Earlier quoted context omitted.
What do they feed into their Radar machine learning system? surely there are lots of signals to use here. I'm not saying take only my word and ban this customer forever. But they have my record as a merchant (successful charges, chargebacks, disputes etc), they have the payer record as a consumer (payments, chargebacks etc), when a merchant submits a dispute, they provide evidence. I provided evidence from DHL that t…
Based on the quote you provided, the CSR was very specific that what they don't use is merchant-provided evidence. They didn't say they don't leverage information about chargebacks or other disputes.
Stripe is friendly to “friendly fraud”
201–210 of 258 posts
Re: Stripe is friendly to “friendly fraud”
#202The customer screwed you over, and then their bank did too. Stripe didn't. I'm not sure why Stripe is getting blamed in the title and the article. Yeah, maybe Stripe could do more without Radar, but I imagine it could also be fraught if Stripe was in the business of blocking customers from their entire network based on one vendor's complaint. Obviously a lot could go wrong with such an approach.
> it could also be fraught if Stripe was in the business of blocking customers from their entire network based on one vendor's complaint “You probably don’t want a system where one annoyed merchant can get someone blocked across the whole Stripe payment system. But there’s a pretty big gap between “automatically block this person everywhere” and “thanks for the screenshots, please consider Radar”, and this is where i…
Re: Stripe is friendly to “friendly fraud”
#203Earlier quoted context omitted.
Use DeviceCheck if iOS app too. Uber does this to ban across accounts
I imagine most fraudsters wouldn't be using iOS. I'm curious if the android app fingerprinting solutions go cross user profile.
Re: Stripe is friendly to “friendly fraud”
#204Earlier quoted context omitted.
Do you imagine someone got a stolen credit card, made a linkedin with that name, used the card to attend a live class under the fake ID, or are you just doing the classic hacker news aaaaactually? Comments like this have ruined this site. We all know that’s never happened once in history.
If you care about the quality of the site, consider the guidelines about not responding to a bad comment with a worse one and not griping about how HN has gotten terrible or turned into reddit or what there you. Downvote, flag, and move on to better discussion, and you'll spend a lot more time engaging and contributing to good discussions. Contributing to good discussions is the highest leverage way to promote the qu…
But probably won’t, so you’re probably right.
Re: Stripe is friendly to “friendly fraud”
#205This is just fraud. "Friendly fraud" is accidental or with the correct intentions – such as the customer not recognising the charge and charging back.
"Just fraud" is already taken for "criminal c uses unwitting cardholder a's card at unwitting merchant b", so what's your objection against "fiendly fraud"?
Re: Stripe is friendly to “friendly fraud”
#206Re: Stripe is friendly to “friendly fraud”
#207Earlier quoted context omitted.
I don’t have one at the moment, at least for my circles (artisans, craftspeople, adult creators in general). Much of it has fallen back on PayPal for folks without an LLC to hide behind, or Square if they’re incorporated as a business. The trick has been discretion and operating in a gray area: “novelty goods”, “graphic design work”, and “outerwear” as item descriptors or db entries, obscuring the actual content with…
That's pretty clearly deceiving. Would expect to run into problems with that kind of approach regardless of the specific payment processor -- everyone has T&C that you must follow.
* You sell legal goods or services and are entirely honest about them to the paypro; if the T&Cs change down the line, your honesty makes you a prime target for having your funds seized and ability to process transactions terminated first, posing an existential threat to your business with no reward for your honesty
* You sell legal goods and services, but don’t volunteer extraneous details about them since that’s not the business of a paypro. Should the T&Cs change, your obscurity buys you time to adapt or seek alternatives before inevitably being caught up in the paypro’s internal surveillance measures.
* You sell legal goods and services, but assume your paypro is hostile from the get go regardless of the T&Cs and hand over the minimal information necessary to process a transaction. You have maximum time to find alternatives should the T&Cs change, because your baseline operations make it that much harder to identify your transactions down the line.
Honesty is inevitably punished while obscurity is rewarded, at least for a time. It’s also worth pointing out the hypocrisy of needling paypro users to follow arbitrary and changing rules of the paypro but allowing said paypros to reject legal transactions for whatever reason they wish or selectively comply with laws because they’re “fintech” and not banks or payment card networks: why should users face more onerous restrictions than the paypro themselves?
Ultimately the solution is the same one we’ve been parroting for years ever since PayPal arbitrarily changed their T&Cs to try booting adult creators off its platform: government regulations barring these entities outright from refusing any legal transaction. It’s part of the playbook at this point for tech companies in light of its success: court adult content creators and communities to grow the platform, then shut them out once there’s money to be made.
Re: Stripe is friendly to “friendly fraud”
#208Anything that actually discourages that behavior directly is better than some slightly more negative reputation in an opaque fraud detection system.
Re: Stripe is friendly to “friendly fraud”
#209I run a saas and we get this every now and then. As a rule of thumb, when you get a chargeback you need to completely ban the customer from your db. This includes: - card ban - email address ban - fingerprint their access and ban This will save you a lot of hassle when they try to signup/buy your product again and cause you the same amount of grief.
All 3 of those identifiers can be easily changed by advanced users. I'm curious what you mean by fingerprint their access. Is this like an on demand fingerprinting, I've only seen browser fingerprinting as a tracker for every user.
Re: Stripe is friendly to “friendly fraud”
#210The customer screwed you over, and then their bank did too. Stripe didn't. I'm not sure why Stripe is getting blamed in the title and the article. Yeah, maybe Stripe could do more without Radar, but I imagine it could also be fraught if Stripe was in the business of blocking customers from their entire network based on one vendor's complaint. Obviously a lot could go wrong with such an approach.
I have worked in card issuing for years and I have seen various submissions by merchants I know that use Stripe where I _know_ that they have an absolute winning case under the network rules that Stripe refuse to contest.
Stripe have decided that fighting most chargebacks is not worth the money, probably becasue they can just pass the costs onto the merchants and let them eat them and the merchants will not go elsewhere.