Show HN: UPUP Simple Credit Card Verification to Reduce Fraud
upupapp.io
upupapp.io
We developed UpUp as a payment verification tool to quickly let customers demonstrate ownership of a payment method and get their transactions approved. In the 4 months we've been using UpUp, we've had a 100% success rate in legitimate customers verifying their accounts and completing purchases. We've also been able to approve more transactions, as we no longer have to wait for customers to provide multiple documents before approving their transactions.
We're launching UpUp as its own stand-alone tool for helping any business verify transactions and combat fraud. We're launching with a Stripe integration today, making it seamless for any Stripe user to add UpUp's fraud verification service.
Do you have plans to support other processors and/or integrate natively with ecommerce platforms like Shopify, BigCommerce and 3dCart?
A button to click in the Ecommerce Platform Admin page for an order that triggers this extra verification would be game changing for many ecommerce companies.
Is there a specific platform you are using that you'd like to see us add next?
Great looking product, and a great idea! Love it!
Note that this is also done by 'carders' and so it can trigger bank's own fraud detection.
I've had this happen to me; a legitimate entity in the USA checked my card with a small fee (with my agreement) and my card was cancelled. Took me a week to get it back.
Not foolproof, but is a help. Also... another reason to use a credit card for all online purchases... it's not your money, and almost always will be refunded in full if disputed (at least in the US). Bank cards/debit cards are your money, and you might have a fight on your hands with your bank if it's a large enough charge.
Like I know someone who's a family member who still does online shopping like on Amazon but still gets their credit card and bank statements mailed to them - unless you can maybe check your card balance and recent transactions by phone... They say they don't trust online banking, yet it's literally probably the same database and servers other than a flag in the database like "hasOnlineAccess" with a username/password combo stored... Probably more at risk of getting their info stolen by installing crap on their own computer than the bank itself being hacked though.
Our recommendation is that most businesses should be prepared to offer a few options for payment or identity verification. In your case, your family member may have been better suited doing something like a drivers license verification or a knowledge-based identification.
That said, I don't see you addressing the key issue, what is the drop-off rate of legitimate purchasers from having to jump through this hoop to get verified? If it negatively affects conversion rate too strongly then the loss outweighs the benefit. It may make more sense in high-value transactions such as with Fetch than in general ecommerce?
Careful that you don't end up in the same bucket.
Not to mention their horrible management of physical goods as well. A lot of vendors like HTC have had serious issues with with product sales, returns etc.
If it's Digital River, I look for alternatives or don't buy. Glad to seem i'm not alone.
It is true that the higher the value of the transaction the more important it is. We tried to be thoughtful about balancing security vs friction.
"We haven't seen drop offs in conversion so far, mainly because we verify after checkout, not before.", which answers the question more directly and succinctly.
no offense to you of course. it's better to get an overly verbose, but still informative, response than none. and the product looks genuinely useful to online businesses.
it can trigger defensiveness, disdain, or even mischievous inquest rather than the desired complicity. being straightforward is a simpler and safer strategy.
† such programming is indicative of coercive business processes, which typically extends to communication with customers to avoid liability due to that coerciveness
I like the initiative and I think this is a step for deterring credit card fraud. However, if someone wants your product bad enough, it's trivial — at an incremental cost — to buy a credit card with login.
Yes, while these issuers have security to prevent logging in/logging in from an unknown device/ip/user agent/hwid, we can all attest that for every secured account, there are plenty that aren't. Even with alerts, OPT, device recognition and notifications, that doesn't deter someone from going to a shop, searching by BIN, by brand, by zip, by email, by password, etc. to narrow down what they want to buy.
If you're the only provider with XyzGood, and someone wants XyzGood bad enough, this won't stop them.
The other most common type of fraud is buying goods with stolen cards, intending to resale the goods on Craigslist or similar.
For both of those cases, this idea would be an immense help. You perform your own "High Risk" criteria checking on all orders, and those flagged as being potentially High Risk, would then receive this extra verification step.
It's pretty rare for someone to steal or buy stolen cards to order products they actually want to keep.
Even something as simple as sending an email or a phone call to "verify the shipping address" is enough to smoke out actual fraud vs. a real customer.
But... that takes time and resources from customer service, and isn't as fool-proof as having access to the actual bank/card account.
If someone wants to break into a bank bad enough a safe won't stop them.
If someone wants to break into a house bad enough locks won't stop them.
etc
This is an unreasonable argument for trying to secure something. Every step that makes something harder to steal is an improvement in security and increases the cost of theft.
Where I come from we have mobile money solutions but they aren't yet integrated to allow you to pay for something online. It's a different problem but the shared element of manual verification for payments has encouraged me it's something worth looking into much more seriously now.
All the best and thanks for the 'motivation'.
Where UpUp slots in is for those transactions in the gray zone. Declining a customer's purchase "because our payment processor said you are risky" isn't the best look.
Also, in many cases, such as rental, the value of the transaction is much smaller than the amount of the risk from the transaction.
Hope that helps provides some context on the different use cases as we see them.
A couple of questions: -can you set this to automatically trigger for high risk transactions? -how do you flag the user as "ok" for charges in stripe? -do you need to disclose random charges to the customer? -are these actual charges that are refunded or just authorizations?
Triggering a verification automatically based on a stripe radar score is definitely on the roadmap. Right now we do not add any metadata to the stripe customer record but that is a great idea!
Are these actual charges that are refunded or just authorizations?
These are just authorizations that will be released as soon as the verification fails, expires, or succeeds.
UpUp provides you with method to provide your customers that lets them prove they are not fraudulent. In turns, this lets you feel correct about denying a transaction or sleep better at night when you have approved a transaction that is questionable.
UpUp also lets ecommerce teams verify customers without requiring their engineering teams to immediately implement 3D secure.
We do expect we'll end up using 3D secure as part of our flow in the future.