -- [0] Fortunately they changed it, but for about a year or so my bank decided that instead of sending a 4-digit code through SMS -which you then typed to verify whatever transaction you were doing- it was "more secure" to just show 5, 10, or 20 4-digit codes on the transaction site and then send you a single number through SMS, say "7", to select the code from the list. And somehow this was applauded and got them some newspaper headlines as the bank investing the most in advanced security in the country or some shit like that.
- c0pium 3y agoTo be a bit more general about this, I have found that the returns to combatting fraud are highly nonlinear. Having a better national ID than SSNs would have effectively no negative impact while being a huge benefit for security and fraud prevention. It would also, if implemented well, be hugely beneficial for privacy. For instance things like Signal could move from requiring phone numbers to a ZKP using a national ID.
- akerl_ 3y agoThe problem is that the people in the USA who think "national ID" is code for "they want to put us all into pods and use our bodies as batteries" really really don't want national unified identification, and the people who aren't crazy don't consider it anywhere near their top 10 issues that would sway their vote. So no politician with any actual power is going to push for it. There's tons of issues like this, where there's a clear technical right answer, but the only people who are foaming at the mouth over it are on the crazy side, so it doesn't happen.
- wwalexander 3y agoThe answer isn’t as clear as you think. https://www.aclu.org/documents/5-problems-national-id-cards https://www.aclu.org/documents/5-problems-national-id-cards
- akerl_ 3y agoIt seems pretty clear. That article is just an example of the craziness I was describing. Notably: having a unified ID structure has a ton of upsides, and "preventing terrorism" seems fully orthogonal. Additionally, we already have IDs that register humans into databases and are tracked when people travel, it's just that the databases are disjoint and thus even more error prone because they're run individually by states. The way you can tell this article is crazy is by noticing lines like this: > When a police officer or security guard scans your ID card with his pocket bar-code reader, for example, will a permanent record be created of that check, including the time and your location? This is already what happens. The police officer logs your interaction alongside your drivers license (or non-driver ID) number. Transposing a nationally-unified ID scheme for the current state-based scheme doesn't increase the amount of logging, it substitutes one log for another.
- russelg 3y agoIn Australia, drivers licenses and passports are defacto national IDs. And we felt the sting of that when Optus (2nd largest telecom provider) leaked half of the population's IDs. Not to mention before this there was almost no way to get a new drivers license number, so if it got stolen good luck, a new license is issued under the same number.
- akerl_ 3y agoAre AU drivers licenses issued by the national government, or by states? The thing that makes DLs wonky in the US is that while you can basically use a DL as a national ID, it is issued, managed, and operated by the state. So no two state's DLs look the same or have the same info. This makes them amazingly easy vectors for fraud. As two amusing anecdotes: A while back, I went to buy some beer in a state other than where I lived. I was asked for my ID, and provided my drivers license. The employee pulled out this comically thick three ring binder, flipped to the page for my state, and had to read through a list of compiled identifying factors for a legitimate ID from my state. Even further back, I worked at a company where a small slice of my job was verifying ID for new signups flagged as high-risk. Except... we were an online business. Our users were global. So if somebody happened to upload a passport or US DL, I could at least eyeball it. But if somebody uploaded an ID issued by basically any other country on Earth... I guess that's what IDs from The Confederacy of Independent Systems look like? The only surefire way to get rejected was either not uploading anything, or the many, many bots that uploaded random pictures of flowers or trains or random nonsense.
- russelg 3y agoAU drivers licenses are issued by each state, but same as the US they can be used as a national ID. And yep, they all have unique designs as well. However there is a baseline for the information they have to have on them, which is: Address, date of birth, first/middle/last name, card number, and license number. The issue here is the license number is the one used for most verification, and that one is static. The card number changes every time the card is re-issued. Examples of them are here: https://www.mygovid.gov.au/verifying-your-drivers-licence https://www.mygovid.gov.au/verifying-your-drivers-licence A funny anecdote along the same lines: A friend of mine recently moved from WA to NSW. If you move state, you have to apply for a new license within three to six months depending on the state. So he got a NSW license, it's a trivial process to convert your license thankfully. He came back to WA to visit for a while, and tried to go clubbing. One bouncer read the post code from the address (like a ZIP code, only 4 digits instead) as his birth year because he had no clue what he was looking at... NSW post codes start at 2000, so you can see how this mistake could come up. WA post codes start with 6000 so there's no possible confusion there, until we reach the year 6000 at least! Of course, the Date of Birth is still clearly labeled on every states driver licenses so this bouncer may also have been a bit daft.
- lotsofpulp 3y ago> For example, the USA's lack of a national ID (and the resulting adoption of realldy ba substitues like SSNs, driver's licenses and "two photo IDs") has made a plethora of fraud techniques ridiculously easy. I US federal government provides passports with passport numbers. All the infrastructure is already in place, it’s just a question of political will to implement an API to use this for identity verification.
- brazzy 3y agoThe problem is that only about a third of all Americans have a passport.
- bsdpufferfish 3y agoCorollary: the more trustworthy people are the less expensive everything is.
- ISL 3y agoWorking with partners who have integrity is a massive boost to everything you do. People with high integrity attract more people with high integrity, compounding that effect.
- quickthrower2 3y agoHell yeah. At the extreme of distrust you have complete war or anarchy and you can’t get anything at any price.
- kevindamm 3y agoUnder the assumption that the only way to bring fraud to zero is to raise the bar high enough that legitimate customers will also be turned away, some fraud is acceptable and the author posits it is even a good thing: it means good customers are having an easy enough time being a customer, too.
- curtisblaine 3y agoI understand this and it's similar to what happens with, for example, theft or shoplifting: if we cracked down really hard on it, the honest user's experience would be disproportionately impacted and our collective freedom could be restricted too (imagine policemen searching whoever exits a supermarket, or cameras spying and tracking virtually everyone everywhere). At the same time, it's profoundly unfair that we need to let a certain class of people (fraudsters, scammers, thieves) to live at society's expense and I would like something could be done about that. Who knows, maybe sample crackdowns with really heavy consequences.
- Spunkie 3y agoAnti-fraud departments have apparently not gotten the memo, and the whole situation has gotten obscene in the last few years. I regularly travel for work and it's impossible for me to make any purchases on major sites like Walmart, Best Buy, Target, Costco, etc. They all will accept an order, charge my card, and then randomly cancel the order some hours to days later, and refund me. Similarly when traveling internationally, Schwab bank decided they didn't like one of my debit charges and blocked the card. I called Schwab and they gave me some "publicly sourced" 3 question quiz about myself that I apparently failed and they locked my entire account until I can fly back to the states and come into a branch. Luckily I have a 2nd bank account and was able to change my payroll. But it's just insane to me that some random debit charge has resulted in my inability to access most of my money or my brokerage positions. I hear similar issues and horror stories from all my coworkers and friends that travel.
- fsckboy 3y agoout of curiosity, are you "privacy conscious", as in minimize sharing your location, personal information, etc? I have a pet hypothesis that a lot of the security heuristics they use are based on being able to spy on you everywhere you go, and the trail of digital litter you leave behind "confirms" it's you where you are. It's difficult to draw conclusions from my own experience because the security landscape changes and I don't know what other people encounter. I do know people who spend their lives online on the phone and they don't complain about having problems blowing their whole paycheck every week; like for instance my assistant who doesn't either have trouble purchasing things for me.
- deathanatos 3y agoI happen to share a name with somebody in my family, and these risk-reduction facets literally cannot tell us apart. I've been told "wrong answer" when giving the right answer to questions about myself, but they're asking me questions about a different person, because again, having the same name is sufficient to get mixed up, apparently.
- pembrook 3y agoDitto to this. My experience has been very similar to yours. The amount of incompetence involved with payment processing and banking is just mind boggling. KYC/AML is very quickly turning into bizarro big brother. But not an all-knowing AI big brother. A stupid 2005-era IP address detecting one. You do a little too much traveling? Poof. There goes a month of your life to banking jail. A simple two-factor mechanism like passkeys or authy (that isn’t based on SMS to unreliable US phone carriers) would solve about 99.999% of this.
- yreg 3y agoI believe this is a trivial thing with a misleading title. Of course the optimal amount of fraud for a business is zero. A world with zero fraud would be optimal for them. And (also of course) given that combating fraud has costs, there is a level at which investing more money and effort into anti-fraud has diminishing returns. Therefore it is not worth it to go all in into the fight against fraud, but accept that some amount of it happens. Surely none of this is surprising.
- tptacek 3y agoIt's very unintuitive. It's come up on threads here several times, with people incredulous about the statement. It has ramifications for the kinds of discussions we have on HN, because the primary stimuli we get are news anecdotes, and anecdotes about fraud can be galling but still under some sane noise floor that organizations don't bother to stop.
- yreg 3y agoIs it unintuitive? The concept of diminishing returns applies to everything any living thing does. I think it's very natural, even in the 'our brains are wired for this' sense.
- tptacek 3y agoIt is unintuitive. It hits some primal part our brain, the same as is isolated in that capuchin monkey experiment where two monkeys get varying levels of grapes. People get either really excited or really pissed off when they see people getting away with something; at the same time, when we read stories about bureaucracy --- a perennial bête noire on HN --- we rarely think in terms of the fraud we should be accepting. We just think fraud is bad, and anti-fraud is bad.
- jacquesm 3y agoI think it is in part rooted in the difference between committing fraud and detecting that there is fraud. They're entirely different things and the misunderstanding results from the fact that. It is indeed very interesting how deeply hardwired this sort of thing is.
- jasode 3y agoFyi... submitter put "not zero" instead of original title of "non-zero" which causes the "past" link's search algorithm to not list this previous discussion: https://news.ycombinator.com/item?id=32701913 https://news.ycombinator.com/item?id=32701913
- GuB-42 3y agoJust like everything. The optimal amount of crime, unemployment, accidents, deaths, etc... is not zero. For example, when building a road, there is a certain chance that an accident will happen, that some people will die, and that could have been prevented. For example, by installing a guard rail, enforcing speed limits, or by taking a different path. But installing that guard rail for a one in a million chance that something bad happens is money better spent elsewhere, like improving safety where it matters more, and people tend to dislike the resulting taxes. Enforcing speed limits have a cost too, that can be recovered from the fines that result from it. But the goal is not to bankrupt your citizens with fines, and constant surveillance is not very popular. And the different path you are planning may go though people homes, relocating people is also expensive, and usually not very popular for the people in question. So, we tolerate a few accidents and deaths over a dystopian society.
- mlyle 3y ago> But installing that guard rail for a one in a million chance that something bad happens is money better spent elsewhere Just for clarity -- guard rails, where we choose to place them, probably cost $500k to $2M per life saved over their lifetime, while the value of a statistical life in the US is >$10M. This comparison ignores costs of non-fatal outcomes (injuries, disability). It seems like we should be deploying more guardrails, even though their marginal return would be less than our current average.
- kevindamm 3y agoThe problem the article poses is actually not one of diverting costs, despite how GP's metaphor would indicate... It's that with fraud, only the most draconian systems can be effective at stopping all fraud. In the above metaphor, it's more like guard rails are already in place, the speed limit is 1/10th a reasonably safe velocity, and the only way you can stop the remaining death-every-decade is to make everyone walk the road instead of driving it, and guarded so that you don't encounter any strangers along the way either. Very safe. But now nobody even wants to take this road. But it's so safe! Zero deaths, no injuries, ever. Sure, the expenses/value argument can be made, too, but that's not ultimately what makes it nonzero. Even if you had limitless resources to apply to the anti-fraud, the only way you're getting nonzero fraud is if a large amount of legitimate customers are inconvenienced or outright denied as well. This is due to how easily fraudsters can still find processes and marks to make it worth their time, and regulations + policies are ever evolving to keep up, but a lot of it comes down to a cost/benefit analysis by the business. The internet just scales this up by several orders of magnitude too.
- borissk 3y agoA problem that a social credit system can mostly solve - just don't do business with people with low social score :)
- nitin-pai 3y agoA lot of the confusion and anxiety will melt away if we distinguish the terms “optimal” and “desirable”. The most desirable amount of fraud, corruption or tax evasion is zero. In the real world we don’t get what we desire. The closest we can came is to the optimal amount, where the marginal cost has to equal the marginal benefit.
- COAGULOPATH 3y agoThis reminds me of Matt Lakeman's "An Attempt at Explaining, Blaming, and Being Very Slightly Sympathetic Toward Enron" https://mattlakeman.org/2020/04/27/explaining-blaming-and-being-very-slightly-sympathetic-toward-enron/ https://mattlakeman.org/2020/04/27/explaining-blaming-and-be... He makes the point that although Enron was clearly doing shady things, it's possible for a legitimate business to do many of the same stuff ("mark-to-market" accounting, tricky SPEs, and so on). Try to categorically eliminate Enron-style fraud and you might take down the next Google in the crossfire.
- DANmode 3y agoYou say that like everyone ubiquitously believes Google is a net-positive.
- deleted 3y ago[deleted]
- vincnetas 3y agoWell basically if you spend more money to prevent fraud of monetary value that is less than amount spend to prevent it, you loosing money by preventing fraud. But this logic is only applicable for things that on both ends measure in money.
- apollo_mojave 3y agoI thought this article was going to be somehow less intuitive, but in reality, it simply says something most people inherently understand: that you have to grease the skids a bit to make things work. Dressing it up in academic sloganeering doesn't make the insight all that much more powerful. I think most people understand that a risk-free society is a poor society. Take driving: the safest way to drive is to not get in the car at all. Similarly, the best way to save yourself from credit card fraud is not to have a credit card. But does this justify driving like a maniac, or being careless with your personal information? Of course not. In other words, the article simply points out that categorical thinking (1 or 0) is useless in this context (as it is in most contexts, to be honest). The meaningful question is what degree of fraud we should be willing to accept, and in what contexts.
- dvdkon 3y agoIt's a common insight, yet you see slogans like "zero tolerance" or "our overriding priority is security" everywhere. You can choose to believe people championing them are just oversimplifying or actually encouraging a bad system for their own gains, but it's important to be able to point to a well-written piece explaining why they're a bad idea.
- delusional 3y agoThis article falls into the common pitfall of over rationalizing "the market". It's true that from first principles you don't want to establish the bureaucratic apparatus it would take to effectively eliminate all forms of fraud, this is the intuition most people tap into when they say "you can't catch every crime". This is in fact not a surprising observation, most people just understand it as common sense. It's also not the main motivating factor driving the enforcement of monetary fraud prevention. The monetary system doesn't care about fraud. Banks, credit card companies, and the rest of the financial sector make money from transactions, with no regard for who spends the money, who owns it, or if the transaction was legitimate. Bad actors need banking too, and their transactions are just as valuable as the ones your grandmother makes. Here we find the sharp divide that fraud controls try to bridge. The social cost of fraud is extremely high. Yet the proportional value, defined in a capitalist sense, of fraud is close to 1. A transaction that happens to be fraud is almost if not as valuable as a transaction that happens to be legitimate. For a bank, the optimal amount of fraud is not just non-zero, it's basically as much as possible.
- deleted 3y ago[deleted]
- super256 3y agoUhhh, it depends on the business? I know there are some businesses which suffer high chargeback rates (pay2cheat SaaS), and most of the chargebacks were happening by customers who said that their card has been stolen (as the merchant could easily disprove any other lie). The usual customer cycle was: buy the cheat, get banned in the game due to suspicious stats, reports or whatever, be mad about it, and then they would turn to their bank and say that their card was stolen -> chargeback. Eventually, they started forcing 3DS (which shifts liability from you to the card issuer, and apparently card issuers don’t like paying!). Revenue didn’t decline, but fraud rates did go indeed to zero.
- quickthrower2 3y agopay2cheat… has trouble with unethical customers. Stop the presses!
- eviks 3y ago> This is counterintuitive and sounds like it is trying a bit too hard to be clever. You should believe it. Yes, you're > you should welcome greater than zero fraud. You can think of it as a necessary expense, just like rent or salary or advertising is. You don't WELCOME costs just because they're necessary. Similarly, you wouldn't welcome fraud just because it's too costly to get rid of it. And if you add a tiny bit of morality into the mix, your too clever "fraud welcome!" message becomes even more invisible (also, it could very well be that some fraud types can be reduced to literal 0 without bringing the whole system down, but then the parts of the system that can make it happen aren't incentivized to do so because they've passed all the costs to other parts of the system)
- thunderbong 3y agoI get your point. But the article is a very interesting read.
- emmelaich 3y agoYou're not wrong but perhaps reading it at at the wrong level. Doing the is/ought mistake.
- cyrillite 3y agoThe argument seems to be a little different than what you’ve taken from it. My interpretation was something like and efficient frontier model between multiple variables where “zero fraud” isn’t actually a position on that frontier. So, if you find a place with zero fraud, you can possibly increase the total utility of the system by aiming for slightly less than perfect but being back on the efficient frontier. Arguably zero of anything is a great ideal but not maximally efficient. Morally, the situation is more in favour of getting to zero.
- regularfry 3y agoI don't think you can even make a moral argument in favour of zero fraud, because that implies choosing to harm genuine users. There's always a trade-off between fraud prevention and genuine use. This is extremely important in social benefit systems, where people can literally die if the system incorrectly thinks they are trying to defraud it and cuts them off. Non-zero fraud is useful for political point-scoring, but zero fraud is a terrible goal on its own. You also need to be measuring false positive cost, and drive that to zero too. The moral argument has to be for the efficiency frontier itself, I can't see any other way this works.
- w10-1 3y agoFor the theoretical background, see Ronald Coase on Transaction Cost Economics. The law can place liability anywhere. In a situation where transaction costs are zero, it doesn't actually matter where liability is placed, because the participants will contract in the most economically efficient manner to share the burden. That means liability choices can reduce to reducing transaction costs. For credit, the $50 is to avoid the adverse incentive of the cardholder permitting fraud, but otherwise the cost and mitigation is better shared among the big players at scale that reduces overhead. (Conversely, shifting liability via forced arbitration and legal disclaimers monetizes market power.) As a policy matter, ask yourself: so why then do debit cards not come with the same limitation of fraud liability to $50, since the same economies of scale apply?
- davidkretch 3y agoA similar insight from economist Daniel Davies from 2005: >> The optimal frequency of disasters is not zero. This graceful formulation is due to Prof. Richard Portes, who used to say it about emerging market financial crises. However, it’s a fundamental principle of risk management and one of entirely general application. Most dangers can be absolutely eliminated for all practical purposes, but only at unacceptable cost. https://blog.danieldavies.com/2005/07/?m=1 https://blog.danieldavies.com/2005/07/?m=1
- fuzzfactor 3y ago>The optimal amount of fraud is non-zero As long as it's in a competitor's operation and not mine, I'll do fine.
- mjw_byrne 3y agoClickbaity, trying-too-hard title. The point being made is mundane: perfection is too expensive, so we settle for "good enough". This is near-universally applicable and near-universally understood. The author is trying to make it sound deep and meaningful with statements like "you should welcome some fraud", as though fraud is actually required for the system to function (clever counterintuitive point made, cue huge dopamine spike). But no, we simply tolerate a certain amount of fraud because eliminating it isn't worth it. Yawn.
- cm2187 3y agoAgree. Particularly the tax writeoff argument is complete bullshit. You could make an argument that you need some level of fraud to keep the anti-fraud dept on its toes. It’s like war. If you have an army that has never fought a war in a century, you should have no confidence you have an army at all. That’s a problem the day a real war or in this case a real fraud, happens.
- mjw_byrne 3y agoYes, and that would be a genuinely interesting point. For example, it could be compared it to the need for regular backup testing, where we generally try to maintain DR readiness with artificial testing and certainly not by accepting a certain frequency of disasters.
- trabant00 3y agoExactly. "We can't divert all of society's resources on policing" is different than "The optimal amount of murder is non-zero" or "you should welcome greater than zero murders".
- regularfry 3y agoThe comment directly above you on the page right now gives an example of people getting the trade-off wrong, so your dismissiveness is pointless. The framing is also relevant for another reason: choosing a conscious trade-off point means that you can choose to move it as circumstances dictate, which can be very non-obvious. There's currently a lot of noise in the UK media about dodgy PPE contracts issued during COVID, and for my money most of the coverage misses the point. The coverage focuses on who the contracts went to, and how much they cost. There is only scant consideration given to whether the contracts were fulfilled (and they weren't - the PPE was no good and couldn't be used). This is precisely backwards: in an emergency situation where you don't have enough of a thing, and the existing systems to provide the thing are very much tuned to preventing fraud, you absolutely want to be able to throw money at the problem and accept that more of it than usual will be going places you wouldn't ordinarily tolerate. That's a lever we should definitely be able to pull, by making a conscious choice to relax . But that's only true if you do actually get what you paid for. Yes, you want to be able to follow up any dodgy procurement after the fact, but in the moment what you need is the critical resource. The scandal should be that none of it worked, not how it was bought.
- amadeuspagel 3y ago> This is counterintuitive and sounds like it is trying a bit too hard to be clever. Indeed. You could make the same counterintuitive and clever point about any bad thing, pointing out that there are things one might do to reduce that thing, which have other costs, and aren't worth it, but for many bad things that would not sound counterintuitive and clever, but deranged. Consider the following statement: > The optimal amount of salt in food is non-zero. That's true, and it's not clever at all, we need salt. It's not that trying to remove all salt from food would be too expensive. But consider also: > The optimal amount of radioactive material in food is non-zero. We might defend this in a similar clever counter-intuitive sense. But it's a completely different statement, and it's wrong. EDIT: The three replies making the same point about bananas are a great illustration of the desire (and failure) to be clever and counter-intuitive that's also evident in the article. We don't eat bananas for their radioactive material. We don't need to eat radioactive material.
- krallja 3y agoI have some bad news for you about bananas.
- konschubert 3y ago> But it's a completely different statement, and it's wrong. Well, then I have some bad news for you regarding bananas. Which is funny, because it proves the point of the article: The optimal amount of [bad] is usually nonzero because otherwise you have give up too much of [good].
- defrost 3y agoNot just bananas .. I can't think of any foods that have zero radioactive material in them. The world is naturally awash with unstable isotopes and low level cosmic radiation.
- tremon 3y ago> The optimal amount of radioactive material in food is non-zero. But this is true! Everything except lead is radioactive in some capacity. Pretty sure us humans cannot live on lead alone.
- rjmunro 3y agoI think that fraud prevention is mostly the wrong approach. Instead they should let the frauds happen, then track the fraudster and send the police to arrest them. Normal prevention just means the criminal has to keep trying until it works. Tracking the money after means that criminals will never know if the next knock at their door will be the police.
- jokethrowaway 3y agoVery true article and it's a pretty shit model for innovation! I want to launch a business which requires investing a lot of resources per customer. Think, the users pay 100$ and I spend 80$ in resources straight away, transform the resources in a peculiar way and provide it to the customer. I have already tried this and failed due to occasional credit card fraud and sneaky chargebacks from users AFTER having used resources. Now, being a small business (zero employees) I can't afford to stomach losses for months, invest into marketing and then wait until 100x growth bring me some profits. Just because of fraud being the problem of the seller and not of the cardholder, my choices are: 1. Go to parasitic VCs and convince them to give me money, in the hope I'll be profitable in a few years 2. Sell 1 on 1 to trusted companies - which doesn't work if you're selling B2C, increase your sales cost and bar you from a typical SaaS paths with random customers 3. Accept only crypto-currency payments - but nobody will bother to convert money to purchase something when they are used to just use their credit card
- mablopoule 3y agoIf you liked the content of the article, I urge you to read the excellent book "Lying for Money: How Legendary Frauds Reveal the Workings of Our World" [1] by Dan Davies, which I believe is the main source of inspiration for this article (I'm just guessing here, I have no proof of that). I discovered this book through another great post by Patrick McKenzie, "The fraud supply chain" [2] where he heartily recommend it, and I haven't been disappointed. On top of being informative, the book is very entertaining to read. [1] https://www.amazon.com/Lying-Money-Legendary-Frauds-Workings-ebook/dp/B078WFT5JV https://www.amazon.com/Lying-Money-Legendary-Frauds-Workings... [2] https://www.bitsaboutmoney.com/archive/the-fraud-supply-chain/ https://www.bitsaboutmoney.com/archive/the-fraud-supply-chai...
- ruthlogan22 3y ago[dead]