Live data from Hacker News

Improved fraud prevention with Radar 2.0

stripe.com

61–70 of 83 posts

Re: Improved fraud prevention with Radar 2.0

#61
We've all but given up on Stripe's radar. We plugged in Signifyd, and it's amazing to see how often Stripe gets things .. completely wrong.

Now obviously Signifyd scrub, but we haven't seen a case where we've had clean transactions scrubbed, and when a CB goes through, you're refunded.

Likewise, you no longer have to worry about your CB% going over and you getting blacklisted for life.

Until Stripe steps up and starts providing chargeback protection, their protection is simply lipservice.

Re: Improved fraud prevention with Radar 2.0

#62
post #2

Engineering manager for Stripe Radar here. Today’s update has been almost a year in the making and we’re excited to help Stripe businesses fight fraud more effectively. Here's more on what's new: https://stripe.com/blog/radar-2018 I (and the entire Radar team) are on hand to answer any questions you may have!

A problem we've run into with Radar is that it only kicks in when you attempt to create a charge, and not when you attach a card to a customer.

This means that if your business model involves "try before you buy" or usage-based billing, you'd better be sure to make an initial charge, otherwise the customer might incur costs before Radar decides to block the charges.

Even if you do require an initial charge, if you allow customers to change their credit card between recurring charges, the new card could be extra risky and "fly under the Radar" until the first charge attempt.

Are there any plans to offer fraud risk and blocking when attaching a card to a customer, or will still be limited to just blocking charges? With Stripe's new emphasis on recurring billing, it seems like this would be important.

We currently see Radar as a liability for us. It might block the occasional fraud and avoid a chargeback, but it also allows customers to incur costs with dodgy cards before we know they're dodgy, and then blocks charges outright before we know.

Re: Improved fraud prevention with Radar 2.0

#63

I really hope that this improves the false-positive rate, as mentioned in another comment. We've been hurt badly as a startup breaking into the US market and getting many of our genuine charges blocked by Radar (and at a "highest risk" level where it is not possible to disable rules). As a developer, I had the best possible impression of Stripe, as they provide easily the cleanest API and best documentation of any pa…

There is also another problem - exactly opposite to what you describe. Stripe can't block fraudulent payments as good as others (Eg. PayPal). I don't know why or why not, but they simply slip it up. And here's the worst part, when there is a chargeback, you can't get hold of anyone to prove your innocence and eventually the case will slide with the customer. If you are selling physical products, this sucks because the scammer now has your product AND your money. Sad.

To be fair, Stripe is excellent for developers. For businesses? Not so much. You're either stuck with a monopoly, with shitty documentation and archaic APIs (PayPal) but works well for businesses or you're stuck with a new age (Startup?) that's really great at everything except helping you make money.

Here's me hoping for a better Stripe alternative. There's really a lot of space in this market.

Re: Improved fraud prevention with Radar 2.0

#64

Ok some really dumb questions if you don't mind, but how "fraud detection" works has always been one of those areas I am interested in, but not enough to seek out a practitioner and pin them down - until now ! - Any idea what the total fraud vs genuine transactions ratio is? And how that breaks down across industries? I am assuming that SaaS services don't get as much of this - i mean would people buy bingo cards wit…

> - how does fraud get monetised? Once i have downloaded my millions of credit card numbers from Tor (or stolen my friends mothers wallet) I need to persuade a merchant to deliver me something - but it's always bugged me that they actually have to deliver it. to a physical address. that can presumably be traced. It all seems very low level

(Disclaimer: I work for a competitor to Stripe Radar)

This is actually really interesting. An important thing to remember about fraudsters is that they're mostly professionals. Every day they wake up thinking "how do I get around anti-fraud systems." Many are located in jurisdictions that have poor enforcement for cyber crimes, so they're not necessarily worried about official action. However you're right that they do actually need to get the goods shipped without too many questions.

Two common strategies for this:

* You know all those "work from home for $100/hour" ads you see? Some are run by fraudsters who use those people as re-shippers. I.e., the website ships to some guy in the US, and that guy reships the good to the fraudster in Eastern Europe for a cut of the profit. If the fraudsters build up a nationwide network of reshippers, they'd be able to find one who lives close to the billing address of the card they're using.

* There's an even cleverer scam that goes like this: the fraudster creates a merchant account on Ebay or similar. They then select high-value goods available on other websites, say BestBuy, and list them for sale at a substantial discount. Then, when an unwitting customer buys the good from their Ebay store the fraudster places an order from BestBuy using a stolen credit card and has it shipped to the buyer. They get the money from the buyer, the buyer gets the goods, and nobody's the wiser until the chargeback comes in to BestBuy a month later.

Re: Improved fraud prevention with Radar 2.0

#66
I love Stripe and am an early and long time customer.

Everything about them is beautiful, simplified and easy - except Radar.

For all the blogs and good intentions of the team, Radar to me means an email 3 days after I've processed and shipped an order telling me it may be fraudulent, followed a month later by a reminder "I'm sorry, you lost your credit dispute for $X" email, followed by a $15 charge by Stripe for no error or bad faith on the part of my company.

When Radar isn't busy sending me reminders that we're having money stolen from us, they are hard at work denying legit charges and sending customers down a Kafka-esque rabbit hole, hell bent on seeing exactly how much friction can be introduced into our website's buying process by a single third party service.

Stripe didn't create the fraud and they are taking on a difficult and emotional part of their business, which is commendable, but it must be said:

1. The false positive rate of Radar is so bad that it renders the product worse than useless - worse because it initially provides a false hope.

2. You can't disable some parts of Radar. Better to throw the whole thing into the sea and use a plugin then be forced into some parts of this.

I know there are good people trying hard to build this product well. Some of the people on it serviced our account in the early days. They had a vision of a better way and they made it real. My hats off to them. Now, people I respect, I have hard words and a hard truth to impart to you:

You are not delivering the value you claim to provide. Do not continue iterating. Discontinue the product. Allow others who focus on this to do it well. You are great at what you do but you are frustratingly, annoyingly, arrogantly bad at this. It pisses us all off to be forced to use it and to be told again and again how great it is going to be or how fixed it is this time. I don't want to engage with Stripe on Radar or "learn more about it", I don't want to be interviewed by you so you can better understand the voice of customer, there is no email or back channel thing you can send to make this better. The beauty of Stripe is that it "just works" but Radar does not just work - and it never will.

Re: Improved fraud prevention with Radar 2.0

#67

I really hope that this improves the false-positive rate, as mentioned in another comment. We've been hurt badly as a startup breaking into the US market and getting many of our genuine charges blocked by Radar (and at a "highest risk" level where it is not possible to disable rules). As a developer, I had the best possible impression of Stripe, as they provide easily the cleanest API and best documentation of any pa…

In India, the government mandates 2 factor (usually via text message) verification for all card transactions.

It's a moderate pain in cases like Uber, but usually we have very few chargeback issues .

Re: Improved fraud prevention with Radar 2.0

#69
post #30

Earlier quoted context omitted.

Broadly speaking, what approach do you use to "build simpler 'explanation models'" from the more complicated "core fraud models"? Do you learn the models separately over the training data, or does the more complicated model somehow influence the training of the simpler model?

Why you so stubborn on IP address? Its not a holy grail! I use proxy for some years now and many times I want to buy something on the frontstore “powered by Stripe” and my card is declined due to “unknow error”. Moment I turn off my vpn, transaction goes thru. I can exect this to be a huge problem for Stripe or anyone deciding on fraud attempt greatly basing it on IP. These days if i find a cool product and see “powe…

I’m sorry that you had this experience. We vehemently agree that any one signal (such as IP address or use of a proxy) is a pretty poor predictor of fraud in isolation. We are trying to move the industry towards holistic evaluation rather than inflexible blacklists; not everyone behind a TOR exit node is a fraudster, for example.

While we can’t fix the previous experience you had, we’ve rebuilt almost every component of our fraud detection stack over the past year. We’ve added hundreds of new signals to improve accuracy, each payment is now scored using thousands of signals, and we retrain models every day.

We hope these improvements will help. We want our customers to be able to provide you services; that’s what keeps the lights on here. We’d be happy to look into what happened if you have specific websites in mind—feel free to shoot me a note at mlm@stripe.com.

Re: Improved fraud prevention with Radar 2.0

#70
post #66

I love Stripe and am an early and long time customer. Everything about them is beautiful, simplified and easy - except Radar. For all the blogs and good intentions of the team, Radar to me means an email 3 days after I've processed and shipped an order telling me it may be fraudulent, followed a month later by a reminder "I'm sorry, you lost your credit dispute for $X" email, followed by a $15 charge by Stripe for no…

PM for Radar here. Really sorry to hear that. Portions of your comment are surprising to me but I don’t want to discuss your business in public. We’d be happy to discuss in private. If you don’t want to, we respect that.

For the benefit of other HNers: if you ever have a concern about this sort of issue, we’d love to hear from you (my email is eeke@stripe.com). This is all I do every day; you can never waste my time.

Post reply on HN