Live data from Hacker News

Bolt: An End-To-End Payments Stack with Zero Fraud

bolt.com

131–140 of 154 posts

Re: Bolt: An End-To-End Payments Stack with Zero Fraud

#131
post #7

Why do companies choose not to be 100% transparent? Any time I have to contact a company to see more or a demo or, even worse, see pricing, I close the page and make a mental note to never work with them in any capacity. I feel this type of boycotting is the only way to change the practice. I mean, you even hide your docs behind a password? How terrible. What are you keeping so secret? Does this translate to your oth…

I always wonder why so many people don't respond to critical comments in the way that rbres has here. It's such a great opportunity to show what your company is all about and win over skeptics. Nice work rbres! Now, let's do an interview with you on http://techzinglive.com because it sounds like you have a great story! Send email to podcast[at]techzinglive.com if you're up for it ;) p.s Thanks skrebbel for digging in…

Thanks jv22222! Much appreciated. Transparency, positivity, and truth is our north star.

Will shoot ya a ping.

Re: Bolt: An End-To-End Payments Stack with Zero Fraud

#133
post #128

Looks nice, but "get a quote" == "close tab".

On the pricing page? What exactly happens when you click it?

I don't mean technically. I mean that's my behavior. If there were at least a "starts at" I would know whether it's a complete waste of time. When there's not, I assume it is.

Re: Bolt: An End-To-End Payments Stack with Zero Fraud

#134
post #87

Earlier quoted context omitted.

True. But it's zero fraud from your perspective as a business. You also have full control over false positives: - First, we put txn's through several layers to ensure the highest rates of order approvals. If our algorithm is about to reject, it goes through a human review process to ensure we're approving as much as possible. - If we reject, you have a force approve time window to approve transactions if you disagree…

Sure, maybe you offer "zero fraud" from a chargebacks-line-item-on-the-balance-sheet perspective. The impacts of fraud on customers' perception of a company, and the effects those perceptions will have on the bottom line, however, can be significant. This is not say I assume your service is deficient in any way...the marketing is just a little snicker-inducing from someone like me who works in the field. The only sur…

It's not zero sum if you have overall greater precision. We believe we do and have proven it across dozens of case studies.

As we publish more, we hope to let data talk. If I were in your shoes, I'd be similarly skeptical. Most companies in the space overpromise and underdeliver.

Re: Bolt: An End-To-End Payments Stack with Zero Fraud

#135
post #134

Earlier quoted context omitted.

Sure, maybe you offer "zero fraud" from a chargebacks-line-item-on-the-balance-sheet perspective. The impacts of fraud on customers' perception of a company, and the effects those perceptions will have on the bottom line, however, can be significant. This is not say I assume your service is deficient in any way...the marketing is just a little snicker-inducing from someone like me who works in the field. The only sur…

It's not zero sum if you have overall greater precision. We believe we do and have proven it across dozens of case studies. As we publish more, we hope to let data talk. If I were in your shoes, I'd be similarly skeptical. Most companies in the space overpromise and underdeliver.

I would argue it is zero sum ("you've got some fraud" vs "you have no fraud") if there is any great volume of transactions and what's being sold is valuable, and/or marketable at a black market price below retail, and/or offers fraudsters liquidity options. I am skeptical because an untrained system is going to make mistakes out of the gate, even if it's trained on oodles of transactions from other businesses. Anti-fraud isn't a one-size-fits-all game.

Re: Bolt: An End-To-End Payments Stack with Zero Fraud

#137
post #108
post #4

Earlier quoted context omitted.

CEO of Bolt here. We'll be writing more about this in the future. In short, our fraud detection is really really good (although not perfect). However, the fraud that ends up making it through the pipeline is so minimal that we cover it fully. So, for a small fee as an online business you never have to pay for / deal with fraudulent chargebacks again. There are other companies that do this, but none of them also do pa…

> However, the fraud that ends up making it through the pipeline is so minimal that we cover it fully. You're contradicting yourself when you also say that you charge $20 for chargebacks.

Because chargebacks aren't fraud. They can be fraudulent but then I assume it would be part of the 'not covered' portion of the sentence you left out.

Re: Bolt: An End-To-End Payments Stack with Zero Fraud

#139

Earlier quoted context omitted.

https://stripe.com/blog/pricing-update-for-europe edit: 1.4% + €0.25

Why are both stripe and braintree so much cheaper in Europe?

I was going to guess that there are lower fraud rates in the EU compared to the US; based on what my former partner said, their company reports all EU fraud, but only fraud in the US over 2k USD. In addition to that, people in the US treat (abuse) consumer protections like a "get a free purchase/built-in scam protection", and try buying iphones for $260 on p2p apps from a complete stranger.

There could be something else there, though.

Re: Bolt: An End-To-End Payments Stack with Zero Fraud

#140

Earlier quoted context omitted.

Looking at the docs ( https://docs.bolt.com/v1/docs/step-2-load-bolt-checkout ) it instructs the reader: "The onSuccess method will be called when Bolt successfully processes a transaction. This can be used as a way to create the order (...)". This opens up a massive security hole if the merchant is making decisions based on this method being called client-side, right? What prevents a malicious actor from calling tha…

> This opens up a massive security hole Have you considered that discussing API design decisions regarding security in a public forum is a bad decision of your own? After literally 10 seconds on the site, I found this: https://bolt.com/security

Nah, his post is what Hacker News is for; if the company and their CEO is announcing coming out of stealth mode and answering responses, it's worth that guy vocalizing that potential vulnerability.

Your post tried to chastise him for calling out a vulnerability, and then tried to shame him for not quietly emailing their security team. Chances are if someone were a bad actor they would have: A) seen that themselves outside of his message, or B) Found out through sheer luck and brute force

If anything, the poster mentioning it invites the team to fix it before someone exploits it. It's worse to blunder on a hole someone told you was 1.5km down the road, so hopefully they either address it or fix it

Post reply on HN