Live data from Hacker News

The underground world of credit card network exploitation

chargebackstop.com

211–220 of 280 posts

Re: The underground world of credit card network exploitation

#211
post #155

Earlier quoted context omitted.

It's more the case that US Consumers are indirectly funding crime by banks turning a blind eye to fraud.

It's curious that the same product isn't cheaper in Europe compared to the U.S., despite Europeans not funding fraud. I can't help but wonder where those extra savings go.

Products are more expensive in Europe because we have (on average) ~20% sales tax. And because the general tax pressure is higher because we have more state services.

In terms of PPP someone should look it up (on mobile)

Re: The underground world of credit card network exploitation

#212
post #83

Earlier quoted context omitted.

In my view, the U.S. is leading the way in this area. Europe seems to be shifting the burden of fraud prevention onto customers with methods like SMS notifications and pins. In contrast, in the U.S., banks and businesses are primarily responsible for dealing with fraud.

It's not leading the way technically but for the end consumer it might be better. If I get charged unfairly my bank will tell me to go to the police. Americans can easily just refuse it.

Not if you use a credit card; a quick call to Visa/MC/Amex will get your money back instantly in Europe too.

The main difference is that, in Europe, debit cards are often used in the same way as a CC - except they are just a direct pipe to one's bank, and once the money comes down the pipe there is no easy way to push it back up.

Re: The underground world of credit card network exploitation

#213
post #111

Earlier quoted context omitted.

Frankly speaking, probably the latter. I've been using Copilot for over a year now, and obviously it makes stupid mistakes, but it sped up my general coding speed. Now, I don't have much experience (maybe around 10ish years of programming professionally) in comparison to greybeards, but it works. Haven't used ChatGPT much, but as long as the user understands its shortcomings and reviews/refines its outputs, it's fine…

>but as long as the user understands its shortcomings and reviews/refines its outputs, it's fine. nice caveat doing a heckuvallot of heavy lifting. i understand that we're talking about coders and sort have this inferred impression that coders will have this understanding, but...that's an awfully broad brush you've used to paint over the simple fact that most people using LLMs (in general) are not understanding this.

Can we please get back to the actual topic is hand. The author clearly says that they took measures that’d seem to imply that they have an understanding of the shortcomings of ChatGPT.

You’re using this as a soapbox to cast holier than thou elitist aspersions on an imagined Everyone Else that isn’t as enlightened as you.

This exact “LLMs bad and here’s why!” thread of conversation is getting so old. The fact that it always has the same few talking points is evidence enough that those indulging themselves in it have been party to these conversations before. They know how it goes. And now it’s their turn to say the same old tired and in this case largely irrelevant things to sound smart and to pat themselves on the back.

Re: The underground world of credit card network exploitation

#214

Earlier quoted context omitted.

I use ChatGPT to write code for work constantly. The quality is quite high, it saves me lots of time, on the order of hours typically. If a company prevents me from using ChatGPT, I will use it clandestinely unless they offer an equivalent. There's no going back.

This is outright false. I have used ChatGPT many times over the last couple months and I have caught it give me un-working code, unfinished code, and terribly buggy code. When you point this out it will say Oh sorry about that here is an updated version, and I've caught it give another bug, and another after that. If you are telling me the quality of code that ChatGPT gives you is high then it pains me to say but you…

Trying to claim that someone else’s personal experience is factually wrong? The internet teaches everyone great arguing quips, sure. But “outright false” actually MEANS something. Your comment is all emotion.

Re: The underground world of credit card network exploitation

#217
post #111

Earlier quoted context omitted.

Frankly speaking, probably the latter. I've been using Copilot for over a year now, and obviously it makes stupid mistakes, but it sped up my general coding speed. Now, I don't have much experience (maybe around 10ish years of programming professionally) in comparison to greybeards, but it works. Haven't used ChatGPT much, but as long as the user understands its shortcomings and reviews/refines its outputs, it's fine…

>but as long as the user understands its shortcomings and reviews/refines its outputs, it's fine. nice caveat doing a heckuvallot of heavy lifting. i understand that we're talking about coders and sort have this inferred impression that coders will have this understanding, but...that's an awfully broad brush you've used to paint over the simple fact that most people using LLMs (in general) are not understanding this.

> simple fact that most people using LLMs (in general) are not understanding this.

And why does that matter? Plenty of people "use JavaScript without fundamental understanding of the language's inner workings" but things are fine (not). My point is, people have always misunderstood the TOOLS that they use, but I don't see the same kinds of rejection before? Yes, people use LLMs thinking it is the end of programming but you can become way, way more productive as a programmer if you use it as a TOOL. The other day I used it to create a simple Python function to generate N distinct colors. It works, it seems to work, it even suggested using hue instead of rgb since its better or whatever (so I looked it up and it is for the eye) so I just used it. Should I spent a week going on a deep dive into the human eye perception and reading up articles on this?

Re: The underground world of credit card network exploitation

#218
post #60

Earlier quoted context omitted.

> the author had ChatGPT write a script to automatically handle payments processing, specifically for chargebacks Feels like a mischaracterization tbh. He had it make a script to go through and accept the chargebacks for these accounts, not handle payment processing or do anything to the chargebacks other than click "accept" essentially. > And based on the context in the article, the author sounds like they lacked th…

ChatGPT is not capable of writing production quality code. Many (most) companies have internal policies against deploying any code written by an LLM. The point isn’t to slow devs down, but to mitigate risk. This is especially important in the customer/payments stack. This is not the right place to “save a couple hours”. Maybe if this was for some one-off offline analysis, sure. The fact that it works is insufficient…

The main reason that the infosec folks have paused the use of LLM's to generate code is copyright concerns: who "owns" the code that's generated, the LLM, or, the company?

Re: The underground world of credit card network exploitation

#219
post #25

If you are a foreign company accepting payments from the USA, you should simply expect this as a cost of doing business. Credit card fraud here is socialized. The end consumer is never liable, and so we don't bother with chip and pin, 2FA, 3D secure or whatever else. If we notice a suspicious transaction we simply tap a button in the bank's app and the charge is reversed in minutes. Banks and payments processors are…

I expect it’s path-dependent legacy practices more than anything else. Credit cards were invented in the US, so the tech is old and upgrades take a long time. For manual payments, UPI in India sounds pretty great. Apparently the customer approves each payment on their phone before it goes through?

UPI is a terrible thing.

0) makes every transaction a trivial SQL query away for the government.

1) everything needs an SMS code. Just as we are trying to get everyone off SMS 2FA

2) doesn’t work for non-Indian numbers or roaming devices

3) can’t get an Indian SIM without proof of address etc. No burners in India

4) regulation expressly forbids devic-local biometrics. This is why there is no Apple Pay in India.

5) Biometrics must be stored with the government. “Unique Identification Authority (UIDAI)” - https://studentbriefs.law.gwu.edu/ilpb/2022/03/22/regulating...

Re: The underground world of credit card network exploitation

#220

Earlier quoted context omitted.

And that is in addition to the outrageous fees CC companies charge merchants. In the US it's typically around 2% of the transaction! The EU caps it at 0.3% maximum, which still seems like a lot when you consider how much money they move. That's another cost that gets socialized and passed on to the consumer of course, even shoppers who pay cash have to pay for this through higher prices. People should know btw that w…

Wild idea: What if secure digital payment was a public service.

No thank you. This is how you get something like UPI in India.

https://news.ycombinator.com/item?id=36980279

Post reply on HN