Beyond that, I'm not sure what that person is talking about.
https://www.candyjapan.com/behind-the-scenes/how-i-got-credi...
This is pretty much why I think credit cards are unfairly one-sided, and is a big advantage to crypto-currencies like bitcoin. CC are as easy as possible for the consumer, but it's up to the business to guess if the consumer is authorized to use it, and there's no good way to be sure. Some people are going to be unfairly shafted. Oh and credit card networks can do things like shut off access to WikiLeaks if the US government asks them to. The system mostly works for most people in western countries - but it is very flawed.
Some fancy online card processors will do this for you automatically. Otherwise, there's companies that do this logic for you, and work across processors.
Ultimately, we should all get out of the business of transferring money by just entering credit card numbers, which are easy t copy. Many parts of the world are already moving to systems that require 2fa, and fraud rates drop like a rock. Good luck convincing US banks and online retailers to change everything to do this though.
They used to use a password, but that risks people putting their bank password into some dodgy shopping site.
VISA's implementation: https://www.visaeurope.com/making-payments/verified-by-visa/
At my company we use Stripe as our payment processor, which has their own fraud detection called Radar. But still, a bit under .1% of our transactions are fraudulent.
Credit card fraud is honestly a great business, even if they know you're doing it, the police wont do anything, and the merchant has to cover the cost and pay $15 for the privilege of being defrauded.
[0] https://www.maxmind.com/en/minfraud-services
[1] https://minfraud.readthedocs.io/en/latest/
Sorta related, turns out there are anti-fraud services for fraudsters https://krebsonsecurity.com/2013/11/anti-fraud-service-for-f...
Professional VPNs are probably fine.
But assuming you don't want to:
1) Validate against the standard checksum formulas (this catches legit typos)
1b) https://en.wikipedia.org/wiki/Luhn_algorithm
1c) Regardless of what happens next, send an order confirmation and play dead.
1d) If it fails any of the following steps, send a politely worded "issue with the order" e-mail and to contact you (after 24 hours). Use a reason that sounds generic rather than credit card specific.
2) Check GeoIP and compare against potentially geographic space. (this catches VPNs, etc. For instance, shipping to a US freight forwarder from a Russian IP is likely highly probably fraud. The customer can call/e-mail you if they get caught in this.)
2b) Services like https://www.maxmind.com/en/minfraud-services qualify for this.
3) Check address locations against known US freight forwarders / PO boxes / UPS Stores / etc. Force additional customer verification, like for IP addresses.
4) To validate repeat card usage, fingerprint cards that were successfully charged and you didn't receive a chargeback after the window closes:
https://security.stackexchange.com/questions/63248/hashing-a...
You can use Stripe/Braintree tokens or your own implementation.
5) If it fails step 4:
5a) Run whatever business heuristics/signals that might be true for your customer base. Too specific to get into really.
5b) Actually charge the card and see what happens. If its declined by the credit card company, send the generic contact e-mail.
Anyone accepting donations via PayPal