Live data from Hacker News

'50% of transactions were fraudulent' when Steam accepted Bitcoin for payments

pcgamer.com

251–260 of 333 posts

Re: '50% of transactions were fraudulent' when Steam accepted Bitcoin for payments

#251
post #8

Unfortunately no details were given about what makes 50% of all bitcoin transactions “fraudulent” ? What does that even mean? * did someone try to send something other then bitcoin to a ₿ address? * did a client claim he payed and did the payment seem to fail on his end? * did a client not realise that you as payee also pay for the network fee? Nowadays these kind of problems would be easily prevented by using bitcoi…

I remember a period somewhere in the 2010s where it wasn't uncommon to see a business experiment with accepting Bitcoin (as Steam did), before transaction fees made it impractical. Given the way people talk about LN, and the (quite understandable!) desire to avoid credit card transaction fees, why don't we see more businesses accepting it? (Asking this in good faith; I am admittedly ignorant about LN and have not tri…

I think it’s just a matter of businesses perceiving the potential revenue increase not worth the overhead, combined with the resulting slow growth and development of ecosystem of service providers.

Running an independent node does take some management above that of a normal bitcoin node and merchant tooling and open source integrations are still coming together (though there are some good and dependable options). A merchant will need to keep an eye on their incoming liquidity, or use a service provider that does.

That being said, once you’re actually using it it’s a great experience, and for the individual enthusiast running a node can be great fun.

One service provider is Bitrefill, where you can buy Steam credits (and much else) over Lightning with a throwaway email faster than it takes for me to dig and type out a credit card out of my wallet or go through the SMS2FA BS of whatever virtual credit card-supporting bank I can find in the country I happen to be living in. Just copy and paste an invoice or scan a QR, depending on your wallet interface.

I do hope we see Lightning support in Coinbase Commerce et al soon. Unfortunately BitPay, one of the oldest and I think the most widely used payment service provider for Bitcoin, has become pretty much unusable as of lately and even if they did add lightning support it wouldn’t be interesting.

Re: '50% of transactions were fraudulent' when Steam accepted Bitcoin for payments

#252

Earlier quoted context omitted.

I’m visiting Macedonia. I changed the email address on my Capital One account (migrating off Gmail) and they froze all 4 of my cards. To unfreeze them, I had to provide my drivers license, social security card, and proof of residence in the USA & then wait two weeks. There was no process for accelerating the timetable. #expatlife

Did you notify Capital One you were in Macedonia at the time? Every time I’ve been abroad, I had to notify any card issuers first, just to make sure the charges weren’t flagged. Otherwise, this level of fraud detection and response should be considered normal (and good).

I did not notify them, but they can clearly see I’ve been using the cards for the last two months. And I’ve called my card companies in the past to notify them of upcoming travel, and they all told me it was unnecessary with the new chips. If I had changed my email using my laptop & VPN connection to the USA, maybe I wouldn’t have had a problem, but I used the mobile app.

I didn’t mind the cards getting frozen. It could have been fraud for all they knew. What I did not appreciate was the fact that it took two weeks & multiple calls to my credit union to resolve proof of address. I was lucky that I had my social security and with me, and that I had a backup credit card from a different bank, otherwise it’s don’t k is what I would have done.

Re: '50% of transactions were fraudulent' when Steam accepted Bitcoin for payments

#253

Context on what I believe they mean by "fraudulent". Steam back in the day used to accept 0 confirmation bitcoin spends. This means that the transaction has been gossiped on the bitcoin p2p network but had not yet been mined into a block and thus had minimal finality guarantees. Steam could see that they were going to receive a bitcoin payment (when the transaction was mined into a block) and would credit the users a…

BCH is trying to keep 0-conf alive by eliminating the artificial block space constraint, removing RBF (which is really dangerous when you have an RBF-flagged grandparent tx that maybe your wallet is t looking for), and implementing double spend proofs to warn tx recipients as soon as a double spend tx appears on the network. It’s obviously impossible for an unconfirmed Bitcoin tx to be guaranteed secure, but the risk can be minimized, which is nice for everyday, low value transactions.

Re: '50% of transactions were fraudulent' when Steam accepted Bitcoin for payments

#254
post #161

Earlier quoted context omitted.

I only have a layman understanding of bitcoin, and I've never used a cheque in my life, but would it not be more like "someone wrote you a cheque and there's no guarantee it won't bounce when you try to cash it in"? Which, again maybe showing my complete lack of knowledge of cheques, is how I thought they worked in the first place.

Here in the UK we had "cheque guarantee cards" - essentially a debit card without a live connection to the bank. When you wrote the cheque the shop took your card details as well and that meant the bank guaranteed to cover the value of the cheque if it bounced (up to a maximum amount). If your cheque bounced your account went into an overdraft for that amount plus a hefty fee. It meant shops didn't need to worry abou…

The US banks I worked with would just overdraw your account (up to an amount), then, overnight, reorder the transactions so the big ones came first and all the little ones came “after” the account went negative and hit you with hundreds of dollars in overdraft fees. I don’t miss the early 2000s.

Re: '50% of transactions were fraudulent' when Steam accepted Bitcoin for payments

#255
The big thing here is that blockchain is a solution in search of a problem and none of the applications that have been mooted have made sense. I have no doubt that it's going to collapse, but I wouldn't dare to put a date on it. I was pointing out the absurdity of it 10 years ago and it's still sucking people in. Then again, people still get suckered into Ponzi schemes 100 years later so ?

Re: '50% of transactions were fraudulent' when Steam accepted Bitcoin for payments

#256
post #186

Earlier quoted context omitted.

Shouldn’t it make most sense in contexts exactly like Steam, where the merchant can take the goods back in case of a fraudulent transaction?

It did, and they did. That's probably exactly why they allowed it like that in the first place - if the transaction is fraudulent then simply remove the user's entitlement, but offer instant access for better experience.

Then the next question is this: why did those 50% even bother to try? Reselling for less btc (or fiat) keys that would soon be revoked? Has piracy decayed to the point where desperate consumers would really fall for something like that?

Re: '50% of transactions were fraudulent' when Steam accepted Bitcoin for payments

#257
post #208

Earlier quoted context omitted.

You say wait 3-6 blocks -- which makes sense for large transactions, but are there cases where 1 blocks have been getting reversed? Is this happening now because some parts of the network are on stale or diverging info?

These are called "orphan blocks" and they happen very regularly, like everyday. https://bitcoin.stackexchange.com/questions/2170/how-often-f...

That’s not really a double spend issue, though. Usually the blocks are found within a very short time between them. Unless the double spender is coordinating with a miner, orphaned blocks are a non-issue. It’s 51% attacks that would be the real problem.

Re: '50% of transactions were fraudulent' when Steam accepted Bitcoin for payments

#258
post #256

Earlier quoted context omitted.

It did, and they did. That's probably exactly why they allowed it like that in the first place - if the transaction is fraudulent then simply remove the user's entitlement, but offer instant access for better experience.

Then the next question is this: why did those 50% even bother to try? Reselling for less btc (or fiat) keys that would soon be revoked? Has piracy decayed to the point where desperate consumers would really fall for something like that?

> keys that would soon be revoked

The BTC acceptance didn't even vend keys, it was just access on the primary steam account.

Re: '50% of transactions were fraudulent' when Steam accepted Bitcoin for payments

#259

Context on what I believe they mean by "fraudulent". Steam back in the day used to accept 0 confirmation bitcoin spends. This means that the transaction has been gossiped on the bitcoin p2p network but had not yet been mined into a block and thus had minimal finality guarantees. Steam could see that they were going to receive a bitcoin payment (when the transaction was mined into a block) and would credit the users a…

BCH is trying to keep 0-conf alive by eliminating the artificial block space constraint, removing RBF (which is really dangerous when you have an RBF-flagged grandparent tx that maybe your wallet is t looking for), and implementing double spend proofs to warn tx recipients as soon as a double spend tx appears on the network. It’s obviously impossible for an unconfirmed Bitcoin tx to be guaranteed secure, but the risk…

With no RBF how will you prevent TX's from getting stuck in a high fee environment? I know BCH thinks block space should be unlimited which means TX fees will never get high but i don't think the economics works out there.

Re: '50% of transactions were fraudulent' when Steam accepted Bitcoin for payments

#260

Earlier quoted context omitted.

It did, and they did. That's probably exactly why they allowed it like that in the first place - if the transaction is fraudulent then simply remove the user's entitlement, but offer instant access for better experience.

“Fraud” and “simply” don’t belong in the same sentence. This is coming from someone who’s spent years working with many fraud departments in major companies. Wack-a-mole doesn’t work, they just scale their account creation.

I think it does, there are levels of fraudulent activity. Calling "simply" doesn't mean to make it benign.
Post reply on HN