What helped fight this was to create a rule in Radar to reject all cards without 3D Secure capability, but it had cut off a sizable chunk of legit revenue.
What helped fight this was to create a rule in Radar to reject all cards without 3D Secure capability, but it had cut off a sizable chunk of legit revenue.
Block every single fraudulent or suspicious transaction, and you're leaving obscene amounts of money on the table.
The amount of credit card fraud that goes unclaimed or is eaten by liability shift is huge, so if Stripe makes a product like Radar ACTUALLY WORK, they would be missing out big time.
I am confident Stripe's radar's shortcomings are deliberate and not simple bugs or design problems.
It appears they have no incentive for the product to be 100% effective and that would explain why Stripe Radar is billed per screened transaction, regardless of outcome.
We benchmark Stripe Radar against other pure play fraud fingerprinting solutions, and the difference is abysmal. The fact that Stripe claims to have seen 80% of any card before it gets to your store make this fact even worse.
So, like parent says, you are going to see radar scores of 90 and 95 for certain charges (clearly fraudulent carding attempts), followed by scores of 15 or 20 for the same card, IP, fingerprint with absolutely no warning.
I've grown tired of escalating this to Support. They just give me the ML model answer. Basically: "It's a black box!"
You can definitely add a rule to start blocking charges from X places, or with Y velocity, or always enforce 3DS, but then you're taking the model into your own hands, and that has some important consequences.
Your acceptance rate goes down. You're heavily interfering with the model and relying (and trusting) it less, and you realise you really don't need Radar to do that for you.
If you're serious about fraud, you must use a pure player solution that is 100% aligned with your interests.
From what we've seen with Stripe Radar in the past, that doesn't seem to be the case.
I'm a big fan of Stripe in may ways, but I really have a love/hate relationship with this side of their business...
Stripe Radar costing money is a bit annoying too - my solution was to block non-Australian cards - but the only way to do that is with Radar, which costs money. Radar doesn't let you whitelist currencies either.
If your fraud has a large enough monetary value, large enough scale, or you work with another person on it, you can get hit with a serious felony charge and end up in prison for a few years. Disclaimer: I am not a lawyer or expert on credit card fraud.
Sort of like the highway system relies on an agreement not to play bumper-cars. There's nothing actually stopping anyone.
Self-preservation.
A chargeback with stripe costs like $15 for the seller. Even if the charge was only $1.5. Imagine the monetary problems you could create and the seller has no other way than to pay and hope to not get banned.
Something cheap turns into a $15 dispute fee.
(Disclaimer: I used to work at Stripe on the dispute resolution team. I no longer work at Stripe.)
Anyway, the merchant eats fraud for card not present transactions. So why would the bank choose to reduce its payment volume in order to reduce fraud it doesn't even have to pay for?
If the merchant says 3D Secure only, it reduces fraud, but also reduces payment volume, because most customers will choose to use a merchant with less friction, especially if their issuing bank doesn't do 3D Secure, or it's broken when they go to purchase.
Reducing fraud is good for merchants, but it the drop in sales may not be worth it. There's a lot of other things merchants can do to reduce fraud that aren't likely to cut into sales as much.
What's a payment method actually worth where you have so little control if the payment succeeds?