zlacker

[parent] [thread] 5 comments
1. brunoT+(OP)[view] [source] 2020-04-21 18:51:13
You may not be aware of how many banks/airlines/ticket websites have outsourced their fraud fighting to solutions like Shape Security, or Sift (Science). Web-wide tracking via cookies is a reasonable and widespread technique for fighting fraud.

Given your background I'd imagine you'd be aware of this.

replies(3): >>mtlync+K3 >>bsamue+i4 >>SahAss+1b
2. mtlync+K3[view] [source] 2020-04-21 19:13:44
>>brunoT+(OP)
> You may not be aware of how many banks/airlines/ticket websites have outsourced their fraud fighting to solutions like Shape Security, or Sift (Science). Web-wide tracking via cookies is a reasonable and widespread technique for fighting fraud.

I view that as a different situation. If a bank/airline/ticketer outsources fraud to a third party, there's presumably an informed exchange of "we'll let you run JS on every page on our website and suck up whatever information you want if you help us detect fraud."

In the case of Stripe, I don't believe they're clear with client applications that they're collecting information from every page of an app. I think most developers integrate with Stripe so they can accept payment on one or two pages and probably don't expect Stripe to be collecting the level of data they're reporting back to Stripe servers.

replies(1): >>brunoT+h6
3. bsamue+i4[view] [source] 2020-04-21 19:17:30
>>brunoT+(OP)
I honestly cannot fault him. While online fraud prevention is a massive industry that touches almost every major website we use, you don't exactly have people giving talks about how serious the problem is or how advanced the detection tooling is because the nature of the industry requires you to keep your methods secret.

Heck, I have a friend who's working on a non-finance web app with <20k MRR, and even at that size he's starting to encounter fraud problems that require tooling to mitigate.

If your app stores any data that may be sellable on the dark web, you are a target.

◧◩
4. brunoT+h6[view] [source] [discussion] 2020-04-21 19:30:01
>>mtlync+K3
This “level of data” doesn’t strike me as alarming. It’s views and mouse locations. Really no different than any simple analytics solution.

Hypothetically: I tell a dev to drop a piece of JS on every page that seems related to payments. That dev probably isn’t doing their job super well if they don’t ask me why or wonder why and find out.

I think you imagine HN readers to be dumb. Nothing here is surprising.

I know it’s covid era and we felt good as a community wagging our fingers at Zoom’s naughty FB tracking inclusion. Legitimate concerns there given the advertising business model, and no good reason for zoom to be doing it. This is fundamentally different: the data is for a good purpose with a narrow scope to a good company with a user-positive value creation model.

I believe your princess is in another castle.

replies(1): >>adamby+9s
5. SahAss+1b[view] [source] 2020-04-21 20:05:41
>>brunoT+(OP)
> reasonable and widespread

One of those can be factual and the other is clearly subjective.

◧◩◪
6. adamby+9s[view] [source] [discussion] 2020-04-21 22:04:29
>>brunoT+h6
You might have some reasonable arguments, but your condescending tone is completely undermining the conversation.
[go to top]