Live data from Hacker News

Stripe is friendly to “friendly fraud”

gingerlime.com

231–240 of 258 posts

Re: Stripe is friendly to “friendly fraud”

#231
post #220

Earlier quoted context omitted.

If the cardholder is doing chargebacks on an US-based card, they cardholder is probably US-based. Not very easy to do with prepaid cards AFAIU.

You're assuming prepaid, I'm just assuming the real card was skimmed during checkout at a gas station or swiped from a payment processor.

Ah, right. I assumed the comment was talking specifically about friendly fraud, as opposed to just fraud in general.

Re: Stripe is friendly to “friendly fraud”

#232
post #78

Earlier quoted context omitted.

how so?

https://www.signifyd.com/fearless-conversions/ They have a comprehensive customer ID system and let you adjust desired risk levels for various forms of fraud. Epic username btw lol

How does it compare to Google Cloud Fraud Defense (previously ReCAPTCHA Enterprise)?

Re: Stripe is friendly to “friendly fraud”

#233
post #27

Earlier quoted context omitted.

You'd better be promptly responsive to legitimate customer support inquiries if you are going to have a policy like that

This comment struck a nerve with me and perhaps you didn't mean it in this way but: Yes, many of us are incredibly responsive to customer support inquiries (I have a I've dealt with my fair share of chargebacks and in every case I've seen it's someone being a jerk and never a legit case. The fact that Stripe won't help you, the banks don't care about all the evidence you have, and you end up out the money for the pro…

Yeah, I know chargebacks are a frequent vector for abuse and of course I don't mean to imply that customers doing chargebacks ought to always implicitly be given the benefit of the doubt.

Given that you are responsive to inquiries, it makes sense that you'd rarely if ever have a legitimate chargeback -- because there's no reason for a customer to resort to chargebacks if the vendor is willing to work with them to resolve legitimate issues.

But I know of many examples of people needing to resort to chargebacks due to ineffectual customer support, and then having their accounts banned and being cut off from other unrelated services from the same vendor as a result. I don't think that's an appropriate response and vendors should be careful not to let that happen if they instate such a policy.

Re: Stripe is friendly to “friendly fraud”

#234
post #108

Earlier quoted context omitted.

> it could also be fraught if Stripe was in the business of blocking customers from their entire network based on one vendor's complaint “You probably don’t want a system where one annoyed merchant can get someone blocked across the whole Stripe payment system. But there’s a pretty big gap between “automatically block this person everywhere” and “thanks for the screenshots, please consider Radar”, and this is where i…

There is no gap between those things. Any fraud signal at all either causes people to get blocked, then it's a cross-merchant block, or it doesn't cause people to get blocked, then it's useless.

The gap between “block on first signal” and “ignore the signal entirely” exists, and it is not small.

Re: Stripe is friendly to “friendly fraud”

#235
post #10

I run a saas and we get this every now and then. As a rule of thumb, when you get a chargeback you need to completely ban the customer from your db. This includes: - card ban - email address ban - fingerprint their access and ban This will save you a lot of hassle when they try to signup/buy your product again and cause you the same amount of grief.

Just force 3d secure, as it shifts the liability to the customer's bank. Most people don't mind opening their banking app on the phone for confirming the transaction if they really want the product for itseprice.

if customer fraudulently claims to their bank that they haven’t received the product, the bank files a chargeback and 3DS does not protect the merchant against it.

Re: Stripe is friendly to “friendly fraud”

#236

The customer screwed you over, and then their bank did too. Stripe didn't. I'm not sure why Stripe is getting blamed in the title and the article. Yeah, maybe Stripe could do more without Radar, but I imagine it could also be fraught if Stripe was in the business of blocking customers from their entire network based on one vendor's complaint. Obviously a lot could go wrong with such an approach.

No, Stripe did. It is a common misconception that chargebacks are decided by the customer's bank. Actually, there is a multiple cycle back-and-forth process after which they are finally decided by _the network_. I have worked in card issuing for years and I have seen various submissions by merchants I know that use Stripe where I _know_ that they have an absolute winning case under the network rules that Stripe refus…

That’s news to me. Stripe always presents it as if they’re simply a conduit and it’s all in the issuing bank’s hands. Do you have any links/info for learning more about it?

Re: Stripe is friendly to “friendly fraud”

#237
post #221

One thing that is so painful with Stripe is the Disputes because no matter how much evidence I show, even emails with the user claiming they did it because of X, Y, Z. ToS not upheld, etc, the customer always wins. For me, I do a cheap subscription (4$/mon, first month 2$) and one dispute costs me like 20-30$. So that one person wipes a ton of profit from me. I always try to refund them (but you can't refund a custom…

Does Stripe have any published stats on the ratios? Did any merchant ever won such a Stripe dispute?

I’d be curious too. Previous experience at a SaaS was that we never won disputes and it was too time consuming on top, so we just ate the dispute fees and refund.

I always thought things are easier with a physical product where you have a 3rd party like DHL that proves delivery was made. But at least in my tiny sample space, that’s not enough to win the dispute.

Re: Stripe is friendly to “friendly fraud”

#238

Earlier quoted context omitted.

What do they feed into their Radar machine learning system? surely there are lots of signals to use here. I'm not saying take only my word and ban this customer forever. But they have my record as a merchant (successful charges, chargebacks, disputes etc), they have the payer record as a consumer (payments, chargebacks etc), when a merchant submits a dispute, they provide evidence. I provided evidence from DHL that t…

According to payment networks, that chargeback was entirely legitimate That's why it doesn't get fed into any fraud prevention system. Legitimate chargebacks shouldn't be used to prevent transactions. You are mad that what you claim to be a flagrantly fraudulent chargeback was approved. Who approved that chargeback, because that's where your actual anger should lie. Ban that bank/provider or whatever and move on with…

Yeah I totally get what you’re saying. It’s true. Still find it frustrating as a tiny merchant because it’s just too easy to get scammed and the system seems skewed against you.

> Plenty of companies don't even try to fight it, because then at least you save the $20 chargeback fee.

That’s sad in my opinion. It shouldn’t be the norm. Stripe support encouraged me to file a dispute and submit evidence but next time I prob won’t bother.

I personally find it disappointing that Stripe is in a position to do something about it but prefers the status quo that clearly allows such fraud to continue.

Re: Stripe is friendly to “friendly fraud”

#239

Earlier quoted context omitted.

None of the technical measures you mentioned are relevant with “friendly fraud”. And that’s exactly the problem that Stripe doesn’t solve. And doesn’t want to help merchants fight against.

Certain 3DS setups would shift fraud liability to the payment network itself. That is the only payment network solution to an entity that will happily sign off on clearly false chargebacks. Then they would themselves be fighting the institution agreeing to sign off on bad chargebacks.

Even when the consumer claims that they didn’t receive the product?

Re: Stripe is friendly to “friendly fraud”

#240
post #145

Earlier quoted context omitted.

That's pretty clearly deceiving. Would expect to run into problems with that kind of approach regardless of the specific payment processor -- everyone has T&C that you must follow.

Problems occur either way due to a lack of regulations on these entities allowing them to dictate acceptable financial transactions regardless of actual legality. Consider the risk matrix: * You sell legal goods or services and are entirely honest about them to the paypro; if the T&Cs change down the line, your honesty makes you a prime target for having your funds seized and ability to process transactions terminate…

Well, fraud prevention requires them to block some transactions that are ostensibly legal right? To the extent that they can’t always tell if a transaction is fraudulent, any effort to fight fraud will block some number of legal transactions. And if it’s something they object to on moral grounds, they can probably always make a case (usually accurately) that the fraud rates are high.
Post reply on HN