Live data from Hacker News

Candy Japan hit with credit card fraud

candyjapan.com

161–170 of 208 posts

Re: Candy Japan hit with credit card fraud

#161

I also had something like this happen on a site I built for my wife's work's site, a Boys & Girls Club[0]. I had a donation button that let people make an open donation to the club. It's such a tiny site with little traffic, but apparently the SEO must be decent because somehow it got targeted by people appearing to come through Brazil and Poland. Suddenly one day, hundreds of donation attempts. Checking the failed t…

Wait, why would someone fraudulently donate somewhere? I don't understand the motive.

From what I've read in research, the reason is four-fold-ish.

1: Using the site as a credit card validator. Only the real ones will get through.

2: By making donations to places with a stolen credit card little bits at a time, it establishes a wider pattern of use for that card. Fast forward a couple steps ahead, the purchases are getting a little weirder each time, and before you know it, you're at whatever level people use stolen cards to buy.

3: Tiny non-profits generally do not have a great deal of extra man-power to deal with such things, and there's a better chance that this sort of behavior goes unnoticed.

4: When people see weird charges on their card, some people are more likely to feel bad enough taking away money from a non-profit organization that they won't report the abuse, or they may not question it if the card is joint-used.

I'm sorry that I don't have sources on these, the research was from a couple of months ago. It's pretty frustrating and there seems to be little retribution for things. You have to just change your charge flow and move on. :/

Re: Candy Japan hit with credit card fraud

#162

Earlier quoted context omitted.

> my card was practically useless That's because merchants pay 3% or more for a creditcard payment, and something like 0.8% for a local bank card payment (with the online equivalent iDeal). On top of that, there is much more risk accepting the creditcard with chargebacks, while the banks guarantee normal/iDeal payments. So most merchants here really dislike creditcard payments, it "costs them" much more. Of course I…

The EU is introducing a cap on credit card interchange fees of 0.3%, and 0.2% for debit cards. This is expected to lead to much lower fees for merchants that accept credit cards (and ultimately, consumers). The new regulations apply from 09 December 2015: https://www.gov.uk/government/news/credit-and-debit-card-fee...

You can ask your payment processor and they will say their prices will stay the same.

Check this response from paypal: PayPal told us that the “European Union’s regulation of Multilateral Interchange Fees (MIF) does not apply to PayPal as we are not an inter-bank card scheme and the fees PayPal charges businesses are not interchange fees”. http://tamebay.com/2015/03/new-eu-caps-on-credit-and-debit-c...

Re: Candy Japan hit with credit card fraud

#163

I commented this on yesterday's jsbin article, and I'll write it again. Don't implement the payment processing code yourself. (And using Stripe is _still_ implementing it yourself - they supply only one part of the process.) Writing this code will take time that you are not using to develop and market your product. (cf opportunity cost). Your code will be buggy. Your code will be weak. Your code will not support the…

Totaly ignorant here: Why would using FastSpring be safer than using Stripe?

Fastspring has a fraud protection system in place. Strip has not and does not prioritise it according to this quora comment by one of its co-founder. https://www.quora.com/How-will-Stripe-overcome-the-huge-loss...

Fraudulent chargebacks is bad, both economical and psychological. As an online seller it is part of life, but you want to keep it to a minimum, say < 1% of all transactions. I wholeheartedly support the sentiment of the OP, do not use Stripe nor do this in-house. Instead, use a payment provider with a proven fraud protection system, such as PayPal.

Re: Candy Japan hit with credit card fraud

#164
post #152

I also had something like this happen on a site I built for my wife's work's site, a Boys & Girls Club[0]. I had a donation button that let people make an open donation to the club. It's such a tiny site with little traffic, but apparently the SEO must be decent because somehow it got targeted by people appearing to come through Brazil and Poland. Suddenly one day, hundreds of donation attempts. Checking the failed t…

How can they not be willing to pay a transaction fee from even PayPal for donations? Seems their options right now is to take donations via a service like Paypal with a transaction fee, or just take no donation.

I don't want to speak for them or go into their financials, but in a literal sense, every dollar counts. When we were talking about taking donations and registrations online, they were frazzled about the transaction fees, and I suggested working them into the costs. (It was only, say a $3 increase in membership price.) The truth of the matter is that some people don't have that much to spare.

Of course, that conversation happened way before the site was used as a credit card validator. Trying to explain to them the bad side of charge backs and why this is a big deal is an on-going challenge. The last time I discussed it with them, they kept asking me if they were going to get stuck with all the transaction fees.

And, being a developer, my first gut instinct is stepping back and saying "you're wasting money here and here and here and here, cut down these inefficiencies and it'll all balance out." However, it's not as simple as that. Everyone needs to be on board, and the people in charge of these things are already overworked and not highly paid.

A catch-22, I suppose. I try to stay out of it as best I can. I made them the site for free in exchange for our two kids to use the club's stuff for free, and with those inefficiencies I hinted at, I can't afford to get caught in being the role of business consultant too.

Re: Candy Japan hit with credit card fraud

#165
post #155

Earlier quoted context omitted.

Not too different from giving out your credit card number. I can reverse any direct debit online with two clicks and a second-factor authentication. Disputing a credit card transaction here on the other hand requires filling out a form, signing it on paper, sending it via post, and waiting for the response.

Very different in the US. US consumer protection laws treat credit and debit cards differently. They favor credit cards. The gap between the two is up to the goodwill of your bank. I prefer to rely on law than goodwill. I have never had a problem with getting a refund on a credit card charge I claimed was fraud. I have no idea why people choose to use a debit card over a credit card here.

The thread might be titled "People tend to use the safest (to them) form of payment available". If your credit card laws protect the consumer a lot (like in the US) then you use credit cards. If you have some in-country debit system with better protection you use that instead.

One reason it's so hard to unseat credit cards in the US is because most of the advantages of the alternatives are on the sellers side. The consumer doesn't seen any benefit from switching to Apple Pay or whatever. Most merchant agreements don't even let stores charge less for using non-credit card type payments (although some stores do anyway).

As a US citizen I use my credit cards constantly. It's an instant 1% discount on everything I buy (thanks to the cash back), and its fast and easy. I pay it off every month to avoid paying interest. There's basically no downside to me.

The story would be different if retailers were allowed to directly pass on the service fees however. I would definitely think twice if every time I used it I got surcharged $0.50.

Re: Candy Japan hit with credit card fraud

#166

Earlier quoted context omitted.

In many countries (such as where I'm from, Sweden, or where I live now, Japan), debit cards and credit cards are interchangeable, and you can't even tell by looking at the card if it's debit or credit. They're both VISA or MasterCard branded, and what's backing it is only the business of the cardholder, not the merchant. I remember Maestro cards in Sweden as being for under-18's, and then when you become an adult you…

In Canada, a distinction is made because the fees on debit are much lower (comparable to cash handling costs) and the banks have put tremendous marketing efforts in pushing for debit cards and branding them "Interac." That said, the cards themselves use exactly the same technology, look the same and debit cards are usually Maestro/Cirrus or Visa/Plus compatible so we can do debit transactions in europe. The online ve…

Yeah, I have a debit card that works as a Visa card if you choose to use it that way. I never use it though because if someone steals the number it is way harder to deal with fraud on a Debit card than on a Credit card. The consumer protection laws on Debit cards are much weaker than the ones for Credit cards.

We probably have old misbehaving banks to thank for our relatively consumer friendly credit card laws. In countries where the banks weren't quite so abusive the laws could be much weaker and give Debit cards an advantage.

Re: Candy Japan hit with credit card fraud

#167
post #159

One other tip: Block all TOR exit node IP's. You'll find mostly fraud and spam coming from them. Deep down, I would love to support TOR in principle. I know there are people living in oppressive regimes that need access to information. I want to support that side of TOR. In reality it's still the transport tunnel of choice for scammers and criminals. The costs just don't outweigh the benefits. Considering the CDNs th…

Hopefully nobody is living in a regime so strict they can't order candy delivery without fearing for their life.

Never underestimate how far San Francisco will go to impose its will.

Re: Candy Japan hit with credit card fraud

#168

Earlier quoted context omitted.

Wait, why would someone fraudulently donate somewhere? I don't understand the motive.

From what I've read in research, the reason is four-fold-ish. 1: Using the site as a credit card validator. Only the real ones will get through. 2: By making donations to places with a stolen credit card little bits at a time, it establishes a wider pattern of use for that card. Fast forward a couple steps ahead, the purchases are getting a little weirder each time, and before you know it, you're at whatever level pe…

Thanks for that, that's very interesting!

Re: Candy Japan hit with credit card fraud

#169
post #88
post #80

Earlier quoted context omitted.

This is true but in this case he's not directly integrated (he's using Recurly). Better fraud tools is something we are actively working on.

Would it be possible to give us a better ETA on when something is likely to be implemented? I was thinking of using recurly and this has put me off somewhat.

FYI take a look at SiftScience and ThreatMetrix products. They wont process your transaction, but at least one of them offers a zero chargeback guaruntee, at $0.03 per transaction I believe.

Re: Candy Japan hit with credit card fraud

#170

Earlier quoted context omitted.

These verification mechanisms don't freak people out once people are used to them. Pretty much anyone who uses credit cards to buy anything online in Europe will have encountered this system before and will be more suspicious if they don't see it! Using customers birthdate is indeed a very poor authentication mechanism, but even that is going to defeat the majority of fraudsters who are simply trying to bulk-authenti…

> My bank asks for three random characters from my online banking password (the same mechanism used to log in to my online banking) which provides enough security without risk of revealing the full password to key-loggers, etc. How can the bank know what any of the letters in your password are unless they are storing it insecurely?

They could be storing a hash for each trigram in the password (assuming he meant three consecutive characters starting from a random offset). Although it might still leak information that could improve a brute force, I suppose.

It's not a good solution anyway. A phishing page could easily claim the entered password was wrong and ask for another one (starting at another offset). Most passwords are probably <= 9 characters, so you'd have the full password after 3 attempts.

Post reply on HN