Live data from Hacker News

Tell HN: Automatic fraud detection is making my life hell

news.ycombinator.com

351–360 of 406 posts

Re: Tell HN: Automatic fraud detection is making my life hell

#351

Wrong assumptions programmers make about fraud prevention: -- A mobile phone number uniquely identifies a single person. -- Every person has a mobile phone number and they only have one mobile phone number. -- If a person's mobile phone number is associated with VoIP or Google Voice, that indicates fraud. -- Every person always has their mobile phone handy and it is always able to receive calls and SMS messages under…

I'm calling BS on this list. Pretty much noone makes any of these assumptions. The thing with many of these (eg VoIP, Google Voice, VPN etc) is that the population who use these for legitimate purposes is too small for most devs to care about given the cost of fraud from people who are using these things nefariously. Both type I and type II errors are important but they mostly only care about type II errors because type I errors just piss off a small number of good people whereas type II errors cost them money and if they go unabated will get them shut down by payment processors, banks, regulators etc.

Re: Tell HN: Automatic fraud detection is making my life hell

#352

Earlier quoted context omitted.

I'll add another to that list: -- People will never have a physical mailing address that contains "funny" numbers like "000", "420", "69420", or "80085".

I used to live in Baltimore, where there are numbered streets that include ½ symbol streets, and worse, house numbers including ½ numbered houses.

How does one enter "½" into a webform?

Re: Tell HN: Automatic fraud detection is making my life hell

#353
post #203

As someone who's previously been involved in KYC/AML I've a long held suspicion that these policies are in place to benefit the United States while deliberately inconveniencing everyone else.

Can you explain? I'm not sure I get how this benefits the US specifically.

I'm not American but have held and used cards from a European and Asian country and am not sure how the behavior is any different.

Re: Tell HN: Automatic fraud detection is making my life hell

#354
post #274
post #83

I am no longer allowed to buy anything at Ikea. The web site declines both my credit card and debit card. I called my credit card company, and no issues there. I called Ikea and tried to order through a person, but my cards were also declined that way. They can't give me any explanation. This happened in 2019 and again the next time I tried in 2021.

i know ikea doesn't accept bitcoin, but what happens if you pay cash

I was only trying to buy online and wasn't close enough to a store to want to try that.

Re: Tell HN: Automatic fraud detection is making my life hell

#355

Earlier quoted context omitted.

I tried to place some online bets for a friend who is in prison. But the betting sites don't allow you to use an ethernet cable to connect to your router o_O (unless you also enable wifi.. except my desktop doesn't have wifi) https://helpcenter.il.betrivers.com/hc/en-us/articles/360049...

How do they scan for wifi?

You have to download an app :(

Re: Tell HN: Automatic fraud detection is making my life hell

#356
Update, Amazon basically said they won't accept to remove the hold on my account, saying:

> The information you supplied was reviewed by Amazon but we cannot remove the hold on your account at this time. For details, check for an email or text message from Amazon describing next steps. Please contact us for further concerns.

I provided my visa + passport + card pic + selfie + Screens of latest Gift card order (email and from the website), still they won't remove the hold and effectively stealing the money in the account. I can't believe this is being done in good faith, this is clear theft, because what else they need?

Re: Tell HN: Automatic fraud detection is making my life hell

#357
post #137

Earlier quoted context omitted.

The problem with many of these examples is that 99% of the time, it is a sign of fraud, and 1% of the time it’s a false positive. > If a person's mobile phone number is associated with VoIP or Google Voice, that indicates fraud. I’ve been using this heuristic (along with VPN and IP geo lookup) when screening job candidates after a massive influx of developers outside the US applying for US-only remote roles. I discov…

My primary phone number is a Google Voice number, and I am entirely legitimate. Just curious, how often are other people filtering with this kind of criteria? I have been considering migrating away from GV for unrelated reasons, but if that sort of thing automatically makes me less attractive when looking for gigs then I'd like to prioritize actually doing that.

Long story short, GV or VOIP numbers will forever be a big red flag for me moving forward.

Longer story:

A few months ago, I posted a job for a remote US-based developer. 90% of the applicants were not in the US. Some of those who were immediately rejected re-applied with new US addresses and phone numbers, but that's another story. In the end, hired someone who was a great fit, passed the background checks, etc. The only odd thing was their phone number was GV and didn't match the location of their address. My mobile number doesn't match where I currently live and lots of people use GV, so we didn't think much of it.

About 4 weeks in, they sent me a message on a Sunday saying there was a family emergency. They would not be online during normal business hours, but would check in and would still work on tasks as they could. No big deal, I asked for follow-up on two assigned tasks so they could be handed off to someone else to finish a sprint that week.

After two days, haven't heard anything, reassigned the tasks and tried to reach out to check on the person. Phone number goes to the generic GV voicemail prompt, I leave a message. I tried calling the emergency contact, same thing. I reach out through LinkedIn & personal email, no RESPONSE. At this point, we disabled accounts and access to systems. No real reason or policy why, just seemed like a good idea.

Two days later, now Thursday, I start getting calls from a random phone number (also GV from another area of the US), but leaving no messages. Then I get texts, "This is I've been trying to reach you, please call me back." I call back within 3 minutes, straight to GV generic voicemail.

A few hours later, the number calls again, I answer "Hey, this is , I was trying to get some work done but it seems my accounts are disabled". After explaining the situation, they simply offered "Well, everything is good now and I'm ready to work." I tried asking some basic things like, are they okay, is their family okay, can we help with something, did you get arrested? Anything to give them a opportunity to offer something. The only response they gave was, "I'm back now and ready to work, if you'll enable my accounts." Over and over.

I explained it wasn't that simple, walked through the communication inconsistencies and asked how that would affect their reliability in the future. You will only need one guess for the response, "I'm back now and ready to work, if you'll enable my accounts."

I thanked them for reaching out and said I'd talk to HR and CEO so we could discuss (both had also reached out through personal LinkedIn, email and phone numbers to check on the person, no responses).

They were still in the 90 day probationary period, so we let them go. They were a very good developer, smart, good coding practices, but inconsistency is a killer. And yes, a GV or VOIP number will be a hurdle any future applicant needs to overcome with flying colors.

Re: Tell HN: Automatic fraud detection is making my life hell

#358
post #200

Earlier quoted context omitted.

You could use identity verification: https://plaid.com/products/identity-verification/ https://stripe.com/identity https://www.id.me/

Or you know, your brain And don't accept candidates without video chatting first, or who behave weirdly in interviews

I'm not a fan of video chat during hiring interviews. It's a great way to discriminate (race, sex, age, disabilities) right out the gate

Re: Tell HN: Automatic fraud detection is making my life hell

#359
post #40

Earlier quoted context omitted.

One thing I try to do to avoid this is to always make a purchase at the airport before I go overseas. This seems to calm down the algos a bit. I used to go through this a bunch too.

Great idea, spend your money to earn the privilege of spending your money later.

I hear you- but buying a coffee or magazine I wanted anyway isn't such a big price to pay to help ensure I'm not in an annoying situation where my card is declined somewhere and I have to call internationally to get it sorted.

Re: Tell HN: Automatic fraud detection is making my life hell

#360
post #173

Earlier quoted context omitted.

> The problem with many of these examples is that 99% of the time, it is a sign a fraud, and 1% of the time it’s a false positive. That’s the key. It may very well be the wrong business decision to care about this 1%.

This is exactly it. Nobody assumes these factors are always true. Absolutely nobody in the fraud prevention chain. They're just true often enough that the company is better off declining to serve the few exceptions than it is trying to build things around the edge cases.

it makes sense that every company ever has a bunch of broken by design security features that were justified after the fact by "risk model", after failing to arrest anyone who pointed out that they were broken, that award people who are uneducated and even moreso not self-accountable to just manage their password or key properly. it makes sense that these features that cannot be opted out require you to constantly give every company your personal id, location, comprehensive profile of your voice and speech patterns (and mouse movement patterns), and selfies using proprietary apps which require you to own highly specific products from 1 or 3 companies.

it makes sense to require email as a second captcha^H^H^H backup authentication thing^H^H^H mechanism we cant explain for your security which requires using one of the 4 remaining email services all of which cant be used without phone verification (btw all these will do things like, lock you out when you switch phone number which is even smaller space than IPv4). what if use different emails for two companies and they are corroborated at some point? do they think i'm identity hopping? but wait, should i be punished for using the same email for my games as my bank? is my email address my identity or should i use multiple to mitigate risk? oooooh i'm thinking too hard, it just makes sense because an adult on HN said they are also totally adults making these decisions based on sound reasoning. if i thought too hard that would also break the risk model because it would no longer be secret which is essential for it to work, and therefore i would be a criminal.

it makes sense that someone can just steal my money from my bank account because he spent an hour figuring out how it really auths you (actually they just learned all they need is the last restaurant you ate at and a rough amount you spent, totally not a guessable number) whereas i assumed just nobody having my password would be sufficient.

it makes sense that my keyboard, monitor, and speaker each have their own OS that takes 10 seconds to boot and also have remote code execution vulnerabilities, because none of that would ever matter for a casual user. it makes sense that my dishwasher doesn't work, that doesn't matter for a casual user since regurgitating crap onto the dishes only gives you disease 1% of the time, its green!

it makes sense that my random photo id is a password and i give it to 50 different companies because everything in the world is good.

some ceo said so, it all makes good business sense.

tl;dr you're literally just defending the garbage dystopia Richard Stallman warned about 70 years ago or whatever.

Post reply on HN