19 ms·
(Disclaimer: I write fraud detection algorithms for Eventbrite, and work closely with the team that built the fraud systems at PayPal.) I'm sorry this happened
by pyduan 13y ago
(Disclaimer: I write fraud detection algorithms for Eventbrite, and work closely with the team that built the fraud systems at PayPal.)
I'm sorry this happened to you. I personally believe the burden of proof should be on the company. However, that some choose to err on the side of caution is perfectly understandable.
The thing is that companies that handle credit card payments are very vulnerable to fraud because they are liable for consumer chargebacks [1], at least in the US. This is particularly unfortunate since US cards also happen to have pretty poor security (which also has probably something to do with the fact the merchants are liable, and not the banks). Stolen credit card numbers are extremely easy to obtain (cf. Target breach) [2], and once this is done fraudsters have basically two main ways to extract money out of it:
1) Use the card number to make purchases online, or better yet, find a self-service platform that lets you become a merchant then purchase your own offerings (eBay/PayPal, Eventbrite, etc.).
2) Duplicate the card (made much easier by the US' slowness in adopting chip-and-pin), and use it to pay for goods or to load the money on some account. Square is perfect for this since you own the card-reading device, which makes it much less risky than attempting to use a duplicated card at an ATM or at a retailer.
Now, the problem is that you potentially need a lot of cushioning to withstand fraud attacks: while the processor only makes profit from the transaction fee, they are liable for the entirety of the charge, so one single fraudulent transaction can wipe out the profit of thousands of good ones. Being attacked by a fraud ring for hundreds of thousands or even millions of dollars in a single day is not impossible (in fact we've seen this happen, and Eventbrite's transaction volume is much smaller than PayPal's or even Square's), so this is a lot of risk to take on for a company, especially a startup.
Regarding the bad customer service you've received, there is a specific reason why companies often decline to comment on fraud security checks: by allowing you a way of recourse, they would be disclosing information about how their system works, which makes it potentially vulnerable to attackers. For example, if they said "sure, just send us a copy of your driver's license and we'll lift the ban", this would be a signal for fraudsters to try to fake such documentation.
Overall, it's a complex issue and unfortunately frustration is part of the game (trust me, if PayPal could have found a way to make operations smoother and less frustrating, they'd have done it). At Eventbrite we've chosen to assume this risk and be more liberal with verification because we decided that providing a good user experience is worth losing some money over (and because we have faith in our ability to keep up with the fraudsters), but this is a decision every company that handles money has to make and it's not an easy one.
[1] http://en.wikipedia.org/wiki/Credit_card_fraud#Merchants http://en.wikipedia.org/wiki/Credit_card_fraud#Merchants
[2] fun fact: you'd be surprised to see how big this underground economy is; it's so well-oiled that some sellers even provide customer service on the credit card numbers they sold, and offer money back guarantees if the card has already been deactivated
- kevinchen 13y agoThanks for the insight -- that makes a lot of sense. I guess you could forge a driver's license with a skilled Photoshopper on the team, since those are hard to validate. (as a consumer, it's still frustrating though.)
- ubernostrum 13y agoThe thing is, "but fraud and chargebacks" are not an excuse for treating people like shit. If you can't provide even the bare basic minimum of customer service, you deserve to be bankrupted by a competitor who will.
- usaphp 13y ago> ... To treat people like shit... Don't you think it's an overstatement? At least They responded to his question and he did not lose any money.
- ruswick 13y agoThis makes sense. These policies are probably warranted for actual credit card companies. But, the OP's grievance was with Square, which isn't liable for fraud and probably doesn't need to use such excessive security. Frankly, it often seems as though many consumer financial companies (like Mint and Square, etc.) go out of their way to make their service harder to use simply to increase their "legitimacy." Sites like Mint refuse to remember login information and automatically log users out after a short period of time. As far as I'm aware actual bank account can't be accessed from Mint; data is only reported. In the grand scheme, this information is not particularly important. It would be far more catastrophic for someone to gain access to my email account or social network profiles (where they could actually do damage) than it would be for them to learn what (little) I have in my bank account. Yet, we all survive using only standard security on most of our other accounts. Moreover, there seems to be a huge disparity between credit card security in the real world and credit card security online anyway. In the real world, I hand my credit card to numerous people with whom I have no relationship and whom I can't trust at all, every single day. No one thinks twice. Yet, when someone wants to look at their bank statement, they need to bend over backwards. It just doesn't make sense. Integral pieces of the financial apparatus might need to be totally secure, but consumer web apps that don't ever handle money don't, and should put user experience first.