Live data from Hacker News

Keeping our free tier sustainable by preventing abuse

geocod.io

1–10 of 47 posts

Re: Keeping our free tier sustainable by preventing abuse

#5
post #2

I get why they don't want to share their detection mechanics for potential fraudulent signups, but that is a very interesting topic to learn and discuss.

I would love do a more in-depth talk about this at some point with some more concrete examples.

Re: Keeping our free tier sustainable by preventing abuse

#6
Thanks for this writeup. Whenever people complain about some service removing or making it harder to try out a free tier, I think they don't realize the amount of abuse that needs to be managed by the service providers.

"Why do things suck?" Because parasites ruined it for the rest of us.

> We have to accept a certain amount of abuse. It is a far better use of our time to use it improving Geocodio for legitimate users rather than trying to squash everyone who might create a handful of accounts

Reminds me of Patrick McKenzie's "The optimal amount of fraud is non-zero" [1] (wrt banking systems)

Also, your abuse-scoring system sounds a bit like Bayesian spam filtering, where you have a bunch of signals (Disposable Email, IP from Risky Source, Rate of signup...) that you correlate, no?

[1] https://www.bitsaboutmoney.com/archive/optimal-amount-of-fra...

Re: Keeping our free tier sustainable by preventing abuse

#7
Great writeup. Simple heuristics very often work wonders. The fraudsters are out there and try to pinch holes in your shield. Some time ago we were running a mobile service provider and had some issues with fraudulent postpaid subscribers - however the cost of using background checking services was substantial. We solved it quite effectively by turning the background checks on when the level of fraud went over a certain threshold which made them go away for some weeks. We kept this on and off pattern for a very long time with great success as it lowered the friction to sign up significantly when turned off…

Re: Keeping our free tier sustainable by preventing abuse

#8

so you implemented some sort of machine learning?

Not at this time. Some simple heuristics go a long way and also makes it very easy to test and debug the logic.

I once did a machine learning project at Intel. The end result was that it was no better than simple statistics; but the statistics were easier to understand and explain.

I realized the machine learning project was a "solution in search of a problem," and left.

Re: Keeping our free tier sustainable by preventing abuse

#10
post #9

Makes me wonder how easy / hard it is to turn this kind of feature into a standalone product? IE, send email, IP, browser agent, and perhaps a few other datapoints to a service, and then get a "fraudulent" rating?

This is basically what Google's reCAPTCHA v3 does: https://developers.google.com/recaptcha/docs/v3

The other versions of recaptcha show the annoying captchas, but v3 just monitors various signals and gives a score indicating the likelihood that it's a bot.

We use this to reduce spam in some parts of our app, and I think there's an opportunity to make a better version, but it'd be tough for it to be better enough that people would pay for it since Google's solution is decent and free.

Post reply on HN