Live data from Hacker News

The underground world of credit card network exploitation

chargebackstop.com

151–160 of 280 posts

Re: The underground world of credit card network exploitation

#151
> We learnt that 15% of the successful fraudulent charges resulted in chargebacks.

I Hope the other 85% are just recent transactions that haven’t been scrutinized yet.

Or did the fraudsters target a bank with high net worth clients that don’t scrutinize smaller billings???

I can see a lot of people not really scrutinizing a random Spotify transaction or something. Especially vendors that let you store multiple cards and then you don’t always keep it straight which transaction went to which card anyway.

Re: The underground world of credit card network exploitation

#152
(Edwin from Stripe here.) Worth noting this is copypasta from an older post from a month ago (https://piotrmierzejewski.com/p/card-networks-exploitation). We've fixed most of these issues since then. This type of card testing has dwindled—Radar should now be catching these types of attacks.

On the chargeback point—we hate chargebacks too and we want to limit them as much as possible (we're actually working on a few things over here that we think will help with this). The banks levy chargeback fees (in varying amounts) and an average of them show in the form of a $20 fee—it's not a Stripe-specific fee and we don't profit from chargebacks.

We've just finished company planning for the rest of the year and reducing this type of fraud is a top priority. So if you think you're seeing something similar, please email me at edwin@stripe.com.

Re: The underground world of credit card network exploitation

#153

Earlier quoted context omitted.

I use ChatGPT to write code for work constantly. The quality is quite high, it saves me lots of time, on the order of hours typically. If a company prevents me from using ChatGPT, I will use it clandestinely unless they offer an equivalent. There's no going back.

This is outright false. I have used ChatGPT many times over the last couple months and I have caught it give me un-working code, unfinished code, and terribly buggy code. When you point this out it will say Oh sorry about that here is an updated version, and I've caught it give another bug, and another after that. If you are telling me the quality of code that ChatGPT gives you is high then it pains me to say but you…

When you used google previous to chatgpt, did you force yourself to only allow yourself to use the “I’m feeling lucky” way of search along with having to use the result as your unadjusted production code. Did you never modify the code you came across?

Of course not, that’s ridiculous. You probably searched, read a few stackoverflow comments, found a relevant GitHub repo, a library for python/language of choice, and probably also a SAAS offering solely focused on the 3 lines of code you need. You quickly parsed all that and decided to modify some code in one of the SO comments for your needs. Next time, you looked passed half the junk and went straight to the first SO result and was able to tweak and use the result. The next time, it didn’t help but did help you write some inspired custom code for the problem, at least you knew what not to try.

My point being ai is useful. It’s not meant to be first result is final answer type solution, if that’s how you use it you will have issues.

Re: The underground world of credit card network exploitation

#154

Earlier quoted context omitted.

This is outright false. I have used ChatGPT many times over the last couple months and I have caught it give me un-working code, unfinished code, and terribly buggy code. When you point this out it will say Oh sorry about that here is an updated version, and I've caught it give another bug, and another after that. If you are telling me the quality of code that ChatGPT gives you is high then it pains me to say but you…

Have you ever hired a junior dev? How is their quality? Does that mean we should never use junior devs? The problem with chatGPT usage is not imperfect code. The problem, when there is one, is not treating its code the way one would treat a human’s.

> Does that mean we should never use junior devs?

No, because junior devs usually improve over time.

I've tried Copilot and a few other AI codegen tools. Aside from producing overall low quality/nonworking code, the only times they seem to get better long-term are when a new update to the model comes out.

Re: The underground world of credit card network exploitation

#155
post #83

Earlier quoted context omitted.

In my view, the U.S. is leading the way in this area. Europe seems to be shifting the burden of fraud prevention onto customers with methods like SMS notifications and pins. In contrast, in the U.S., banks and businesses are primarily responsible for dealing with fraud.

It's more the case that US Consumers are indirectly funding crime by banks turning a blind eye to fraud.

It's curious that the same product isn't cheaper in Europe compared to the U.S., despite Europeans not funding fraud. I can't help but wonder where those extra savings go.

Re: The underground world of credit card network exploitation

#156

Earlier quoted context omitted.

Have you ever hired a junior dev? How is their quality? Does that mean we should never use junior devs? The problem with chatGPT usage is not imperfect code. The problem, when there is one, is not treating its code the way one would treat a human’s.

> Does that mean we should never use junior devs? No, because junior devs usually improve over time. I've tried Copilot and a few other AI codegen tools. Aside from producing overall low quality/nonworking code, the only times they seem to get better long-term are when a new update to the model comes out.

copilot is straight trash compared to ChatGPT 4. It's not even a contest.

Re: The underground world of credit card network exploitation

#157
post #60

Earlier quoted context omitted.

> the author had ChatGPT write a script to automatically handle payments processing, specifically for chargebacks Feels like a mischaracterization tbh. He had it make a script to go through and accept the chargebacks for these accounts, not handle payment processing or do anything to the chargebacks other than click "accept" essentially. > And based on the context in the article, the author sounds like they lacked th…

ChatGPT is not capable of writing production quality code. Many (most) companies have internal policies against deploying any code written by an LLM. The point isn’t to slow devs down, but to mitigate risk. This is especially important in the customer/payments stack. This is not the right place to “save a couple hours”. Maybe if this was for some one-off offline analysis, sure. The fact that it works is insufficient…

Realistically chatgpt isn't writing the financial code. Stripe did that already. Chatgpt is just reading snippets of Stripe's API examples for you and applying the code for a common use-case.

Re: The underground world of credit card network exploitation

#158

Earlier quoted context omitted.

I've lived in Europe my whole life and I've never made an online payment with a card reader (even though my ThinkPad has one), or know anyone who has.

But you do use 2FA when paying with your credit card online. What kind of 2FA does the bank providing your credit card mandate you to use?

My bank's app.

Re: The underground world of credit card network exploitation

#160

Earlier quoted context omitted.

Your causality chain doesn't track for me. Here in Denmark we have the same consumer protections, the ability to do chargebacks and the (government funded) guarantee that the consumer does not lose any money if their bank account is drained. Yet we still have very strong protections at the time of purchase with mandatory chip-and-pin as well as 3D secure (which replaced Verified by Visa). I don't really think there's…

My guess is the difference lies in the fact that the EU limits credit card fees to something around 0.5% That means the CC companies can't offload the financial burden of this onto the vendors (and they in turn onto their customers), which leads to them having an actual incentive to improve security.

> That means the CC companies can't offload the financial burden of this

Most CC company (CCC) revenue comes from charging the poor people who can't pay their bills ("interest"). Merchant fees are only a small portion of revenue for most cards [1]. In the case of Discover for example it's less than 10% of their revenue, and in the case of Amex it's less than 33%. Other cards fall in-between.

[1] https://www.valuepenguin.com/how-do-credit-card-companies-ma...

Post reply on HN