Live data from Hacker News

The optimal amount of fraud is non-zero (2022)

bitsaboutmoney.com

181–190 of 203 posts

Re: The optimal amount of fraud is non-zero (2022)

#181

Earlier quoted context omitted.

> Is this an American thing? No. My (UK) bank will decline purchases if they look suspicious and send me an SMS with the information and ask me to yay/nay them. (For 4 years running, they did this for my early September purchase to Apple. Most annoying.)

Apple iPhone release day is a right royal pain in the arse for banks. The surge of one-off high value payments causes a huge spike in false positive fraud detections, which then swamps staff responsible for performing manual checks. And that’s after we’ve already tweaked rules to prepare for iPhone day On top of all the, the fraud systems at the major card networks also go haywire. They start seeing huge spikes in hi…

>On top of all the, the fraud systems at the major card networks also go haywire. They start seeing huge spikes in high value transactions, and start randomly declining transactions. On the banks side, we can see these transactions being declined by the network, but it’s damn near impossible to stop them.

With 3DS2 why is this even a thing?

Re: The optimal amount of fraud is non-zero (2022)

#182
post #180

Earlier quoted context omitted.

Forget trusting the state, do you trust the endless parade of crappy companies that will demand your national ID verification to but everything from house insurance to fortnight skins to prevent fraud, and then promptly lose it in a data breech without ever receiving meaningful punishment? Because that is the state of things.

Isn’t this just already the case? It’s not clear to me why it would get worse for the drivers license I give everybody as proof of identity to be issued by the federal rather than state government. This is especially true given that for many applications, I can already use my passport as an ID.

Actually, the more I think about this the weirder it is as a threat model. Photo ID pictures are basically only worth the value of the info printed on them to an attacker. They’re likewise not really valuable to retain as a business, because you might as well retain the information as tabular data, and then have a checkbox for “we saw this on a physical ID”. The only upside of storing the photo of the ID is if a business doesn’t trust its own employees, so having the photo provides them a way to make sure their employee really checked it.

An attacker who pops my bank’s network doesn’t need to look for ID photocopies: my identifying info is in the database in an already parsed format.

Re: The optimal amount of fraud is non-zero (2022)

#183
post #53

Earlier quoted context omitted.

Why is that zero? I don't want to die in a plane any more than the next person, but is zero really optimal ? It's least life losing, it's least catastrophic, but is it optimal ? the question becomes, what are we optimizing for? If the optimization equation is for lives lost, I can make that zero real easily by just stopping air travel entirely. If no one travels by air, then no one can die by air. But of course that'…

Optimum is zero, because if you could wave a magic wand to magically make the amount of accidents zero, it would be a good thing to wave the wand. The optimum is non-zero only if there are enough costs associated with making it zero. That's why asking for optimum amount of fraud is misleading. It omits the costs. Once the costs are taken into account (i.e. it is clarified what the question means) the answer is obviou…

"Optimum is zero, because if you could wave a magic wand to magically make the amount of accidents zero, it would be a good thing to wave the wand."

You are conflating optimum (highest value outcome for all variables) and ideal (highest value outcome for one variable). The ideal number of any bad thing is zero. I can't, off the top of my head, think of any bad thing for which the optimum number is zero. Extinction level events, perhaps.

Re: The optimal amount of fraud is non-zero (2022)

#184
post #4

Earlier quoted context omitted.

Important corollary: it may well be possible to reduce fraud much closer to zero (then the currently accepted rate) without negative effects on legitimate business. For example, the USA's lack of a national ID (and the resulting adoption of realldy ba substitues like SSNs, driver's licenses and "two photo IDs") has made a plethora of fraud techniques ridiculously easy. In many other countries, "identity theft" so rar…

> For example, the USA's lack of a national ID (and the resulting adoption of realldy ba substitues like SSNs, driver's licenses and "two photo IDs") has made a plethora of fraud techniques ridiculously easy. I US federal government provides passports with passport numbers. All the infrastructure is already in place, it’s just a question of political will to implement an API to use this for identity verification.

The problem is that only about a third of all Americans have a passport.

Re: The optimal amount of fraud is non-zero (2022)

#185
post #162

Earlier quoted context omitted.

It's always about that 0.01%. And expecting people to come up with their own solutions for problems that banks struggle to solve, is going to be a recipe for disaster for 99.99% of the people.

Couldnt that 0.01% be solved by coming physically with a photo ID card or a passport and legal papers to some trusted employee ?

And we’re back to where banks are today. Stopping fraud is a very tough problem to solve remotely.

Re: The optimal amount of fraud is non-zero (2022)

#186

Earlier quoted context omitted.

because they somehow have this idea that they own the rights to control others. Once you consider that you can force others to do anything, regardless of reason, you can begin to rationalize anything, and it will be "for the greater good" or "for their own good". They probably even sincerely mean it too. some kind of bald man once quoted someone: "With the first link, a chain is forged..."

> because they somehow have this idea that they own the rights to control others The flip side, of course, being the folks who believe they somehow have no responsibility for how they use their rights to impact others. Society can only function with at least some balance between these two extremes. Some of us need a little bit of chain.

you cannot perform crimes on others, thats about it. If someone comes to my house dying of cold, they have no right to demand I help them. I would be an asshole if I dont, and I think people SHOULD help, but you have no right to demand I do (and again, not saying I wouldnt, just that nobody gets to be entitled to it)

Re: The optimal amount of fraud is non-zero (2022)

#187
post #165

Earlier quoted context omitted.

You don’t seem to understand, the Byzantine problems are caused by Apple. They don’t bother properly following the network rules and guidelines, as a consequence the data banks get about their transactions in order decide an approval or detect fraud is a complete and total mess. Makes detecting fraud vs legitimate transactions harder than it should be. Eh, I assume you also want your bank to block fraudulent transact…

That, to me at least, is the difference between credit cards and bank cards: the only way to spend a significant amount of money with my bank card is with my authorization. Admittedly cracking a 4-digit PIN number is not that hard, but fraud with this is hard to commit and easy to detect (because I'm missing my card). With credit cards, the information needed to authorize payment is written on the card, easily photog…

What country are you talking about? That distinction between credit and debit cards doesn't exist in many countries.

Re: The optimal amount of fraud is non-zero (2022)

#188
post #187
post #165

Earlier quoted context omitted.

That, to me at least, is the difference between credit cards and bank cards: the only way to spend a significant amount of money with my bank card is with my authorization. Admittedly cracking a 4-digit PIN number is not that hard, but fraud with this is hard to commit and easy to detect (because I'm missing my card). With credit cards, the information needed to authorize payment is written on the card, easily photog…

What country are you talking about? That distinction between credit and debit cards doesn't exist in many countries.

Netherland. It's not entirely clear to me what Americans mean by a debit card, but over here, we tend to pay with our bank card, and simply transfer money directly that way. Although with smartphone apps, the card is now mostly optional; I just pay with the app. Over NFC in a shop, or by scanning a QR code online.

Although one of my banks has recently sent me a new bank card with a credit card number on the outside, and that worries me a bit, because I don't have or want a credit card from that bank, and I certainly don't want to expose myself to that kind of security hole.

Re: The optimal amount of fraud is non-zero (2022)

#189
post #86
post #80

Earlier quoted context omitted.

Yeah, sure. I mean "we don't do fraud detection, it's literally one of our design decisions that you can't do anything after fraud has happened, and also, fraud is kinda in our DNA" systems are totally well suited to solve that.

Famously, the optimal amount of fraud is non-zero. We may yet discover that the amount of fraud in crypto is superior to the fiat systems. In COVID times governments noticed that freezing bank accounts was an option. Having systems that cannot be subjected to that is wise; even if it involves high costs.

Yeah? Lol

Re: The optimal amount of fraud is non-zero (2022)

#190

Earlier quoted context omitted.

> because they somehow have this idea that they own the rights to control others The flip side, of course, being the folks who believe they somehow have no responsibility for how they use their rights to impact others. Society can only function with at least some balance between these two extremes. Some of us need a little bit of chain.

you cannot perform crimes on others, thats about it. If someone comes to my house dying of cold, they have no right to demand I help them. I would be an asshole if I dont, and I think people SHOULD help, but you have no right to demand I do (and again, not saying I wouldnt, just that nobody gets to be entitled to it)

Unfortunately, we encounter far more complex scenarios, from "can the car dealership dump engine oil into the creek behind their maintenance bay?" to "we sold a product that provably killed thousands of people, but none in a way that can cause us direct individual liability".

Societally, we've largely decided we're all better off without a pile of frozen bodies at our door.

Post reply on HN