Live data from Hacker News

A large collection of fraudulent web stores

chair6.net

61–70 of 75 posts

Re: A large collection of fraudulent web stores

#61

Earlier quoted context omitted.

If homophones are the pattern to follow, then (since a large collection of legitimate stores can be thought of as a "mall") perhaps the new word should be "a maul" or "a mawl" (suggestive of being something that swallows your money, and doesn't give you anything of value in return).

Maybe I should have said a phishbowl then!

[deleted]

Re: A large collection of fraudulent web stores

#62
post #58

Earlier quoted context omitted.

As weird as it sounds, it is still the best. If we have centralised "licensing" solution it is abused by large capital to wash off smaller - there is plenty of examples. If we have decentralised solution (which is basically what review is) - it is immediately abused by "marketers". There is no simple and easy solution to the problem.

IMO, the best solution to the problem is friction. Criminals are criminals because it's easy. If opening a fraudulent store is 90% as difficult as opening a legit one, no one is going to bother.

I see what you're saying: if you add more startup cost then it makes it harder for spammers without legitimate business interest to profit. I think I disagree, though. Legitimate "mom and pop" businesses experience all the pain of learning the process of setting up a store, creating real products and pricing, inventory, delivery etc. They don't need more friction.

These criminals on the other hand are likely automating everything and have the advantage of lessons learned from dozens of iterations.

The article indicated the mimic sites accept credit card numbers but don't actually process them -- to me that is the Achilles heel of the process. If credit card companies started requiring instantaneous verification of the card's actual use (via a card chip reader or an app on user's phone, for example) instead of allowing payment via static information vulnerable to replay at any time, I think that could do a lot more to improve security of online transactions than green check boxes.

Re: A large collection of fraudulent web stores

#63
post #47

Earlier quoted context omitted.

To me it's very simple: nation states should have their own layer that uses the national registry for companies to verify a domain. When you register a business you also provide your official domains and so the validity of the website is checked against the validity of the business.

The thing is, we tried this already. Twice. First with domain names. The domain "nissan.com" is not owned by the well-known car company but by a completely unrelated computer company. As "Nissan Motors v. Nissan Computer" settled, this is totally fine and Nissan Computer still owns the domain. Besides exact matches there are also similar-looking names. For example, a student named Mike Rowe started a small webdesign…

Semi-OT: You just reminded me of dealing with subsidiaries in the1980s and 1990's. (Before chain of certs).

I spoke up about it on a mailing (probably an IETF one) list about subsidiary companies should be required to have not xyz.com but xyz...com as their address. Example: In the U.S. it's not simple to get /real/ xyz with all the vitamins. So a hypothetical xyz.com should really turn up on search result as xyz..com.

Adjust as fit. Maybe $xx/year or the quantity of companies underneath the majorowner before compliance.

I was praising the value of something I did know the USian market had a distributorship over [in the geographical real] with a sub-standard product.

Let me know that I am looking at stats on y product (only served in z country).

Let me know that xyz name in my country is different ta your place.

Re: A large collection of fraudulent web stores

#66
post #58

Earlier quoted context omitted.

As weird as it sounds, it is still the best. If we have centralised "licensing" solution it is abused by large capital to wash off smaller - there is plenty of examples. If we have decentralised solution (which is basically what review is) - it is immediately abused by "marketers". There is no simple and easy solution to the problem.

IMO, the best solution to the problem is friction. Criminals are criminals because it's easy. If opening a fraudulent store is 90% as difficult as opening a legit one, no one is going to bother.

Organised criminal syndicates are behind most of these operations. They have immense resources from which to draw. It's another example of the saying, 'It takes money to make money.'

IOW, adding friction wouldn't be a sufficient deterrent. Criminals are resourceful, and enriching themselves further is a strong motivator.

Re: A large collection of fraudulent web stores

#67
post #58

Earlier quoted context omitted.

IMO, the best solution to the problem is friction. Criminals are criminals because it's easy. If opening a fraudulent store is 90% as difficult as opening a legit one, no one is going to bother.

I see what you're saying: if you add more startup cost then it makes it harder for spammers without legitimate business interest to profit. I think I disagree, though. Legitimate "mom and pop" businesses experience all the pain of learning the process of setting up a store, creating real products and pricing, inventory, delivery etc. They don't need more friction. These criminals on the other hand are likely automati…

There’s danger on the other side of this: Credit card companies are already stifling creators because of the power they have when CCs are the primary payment method. Additional security gives them a tighter grip.

Re: A large collection of fraudulent web stores

#70

I wonder if the best bet would be to hash the main site and its images. Then retroactively scan sites with similar HTML hash and flag them? Fairly sure you could do a HTML search with Google, 7 stores having extremely similar HTML and images seems rather unlikely. Effectively, it's virus total but for copycat sites.

But there's no such thing as a "similar" hash - change one character in the HTML, and the hash would be completely different.
Post reply on HN