Live data from Hacker News

Candy Japan 2015 Year in Review

candyjapan.com

1–10 of 67 posts

Re: Candy Japan 2015 Year in Review

#3
Interesting to read about those fraudsters. Really annoying when you're a small business. I remember reading something similar from Gittip[0], and also mentioned on the linked blog post, jsbin[1].

I wonder what other small startups are using to detect / prevent this kind of fraud?

Are there any good services in this space? and why won't recurly/stripe et al bundle this in? (or maybe they do, and I just don't know about it...?)

[0] http://blog.gittip.com/post/35057426257/stolen-money-on-gitt...

[1] https://remysharp.com/2015/09/17/jsbin-toxic-part-4

Re: Candy Japan 2015 Year in Review

#4
See the recent article on [hoverboards @ Buzzfeed](http://www.buzzfeed.com/josephbernstein/steal-a-credit-card-...) and [responses here @ HN](https://news.ycombinator.com/item?id=10727371) - I believe they mention options to help with fraud detection but it's not clear how useful they are. Sorry.

Re: Candy Japan 2015 Year in Review

#5
I think someone else mentioned this in another post about this. Thought it was a great idea so I'll repeat it here:

To prevent fraudsters from using you to authenticate their stolen credit cards, set it up so that every purchase automatically redirects to a 'order successful' page. After seeing that a few their credit card numbers all seem to work on your site, the fraudster will realize they can't use your site to test and move on. In the back-end, turn on manual approval of each purchase and let through the ones you deem legitimate.

Should a legitimate customer mistype their credit card info, send them a follow up email with a link to the order page briefly explaining to them the situation and asking them to enter their details again.

(If there's some issue with this method I haven't thought of, let me know.)

Re: Candy Japan 2015 Year in Review

#7
post #5

I think someone else mentioned this in another post about this. Thought it was a great idea so I'll repeat it here: To prevent fraudsters from using you to authenticate their stolen credit cards, set it up so that every purchase automatically redirects to a 'order successful' page. After seeing that a few their credit card numbers all seem to work on your site, the fraudster will realize they can't use your site to t…

How does one deem a purchase as legitimate or not?

And how would you differentiate between a legit customer who mistyped their info versus a fraudulent attempt?

Re: Candy Japan 2015 Year in Review

#8
post #5

I think someone else mentioned this in another post about this. Thought it was a great idea so I'll repeat it here: To prevent fraudsters from using you to authenticate their stolen credit cards, set it up so that every purchase automatically redirects to a 'order successful' page. After seeing that a few their credit card numbers all seem to work on your site, the fraudster will realize they can't use your site to t…

Best reply, but... How often is a typo made (1:1000?), how much time for support staff is needed and how many lost orders due to a ~24 hour delay in some orders being placed. Also, easy to flood the system with bad orders that need to be manually sorted, like a fake order DDoS.

Re: Candy Japan 2015 Year in Review

#9

Before people suggest bitcoin--and I love bitcoin--it probably wouldn't solve this guy's fraud problem. Yes, it would stop the fraud, but there are simply too few people willing to pay in bitcoin.

For what it's worth, I'm a long time Candy Japan subscriber and I would be willing to pay in BTC. Hell, I'd pay more just to be supportive of businesses willing to accept BTC.

Re: Candy Japan 2015 Year in Review

#10

Before people suggest bitcoin--and I love bitcoin--it probably wouldn't solve this guy's fraud problem. Yes, it would stop the fraud, but there are simply too few people willing to pay in bitcoin.

Wouldn't bitcoin give rise to the opposite problem - consumers paying bitcoin now shoulder all the risk of buying from a bad vendor.
Post reply on HN