Live data from Hacker News

Preventing online payment fraud

binpress.com

21–25 of 25 posts

Re: Preventing online payment fraud

#21

Well, I am thinking of selling goods in the future. It'll be bank transfers or bitcoins. Simple. add: if someone worries about if I have the goods or will ship, I'll offer to take a photo of me holding them next to that day's newspaper and have some testimonials up on the site. Simple.

Some bank transfers can be reversed.

Well, I think having proof of shipping to show bank, customer or police would help too if one is notified of a dispute - that itself should be a deterrent for pathological customers.

Re: Preventing online payment fraud

#22
Very relevant. I was listening on Mixergy about how BrandStack shut down because of credit card fraud. For anyone contemplating building a marketplace, for heaven's sake, outsource this.

For digital sites like BinPress, an automated capture of a photo via a web cam might be sufficient to deter fraudsters. Anyone care to build something like this?

Re: Preventing online payment fraud

#23
post #5

Earlier quoted context omitted.

Loved the write-up. If you expand outside paypal/ccs into other methods like direct debits (common for Germany) I would be curious to hear similar stories. Accidental chargeback rates are way up on direct debits so any stories for dealing with that efficiently would be very interesting. One thing I didn't really see was "previous successful purchase" - that should be a strong indicator of "not fraud". Even if other d…

If you expand outside paypal/ccs into other methods like direct debits (common for Germany) I would be curious to hear similar stories. Accidental chargeback rates are way up on direct debits so any stories for dealing with that efficiently would be very interesting. Would you mind expanding on this, please? We're looking at different payment possibilities for a start-up and direct debits is one method that we are co…

If you are using direct debits you have no way of pulling the money directly from the account - you will always have some serious lag (day or two at least, often more). In that time you don't have a hold or similar on the funds, so either you delay giving product to customer or you have a few days where you trust him to actually have the funds available when your claim hits his bank. If he doesn't actually have funds at that time you effectively have a chargeback (no funds were actually available to take in the first place). Usually these are honest mistakes, especially if you do recurring billing that the customer may forget, but it's costly and time consuming to explain what happened and have the customers pay you again for something they actually want.

Re: Preventing online payment fraud

#24
post #23

Earlier quoted context omitted.

If you expand outside paypal/ccs into other methods like direct debits (common for Germany) I would be curious to hear similar stories. Accidental chargeback rates are way up on direct debits so any stories for dealing with that efficiently would be very interesting. Would you mind expanding on this, please? We're looking at different payment possibilities for a start-up and direct debits is one method that we are co…

If you are using direct debits you have no way of pulling the money directly from the account - you will always have some serious lag (day or two at least, often more). In that time you don't have a hold or similar on the funds, so either you delay giving product to customer or you have a few days where you trust him to actually have the funds available when your claim hits his bank. If he doesn't actually have funds…

Thanks, that makes a lot of sense. Innocent mistakes we can deal with. I was more worried about a high rate of formal disputes where customers might claim we took money fraudulently. It sounds like a track record full of that sort of thing can make it harder to get good terms in the future, and I didn't see why that should be significantly higher with one form of payment than another.

Re: Preventing online payment fraud

#25

It's a good article. I'd like to add two other things you should consider when handling credit cards. The first is 3DSecure (or VbV). They are the most secure ways to accept credit cards, though they aren't as easy for users to use. However, they do go a long way to protecting the merchant. If your handling b2b transactions that are high risk, you might consider enforcing this. Again, it's not a solution to wield lig…

Counterpoint: the only businesses that force VbV etc. I will deal with are airlines (because they all do), which meant the last time I flew transatlantic I took 800 euro out of my bank account and _walked_ to Air France's bank rather than use it. In _any_ other industry? They've just given my business to a competitor. It is not in my interest to use a service _designed_ to lessen my protection from fraud. (see http:/…

I know it's been a few days, but, just wanted to add that this is a good point, and a part of what I meant with not using VbV lightly. There are valid reasons to use it, but frankly, it should be close to the last thing you implement.

The only times I've used it where when offering a b2b product/service where fraud was a real fraud.

Post reply on HN