Live data from Hacker News

The optimal amount of fraud is non-zero (2022)

bitsaboutmoney.com

171–180 of 203 posts

Re: The optimal amount of fraud is non-zero (2022)

#171
post #147

Earlier quoted context omitted.

That being said: GPS based speed limiters are cheap, effective and not dystopian as long as they don't send telemetry back home. > But the goal is not to bankrupt your citizens with fines, There is this one crazy trick to avoid speeding tickets. Cops hate it.

> GPS based speed limiters are cheap, effective [...] While this is technically true (the devices themselves are cheap and effective), the data required for them to work well doesn't exist. If the data exists at all, it is usually horribly out of date. So in practice there will be many cases where these devices limit you to the 30mph from last year's big construction project. Then you get rear-ended because nobody ex…

I feel like this "bad data" problem would disappear immediately if there were real world consequences for it being incorrect.

Which is to say, if you were to build out a system that limits speed based on some authoritative database of speed limits, then suddenly there's an incentive to make sure that database is actually correct (where there was no such incentive before).

Re: The optimal amount of fraud is non-zero (2022)

#172

Clickbaity, trying-too-hard title. The point being made is mundane: perfection is too expensive, so we settle for "good enough". This is near-universally applicable and near-universally understood. The author is trying to make it sound deep and meaningful with statements like "you should welcome some fraud", as though fraud is actually required for the system to function (clever counterintuitive point made, cue huge…

The comment directly above you on the page right now gives an example of people getting the trade-off wrong, so your dismissiveness is pointless. The framing is also relevant for another reason: choosing a conscious trade-off point means that you can choose to move it as circumstances dictate, which can be very non-obvious. There's currently a lot of noise in the UK media about dodgy PPE contracts issued during COVID…

> The comment directly above you on the page right now gives an example of people getting the trade-off wrong, so your dismissiveness is pointless.

I was only dismissing the way the article presented fraud tolerance as something deeper than a trade-off. I did acknowledge that the trade-off exists and in my other comment stated explicitly that I think discussion of how one finds the right trade-off is interesting.

On your COVID example, I agree that in an emergency it's worth pulling the lever as you put it, i.e. grease the wheels and get the stuff we need. But I wouldn't expect the extra spending to be directed disproportionately at cronies of the government, fraudulent or not.

Re: The optimal amount of fraud is non-zero (2022)

#173

Earlier quoted context omitted.

How you feel about reliable national ids really comes down to "do you trust the state or not". Error-prone-ness is a feature for people who want the state to be less powerful. Personally I think that for purely practical reasons national ids are good infrastructure. I don't think in 2023 a "weak" national identity system offers much protection against an adversarial government.

Forget trusting the state, do you trust the endless parade of crappy companies that will demand your national ID verification to but everything from house insurance to fortnight skins to prevent fraud, and then promptly lose it in a data breech without ever receiving meaningful punishment? Because that is the state of things.

Yep this is a fair concern. Proponents would say that a good implementation would mitigate a lot of the data loss issues we currently see (I work in the digital id space so not entirely disinterested here).

Right now the way we verify identity is "dumb" in the sense that we prove identity using document ids or photos. This is "too strong" - to prove I am over 18 or just "the account holder" I must present valuable document IDs or scans which disclose other things about me such as my exact date of birth or my legal name. It is also "too weak" in that any verifier who receives these things can present them to someone else and impersonate me.

Today, every entity we deal with who verifies our identity can also impersonate us. There are billions of ID scans absolutely everywhere, in realtor's offices and lawyer's cabinets, at car rental agencies, etc ad nauseum.

A good "digital id" scheme allows for cryptographic proofs of identity which are non-transferable between verifiers. It allows things like proving that I am John Smith who is over 18 and holds a driver's license in a way that does not allow the verifier to then present those to someone else and impersonate me. It can allow for proofs of uniqueness, e.g. I can prove that I'm a person you've seen before with id xxxyyy in your database without disclosing my name (if the verifier chooses not to collect that). It can allow "blinding", e.g. I can hand over a token to someone who doesn't need to "see" my actual identity details unless they initiate legal process (say car rental scenario) and then I can be notified if that happens.

It is likely that a lot of verifiers might choose to "over collect" (say, request up-front proof of my legal name when strictly speaking they don't need that to rent me a car) but this can at least be discouraged by measures like tuning service charges so that more invasive verifications cost them more and ensuring that verifiers are subject to different regulation tiers based on the scope of data they collect. Even if the entity loses my PII e.g. my name, DOB, phone number, the systems are designed to not allow anyone accessing that information to impersonate me.

Strictly speaking digital id schemes / properties are orthogonal to "national ids". There are centralised, de-centralised and more or less anarchic (p2p) "versions" of digital identity. However, a government operated scheme at the national level could reduce a lot of commercial capture and the kind of "waste" that happens when you need to stitch together many disparate data sources.

Re: The optimal amount of fraud is non-zero (2022)

#174

Clickbaity, trying-too-hard title. The point being made is mundane: perfection is too expensive, so we settle for "good enough". This is near-universally applicable and near-universally understood. The author is trying to make it sound deep and meaningful with statements like "you should welcome some fraud", as though fraud is actually required for the system to function (clever counterintuitive point made, cue huge…

Your mundane explanation misses the main point that perfect security can't exist while maintainint function. It is not just a matter of cost cutting, it is a (sort of) fundamental law that security and usability are opposite ends of a spectrum, at the limit any gains in security can only be achieved by a loss of usability. So any system that is perfectly secure will be perfectly unusable, or in the business angle, an…

I'm not sure this is true in principle though. For example, there's plenty of encryption in use today that has "perfect" security (in the sense that a cipher hasn't been broken) and which is transparent to the end user. This wouldn't have been true a long time ago, when there was no such thing as computer science and the security of information was more to do with how many soldiers you had and how beefy your strongbox was.

Similarly, there's no reason in principle why certain classes of fraud couldn't be rendered practically impossible by an advance in technology, which would undermine the whole "you should welcome some fraud" argument.

Re: The optimal amount of fraud is non-zero (2022)

#175
post #7

Anti-fraud departments have apparently not gotten the memo, and the whole situation has gotten obscene in the last few years. I regularly travel for work and it's impossible for me to make any purchases on major sites like Walmart, Best Buy, Target, Costco, etc. They all will accept an order, charge my card, and then randomly cancel the order some hours to days later, and refund me. Similarly when traveling internati…

I have been traveling internationally continuously for 6 years and haven’t had any of these issues. I use Schwab, Capital One, and Chase for banks and credit cards. I don’t stay any one place longer than 6 months; usually just 3months in a country. When my bank card expired Schwab even overnighted a new card to Peru for me. I order from Amazon a fair amount and don’t have any issues. Maybe you are in this weird algor…

I've been traveling issue free for a long long time before these things started happening. It's really only in the last couple of years it's become a problem.

Also I don't have issues with classic eCommerce stores like Amazon, Newegg, B&H, ebay. It's only the new wave of eCommerce stores trying to enter the market this decade, like all the big box stores. It's like they all got sold the same crap anti-fraud software/service.

Re: The optimal amount of fraud is non-zero (2022)

#176
post #47

Earlier quoted context omitted.

because they somehow have this idea that they own the rights to control others. Once you consider that you can force others to do anything, regardless of reason, you can begin to rationalize anything, and it will be "for the greater good" or "for their own good". They probably even sincerely mean it too. some kind of bald man once quoted someone: "With the first link, a chain is forged..."

> Once you consider that you can force others to do anything, regardless of reason, you can begin to rationalize anything, and it will be "for the greater good" or "for their own good". They probably even sincerely mean it too. Eh, I know lots of people who are neither anarchists nor totalitarians, so I'm not sure this is true.

i said you CAN begin to rationalize... I didnt say most would do it about everything, but as is clearly evidenced here, many would about a great many things.

"Red cars are more involved in traffic accidents, I therefore think you must be a murderous lunatic if you get a red car, and we cant have that, so lets forbid it"

Re: The optimal amount of fraud is non-zero (2022)

#177
post #81
post #61

Earlier quoted context omitted.

Working with partners who have integrity is a massive boost to everything you do. People with high integrity attract more people with high integrity, compounding that effect.

Corollary: it's easier to fraud if you can fake high integrity.

Unfortunately true.

Re: The optimal amount of fraud is non-zero (2022)

#178

Earlier quoted context omitted.

Disagreed, the banks aren't cancelling it - they wouldn't authorize the transaction in the first place. Chances are, the banks are correctly returning an address verification mismatch if you didn't use your true billing address. Most likely the stores are cancelling the orders because of billing/delivery address mismatch or (if you didn't set a different billing address) that it doesn't verify against your card.

Or, in the case of one particularly annoying site I tried to order from--a name mismatch. The site was clear upfront that everything had to match EXACTLY or they would cancel the order. I logged in to my online banking and copy and pasted my debit card details to make sure there were no issues. The one thing I didn't think to copy and paste was my own name because, I mean, I know my own name, right? Apparently not as…

And here are I am who always writes %BANK NAME% and it works. Though my bank always demand 3DSecure.

Re: The optimal amount of fraud is non-zero (2022)

#179

Earlier quoted context omitted.

The point is you have total control over your key. You don't control the banks and there's no guarantee you can always get your money from them.

What if you get Dementia (or even die) and forget the password? It's possible to have set up a second password with a trusted third party, but then you have to trust that entity the same way you trust the bank - not just against them stealing your money, but against other parties hacking their systems and recovering your keys.

It’s also possible to split your seed phrase into n pieces, requiring m of them to recover it, and give those pieces to third parties. You don’t need to trust any individual or entity, but together they can get your keys if you lose them or die.

Various other approaches exist, too.

Re: The optimal amount of fraud is non-zero (2022)

#180

Earlier quoted context omitted.

How you feel about reliable national ids really comes down to "do you trust the state or not". Error-prone-ness is a feature for people who want the state to be less powerful. Personally I think that for purely practical reasons national ids are good infrastructure. I don't think in 2023 a "weak" national identity system offers much protection against an adversarial government.

Forget trusting the state, do you trust the endless parade of crappy companies that will demand your national ID verification to but everything from house insurance to fortnight skins to prevent fraud, and then promptly lose it in a data breech without ever receiving meaningful punishment? Because that is the state of things.

Isn’t this just already the case? It’s not clear to me why it would get worse for the drivers license I give everybody as proof of identity to be issued by the federal rather than state government.

This is especially true given that for many applications, I can already use my passport as an ID.

Post reply on HN