Live data from Hacker News

Tell HN: Automatic fraud detection is making my life hell

news.ycombinator.com

301–310 of 406 posts

Re: Tell HN: Automatic fraud detection is making my life hell

#301

Earlier quoted context omitted.

The result is the same, and it's the result that is the issue. If potential applicants aren't given consideration because they're not in the network, it doesn't matter that the hiring committee thinks they're innocent, or isn't technically rejecting them. It's a bad heuristic.

Be careful with your logic and framing. I explained why it was poor framing above. But the way you've (and the gp) framed it is dangerous. Swap "voip numbers" for "x skin color" and you're in clear unethical and illegal territory. But swap the attributes of the parent and you don't get this issue. If parent is x race and all their friends are also x race you're not discriminating against y race through their means be…

This is wrong. You are expected to discriminate against samples from the distribution in a variety of ways, like the formatting of their resume and their work history; it only becomes unethical when you discriminate based on race, gender, etc. If you replace "voip numbers" with "x skin color", of course that would be unethical, but being able to switch phrases to make them unethical is irrelevant, because we're not discussing the unethical case.

The example of networking you give has even more potential for unethical behavior than filtering voip numbers.

Re: Tell HN: Automatic fraud detection is making my life hell

#302
post #137

Earlier quoted context omitted.

The problem with many of these examples is that 99% of the time, it is a sign of fraud, and 1% of the time it’s a false positive. > If a person's mobile phone number is associated with VoIP or Google Voice, that indicates fraud. I’ve been using this heuristic (along with VPN and IP geo lookup) when screening job candidates after a massive influx of developers outside the US applying for US-only remote roles. I discov…

I'm confused about what such applicants hope to gain by this. What's their business model? They're going to have to give you a SS# or EIN (if they're a self-employed consultant) before you can send them a paycheck, right? And the Social Security Administration has a website where you can verify SS numbers. So what's the play here?

Basically you are getting a mole infiltrated into your company. There was even an US govt warning about North Korean IT workers, heuristics included.

> The hiring or supporting of DPRK IT workers continues to pose many risks, ranging from theft of intellectual property, data, and funds, to reputational harm and legal consequences, including sanctions under U.S., ROK, and United Nations (UN) authorities.

This is the funniest part:

> Repeated requests for prepayment; anger or aggression when the request is denied.

https://www.ic3.gov/Media/Y2023/PSA231018

Re: Tell HN: Automatic fraud detection is making my life hell

#303

I move to random corners of the world every 2-3 years and this is starting to give me real anxiety every time I try to make a purchase. One of my credit cards makes me jump through all of the verification and "Was this really you?" messages, then still locks my account half the time. So many online stores will approve my purchase and bill the card with no issue, then cancel it a few hours later for vague security rea…

When I was traveling abroad, I placed an order on Walmart, shipping to my home address, so that it would be there for me when I got back home. Walmart cancelled the order, "due to location restrictions on placing and shipping orders", even though the delivery address was in the US! I have no idea why the physical location of the computer placing the order should matter to Walmart. Eventually I just had to get my frie…

I don't know how the numbers break down, but plenty of people that buy credit card numbers are happy to orchestrate a scheme to ship packages to the US and have someone forward them to the scammer. Or steal them off your porch.

It is probably exceptionally rare for a fraud protection algorithm to be in place to inconvenience and spite you. Rather, some ne'er-do-well has cooked up a bafflingly complicated scheme that looks like your legitimate business. Such is the tragedy of operating at scale.

Re: Tell HN: Automatic fraud detection is making my life hell

#304
So you move around a lot between 2 locations. Is it possible to set up two completely isolated systems (e.g. bank accounts, online accounts & devices), including a cheap second phone. The only interface between your two isolated systems would be the proven international money transfer services? Global money transfer between individuals (or yourself) I believe is the focus of all these remittance services of which I see all these ads lately. Of course they will charge a fee. I believe your use case is super common and many services target this use case.

TLDR: Global money transfer is probably not something you can do casually and frequently. There are specific services, and fees, and headaches. Probably you want to minimize the amount of individual transactions as much as possible to minimize the headaches (of course there are cashflow limitations).

Re: Tell HN: Automatic fraud detection is making my life hell

#305
post #262

Earlier quoted context omitted.

If you get a list of wifi networks, you can look them up in various databases too check possible locations of the device.

... which reminds me of an experiment I keep meaning to run: Can I do a quick wifi survey (somewhere) and then replicate the SSIDs and channels in a completely different location and fool one of these SSID mapping functions ? What are these functions scanning for to perform the geolocation other than SSID and frequency and MAC addresses ? Relative or triangulated signal strength ?

Yes I think that would work. I remember moving house before withing the same city and moving our wifi router with us. For a while my phone kept placing me at my old house, when it didn't have a GPS signal.

Re: Tell HN: Automatic fraud detection is making my life hell

#307

>who are you (as a random online service) to assume you can act as my big brother? we're the people who suffer the consequences of the fraud. if your card gets used fraudulently, you call your bank and get the transactions cancelled, no big deal. if my website lets a fraudulent transaction through, my processing fees go up. if my website lets more than a couple fraudulent transactions through (or not even necessarily…

Yup. Having been on this side of the fraud business, I empathize with the OP but will definitely defend overly-aggressive fraud systems. As you make more money, it's less of an impact on your business, and you can tone them down. But at day 1, if people are only signing up for your service to see if their stolen credit card numbers work, there might not be day 2 unless you're aggressive about blocking this. So, sometimes innocent civilians will get caught up in the safety net.

Re: Tell HN: Automatic fraud detection is making my life hell

#308

Earlier quoted context omitted.

Almost everyone uses wifi for everything now. If you're using Ethernet there is a very high probability you are actually a proxy/vpn exit on a rack in some random residential location.

Well that's a shitty filter because now criminals will use wifi or fake using wifi. And then they will get right through. It's not that hard to fake. Security Theater.

You're filtering for people using vpns to access your site from a country other than the one they are claiming. They likely aren't criminal operations just users operating outside the bounds of your service. They aren't going to have the ability to do anything but sign up for a vpn service so it works quite well for stopping them.

Re: Tell HN: Automatic fraud detection is making my life hell

#309

Wrong assumptions programmers make about fraud prevention: -- A mobile phone number uniquely identifies a single person. -- Every person has a mobile phone number and they only have one mobile phone number. -- If a person's mobile phone number is associated with VoIP or Google Voice, that indicates fraud. -- Every person always has their mobile phone handy and it is always able to receive calls and SMS messages under…

> Geolocated IP addresses always indicate the preferred and correct human language of the person on the other end. My Google Maps language (on my PC) is STILL in Portuguese, but I only happened to be visiting Portugal (for 3 days) when they did the subdomain switch... Every time I change it back to English, it changes the language back the next time I visit the site. It's super frustrating.

Make sure you’re not visiting with a bookmark that includes the specific language code.

I had a similar issue with some history item that would annoyingly point me to the previous version of a page. Only to realize that I was opening a permalink to it.

Re: Tell HN: Automatic fraud detection is making my life hell

#310
post #137

Earlier quoted context omitted.

The problem with many of these examples is that 99% of the time, it is a sign of fraud, and 1% of the time it’s a false positive. > If a person's mobile phone number is associated with VoIP or Google Voice, that indicates fraud. I’ve been using this heuristic (along with VPN and IP geo lookup) when screening job candidates after a massive influx of developers outside the US applying for US-only remote roles. I discov…

The cost of the false positives are much higher than the false negatives. Temporarily slowing down down 99 scammers is not worth stranding one normal person in a foreign country with no means to access their money and no means to recover their account. The reality is that most lockdown-type protection schemes are just a roadbump, not a solution. They slow down the attacker. In fact, hackers are employing account lock…

> Temporarily slowing down down 99 scammers is not worth stranding one normal person in a foreign country with no means to access their money and no means to recover their account.

To that one person it obviously isn't worth it. To the company it absolutely is.

Post reply on HN