Live data from Hacker News

How Candy Japan got credit card fraud somewhat under control

candyjapan.com

81–90 of 128 posts

Re: How Candy Japan got credit card fraud somewhat under control

#81
In the article, PayPal it's often mentioned that PayPal is generally disliked.

As an international customer, I prefer PayPal over giving them my credit card details. When entering my CC, there is a big risk that my data gets stolen (is the data truly securely transmitted, stored, and processed?). I know I can request a refund that any time with my bank but that is a big hassle. I have to write them a physical letter, and wait for a couple of days. During that period, my CC is blocked and I they will likely issue me a new credit card (which costs 10€). When paying with PayPal, I can report a fraud online or call them and they have been really quickly in responding (I have once not gotten a product and they were very quick in issuing a refund). Also, I feel way more comfortable using PayPal because I can see that the site I'm entering my information to is actually PayPal, and I have two factor authentication. Before I didn't have a CC, PayPal was the best solution because they would just withdraw the money from my bank account and they merchant would get their money immediately.

I can understand why PayPal is not a good choice for sellers (I've heard stories where PayPal blocked merchant accounts for a few months without giving them their money they had on PayPal, and refusing any new transactions). So, can you explain to me why PayPal is a bad/unpopular choice as a customer.

Re: How Candy Japan got credit card fraud somewhat under control

#82
post #80

Earlier quoted context omitted.

Not bad, but even that reads like a bit of an FU from the devs. ("Pig Iron?") The best thing to do is to make it definitely seem like it was a bug introduced by the crack. (Maybe James Bond villains giving their secret projects suggestive code names and telling their entire plan isn't unrealistic?)

It's important not to disguise any anti-piracy measures as bugs, because pirates (or even reviewers playing pirated copies) will loudly proclaim that the game is buggy, and discourage legitimate buyers. This may have contributed to the closing of at least one development studio (Iron Lore, developer of Titan Quest)[1]. [1] http://www.quartertothree.com/game-talk/showthread.php?42663...

This must be specific to the games, because they do tend to be buggy on their own.

With non-gaming software the situation is completely different. When a cracked version craps out the prevailing sentiment is always that it was a bad crack. Always.

Re: How Candy Japan got credit card fraud somewhat under control

#83

In the article, PayPal it's often mentioned that PayPal is generally disliked. As an international customer, I prefer PayPal over giving them my credit card details. When entering my CC, there is a big risk that my data gets stolen (is the data truly securely transmitted, stored, and processed?). I know I can request a refund that any time with my bank but that is a big hassle. I have to write them a physical letter,…

Keep in mind that PayPal leaks lots of your personal information to the sellers, including full street address. Merchants don't even need to opt-in to get it, it's all provided by default for all purchases, even when there are no physical goods involved.

Re: How Candy Japan got credit card fraud somewhat under control

#84
post #83

In the article, PayPal it's often mentioned that PayPal is generally disliked. As an international customer, I prefer PayPal over giving them my credit card details. When entering my CC, there is a big risk that my data gets stolen (is the data truly securely transmitted, stored, and processed?). I know I can request a refund that any time with my bank but that is a big hassle. I have to write them a physical letter,…

Keep in mind that PayPal leaks lots of your personal information to the sellers, including full street address. Merchants don't even need to opt-in to get it, it's all provided by default for all purchases, even when there are no physical goods involved.

And yet 95% of all my purchases require a billing address, even if they we'll never ever send me a letter. Even better, some even check if the billing address is correct (they send it along with my CC# to my bank and my bank will decide what to do).

Re: How Candy Japan got credit card fraud somewhat under control

#85

Earlier quoted context omitted.

Yes. At $DayJob we have a similar process [e.g. Accept any card that passes the checksum, hand out rejections on a 24 hour delay after we've handled our fraud signals and processed the charge with the gateway] The credit card processors aren't particularly interested in handling this for you and you [the merchant] pay the price if you gave the processor stolen card numbers. Services like these: https://www.signifyd.c…

Completely agree with fweespee_ch. Major CC processors such as Authorize.net, Braintree, etc. offer fraud protection measures but in our experience they do very little to prevent even a remotely-capable fraudster. Typical features offered are IP Velocity & regional IP (useless when the fraudsters spin up thousands of amazon servers), # of transactions per hour (not too helpful when your business already does hundreds…

There seems to be a huge conflict of interest here: as card processors slap you with an extra chargeback fee for the fraudulent transactions (in addition to the amount they take back anyway) it's difficult to believe that they would work very hard to help you avoid this.

Re: How Candy Japan got credit card fraud somewhat under control

#86
post #65
post #56

Earlier quoted context omitted.

Blue Byte did something along the lines of your suggestion with the copyright protection of Settlers III. When the game detected that the DRM was broken, iron smelters would only produce pigs instead of iron. https://en.wikipedia.org/wiki/The_Settlers_III

reminds me of "Game Dev Tycoon", where if it detected it was cracked, the player had a hard time progressing because their virtual company kept getting ripped off by crackers. http://gameological.com/2013/05/inventory-9-games-with-creat... (it is the first one)

For a much older example, Sim City gave continual disasters after about 10 minutes if the version was detected as pirated. This was 1990 or so.

Re: How Candy Japan got credit card fraud somewhat under control

#87
post #85

Earlier quoted context omitted.

Completely agree with fweespee_ch. Major CC processors such as Authorize.net, Braintree, etc. offer fraud protection measures but in our experience they do very little to prevent even a remotely-capable fraudster. Typical features offered are IP Velocity & regional IP (useless when the fraudsters spin up thousands of amazon servers), # of transactions per hour (not too helpful when your business already does hundreds…

There seems to be a huge conflict of interest here: as card processors slap you with an extra chargeback fee for the fraudulent transactions (in addition to the amount they take back anyway) it's difficult to believe that they would work very hard to help you avoid this.

Why? They have a profit motive for you to get scammed.

Re: How Candy Japan got credit card fraud somewhat under control

#88
post #83

Earlier quoted context omitted.

Keep in mind that PayPal leaks lots of your personal information to the sellers, including full street address. Merchants don't even need to opt-in to get it, it's all provided by default for all purchases, even when there are no physical goods involved.

And yet 95% of all my purchases require a billing address, even if they we'll never ever send me a letter. Even better, some even check if the billing address is correct (they send it along with my CC# to my bank and my bank will decide what to do).

In Europe it's the law that you need to record the billing address (for 10 years) otherwise you can't obey the VAT laws.

Re: How Candy Japan got credit card fraud somewhat under control

#89

Eliminating immediate feedback about failed transactions makes things harder for everyone the fraud detection system identifies, both fraudsters and the many false-positives. And the false-positive rates seem very high, IME; it seems like I and everyone I know has encountered that problem multiple times. Imagine that you place a legitimate order and they don't tell you it failed; how do you find out? Days later when…

There's nothing inherently bad about very angry customers. It's more about how you handle them and whether you are continuously looking for ways to decrease them in number.

In this case, the idea is these are people who tripped red flags for you, and upon investigation didn't give you any reason to believe they were legitimate orders.

If you're really worried, you can contact them and ask.

Re: How Candy Japan got credit card fraud somewhat under control

#90
post #28

Earlier quoted context omitted.

Why not just refuse to do business with Vietnam, Nigeria, Russia, and other fraud havens entirely?

I am a native-born American citizen living in Russia. The amount of grief that your solution causes me is significant. I'm a legitimate customer who does nothing fraudulent. However, whole swaths of the internet treat me as if I have leprosy just because my IP address is in Russia.

I don't know how to say this without coming off harsh, so I'll say it and ask you to use the principle of charity when reading it.

If the Russian state refuses to stamp out crime that is causing negative externalities, then people should rightly stop dealing with people inside Russia as a logical response.

Post reply on HN