Live data from Hacker News

'50% of transactions were fraudulent' when Steam accepted Bitcoin for payments

pcgamer.com

221–230 of 333 posts

Re: '50% of transactions were fraudulent' when Steam accepted Bitcoin for payments

#221

At this point is BTC a good idea? Does it actually provide any damn value at all at a macro level?

It's a permission-less payment network, can you not think of a single thing that would be useful for?

Xi angrily joins the chat.

Re: '50% of transactions were fraudulent' when Steam accepted Bitcoin for payments

#222

Earlier quoted context omitted.

The only real use case that people keep mentioning is transferring large-ish amounts of money (>1000 USD) internationally.

Which is not hard if you have a bank account that is in any tier above poor person consumer level.

Unless you're Russian now

Re: '50% of transactions were fraudulent' when Steam accepted Bitcoin for payments

#223
post #220

Context on what I believe they mean by "fraudulent". Steam back in the day used to accept 0 confirmation bitcoin spends. This means that the transaction has been gossiped on the bitcoin p2p network but had not yet been mined into a block and thus had minimal finality guarantees. Steam could see that they were going to receive a bitcoin payment (when the transaction was mined into a block) and would credit the users a…

You don't even need to do anything on bitcoin side if you value the 0 confirmation. You offer the goods or services before you receive the payment. It's like a restaurant that serve the food first and receive payment later. The restaurant do that because they trust the customer to pay up.

This doesn't work,people don't know the amount to pay before they finish their meal.

Re: '50% of transactions were fraudulent' when Steam accepted Bitcoin for payments

#224
post #211

Earlier quoted context omitted.

> Does bestbuy run analytics on the cash they receive to see how much % of their cash purchases were "fraudulent"? Credit card companies do, yes.

Again, that's because credit card companies and/or merchants eat the cost of fraud. That's not the case with cash. The FBI isn't going to be raiding bestbuy's stores looking for stolen bills.

In this case, it's still private self interest in the exact same way. If a stolen credit card is used to buy Bitcoin, then Bitcoin is used in Steam, who eats the fraud and why would they not push against the others for restitution if it's all trackable?

Re: '50% of transactions were fraudulent' when Steam accepted Bitcoin for payments

#225
post #220

Earlier quoted context omitted.

You don't even need to do anything on bitcoin side if you value the 0 confirmation. You offer the goods or services before you receive the payment. It's like a restaurant that serve the food first and receive payment later. The restaurant do that because they trust the customer to pay up.

This doesn't work,people don't know the amount to pay before they finish their meal.

You pay up front in most cafeterias for example.

More likely the reason this isn't done is to allow customers to buy more (drinks/dessert, do so in a single transaction, and tip post-service. Not because the amount is unknown.

Re: '50% of transactions were fraudulent' when Steam accepted Bitcoin for payments

#226
post #161

Earlier quoted context omitted.

> There are many context where a 0conf tx makes sense, mostly IRL. I'm curious, like what? To me this is more like "someone wrote a cheque but there's no guarantee that they'll give it to you".

I only have a layman understanding of bitcoin, and I've never used a cheque in my life, but would it not be more like "someone wrote you a cheque and there's no guarantee it won't bounce when you try to cash it in"? Which, again maybe showing my complete lack of knowledge of cheques, is how I thought they worked in the first place.

Here in the UK we had "cheque guarantee cards" - essentially a debit card without a live connection to the bank. When you wrote the cheque the shop took your card details as well and that meant the bank guaranteed to cover the value of the cheque if it bounced (up to a maximum amount). If your cheque bounced your account went into an overdraft for that amount plus a hefty fee. It meant shops didn't need to worry about bounced cheques which customers could pay using them. It worked pretty well.

Re: '50% of transactions were fraudulent' when Steam accepted Bitcoin for payments

#227

Context on what I believe they mean by "fraudulent". Steam back in the day used to accept 0 confirmation bitcoin spends. This means that the transaction has been gossiped on the bitcoin p2p network but had not yet been mined into a block and thus had minimal finality guarantees. Steam could see that they were going to receive a bitcoin payment (when the transaction was mined into a block) and would credit the users a…

Depending on what it is, 3-6 is a _lot_. For something like a Steam game, it seems like waiting for 1 should be more than enough.

I say "more than enough" because can't they just revoke the key of whatever was purchased if it gets double-spent? Seems easy enough.

Re: '50% of transactions were fraudulent' when Steam accepted Bitcoin for payments

#228

Earlier quoted context omitted.

It did, and they did. That's probably exactly why they allowed it like that in the first place - if the transaction is fraudulent then simply remove the user's entitlement, but offer instant access for better experience.

“Fraud” and “simply” don’t belong in the same sentence. This is coming from someone who’s spent years working with many fraud departments in major companies. Wack-a-mole doesn’t work, they just scale their account creation.

Well then please explain what is difficult here. You initiate a purchase with bitcoin, valve instantly grants you access, then few hours later valve checks if the transaction has been confirmed in the blockchain or not. If it hasn't, then the entitlement is removed. What's not simple about it?

Re: '50% of transactions were fraudulent' when Steam accepted Bitcoin for payments

#229

Earlier quoted context omitted.

It did, and they did. That's probably exactly why they allowed it like that in the first place - if the transaction is fraudulent then simply remove the user's entitlement, but offer instant access for better experience.

“Fraud” and “simply” don’t belong in the same sentence. This is coming from someone who’s spent years working with many fraud departments in major companies. Wack-a-mole doesn’t work, they just scale their account creation.

What whack-a-mole? Just automate it so if it gets double-spent, you revoke the key. If you really feel like it, cancel the account if they keep doing it, but I'm not sure you even need to bother. What have you lost? The bandwidth to download the game?

Re: '50% of transactions were fraudulent' when Steam accepted Bitcoin for payments

#230
post #224
post #211

Earlier quoted context omitted.

Again, that's because credit card companies and/or merchants eat the cost of fraud. That's not the case with cash. The FBI isn't going to be raiding bestbuy's stores looking for stolen bills.

In this case, it's still private self interest in the exact same way. If a stolen credit card is used to buy Bitcoin, then Bitcoin is used in Steam, who eats the fraud and why would they not push against the others for restitution if it's all trackable?

> If a stolen credit card is used to buy Bitcoin, then Bitcoin is used in Steam, who eats the fraud

The credit card company and/or cryptocurrency exchange would eat the fraud.

>and why would they not push against the others for restitution if it's all trackable?

This is moving the goalposts. We're not discussing whether such a scheme would benefit banks/credit card companies/crypto exchanges, we're discussing whether valve implemented such a scheme for steam. I'm sure the aforementioned parties appreciate such a scheme, just as banks would appreciate a scheme where stores were checking the bills they accept were stolen or not. However, that says nothing about whether such a scheme exists, or whether steam was voluntarily doing so with no apparent benefit to itself. Nor does it change the fact that such a push was non-existent (or at least non-visible) in 2017.

Post reply on HN