Live data from Hacker News

How Candy Japan got credit card fraud somewhat under control

candyjapan.com

111–120 of 128 posts

Re: How Candy Japan got credit card fraud somewhat under control

#111

Earlier quoted context omitted.

So, I use VPN, and order my stuff to arrive where? If someone doesn't ship to Russia, they don't ship to Russia, how can VPN help there?

Freight forwarders are how most of us outside of the US get stuff from companies that only ship to the US - There must be a market for such services that ship to Russia too.

Sure, but you've just made fraud cost them actual money.

Re: How Candy Japan got credit card fraud somewhat under control

#112
Not sure if the author tried this, but there are many experts on carding around the internet (the most famous being Brian Krebs) who might give advice for free on credit card fraud countermeasures. The simplest way to find them is to google for presentations at hacker conferences about carding, cyber criminals, credit card theft, etc.

Re: How Candy Japan got credit card fraud somewhat under control

#113
post #105

Earlier quoted context omitted.

I currently use Maxmind's midfraud service. It is useful for identifying KNOWN fraudulent email addresses and proxy servers but not much else. It is just one of the signals that I currently use as a part of a fairly manual fraud review process. I have evaluated a number of different options and I am about to start using Sift Science[1]. In addition to using standard ip address/email based information they also use so…

I'll say that I like Sift better than MaxMind, but it still doesn't cover a lot of things that it should. I won't go into details, as I'm in the middle of building a platform to solve this issue myself, but as someone who used to be on the other end of credit card fraud, it's really laughable how many things these companies don't see.

Hi Josh, Jason here, CEO of Sift Science. Would love to hear your feedback on what we could do better, whether publicly or privately - jason at siftscience dot com. We want to do better.

Re: How Candy Japan got credit card fraud somewhat under control

#114
post #111

Earlier quoted context omitted.

Freight forwarders are how most of us outside of the US get stuff from companies that only ship to the US - There must be a market for such services that ship to Russia too.

Sure, but you've just made fraud cost them actual money.

As a seller, it is not your responsibility to compensate for the fraud issues impacting your customer's ability to participate in the marketplace without it being worth it.

I don't know exactly what causes Russia to be a fraud hot spot but Australia not to be, but the issue can only really be resolve inside Russia.

Re: How Candy Japan got credit card fraud somewhat under control

#115
post #58

PM from a fraud detection company here. One thing I didn't see mentioned on this thread is Device ID, which is very common on fraud detection platforms. When a user comes to your website or mobile app, you have access to hundreds of signals from their device. Some like IP address are easy to spoof. Others like whether the user has changed their phone alarm from the default settings are often ignored by fraudsters but…

Just a thought: have you ever considered that by publishing such red flags for fraud, fraudsters will adopt these "organic" behaviors in order to appear more legitimate? I understand that the idea is to make illicit transactions more difficult and that adopting these "organic" behaviors is more difficult, but automated fraud tools (ie - what most 'script-kiddies' use) also become more sophisticated over time. Regardl…

I'd be surprised if all of the published vectors are genuine, too, for the same reason :)

Re: How Candy Japan got credit card fraud somewhat under control

#117
post #80

Earlier quoted context omitted.

It's important not to disguise any anti-piracy measures as bugs, because pirates (or even reviewers playing pirated copies) will loudly proclaim that the game is buggy, and discourage legitimate buyers. This may have contributed to the closing of at least one development studio (Iron Lore, developer of Titan Quest)[1]. [1] http://www.quartertothree.com/game-talk/showthread.php?42663...

It's important not to disguise any anti-piracy measures as bugs, because pirates (or even reviewers playing pirated copies) will loudly proclaim that the game is buggy, and discourage legitimate buyers. I'm wondering why there isn't a service that lets you search for people encountering your crack-penalty. A really sneaky company would disguise itself as a hacker group, then offer a copy of the game that doesn't have…

Green Heart Games did basically that. http://www.greenheartgames.com/2013/04/29/what-happens-when-...

Re: How Candy Japan got credit card fraud somewhat under control

#120

When I worked on an e-commerce website shipping physical goods we would only ship to the customer's billing address for credit card payments. Anyone shipping to a different address needed to call their credit card company to add the address (every credit card company I've dealt with would allow customers to have multiple valid addresses on file), or use a different payment method. We never had big issues with fraud a…

You do know that some cards allow any billing address right?
Post reply on HN