Live data from Hacker News

The underground world of credit card network exploitation

chargebackstop.com

171–180 of 280 posts

Re: The underground world of credit card network exploitation

#171
post #72

Earlier quoted context omitted.

FedNow: https://www.federalreserve.gov/newsevents/pressreleases/othe... Unfortunately not many banks support it yet.

I think "secure" is the key part that's missing here. There's no incentive for a consumer to use a payment method such as this when paying with a bank. The reason is that credit cards come with consumer protection that this just doesn't offer.

I don't think customer protection is necessary unless you are dealing with unusually small or shady companies. I live in Germany and do not own a credit card, they are uncommon here. Mostly we pay per bank transfer or debit card. Even with the possibility of fraud, this is probably significantly cheaper in expectation than paying a 2% credit card fee each time just to have the possibility of chargeback.

Re: The underground world of credit card network exploitation

#172
post #34

Earlier quoted context omitted.

Article author here. Really valuable stuff, thanks for sharing! Do you handle this for Mastercard in any way? I've heard of Ethoca (they are really good at SEO), it seems quite similar to Verifi.

Ya, for Mastercard we use their Ethoca network. They are much more expensive, like $25 per resolved charge but now our chargeback rate is near 0% for Visa / MC and get incredible rates on the front end from such clean processing. Plus we never have to worry about chargebacks threatening our merchant account again.

What do you do for Amex/Discover?

Re: The underground world of credit card network exploitation

#173
post #36

Earlier quoted context omitted.

> I created a restricted key in Stripe with lowest possible permissions, and prompted ChatGPT to create a script to accept the chargebacks. From my understanding, it also seems that the author submitted a Stripe API key alongside the prompt to create the scripts. This is pretty much a big security no no regardless of the permissions of the key.

Author here. GPT only got minimal context it needed to run the prompt. No customer data, no IDs, definitely no API keys were passed as a prompt.

Ahhh ok, that sounds much more logical. I got the wrong impression :)

Re: The underground world of credit card network exploitation

#174

Earlier quoted context omitted.

Ya, for Mastercard we use their Ethoca network. They are much more expensive, like $25 per resolved charge but now our chargeback rate is near 0% for Visa / MC and get incredible rates on the front end from such clean processing. Plus we never have to worry about chargebacks threatening our merchant account again.

What do you do for Amex/Discover?

Just standard cb dispute process. We outsource this.

Re: The underground world of credit card network exploitation

#175
post #111

Earlier quoted context omitted.

ChatGPT is not capable of writing production quality code. Many (most) companies have internal policies against deploying any code written by an LLM. The point isn’t to slow devs down, but to mitigate risk. This is especially important in the customer/payments stack. This is not the right place to “save a couple hours”. Maybe if this was for some one-off offline analysis, sure. The fact that it works is insufficient…

Frankly speaking, probably the latter. I've been using Copilot for over a year now, and obviously it makes stupid mistakes, but it sped up my general coding speed. Now, I don't have much experience (maybe around 10ish years of programming professionally) in comparison to greybeards, but it works. Haven't used ChatGPT much, but as long as the user understands its shortcomings and reviews/refines its outputs, it's fine…

>but as long as the user understands its shortcomings and reviews/refines its outputs, it's fine.

nice caveat doing a heckuvallot of heavy lifting. i understand that we're talking about coders and sort have this inferred impression that coders will have this understanding, but...that's an awfully broad brush you've used to paint over the simple fact that most people using LLMs (in general) are not understanding this.

Re: The underground world of credit card network exploitation

#176

Why does the US seem so far behind when it comes to banking? - Chip and PIN has been in the UK since 2004 and mandatory since 2006. It wasn't until a decade later that the US caught up. - Faster Payments allow for instant bank transfers (usually) between any bank account for free. Receiving transfers from clients in US (even with a US Wise bank account) was always a nightmare. - Since the EU introduced Strong Custome…

> These measures seem like a way of banks shifting the responsibility for fraud onto the customer.

Onto the vendor, not the customer. The customer can chargeback anything instantly, and the vendor is on the hook for the fraud.

It's intentional, so the banks and payment processors can make more profits. By making it easier for customers to chargeback, they incentivize customers to buy more stuff, by getting the customer to feel more comfortable charging everywhere. Charging more stuff makes payment processors more money.

Re: The underground world of credit card network exploitation

#177
post #83

Why does the US seem so far behind when it comes to banking? - Chip and PIN has been in the UK since 2004 and mandatory since 2006. It wasn't until a decade later that the US caught up. - Faster Payments allow for instant bank transfers (usually) between any bank account for free. Receiving transfers from clients in US (even with a US Wise bank account) was always a nightmare. - Since the EU introduced Strong Custome…

In my view, the U.S. is leading the way in this area. Europe seems to be shifting the burden of fraud prevention onto customers with methods like SMS notifications and pins. In contrast, in the U.S., banks and businesses are primarily responsible for dealing with fraud.

I'm sorry but using strong authentication to make my payment is not a burden, it's a bloody feature.

Here's how much of a "burden" that is: you hold your ATM card next to the terminal. Done. Paid. Every once in a while (based on a configurable max per week) it will prompt for a PIN. Which you enter in 5 secs. That would be 1 in 10 payments.

Online payment: scan payment QR with phone, which takes me to my banking app. Authentication is FaceID, TouchID or PIN. Then you click "Yes". Done.

Both methods are highly secure, require no or minimal input and are extremely fast.

Re: The underground world of credit card network exploitation

#178
post #111

Earlier quoted context omitted.

Frankly speaking, probably the latter. I've been using Copilot for over a year now, and obviously it makes stupid mistakes, but it sped up my general coding speed. Now, I don't have much experience (maybe around 10ish years of programming professionally) in comparison to greybeards, but it works. Haven't used ChatGPT much, but as long as the user understands its shortcomings and reviews/refines its outputs, it's fine…

>but as long as the user understands its shortcomings and reviews/refines its outputs, it's fine. nice caveat doing a heckuvallot of heavy lifting. i understand that we're talking about coders and sort have this inferred impression that coders will have this understanding, but...that's an awfully broad brush you've used to paint over the simple fact that most people using LLMs (in general) are not understanding this.

> the simple fact that most people using LLMs (in general) are not understanding this

How do you know most people using LLMs are not understanding this?

Re: The underground world of credit card network exploitation

#179

Earlier quoted context omitted.

>but as long as the user understands its shortcomings and reviews/refines its outputs, it's fine. nice caveat doing a heckuvallot of heavy lifting. i understand that we're talking about coders and sort have this inferred impression that coders will have this understanding, but...that's an awfully broad brush you've used to paint over the simple fact that most people using LLMs (in general) are not understanding this.

> the simple fact that most people using LLMs (in general) are not understanding this How do you know most people using LLMs are not understanding this?

Because ChatGPT has been opened to the public

Re: The underground world of credit card network exploitation

#180
post #160

Earlier quoted context omitted.

My guess is the difference lies in the fact that the EU limits credit card fees to something around 0.5% That means the CC companies can't offload the financial burden of this onto the vendors (and they in turn onto their customers), which leads to them having an actual incentive to improve security.

> That means the CC companies can't offload the financial burden of this Most CC company (CCC) revenue comes from charging the poor people who can't pay their bills ("interest"). Merchant fees are only a small portion of revenue for most cards [1]. In the case of Discover for example it's less than 10% of their revenue, and in the case of Amex it's less than 33%. Other cards fall in-between. [1] https://www.valuepeng…

There's a recurring myth, very prevalent in the US, that credit card companies would prefer people who pay off their bills every month as cheap margin versus being predatory. It's bizarre, and as you've pointed out, completely unsupported by how they actually make their money.
Post reply on HN