Live data from Hacker News

Improved fraud prevention with Radar 2.0

stripe.com

71–80 of 83 posts

Re: Improved fraud prevention with Radar 2.0

#71
post #2

Engineering manager for Stripe Radar here. Today’s update has been almost a year in the making and we’re excited to help Stripe businesses fight fraud more effectively. Here's more on what's new: https://stripe.com/blog/radar-2018 I (and the entire Radar team) are on hand to answer any questions you may have!

A problem we've run into with Radar is that it only kicks in when you attempt to create a charge, and not when you attach a card to a customer. This means that if your business model involves "try before you buy" or usage-based billing, you'd better be sure to make an initial charge, otherwise the customer might incur costs before Radar decides to block the charges. Even if you do require an initial charge, if you al…

My perspective on this is colored by selling SaaS.

In software sold on a free-trial model, you assume most trials don’t convert (overwhelmingly due to declining to pay but with a bit of fraud) and then the cost to provision the service (COGS) is, effectively, a marketing expense. COGS in SaaS are typically negligible to low; this is why the industry is OK with providing services on, basically, a digital handshake. If you want to allow users to try out high-COGS services (or highly-abused services) prior to verifying capacity/willingness to pay, you’d need some way to credit score potential customers outside the context of a particular payment.

To date, we’ve generally focused the bulk of our ML efforts on things which apply to the majority of our users, but as we get better at customizing these technologies to specific industries at scale and even on a per-account basis, we could certainly imagine applying them in contexts that are more relevant in your model. I’d love to hear more detail about your use case; feel free to email me (my HN username at stripe.com). If we get closer to shipping something that is probably interesting, we’d be happy to give you a heads up.

Re: Improved fraud prevention with Radar 2.0

#72
post #61

We've all but given up on Stripe's radar. We plugged in Signifyd, and it's amazing to see how often Stripe gets things .. completely wrong. Now obviously Signifyd scrub, but we haven't seen a case where we've had clean transactions scrubbed, and when a CB goes through, you're refunded. Likewise, you no longer have to worry about your CB% going over and you getting blacklisted for life. Until Stripe steps up and start…

Radar PM here. I’m sorry to hear this. If you’re up for it, I’d love to dig into the charges you think Radar’s gotten wrong (my email is eeke@stripe.com).

Re: Improved fraud prevention with Radar 2.0

#73

I really hope that this improves the false-positive rate, as mentioned in another comment. We've been hurt badly as a startup breaking into the US market and getting many of our genuine charges blocked by Radar (and at a "highest risk" level where it is not possible to disable rules). As a developer, I had the best possible impression of Stripe, as they provide easily the cleanest API and best documentation of any pa…

> ethically it's hugely problematic to deny people service based on their country

Practically though I worked for a company that saw hundreds of purchases from the Vietnamese IP space of which only two were not fraud. For the rest of the world it was in inverse.

Re: Improved fraud prevention with Radar 2.0

#74
post #47

Ok some really dumb questions if you don't mind, but how "fraud detection" works has always been one of those areas I am interested in, but not enough to seek out a practitioner and pin them down - until now ! - Any idea what the total fraud vs genuine transactions ratio is? And how that breaks down across industries? I am assuming that SaaS services don't get as much of this - i mean would people buy bingo cards wit…

> - how does fraud get monetised? In the early days of ecommerce, we jokingly called it 'Toners for Taliban'. They would purchase goods with a stolen card from a company that ships fast. They'd have the item shipped to a rube who answered a "Make money fast! All you need is a computer and a mail box!" advertisement. Then, the rube would resell the item on Ebay and send a cut back. The rube takes the fall, if any. Det…

oh !!! That's what those ads were for !!!

Today I learnt ... :-)

Re: Improved fraud prevention with Radar 2.0

#75
post #45

Earlier quoted context omitted.

This reminds me of Bank of America and Air Canada. I used to fly to Canada every week for work and every week my card would be declined by BoA when I tried to book on AirCanada.com. I had it down to a science, I knew the direct number to their fraud dept and I knew when I should place my call so that I'd usually be connected at just the right time to get the charge authorized with enough time to avoid the website ses…

Heh. My bank did something right, and my yearly $AUS payment to Fastmail finally went through without getting flagged by the automated systems. Alas, a human also saw the transaction, failed to read the note or look in the history and locked the card up anyway.

Fastmail charges you in AUD? Weird, I know it's an Australian company but I paid for service earlier this month and was charged in USD. And I'm not misinterpreting the "$" as a USD-only sign, the invoice literally says "USD".

Re: Improved fraud prevention with Radar 2.0

#76
post #75
post #45

Earlier quoted context omitted.

Heh. My bank did something right, and my yearly $AUS payment to Fastmail finally went through without getting flagged by the automated systems. Alas, a human also saw the transaction, failed to read the note or look in the history and locked the card up anyway.

Fastmail charges you in AUD? Weird, I know it's an Australian company but I paid for service earlier this month and was charged in USD. And I'm not misinterpreting the "$" as a USD-only sign, the invoice literally says "USD".

(I work for FastMail) We charge in USD, but the payment is processed in Australia. For some reason, American banks often block all payments processed outside of the USA; it's like they haven't heard of the concept of the internet and global trade…

We don't see this problem with banks in any other country (not do I ever have the problem in reverse, buying goods and services from foreign websites with my Australian credit card).

Re: Improved fraud prevention with Radar 2.0

#77
post #75

Earlier quoted context omitted.

Fastmail charges you in AUD? Weird, I know it's an Australian company but I paid for service earlier this month and was charged in USD. And I'm not misinterpreting the "$" as a USD-only sign, the invoice literally says "USD".

(I work for FastMail) We charge in USD, but the payment is processed in Australia. For some reason, American banks often block all payments processed outside of the USA; it's like they haven't heard of the concept of the internet and global trade… We don't see this problem with banks in any other country (not do I ever have the problem in reverse, buying goods and services from foreign websites with my Australian cre…

Working in information security, I see this a lot in security practices for US companies. The client says "let's block all traffic from outside the US" because they don't do business outside the US. Then come to find out they have contractors in India... and a partner datacenter in Singapore, and oh yeah their factory in China. And now the CEO is on vacation in Costa Rica and can't get on the VPN. And oh shit, there's the field office at one of their suppliers in the UK.

I say this as an American who has never lived outside the US but who deals with international clients regularly: the US seems uniquely inclined (in my experience) to think that everything they need falls within their borders, and everything outside their borders should be treated with suspicion. I've never had a German client want to block all traffic from South Africa. That's just an observation, I make no judgements as to why that is.

I did have an American university for a client who said "we cannot block or otherwise discriminate traffic from anywhere, since we have students or staff in every country outside of North Korea" which is a refreshing outlook IMO.

Re: Improved fraud prevention with Radar 2.0

#78
post #75

Earlier quoted context omitted.

Fastmail charges you in AUD? Weird, I know it's an Australian company but I paid for service earlier this month and was charged in USD. And I'm not misinterpreting the "$" as a USD-only sign, the invoice literally says "USD".

(I work for FastMail) We charge in USD, but the payment is processed in Australia. For some reason, American banks often block all payments processed outside of the USA; it's like they haven't heard of the concept of the internet and global trade… We don't see this problem with banks in any other country (not do I ever have the problem in reverse, buying goods and services from foreign websites with my Australian cre…

Do you know if this mainly a Visa/Mastercard issue or does this affect American Express as well? The latter isn't a network of banks and seems to be less restrictive towards international payments, but I could be wrong.

FWIW, I paid with AMEX (using Stripe not PayPal) and it went through right away.

Re: Improved fraud prevention with Radar 2.0

#79
post #21
post #15

Earlier quoted context omitted.

One of the issues that I faced during my short stint building ML models for fraud detection in debit card transactions was dealing with class imbalance. I was not completely convinced that over sampling techniques or under sampling techniques would work. My initial experiments just resulted in more false positives. Just curious if you guys faced similar problems. The other point I bring about is rather rhetorical - T…

I agree that the lack of standards and baselines in the fraud detection space isn't ideal. One example: some fraud products will build models using human labels as the target to be predicted. Radar, on the other hand, tries to predict whether a charge actually turns out to be fraudulent (we use dispute/chargeback data we get directly from card issuers/networks). These are in fact different problems and the fact that…

If you are still on this thread - check this video out at 28:56

https://www.youtube.com/watch?v=4inIBmY8dQI&feature=youtu.be

Re: Improved fraud prevention with Radar 2.0

#80
On a throwaway so I can reply to this. Creditcard fraud is ripe and easy when it came to stripe a few years ago, I havn't carded anything for awhile. But glad to see stripe working on fraud prevention. We use to use tor and not even need to hop exit nodes and we could drain 100+ ccs into twitch streamers alerts for a gag and without stripe then we'd be stuck with paypal, screw carding paypal stripe all the way. Might be useful if stripe tried to card their services themselves to learn to prevent it, but they didnt even appear to try. Atleast block tor for credit card transactions come on, no one is going to use tor to pay for something under their own credit card. Kinda defeats the purpose of tor.
Post reply on HN