Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is gobbledygook. You are still thinking in terms of security, but with credit card fraud there is no security issue or system to be cracked per se. Rather it's an identity and information problem. You can impose additional steps to vet the legitimacy of a transaction, but there is nothing that can ever give you a 100% guarantee. So you have to balance your efforts at vetting the transaction against usability barriers that add friction to your core business function.

The difference between publishing your techniques (even with specific variables hidden) and often the difference between attackers being able to iteratively determine the minimum work around to get desired results and having to dedicate orders of magnitude more effort than necessary to ensure they are flying under the radar.



You're correct. I was not thinking about conning the system but actually breaking into it which is obviously a lot harder. It is a lot easier to look at ways to dupe the algorithms for determining fraud rather than breaking the system and bypassing them. Thanks for opening my eyes.


Thanks for your comment, sorry if I was harsh.


No worries. I was wrong. Better to be corrected and have my feelings hurt than to go on being ignorant.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: