TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Radar – A new set of integrated tools to help prevent fraud

293 pointsby sinakover 8 years ago

23 comments

compumikeover 8 years ago
Just checked our Stripe dashboard and it looks like this has quietly been doing good work for us for many months now blocking suspicious charges. It took me a few clicks to find <a href="https:&#x2F;&#x2F;dashboard.stripe.com&#x2F;search&#x2F;rules?rule_token=block_if_high_risk" rel="nofollow">https:&#x2F;&#x2F;dashboard.stripe.com&#x2F;search&#x2F;rules?rule_token=block_i...</a> and after going through a few of them, the per-charge risk factor descriptions are really helpful too. The high-risk reasons are messages like: &quot;This card has been used from an unusually large number of IP addresses across the Stripe network over the last 24 hours.&quot; and &quot;This email has been linked to an unusually large number of cards across the Stripe network over the last hour.&quot;<p>Thanks to Stripe for making it not-a-black-box! I hope others who build machine learning systems also find a way to make its decisions understandable by humans (when possible).
评论 #12748589 未加载
评论 #12747768 未加载
评论 #12746994 未加载
bfleschover 8 years ago
I like the rotating 3D model in the landing page very much. Are they using some sort of pre-baked library which lets you create such an visualization with 30 lines of Javascript, or is it 100% custom? Maybe someone can point me to a good resource for such elegant WebGL renderings.
评论 #12746658 未加载
评论 #12746611 未加载
评论 #12746585 未加载
评论 #12751368 未加载
rwmurrayVTover 8 years ago
I think the &quot;golden age&quot; of online fraud is coming to an end quickly. I&#x27;ve posted quite heavily on Stripe and fraud threads on HN previously if you want to read my comment history.<p>This is a big step for Stripe. I&#x27;ve often asked why they didn&#x27;t have an integration with MaxMind or SiftScience already set up. They&#x27;ve been building their own behind-the-scenes the entire time! This feature is fantastic if you are a merchant and want to avoid fraud.<p>To me, the more interesting side of online credit card fraud is the merchant&#x2F;payment processor side. Stripe has a cult-like following in the fraud world because it&#x27;s known as the the easiest target. They make it so easy to sign up and process transactions compared to other services like Authorize.net&#x2F;BrainTree&#x2F;etc. They&#x27;ve shed this label recently, in part because the biggest forum thread discussing it was closed. The other reason was because it became so much more difficult. With this release, I think it&#x27;s simply because they could identify accounts with high numbers of suspected fraudulent transactions. All the fraudsters were used to just signing up, running charges on their webstore with sock5, and waiting 2 days for bank transfers. Now Stripe can identify those transactions well in advance and assign each account a risk score. Previously, Stripe had to identify the account risk by sales volume, chargebacks, bank account provider, sign up IP, and every one&#x27;s favourite privacy invader IESnare.<p>Fraudster&#x27;s have one last shining hope against Stripe. Passing their card data to Stripe via API, instead of Stripe.JS&#x2F;Checkout. Radar only works with Stripe.JS&#x2F;Checkout. Setting up your own web server to pass card information prevents them from ever seeing any IP address except the web server. All you have to do to get them to be okay with this is to turn over a PCI self-compliance form. Rumour on the internet has it that there&#x27;s a pre-built web application specifically for charging Stripe accounts via API.<p>I&#x27;m still looking for a job in fraud prevention friends at Stripe :D
评论 #12748685 未加载
评论 #12748677 未加载
评论 #12749148 未加载
joe-stantonover 8 years ago
This looks good, and is sorely needed.<p>It seems one of Stripe&#x27;s biggest risks is the impending PSD2&#x2F;XS2A changes within the EU&#x2F;UK. This means banks&#x2F;merchants&#x2F;retailers will ditch traditional card networks (and their fees) to instruct P2P payments directly. This probably opens up a host of very effective anti-fraud measures too (eg. 2FA with mobile devices).<p>I wonder how Stripe will react to this major change in the market?<p>For example: <a href="https:&#x2F;&#x2F;developer.americanexpress.com&#x2F;products&#x2F;accept-amex" rel="nofollow">https:&#x2F;&#x2F;developer.americanexpress.com&#x2F;products&#x2F;accept-amex</a>
评论 #12747691 未加载
Cyph0nover 8 years ago
This is why Stripe is my favorite startup out of the so-called unicorns. They are really good at finding ways to make more money, while at the same time improving customer experience.
robotnoisesover 8 years ago
Stripe consistently produces some of the best-looking web design out there.
评论 #12747634 未加载
评论 #12747957 未加载
aantixover 8 years ago
It&#x27;s a bit unclear to me; these rules appear to be automated but then they show a rule builder interface?<p>How would I ever know if the rule I&#x27;ve built is too constraining, or too loose in accepting payments?<p>Payment is not exactly an area of my business that I want to do a lot of trial and error..
评论 #12746642 未加载
Lironover 8 years ago
&gt; On its own, a bimodal distribution does not tell you that a model is good. (A vacuous model that randomly assigns probabilities of just 0.0 and 1.0 would also have a bimodal score distribution.) However, in the presence of evidence that transactions with a low score are not fraudulent and transactions with a high score are fraudulent, an increasingly bimodal distribution is a sign of improved efficacy for a model.<p>To do this more precisely, a scoring rule (<a href="https:&#x2F;&#x2F;wiki.lesswrong.com&#x2F;wiki&#x2F;Scoring_rule" rel="nofollow">https:&#x2F;&#x2F;wiki.lesswrong.com&#x2F;wiki&#x2F;Scoring_rule</a>) gives a system credit for both (1) making accurate predictions and (2) being confident at the right times.
epsover 8 years ago
Is there support for whitelisting transactions?<p>E.g. if we are executing a charge for a known-good customer, but using acompletely new card - we&#x27;d like to suppress all automated fraud checks and, ideally, indicate to the client&#x27;s bank that this is a legit charge.
评论 #12746978 未加载
评论 #12746895 未加载
hisyamover 8 years ago
The webpage automatically loads a 206MB video <a href="http:&#x2F;&#x2F;imgur.com&#x2F;a&#x2F;Xyie6" rel="nofollow">http:&#x2F;&#x2F;imgur.com&#x2F;a&#x2F;Xyie6</a><p>That&#x27;s insane.
评论 #12766667 未加载
maratcover 8 years ago
Most merchants don&#x27;t want a rule engine, or rules. Most merchants want either a declined transaction (possibly with explanation -- possibly), or an accepted one with a guarantee against chargebacks.<p>If Stripe is sure that their models work, they should offload the chargebacks from the merchants.<p>A friend of mine worked for a startup that did exactly that. They were sold to an online payments behemoth in about 2009.
评论 #12750430 未加载
评论 #12748233 未加载
评论 #12747935 未加载
dorianmover 8 years ago
The video (from Teespring) is 206M, easily explains why it&#x27;s so slow to load.<p>(Congrats, we were using a separate fraud detection company that was quite intrusive and this seems much better)
brightballover 8 years ago
I love having this built in, but if you&#x27;re NOT using Stripe and you want similar protections I&#x27;d strongly urge you to check out MaxMind&#x27;s minFraud.<p><a href="https:&#x2F;&#x2F;www.maxmind.com&#x2F;en&#x2F;minfraud-services" rel="nofollow">https:&#x2F;&#x2F;www.maxmind.com&#x2F;en&#x2F;minfraud-services</a>
Silhouetteover 8 years ago
This looks very promising. Stripe seems to have sometimes let surprising payments through up to now, even with all the card details security checks they provided activated, and they&#x27;ve never supported 3-D Secure. They&#x27;ve also suffered from surprisingly high rates of unexpected declined charges in our experience. Hopefully if they&#x27;re now rolling out more comprehensive fraud protection, that will go some way to addressing all of those concerns, so best of luck to them with this new development.<p>Edit: It appears there&#x27;s a small per-transaction charge for their enterprise customers on custom plans but it&#x27;s now included for free with the standard pricing. Can anyone confirm this?
评论 #12746681 未加载
评论 #12746525 未加载
评论 #12746926 未加载
评论 #12746536 未加载
评论 #12746501 未加载
patmcguireover 8 years ago
I work at a company with a fairly large number of transactions and we don&#x27;t really have a problem with fraud. I don&#x27;t know anyone else who&#x27;s really battled it either. Is it much more prevalent for certain industries and products?
评论 #12747442 未加载
评论 #12747111 未加载
评论 #12746967 未加载
评论 #12746671 未加载
评论 #12748153 未加载
评论 #12752268 未加载
评论 #12746593 未加载
mgkimsalover 8 years ago
Doesn&#x27;t seem to be a way to use this <i>without</i> using stripe. Would be handier to send them info, have them give a pass&#x2F;fail or score, and return that info. And charge for the service, vs having to migrate to them.<p>Thanks to uladzislau - wasn&#x27;t aware of SiftScience - will have to check them out...
评论 #12746556 未加载
rtcomsover 8 years ago
I hope stripe open source some of their UI related stuff.
uladzislauover 8 years ago
What is the advantage of this vs SiftScience or other tools?
评论 #12746479 未加载
评论 #12746471 未加载
评论 #12746631 未加载
评论 #12747203 未加载
_RPMover 8 years ago
Stripe is really the next Google with their innovative technology. They really are solving hard Computer Science problems.
jamies888888over 8 years ago
Cool feature. Stripe are pretty awesome at creating marketing pages for these things too. Although it&#x27;s a shame they messed up the green HTTPS padlock on that page by serving mixed content. (The Teespring video on AWS S3 simply needs the protocol changing from http to https to rectify this.)
ctdeanover 8 years ago
Pretty neat. Anyone know how this compares to the WePay offering?
FabioFleitasover 8 years ago
Always gotta hand it to Stripe to build a killer looking landing page
评论 #12746634 未加载
评论 #12746569 未加载
评论 #12746421 未加载
joshmnover 8 years ago
Yeah, I still wouldn&#x27;t trust it.<p>Nothing beats manual verification. People aren&#x27;t sharing credit card numbers on public forums and mashing them against Stripe. People are paying for fulls, and grabbing a socks5 that&#x27;s piped within a few miles of the address of the cardholder.<p>Never trust your processor to protect you against your (potential) customers. Stripe has very little incentive to do so. They&#x27;d rather you pay that fat $15 fee when you get hit with a chargeback. They really would.<p>I&#x27;m coming out with a book about Stripe (and a few other processors) and fraud. Trust me it will be good, and this is already a part of it.<p>Sincerely,<p>Someone who was once your enemy<p>PS my favorite part of this? Telling the carder how to defeat their algos:<p>* &quot;This card has been used from an unusually large number of IP addresses across the Stripe network over the last 24 hours.&quot;<p>* &quot;This email has been linked to an unusually large number of cards across the Stripe network over the last hour.&quot;<p>Thanks for not saying the card was declined. If you wouldn&#x27;t mind, please hold while I switch socks and make a new email.<p>Sorry if this is crass, but whoever decided on telling the end-user why a card was declined... complete fucking idiot and should never work in fraud protection or payment processing again.
评论 #12752457 未加载