Live data from Hacker News

API providing threat analysis of any given IP address

fraudguard.io

51–60 of 84 posts

Re: API providing threat analysis of any given IP address

#51

Earlier quoted context omitted.

It's my fault. I'll try to find a way to get this data and eventually adjust my code to not include non-exit relays or at least recategorize them as a lower severity.

Why would they increase the threat profile of an IP in any way at all ? An exit node, sure, but a relay? What possible threat could a relay pose?

Doesn't really matter - it happens. I'm not specifically talking about the OP's service but rather another third party list that was purchased by other companies. My IP was banned. Whether it should have been or not is up for debate, but I can tell you I was confused for a week straight when I was getting cryptic Hulu/Netflix/Bank/etc error messages.

Re: API providing threat analysis of any given IP address

#52
post #49
post #34

Earlier quoted context omitted.

If it's default ports, you can just probe on login and deny it. We do this for a game I've admined for, and it's in the terms of service. Common L2TP, PPTP, etc.

Since the OP said: > I help develop a fairly popular webgame. ... unless the web-based game relies on a plugin that can skirt the browser's sandbox, there's no way to probe for active ports.

You can ask the server to do it for you.

Re: API providing threat analysis of any given IP address

#53
post #47

I like this, but I have to tell you what I've been looking for in one of these services for forever. I help develop a fairly popular webgame. One of our biggest headaches is people who are evading bans by using VPNs (public or not), VPSes, etc. Although we've outright blocked some large chunks of IPs (AWS, for instance), I've never seen a good service that identifies those specific blocks. Sometimes I go manually dig…

> One of our biggest headaches is people who are evading bans by using VPNs (public or not), VPSes, etc. Although we've outright blocked some large chunks of IPs (AWS, for instance) Please don't do this. It's perfectly legitimate to route one's traffic through other nodes one owns. Please consider other ways of dealing with banned players — perhaps make creating an account slow and/or costly.

We've examined all the options. We already use browser fingerprinting, and that takes care of a good percentage of it, but for the truly committed there are really only two options: Blocking all VPNs, or using supercookies. I'm actually a bigger fan of the supercookie solution, but one of the other developers is staunchly against that. It's an ongoing battle.

The problem with the slow/costly account thing is that one of the big draws of our game is that there's no registration necessary. You can jump in a game instantly by pressing 'Play Now', and you just get named 'Some Ball 1/2/3/4/etc' and tossed with the registered players.

Re: API providing threat analysis of any given IP address

#54
post #7

If the creators are on HN, curious to know what sets this apart from other threat intel services like IBM X-Force, ThreatConnect, VirusTotal, Carbon Black, etc.

I'm Ryan, one of three devs that built FraudGuard.io. The answer is basically price. We do EVERYTHING ourselves and try to keep price extremely fair. We have plans that start at $10 /month and we also have a small free-for-life plan too. Thats the best answer. The secondary part is we want a simple way for any dev off the street to integrate with api.fraudguard.io in 5 minutes. Imagine you are a small company and you…

Hey Ryan, I applaud the free tier and think it's important, but I'd caution that it can be awfully hard to make a business-sustaining revenue on $10/mo. I think it's smart to start low and compete on price, but I think there's value here, it's why there are larger competitors in the space, and if you can climb that value chain and raise prices along the way you will be better off for it.

From a merchandising POV, you could consider moving up-market by building new more powerful features and giving them only to the $25 plan. Then, rename the plans to match who you expect to buy them. People identify with who they are more naturally than they do a number of requests per month.

Also, congrats on shipping.

Edit: Also, pre-fill the form with the visitors own IP -- or better yet just display the results?

Re: API providing threat analysis of any given IP address

#55

Earlier quoted context omitted.

We never considered it I guess. Like someone else already mentioned there are other options out there but their prices are insanely ridiculous. Starting at $10 /month the three of us devs/creators feel like a competitive price will keep big and small customers happy hopefully long-term.

Look up articles on pricing plans. $10 is really low and makes your product seem less valuable (if it's so good why are you almost giving it away?). Cheap and free customers are often not worth the headache. You probably want the entry-level plan to be at least $39, $49 or so. Maybe more. Offer a free trial, and let that be enough for the cheap customers. I don't think there are 100s, let alone 1000s, of low-maint cu…

You know, I remember some old Tom & Jerry cartoon where an older mouse was explaining capitalism. How a factory that sells great volumes is able to reduce its margins and make even more total profit. Something like that.

So... what is wrong with a "low" price?

Must pricing nowadays be all game-theory where you want to extract the maximum amount without any regard for underlying value or actual costs?

It's almost a meme on HN: "you are asking too little!" "Raise your prices, double your consulting rate!" "Businesses don't even notice bills under $4999!"

I'm from Romania where my "business" cell phone (with 1GB internet and basically unlimited calls) is costing me $7/month. My build server on AWS used to cost me $25/month. Nowadays I use my own machines so I only pay for some leftover storage and I get a whooping $1.50/month bill on my card. I pay $39/month for accounting.

No matter how great a startup believes their thing is, a business has to cover a lot of expenses and 100 super-duper-products to purchase do add up. At some point it might even make sense to say: yes, I'll have an employee waste 1 hour each month on this problem instead of adding another vendor/product/contract to the list.

Re: API providing threat analysis of any given IP address

#56

Earlier quoted context omitted.

Look up articles on pricing plans. $10 is really low and makes your product seem less valuable (if it's so good why are you almost giving it away?). Cheap and free customers are often not worth the headache. You probably want the entry-level plan to be at least $39, $49 or so. Maybe more. Offer a free trial, and let that be enough for the cheap customers. I don't think there are 100s, let alone 1000s, of low-maint cu…

Thats really great advice, we're talking about it on Slack now. Thanks

As a converse to this....

If you raise your price, you will only end up dealing with businesses that have identified a need for your product, and know exactly how much fraud and other issues cost them.

With your price as is anyone can use it for any purpose, including those that don't involve losing money because of a fraud transaction.

I considered using you for my site just to get GEO-IP. Sure, I could setup a geoip database myself and keep it in sync manually, but at your price point... it was a no brainer.

Plus I'd get threat analysis thrown in so I can know if one of my users isn't able to see the site because Cloudflare is blocking them for being a tor exit node.

But of course if you charge $1000 a month for that, I won't use it for 'any purporse'. I'll just use it for pre-screening new subscriber accounts (and not free ones) because that's the only time it'd make sense.

Re: API providing threat analysis of any given IP address

#58

Earlier quoted context omitted.

Thats really great advice, we're talking about it on Slack now. Thanks

As a converse to this.... If you raise your price, you will only end up dealing with businesses that have identified a need for your product, and know exactly how much fraud and other issues cost them. With your price as is anyone can use it for any purpose, including those that don't involve losing money because of a fraud transaction. I considered using you for my site just to get GEO-IP. Sure, I could setup a geoi…

Look at the numbers again. 1,000,000 checks a month for $25? Even for an ad-supported site (using the checks for commenting) will get vastly more revenue and be able to afford it.

Remember, at $10 for $100, he has to convert 10x the number of accounts. People that are considering setting up their own DB usually don't fall into the category of "good SaaS customers".

Re: API providing threat analysis of any given IP address

#60

Earlier quoted context omitted.

Look up articles on pricing plans. $10 is really low and makes your product seem less valuable (if it's so good why are you almost giving it away?). Cheap and free customers are often not worth the headache. You probably want the entry-level plan to be at least $39, $49 or so. Maybe more. Offer a free trial, and let that be enough for the cheap customers. I don't think there are 100s, let alone 1000s, of low-maint cu…

You know, I remember some old Tom & Jerry cartoon where an older mouse was explaining capitalism. How a factory that sells great volumes is able to reduce its margins and make even more total profit. Something like that. So... what is wrong with a "low" price? Must pricing nowadays be all game-theory where you want to extract the maximum amount without any regard for underlying value or actual costs? It's almost a me…

1 million checks a month. If the problem rate is even 1%, that's 10,000 "problems" that need to be resolved. At 1/minute, that's a full-time person on the job! If that's not worth $$$$, the business isn't in the target audience.

And for people using this for fraud, it's gonna take more than a minute, and there might be even more damage. For instance, avoiding chargebacks on 0.1% would more than pay for itself. And that's a good selling point: "Our product will save you $x% a month". It makes it a no-brainer, instant ROI.

So getting, say, $995 vs $25 means he has to find 40x less customers! He can afford to spend a bit on sales. It's a meme on HN because it's true and us engineers have a terrible habit of repeatedly undervaluing things.

He could even offer a "pre-launch" plan if he's worried about startups not wanting to rack up bills before actually having customers. That way they can maintain price plan integrity.

Overall I feel HN/engineers (myself included; I have to force myself here) worry too much about edge cases and keep thinking somehow these cases will make a serious business.

Post reply on HN