{"author":"jasontan","children":[{"author":"JimmaDaRustla","children":[{"author":"justin66","children":[],"created_at":"2014-05-14T17:35:36.000Z","created_at_i":1400088936,"id":7744955,"options":[],"parent_id":7744909,"points":null,"story_id":7744861,"text":"That&#x27;s exactly wrong. Barring some sort of insurance, merchants eat the cost of fraud. This is the incentive for some of the weird behavior and lack of progress when it comes to CC transactions in the United States. Ideally Sift&#x27;s clients would be the banks, since they&#x27;ve got all the money, but the banks can foist most of the cost of theft onto someone else, so...","title":null,"type":"comment","url":null},{"author":"zt","children":[{"author":"JimmaDaRustla","children":[],"created_at":"2014-05-14T18:35:51.000Z","created_at_i":1400092551,"id":7745367,"options":[],"parent_id":7744957,"points":null,"story_id":7744861,"text":"Correct - I always assume terminal based transactions when it comes to fraud.","title":null,"type":"comment","url":null}],"created_at":"2014-05-14T17:35:52.000Z","created_at_i":1400088952,"id":7744957,"options":[],"parent_id":7744909,"points":null,"story_id":7744861,"text":"It actually depends on whether you&#x27;re in a card-present or card-not-present situation. For historical (i.e. irrational) reasons, merchants are responsible for fraud in the CNP situation.","title":null,"type":"comment","url":null},{"author":"lestinkycowboy","children":[{"author":"JimmaDaRustla","children":[],"created_at":"2014-05-14T18:38:37.000Z","created_at_i":1400092717,"id":7745381,"options":[],"parent_id":7744972,"points":null,"story_id":7744861,"text":"I was meaning in a physical transaction, where the customer pays at a terminal.<p>I guess I spoke out of context!","title":null,"type":"comment","url":null}],"created_at":"2014-05-14T17:38:30.000Z","created_at_i":1400089110,"id":7744972,"options":[],"parent_id":7744909,"points":null,"story_id":7744861,"text":"You are not correct. BestBuy is absolutely liable for that $1,000. If they ship the TV to the fraudster, the TV is gone and the $1000 is gone, too.<p>When the actual owner of the credit card charges back, the $1000 BestBuy received is automatically taken from their account (or subtracted from their next settlement).<p>FIs do try and predict fraud, but they do a very poor job of it.  In the ecommerce space, the merchant is liable for, essentially, all fraud.","title":null,"type":"comment","url":null},{"author":"jasontan","children":[{"author":"JimmaDaRustla","children":[],"created_at":"2014-05-14T18:21:23.000Z","created_at_i":1400091683,"id":7745270,"options":[],"parent_id":7744985,"points":null,"story_id":7744861,"text":"Edited this comment - misread your comment. Correct, thank-you for the feedback!<p>Edit #2 - when you say offline&#x2F;online, I&#x27;m assuming you mean in terms of an online store, versus a physical retail store.<p>I took it as if the transaction was done in realtime to the backend FI system, or if it were verified offline at a terminal. In EMV terminals at a physical merchant location, transactions can be either online or offline ;)","title":null,"type":"comment","url":null}],"created_at":"2014-05-14T17:39:10.000Z","created_at_i":1400089150,"id":7744985,"options":[],"parent_id":7744909,"points":null,"story_id":7744861,"text":"Jason here, op (and CEO of Sift Science). It wasn&#x27;t quite clear in the article - in the example of the stolen television, there is a key difference between Best Buy and bestbuy.com. In the latter, the merchant takes the hit on fraud (e.g. $1000 will be subtracted from the bank account of bestbuy.com), whereas in the former, the merchant is off the hook for fraud. This is one of the key differences between Card Present (offline) and Card Not Present (online) transactions.<p>I&#x27;ve contacted the reporter to try and clear this up.","title":null,"type":"comment","url":null}],"created_at":"2014-05-14T17:29:29.000Z","created_at_i":1400088569,"id":7744909,"options":[],"parent_id":7744861,"points":null,"story_id":7744861,"text":"Just off the top of this article - BestBuy wouldn&#x27;t be liable for that $1000, it is the FIs liability, if we&#x27;re talking about a transaction at a physical terminal, not CNP.<p>Edit: FIs also have to follow rules and regulations to monitor and predict fraud activity.","title":null,"type":"comment","url":null},{"author":"jliptzin","children":[{"author":"necubi","children":[],"created_at":"2014-05-14T18:19:00.000Z","created_at_i":1400091540,"id":7745256,"options":[],"parent_id":7745174,"points":null,"story_id":7744861,"text":"(Disclaimer: I&#x27;m an engineer at Sift Science).<p>For online purchases (card-not-present transactions), the merchant takes on all of the fraud risk. This means that the banks do not have much incentive to protect against fraud. The merchants must go on the information they have, which probably doesn&#x27;t include the card holder&#x27;s verified phone number.<p>Sift Science has been successfully protecting online businesses for over a year, and it turns out that machine learning is (unsurprisingly) a good tool for this sort of classification problem.","title":null,"type":"comment","url":null},{"author":"laurenbee","children":[{"author":"jliptzin","children":[],"created_at":"2014-05-14T22:29:48.000Z","created_at_i":1400106588,"id":7746844,"options":[],"parent_id":7745271,"points":null,"story_id":7744861,"text":"That&#x27;s true, things that sound simple on the surface often turn out to be pretty complex in implementation. I think that the number of people making purchases without cell phones on them is converging towards zero and will be there soon, so I think it&#x27;s safe to think about these systems now.<p>What about implementing a 2FA system for larger purchases (online or off), implemented in an app on the consumer&#x27;s phone like google authenticator or sms? Swipe your card at checkout, if amount is &gt; $XX (or otherwise suspicious according to current models), prompt the buyer for a one-time code from SMS or an app. I use the same system when logging into gmail, my bank account, etc - I&#x27;d have no problem (and would even welcome) a similar system when using plastic. It&#x27;s at least a lot more convenient than having the txn declined and your card disabled until you call their security hotline. This way, thieves would need to steal your card <i>and</i> your phone to cause damage.","title":null,"type":"comment","url":null}],"created_at":"2014-05-14T18:21:25.000Z","created_at_i":1400091685,"id":7745271,"options":[],"parent_id":7745174,"points":null,"story_id":7744861,"text":"Interesting ideas, but I don&#x27;t think these suggestions would be so simple. They would put a burden on consumers to always have a phone at the ready. What happens if your phone can&#x27;t connect to GPS inside a store? What if you don&#x27;t have your phone with you (or if you don&#x27;t have a phone at all)? Buying goods and services would be far less convenient.","title":null,"type":"comment","url":null},{"author":"dminor","children":[],"created_at":"2014-05-14T20:03:41.000Z","created_at_i":1400097821,"id":7746015,"options":[],"parent_id":7745174,"points":null,"story_id":7744861,"text":"When fighting ecommerce fraud, you have to be careful that the cure isn&#x27;t worse than the disease. You could absolutely institute procedures that would cut fraud down to nothing, but your conversion rate and fraud prevention costs may suffer.","title":null,"type":"comment","url":null}],"created_at":"2014-05-14T18:07:38.000Z","created_at_i":1400090858,"id":7745174,"options":[],"parent_id":7744861,"points":null,"story_id":7744861,"text":"I can think of some simple things FIs can do to prevent fraud. For example they could leverage your cell phone&#x27;s GPS at the time you make a purchase to make sure you&#x27;re actually in the store where the purchase is coming from. For online purchases, they could text you a confirmation that you were the one who made the purchase. Just some simple things that seem a lot less complicated than machine learning that we haven&#x27;t tried yet.","title":null,"type":"comment","url":null},{"author":"milkmanjr","children":[],"created_at":"2014-05-14T18:21:02.000Z","created_at_i":1400091662,"id":7745268,"options":[],"parent_id":7744861,"points":null,"story_id":7744861,"text":"Awesome stuff. I use sift science, in addition to some basic fraud prevention, and what they are doing has allowed me to sleep easier at night.<p>Kudos to the Sift Science team!","title":null,"type":"comment","url":null},{"author":"JackFr","children":[{"author":"jasontan","children":[],"created_at":"2014-05-14T21:42:36.000Z","created_at_i":1400103756,"id":7746614,"options":[],"parent_id":7745287,"points":null,"story_id":7744861,"text":"Hi JackFr,<p>Jason here, op and CEO of Sift Science. You have a point, but do keep in mind that the TV is going to a bad customer -- one that won&#x27;t reward Best Buy with repeat business (perhaps just more fraud) and won&#x27;t spread positive word of mouth (except to let other fraudsters know that Best Buy is a great fraud target). So there is some &quot;lose&quot; in shipping the TV to a bad customer, different from shipping it to a good customer. Does that make sense?","title":null,"type":"comment","url":null}],"created_at":"2014-05-14T18:23:02.000Z","created_at_i":1400091782,"id":7745287,"options":[],"parent_id":7744861,"points":null,"story_id":7744861,"text":"Calling it &#x27;lose-lose-lose&#x27; doesn&#x27;t actually make sense.  1) They lose the TV; 2) they lose the $1000 dollars they obtained in the transaction; 3) the chargeback negatively impacts relationship with the card issuer.<p>By that accounting, a legitimate sale would count as a &#x27;lose&#x27;, since they lose the TV.<p>&#x27;Lose-lose&#x27; would be fine, but even by the standards of hastily written press releases, this is kind of silly.","title":null,"type":"comment","url":null},{"author":"mahyarm","children":[],"created_at":"2014-05-14T18:26:38.000Z","created_at_i":1400091998,"id":7745313,"options":[],"parent_id":7744861,"points":null,"story_id":7744861,"text":"When do you think credit cards &#x2F; bank accounts will become push transactions vs. the pull transactions by a few trusted banking agents as they are now.  How much will that reduce fraud?","title":null,"type":"comment","url":null},{"author":"suprgeek","children":[{"author":"jasontan","children":[{"author":"suprgeek","children":[],"created_at":"2014-05-14T19:21:48.000Z","created_at_i":1400095308,"id":7745715,"options":[],"parent_id":7745467,"points":null,"story_id":7744861,"text":"Hi Jason, Thanks for replying and that (no rules just data) is a pretty cool ML + Big Data play.<p>Having worked in this space a bit, I know where the dragons be in such an approach. \nI imagine that you are doing some kind of Pattern Matching:\ne.g. known Fraudster uses these signals (Browser +OS + Email+Time of shopping + something else... + type of Card) to teach the system what to look for.  The real trick is to avoid over training and evolving the patterns to keep pace with the fraudsters by incorporating feedback from the merchants.<p>Can you point to some blog posts&#x2F;text that provides a sneak peak into the kinds of technology that you use to cut down on false positives?","title":null,"type":"comment","url":null}],"created_at":"2014-05-14T18:51:44.000Z","created_at_i":1400093504,"id":7745467,"options":[],"parent_id":7745342,"points":null,"story_id":7744861,"text":"hi suprgeek, I&#x27;m the op (and CEO of Sift Science). it&#x27;s true - we do not have any rules in our product. we believe that rules can serve as an effective short-term solution, or for special cases, e.g. prematurely blocking a massive wave of fraud from an IP address because you know it&#x27;s coming.<p>but, rules are rather easy for fraudsters to circumvent, and they require merchants to play whack-a-mole. with today&#x27;s technologies, it&#x27;s easier than ever to analyze massive amounts of data, and we believe that machine learning can go a really long way in detecting fraud.<p>does that make sense? happy to discuss further, and we&#x27;d be happy to put you in touch with our customers if you&#x27;d like to hear more about our results.","title":null,"type":"comment","url":null},{"author":"rm999","children":[{"author":"bravura","children":[{"author":"rm999","children":[],"created_at":"2014-05-14T21:03:44.000Z","created_at_i":1400101424,"id":7746422,"options":[],"parent_id":7746211,"points":null,"story_id":7744861,"text":"&gt; But rules can be converted into features, which you use as primitives in an ml model<p>&quot;Rule&quot; has a very specific meaning in this industry, and it&#x27;s basically a manual decision that exists outside the ML model - usually written by experts. The people who build the models never see the rules (per se), and the rules are integrated after the models are deployed. I wouldn&#x27;t describe a modeler integrating logic into the modeling process a &quot;rule&quot; because it would confuse terminology.<p>The whole rule-based thing is sort of a testament to how old-fashioned the industry is IMO. The problem is two-fold: banks don&#x27;t fully trust ML (or the &quot;experts&quot; want to keep their jobs), and they don&#x27;t tolerate much change in their computing platforms. That last point is pretty important: banks&#x2F;issuers don&#x27;t refresh their fraud models very often, so they can miss new types of fraud, which ends up being a great use-case for rules.","title":null,"type":"comment","url":null}],"created_at":"2014-05-14T20:30:52.000Z","created_at_i":1400099452,"id":7746211,"options":[],"parent_id":7745764,"points":null,"story_id":7744861,"text":"Not exactly correct.<p>Rules composed into cascdes or manual decisions trees are not as powerful as ml.<p>But rules can be converted into features, which you use as primitives in an ml model.<p>In fact, one pattern for feature engineering is to build a good rules-based system. You then can treat that as features of a degenerate model, with weights of plus or minus infinity. By training, you can induce better weights.<p>Edit: in a sense, rules and training method are almost orthogonal concerns.","title":null,"type":"comment","url":null}],"created_at":"2014-05-14T19:29:51.000Z","created_at_i":1400095791,"id":7745764,"options":[],"parent_id":7745342,"points":null,"story_id":7744861,"text":"&gt;I am not sure that a purely data centric approach with no rules even makes sense.<p>Fraudsters generally follow fairly specific patterns that can definitely be picked up in a rich enough dataset, and the consortium-based approaches of Falcon and Sift allow the models to generalize pretty well. Rules are way less expressive than complex-enough machine learning methods (combined with good data).","title":null,"type":"comment","url":null}],"created_at":"2014-05-14T18:31:34.000Z","created_at_i":1400092294,"id":7745342,"options":[],"parent_id":7744861,"points":null,"story_id":7744861,"text":"Is the fact that this is based on &quot;no rules just data&quot; even sensible? Or is it an artifact of bad reporting?<p>Many Credit card fraud prevention systems such as the Falcon Fraud Manager use both Rules and ML (Neural Network modelling) to tackle this issue. I am not sure that a purely data centric approach with no rules even makes sense.","title":null,"type":"comment","url":null},{"author":"svmegatron","children":[{"author":"jasontan","children":[],"created_at":"2014-05-14T18:57:07.000Z","created_at_i":1400093827,"id":7745511,"options":[],"parent_id":7745347,"points":null,"story_id":7744861,"text":"thank you, will!","title":null,"type":"comment","url":null}],"created_at":"2014-05-14T18:32:39.000Z","created_at_i":1400092359,"id":7745347,"options":[],"parent_id":7744861,"points":null,"story_id":7744861,"text":"I run a product in this space (<a href=\"https://www.merchantprotector.net\" rel=\"nofollow\">https:&#x2F;&#x2F;www.merchantprotector.net</a>) and I&#x27;m quite impressed with Sift Science&#x27;s pricing.<p>No charge for the first 10k transactions&#x2F;month is impressive.","title":null,"type":"comment","url":null},{"author":"ripberge","children":[{"author":"jasontan","children":[],"created_at":"2014-05-14T18:54:22.000Z","created_at_i":1400093662,"id":7745490,"options":[],"parent_id":7745448,"points":null,"story_id":7744861,"text":"hi ripberge, would love to hear what was confusing about our documentation, and what bugs you&#x27;ve seen. we&#x27;re always looking to improve the customer experience - can you email me (jason at siftscience dot com)","title":null,"type":"comment","url":null}],"created_at":"2014-05-14T18:49:14.000Z","created_at_i":1400093354,"id":7745448,"options":[],"parent_id":7744861,"points":null,"story_id":7744861,"text":"Anyone care to share their experience with Sift Science? How well does it actually work for you?<p>I have been integrating it for a day or so. The documentation is slightly confusing and they&#x27;ve had a few minor bugs in their UI, but support has been really good thus far.","title":null,"type":"comment","url":null},{"author":"saurabhnanda","children":[{"author":"Tarang","children":[],"created_at":"2014-05-14T18:59:09.000Z","created_at_i":1400093949,"id":7745532,"options":[],"parent_id":7745477,"points":null,"story_id":7744861,"text":"It decreases the chances of successful legitimate transactions just as a barrier to completing payment. In India nearly 1&#x2F;3 of card based transactions online don&#x27;t go through successfully. I.e want to order pizza but the phone battery is dead (so no 2fa&#x2F;otp)","title":null,"type":"comment","url":null}],"created_at":"2014-05-14T18:52:52.000Z","created_at_i":1400093572,"id":7745477,"options":[],"parent_id":7744861,"points":null,"story_id":7744861,"text":"why cant credit card transactions be mandated to go through a second layer of auth that is <i>not present</i> on the card? in india, the banking regulator RBI, forced this a few years ago and the CNP fraud rates tanked to negligible levels. All domestic transactions now go through a 3d-secure or OTP process.","title":null,"type":"comment","url":null},{"author":"lsh123","children":[],"created_at":"2014-05-14T23:45:00.000Z","created_at_i":1400111100,"id":7747198,"options":[],"parent_id":7744861,"points":null,"story_id":7744861,"text":"The biggest problem with ML is that it takes time for it to react to the new fraud patterns&#x2F;schemes. While rules engines have their limitations, they also have one big benefit: they allow to block recognized fraud really fast.<p>So the actual question here is whether the ML for detecting fraud is better than a flexible rules engine and goods analysts&#x2F;statisticians. In my personal experience, statistical analysis and anomalies detection effectively handles majority of the fraud. I would be interested to see a more detailed analysis of Sift Science performance with some numbers for false positives&#x2F;false negatives for example, though (of course) it is probably proprietary information.","title":null,"type":"comment","url":null}],"created_at":"2014-05-14T17:22:19.000Z","created_at_i":1400088139,"id":7744861,"options":[],"parent_id":null,"points":95,"story_id":7744861,"text":null,"title":"Sift Science (YC S11) raise $18M to stop credit card fraud with machine learning","type":"story","url":"http://techcrunch.com/2014/05/14/sift-science-raises-18m/"}
