10 ms·
Stolen Money on Gittip, Part 1
- japhyr 14y agoI am a strong supporter of Gittip. I think it is an important funding model to make available, across a variety of disciplines. I hope there are some people around with experience identifying money laundering patterns, who can keep Chad from having to reinvent the wheel on this.
- singingwolfboy 14y agoKudos for being open and honest about this sort of thing. Publicly acknowledging difficult issues makes me support a company even more.
- whit537 14y ago:^)
- zzzeek 14y agowhat's the responsibility of Balanced in this regard, isn't it on them to ensure the validity of credit card numbers?
- dangrossman 14y agoIt's impossible to tell, with certainty, if a credit card is being used by its rightful owner or someone else. That's not something anyone anywhere in the payment processing industry guarantees. In terms of who can do the best at predicting the likelihood a transaction is fraudulent or not, it's definitely the merchant/website, not their processor. He has much more information available to him (IP address, github account, etc) than Balanced has.
- zende 14y agoThere's a field (meta) on the Debit resource that allows a marketplace to pass fraud signals like IP address and shipping address. Gittip is facing this issue much earlier than another marketplace in comparison to their volume. Otherwise, we don't ask a marketplaces to pass in more information until they've grown more. The problem in being restrictive too early is that you can hinder a marketplace from growing by having false positives. In the end, I think we (Balanced) should have done a better job here, and we'll work hard to do so in the future.
- driverdan 14y agoNice job being proactive and catching on quickly. Have there been any chargebacks? Chargebacks are usually what alerts people to credit card fraud.
- whit537 14y agoI am not aware of chargebacks yet. My understanding from other comments in this thread is that it takes months for chargebacks to hit.
- kmfrk 14y agoThis is always a concern when new value exchange services are invented. None have been as open and ethical about this as you, though, so it's very comforting to know that gittip won't be a free-for-all bonanza for asshats.
- tkahn6 14y agoIANAL but isn't this one of those things where you need a lawyer?
- flibble 14y agoLooks like you have just discovered chargebacks, something that just about every merchant discovers at some point. What to do? Some options to reduce your fraud are - outsource the problem by using an indemnified payments system (a payment processor who do their own fraud checks and don't pass on any chargebacks to you). Pros: easy. Cons: expensive and lots of valid payments will be refused. - Use an e-wallet that usually has few/no chargebacks, eg Skrill & Neteller. Pros. Easy, not too expensive. Cons: more difficult for people to make payments as they need to create an account with the e-wallet first. - Use services to help with your fraud detection. Eg. Iovation. Pros: you can keep it easy for your customers to make payments. Cons. a lot of work to implement (relatively speaking). - Use bitcoin, eg bitcoin247.com. Pros. no chargebacks ever. Cons. about 0.00001% of your customers use Bitcoin. Edit: I forgot to add: - require 3D Secure / Verified by Visa payments. This removes the chargeback liability from the merchant in most cases and shifts it to the card owners bank. Pros. much fewer chargebacks. Customers can still deposit directly on your site using their card (apart from the 3D redirect). Cons: entering 3DS details another barrier to making payments so will reduce payments. Plus I'm not sure of the penetration of 3DS cards in the US.
- antiterra 14y agoGittip's professed concern is with ethics (and possibly sustainability), not losing money from chargebacks. The author realizes he has stolen money in his bank account, and that bothers him.
- AUmrysh 14y agoI'll take it off his hands for him if it makes him feel better.
- whit537 14y agoSure, what's your Gittip? :^P
- jerguismi 14y agoI'm pretty sure that their concern is also not needing to do the dirty legwork related to these cases. The time they need to deal with these problems is away from productive development time.
- dmethvin 14y agoOpenness about the problem is good, but I am not sure that it helps to provide that much detail about the ways you detected the fraud. That just give the attacker more information about how to circumvent your detection.
- reidmain 14y agoSecurity through obscurity is never the solution.
- scott_s 14y agoObscurity is necessary for fraud prevention. If perpetrators know exactly what behavior gets flagged as fraud, it's easier for them to figure out ways to avoid it. If they don't know, perpetrating fraud is harder.
- reidmain 14y agoThat is a good point. It honestly slipped my mind. Thanks for pointing that out.
- dasil003 14y agoYou're cargo culting on security dogma. Information assymetry is probably your only advantage against credit card fraudsters, because there is no security hole, rather they are exploiting your core business flow.
- whit537 14y agoI want to explore openness wrt fraud prevention, not out of a facile rejection of "security through obscurity," but as part of Gittip's identity as an open company. It's accepted doctrine that "information asymmetry is probably your only advantage." I'm asking: can we be open about fraud prevention and prevent fraud? If we can be, we should. What are your thoughts on the value of the social graph in spotting suspicious accounts? It seems to me that we should be able to whitelist new accounts based on a review of GitHub or Twitter profiles, and perhaps for flagged accounts we "authorize without capturing," as dangrossman suggests above.
- hcarvalhoalves 14y agoWelcome to the nightmares of dealing with money. Any good payment gateway should be managing the risk of stolen credit cards, but it's likely that because Gittip works with small recurrent payments instead of big upfront payments, it doesn't trigger any red alerts.
- mbesto 14y agoHence also why most people don't realize that Paypal was the side effect of a company that originally was created to handle fraud. Source: http://www.amazon.com/gp/product/1430210788/ http://www.amazon.com/gp/product/1430210788/ To take this to the next step, this is also why I believe Paypal is one of the very few companies that has been able to scale online payments. I'd love to see anyone challenge their ability to balance customer service with fraud prevention at scale.
- jacquesm 14y agoStarting a new payment service, even from the point of view of a company specializing in fraud prevention is a lot harder now than it was in the past. You're basically entering an arms race that has been going on for a decade+ as a rookie or at best a semi adept. Likely your main contribution to the field before folding is target practice. Gittip should work with a party that is already in the possession of the required knowledge or they'll be shutting down. This post raised their visibility as rookies considerably and you can expect the sharks to move in now that there is blood in the water.
- whit537 14y agoThanks, I started a ticket for this: https://github.com/whit537/www.gittip.com/issues/357 https://github.com/whit537/www.gittip.com/issues/357
- davidu 14y agoGood catch. You'll be fine. For what it's worth, a little bit of fraud is a good thing. It means people are using your system and it's growing. Too much fraud and people will lose confidence and your payment processors will punish you. Too little fraud and your system is probably too complicated to be useful to anyone, including fraudsters.
- noeltock 14y agoThis doesn't seem to be a case of money laundering, but credit card fraud. Thanks for the share!
- pyre 14y agoIt's both. Gittip is 'laundering' the money, so that it's clean on the other side. It's not the greatest money laundering scheme as the launderer is unwitting, and therefore can 'flip' exposing the source of the ill-gotten gains.
- noeltock 14y agoNegative. The layering stage of ML does indeed lead to "cleaning" funds, but Gittip isn't doing that. ML means giving money a clean-slate with virtually no history. Everything from casinos, offshore entities, to wiring funds through FATF blacklisted countries will be closer to what ML actually is.
- whit537 14y agoRight. https://en.wikipedia.org/wiki/Money_laundering https://en.wikipedia.org/wiki/Money_laundering I changed the blog post and GitHub issue to not refer to money laundering anymore.
- huhtenberg 14y ago> My heuristic boiled down to the following: So that's that for that heuristic. They will adapt now.
- whit537 14y agoThe problem with hiding heuristics is that false positives get squished. I want to avoid the horror stories we hear about people getting their Google account shut off or their PayPal funds withheld.
- VBprogrammer 14y agoI'm impressed at how quickly the criminal underground pivots. To identify Gittip as a potential money laundering scheme while it is relatively unknown even with Tech circles is, in a slightly discussing way, actually quite impressive. It does make me wonder, did the bad agent happen across Gittip independently or are they active within Tech communities?
- pyre 14y agoMakes me think that it's probably some blackhat with a few stolen credit cards, looking for a way to extract some value out of them (other than using them to pay for hosting). This isn't necessarily a large-scale operation.
- jasonlotito 14y agoAnyone that knows about these things would see this immediately. Anything that involves transferring money from one agent to another is quickly pounced upon. That HN is a popular place for launching new startups would make this an obvious target to watch. And most people starting new money transfer systems are ignorant of the potential for fraud and laundering. Essentially, this is standard practice.
- whit537 14y agoFor the record, I've been waiting and watching for this to happen. It did happen sooner than I expected, however. Not sure if that means Gittip has grown faster than I expected, or our Jokers are earlier to adopt than I expected. ;^)
- neilk 14y agoI am shocked, shocked to discover criminals on boards dedicated to hacking. Just kidding, but it is funny how outsiders might not understand why you are surprised to find criminals in the "hacking" world. Even so, a significant proportion of the people who go to something like DefCon have done some low-level fraud with credit cards, and some have done much more than that.
- moxie 14y ago
- ig1 14y agoPull this post and talk to lawyers if you haven't already. Depending on where you're based you'll have legal obligations that'll define what you should be doing at this point. This may well involve lawyers, your regulators and the police. Some countries make it a criminal offence if you let a criminal know that you suspect them of money laundering or similar offences (this is known as "tipping off") so you should be very very careful about what you're disclosing both to your users and the general public.
- bmj1 14y agoJust wanted to +1 on this - this is a fairly severe offence in the UK
- whit537 14y agoThanks for weighing in. I'm based in the US. I am going to proceed along the path of openness for now.
- jspthrowaway 14y agoYou should heed this advice BECAUSE you are based in the U.S.
- cynicalkane 14y agoI'm based in the US You should still pull this post and talk to lawyers.
- whit537 14y agoYeah, sorry, I wasn't clear: I'm pursuing openness because I believe in openness, not because I'm based in the US. I am glad to learn about this potential legal ramification, however.
- jspthrowaway 14y agoNot only that, "we are complicit in the crime" is open and shut liability. That's probably the worst thing anybody could ever write, legally, on behalf of a company. The victim cardholders and institutions would surely love a statement like that from the defense...
- dsl 14y agoThis isn't money laundering (from your initial github ticket its obvious that is what you were looking for, so thats what you found). Before selling stolen credit cards, bad guys have to verify them. This is often done with small (<$10) donations to charities or small purchases of intangible goods that are considered low risk merchants. With Gittip they found a way to get the low dollar amounts to come back to them, but since this wasn't really the goal to start with, you'll likely see donations to random leaderboard members that are unaffiliated with the fraud itself in the future.
- jusben1369 14y agoAgreed. When I read this it looks like a verification process for a batch of stolen credit cards to see which are still valid and which aren't. Note that the "successful" transactions may very well be charged back to you at $15 each or more so you want to refund any suspicious payments quickly to avoid going into the negative.
- dangrossman 14y agoYou basically have to catch it before the charge is even settled; either within the same business day before your settlement cutoff, or by authorizing without capturing for a day or two so you have time to review. Once the charge is settled, a refund almost never stops someone from charging back the payment -- for whatever reason, when a card is reported stolen, people and banks simply charge back everything unauthorized even if a quick review of the account would show some of the payments were already refunded. You can dispute these chargebacks by providing proof of the previous refund, but you're still out the chargeback fees, and these chargebacks still count against your account -- so they can end up getting you terminated if your CB rate is pushed too high.
- whit537 14y agoThanks, good info. My plan at this point is to whitelist accounts, because I want to try to keep from charging suspicious accounts in the first place.
- 14y ago
- davepeck 14y agoThis is unfortunate, but quite common. If you accept credit cards online, you're at risk. The specific kind of fraudulent behavior you see will depend on several factors (the nature of your business; whether you enable transfer from users to just yourself, or whether you push money from one user to another.) Credit card companies will, some time later, probably notice the fraud. At that point, you'll get a chargeback: you'll have to pay back the money you charged in addition to a fixed penalty per fraudulent charge (usually $15.) Especially if you're enabling a marketplace, like gittip does, these fees can be devastating. Regardless, if chargebacks become too common, your merchant account may be suspended. I've written some about my company's experiences with fraud, if it's of interest: http://davepeck.org/2011/11/17/fraudsters-gonna-fraud/ http://davepeck.org/2011/11/17/fraudsters-gonna-fraud/ http://davepeck.org/2011/12/01/dealing-with-credit-card-fraud/ http://davepeck.org/2011/12/01/dealing-with-credit-card-frau...
- whit537 14y agoThanks, Dave, lots of good pointers. I made these new Gittip issues based on your posts: use a fraud detection service: https://github.com/whit537/www.gittip.com/issues/357 https://github.com/whit537/www.gittip.com/issues/357 detect and prevent botnets: https://github.com/whit537/www.gittip.com/issues/358 https://github.com/whit537/www.gittip.com/issues/358 detect and prevent scripting: https://github.com/whit537/www.gittip.com/issues/359 https://github.com/whit537/www.gittip.com/issues/359
- olalonde 14y agoAnother alternative would be freezing money transfers for 30 days or so. Or use a payment processor that is used to deal with high risk websites (for example, CCBill). > The uncomfortable truth is that Gittip, Balanced, and our legitimate users are financially incentivized to turn a blind eye to laundering, because we have benefitted and are benefitting from it. That's only true until you start getting chargebacks.
- whit537 14y ago> That's only true until you start getting chargebacks. Phew. I'm saved from the moral burden by the financial burden. :^)
- zende 14y ago> That's only true until you start getting chargebacks. There are compliance ramifications of permitting money laundering, but collusion isn't always money laundering. Here's a few different scenarios: 1. Legitimate money laundering where someone is trying to obfuscate the origin of the money for some illicit reason. The ramifications of permitting or not having strong enough systems to prevent money laundering results in being shutdown. That's a bigger incentive than financial loss 2. Fraud where someone is trying to get cash off of someone else's card. This is the number one form of fraud on a marketplace and, by far, the hardest to catch. This is where the incentive is financial due to chargebacks 3. Cash advance where a marketplace has set their fees low (sometimes even lower than the fees Balanced charges) and someone is incentivized to get money off their card or simply get miles/points. Venmo and a lot of similar services experienced would get targeted by this form of collusion when they didn't charge any fees. This should be prevented due to card network (Amex, Visa, MC, Discover) policies, but they generally won't result in a chargeback
- arjunbajaj 14y agoLooks like Tumblr can't handle HN! The site is down. :( Haha! That's why i'm never gonna use Tumblr! :P
- sdrgalvis 14y agoThe link is broken. the tumblr page is down. you can still read the post at Altavista's cache at http://74.6.117.15/search/srpcache?ei=UTF-8&p=http%3A%2F%2Fblog.gittip.com%2Fpost%2F35057426257%2Fmoney-laundering-on-gittip-part-1&fr=altavista&u=http://cc.bingj.com/cache.aspx?q=http%3a%2f%2fblog.gittip.com%2fpost%2f35057426257%2fmoney-laundering-on-gittip-part-1&d=485744127291&mkt=en-US&setlang=en-US&w=uTdF6zbG3Yk&icp=1&.intl=us&sig=3bb8L0Lthk9mqSGJfyK_DA-- http://74.6.117.15/search/srpcache?ei=UTF-8&p=http%3A%2F...
- PeterisP 14y agoThis is why banks frown upon offering CC merchants to "marketplaces" - anyone who is not charging cards for their own business, but allows one user to give money to another. You didn't get money laundering, but if your volumes would be larger, you would get also money launderers.
- brandonb 14y agoMy company (Sift Science) helps sites fight credit card fraud. We work with a few large ($100m+ revenue) marketplaces, and here are some things I've learned. First off, strictly speaking, this is most likely to be a stolen credit card (i.e., fraud) rather than money laundering. You do NOT benefit from fraud, because when the cardholder notices the charges, they'll call up their bank and issue a chargeback. The $488.15 in your account will actually be removed and given back to the original cardholders. In addition, each fraudulent charge carries a $15-$25 fee, which you're liable for. https://www.balancedpayments.com/docs/testing#chargebacks---disputes#tokenization https://www.balancedpayments.com/docs/testing#chargebacks---... What's worse, chargebacks can take 60-120 days to reach you, since there's delay at every step: the customer's bank, the credit card networks, your payment gateway, and the acquiring bank (your bank). Unfortunately, that means you won't know how much fraud you have today until February (!). It's a broken system, but that's how all the major card networks work, so it's something that everybody who sells online has to deal with. If your fraud rate is higher than about 2% for two months in a six month period, Visa and Mastercard reserve the right to block payments entirely to your (or Balanced's) account unless you prove you can get the chargeback rate down. This is called an "excessive chargeback program." In terms of heuristics, fraudsters adapt rapidly to whatever counter-measures you use. The half-life of a good heuristic is maybe a couple of months. The best approach is to evaluate hundreds of different signals, using a machine learning algorithm to constantly adapt to changing fraud patterns. My company is running a private beta of exactly this technology and we're happy to help: http://siftscience.com http://siftscience.com. Even if you don't use us, I can recommend other services or give you general pointers. Hope that helps! Let me know if you have any questions: brandon@siftscience.com.
- whit537 14y agoThanks Brandon! Great info. If you see a way for Sift Science to add value to Gittip then I'm open to a proposal. Balanced won our business by stepping forward and contributing the integration themselves: http://blog.gittip.com/post/28351995405/open-partnerships http://blog.gittip.com/post/28351995405/open-partnerships I'd welcome a conversation with Sift Science along the same lines.
- 14y ago
- maplesyrupghost 14y agolooks like Bitcoin could prevent this.
- colindean 14y agoWe'd love help implementing it. https://github.com/whit537/www.gittip.com/issues/search?q=bitcoin https://github.com/whit537/www.gittip.com/issues/search?q=bi...
- shawnee_ 14y agoThe most unfortunate thing about this whole situation is that it was poor Chad himself who ended up discovering and shutting down the fraudsters. This should not have been the case, and I apologize on behalf of my former employer. I sincerely wish I would have been able to help catch this before it got out of hand. (Disclaimer: I am the former Operations / Support / Fraud Investigator for Balanced Payments). As it turns out, the CEO of BalancedPayments is (there is just no nice way to put this) an unethical bag of scum. He recently went on some kind of insane power trip, completely disregarding the needs of his customers, putting me on unpaid leave for ... reporting an incident of fraud to a bank. I reported an incident exactly like the one Chad discusses here, but the dollar amount stolen was much higher, and the fraudster a repeat offender. Anyway, after that last meeting where he was sneering and enjoying way too much the power trip of getting to "fire" somebody, I can confidently exhort that Balanced should not be trusted. It's important that any company a marketplace entrusts its financial data with is an ethical one. So, yeah, looks like I'm on the job market; ping me : http://lnkd.in/NuBGDY http://lnkd.in/NuBGDY
- whit537 14y agoWell, this thread just took a turn for the ... wow.
- steve8918 14y agoThere are so many things wrong with this post, I would strongly advise you to delete this. Besides the libel, it doesn't really paint you in a good light either, especially if you're going to be looking for a job. I would suggest keeping your dirty laundry off the Internet, and delete this post.
- shardling 14y agoHow does it paint them in a bad light?
- tlrobinson 14y agoWhistle blowing is one thing, calling people names is another. It makes him sound vindictive.
- jacquesm 14y agoAny system handling funds should be approached from the angle of minimizing the potential for fraud. If you don't do that right from day one there will be a lot of hard lessons which are more than likely to kill your company. Please team up with a company that has the experience to deal with this, balanced (which should have been your first gatekeeper here) dropped the ball in a terrible way, their anti-fraud measures should have definitely tripped over this so clearly they're not in control of the situation. From your posting and the comments here it is clear that you have the right general idea but you lack the relevant experience and tools.
- whit537 14y agoThanks, I started a ticket for this: https://github.com/whit537/www.gittip.com/issues/357 https://github.com/whit537/www.gittip.com/issues/357
- deleted 14y ago[deleted]
- noagendamarket 14y agoShould have used bitcoin :X
- Codhisattva 14y agoSo basically this is the most popular article about Gittip?
- whit537 14y agoYes, though HNSearch hasn't quite caught up yet: http://www.hnsearch.com/search#request/submissions&q=gittip&sortby=points+desc http://www.hnsearch.com/search#request/submissions&q=git...
- loceng 14y agoBest of luck. I imagine noone imagines themselves being in this situation.
- splicer 14y agoMy GF just found out a few hours ago that she was the victim of a similar scheme. Someone used her Amazon account (which has her credit card info) to donate to a Kickstarter account. Unfortunately, she has no way of finding out which Kickstarter account. Luckily, her credit card company took care of everything without a hassle. She also spoke with Amazon customer service, and they "were completely useless and almost hung up because they didn't know what Kickstarter was."