The optimal amount of fraud is non-zero (2022)
bitsaboutmoney.com
bitsaboutmoney.com
I regularly travel for work and it's impossible for me to make any purchases on major sites like Walmart, Best Buy, Target, Costco, etc. They all will accept an order, charge my card, and then randomly cancel the order some hours to days later, and refund me.
Similarly when traveling internationally, Schwab bank decided they didn't like one of my debit charges and blocked the card. I called Schwab and they gave me some "publicly sourced" 3 question quiz about myself that I apparently failed and they locked my entire account until I can fly back to the states and come into a branch.
Luckily I have a 2nd bank account and was able to change my payroll. But it's just insane to me that some random debit charge has resulted in my inability to access most of my money or my brokerage positions.
I hear similar issues and horror stories from all my coworkers and friends that travel.
I have a pet hypothesis that a lot of the security heuristics they use are based on being able to spy on you everywhere you go, and the trail of digital litter you leave behind "confirms" it's you where you are.
It's difficult to draw conclusions from my own experience because the security landscape changes and I don't know what other people encounter. I do know people who spend their lives online on the phone and they don't complain about having problems blowing their whole paycheck every week; like for instance my assistant who doesn't either have trouble purchasing things for me.
The amount of incompetence involved with payment processing and banking is just mind boggling. KYC/AML is very quickly turning into bizarro big brother. But not an all-knowing AI big brother. A stupid 2005-era IP address detecting one. You do a little too much traveling? Poof. There goes a month of your life to banking jail.
A simple two-factor mechanism like passkeys or authy (that isn’t based on SMS to unreliable US phone carriers) would solve about 99.999% of this.
For example, my banking app requires Face ID to unlock it and to approve payments. But for certain types of payments, such as more than 3k USD, instead of using Face ID to process the payment it requires and SMS OTP entered into the app. Which tends to suck when I'm using another SIM or if the SMS does not arrive in time if I'm traveling internationally. How on earth do they think SMS is more secure than biometrics beats me.
No SMS or notification on my phone to verify myself either.
Wrote them a mail to ask what this was about and why I cannot use my card, but they only wrote back that the card was not blocked and everything was fine, but sometimes they are afraid of fraud etc.
You’ll probably also find that banks are much twitcher around merchants like Nike and Apple because their products hold value really well, and are easy to sell on the second hand market. Makes those products a really great way to exfiltrate stolen funds because the products are almost as liquid as actual cash.
I got hit by these blocks with a EU card a long time ago, as the shop was trying to pass the charge with the magnetic strip. Had to phone to the VISA center to let the charge pass through on next retry.
Nowadays I'd assume any "card in the machine" transaction done with a PIN would go through no questions asked, even if you're located in Antarctica on their database.
When I buy something with my bank card, I always have to provide my PIN. If I buy something online, the site redirects me to my bank, where I authenticate myself with my bank's system, and then authorize the payment with my bank's system (involving 2FA), and then the bank tells the site that the payment has been authorized. The site can blindly trust my bank and can immediately ship stuff to me, because the payment will go through.
I've never had any blocks nor fraud issues with this system.
No. My (UK) bank will decline purchases if they look suspicious and send me an SMS with the information and ask me to yay/nay them. (For 4 years running, they did this for my early September purchase to Apple. Most annoying.)
On top of all the, the fraud systems at the major card networks also go haywire. They start seeing huge spikes in high value transactions, and start randomly declining transactions. On the banks side, we can see these transactions being declined by the network, but it’s damn near impossible to stop them. The card networks themselves set the rules, and getting hold of someone technical enough to turn them off is surprisingly hard to do.
Suffice to say, iPhone day each year is a bit of an all-hands-on-deck situation for bank fraud teams. You’ve got your technical teams trying to tweak rules to better detect and ignore iPhone purchases, which it much harder than it should be because Apples payment processing system is a Byzantium nightmare that creates so many different types of transactions, and uses so many merchant identities you can just do a simple “if Apple, ignore” rule. Then you’ve got your reviewer teams working hard to rapidly the all the flags so customers are impacted for too long.
It doesn’t help that buying MacBooks and iPhones is a classic way for people to commit credit card fraud and money laundering. The products hold their value so well, and are so easy to shift on the second hand market, that’s it’s a prime method for organised crime groups to liquidate and launder stolen funds.
Given the fraud generally effect all businesses in the same market equally, there’s little incentive for businesses to reduce fraud, because it cost all of their competitors are having to absorb, so everyone just bakes the cost of fraud into their prices.
Any rules that are around detecting terrorism are mostly to do with sending money to sanctioned countries and individuals. Those rules are stupidly annoying to work with, because you’re basically force to write a rule that boils down to “does transaction description include the word ‘Iran’ then flag/block transaction”. As you can probably imagine they’re not very effective, but you look like a fucking idiot if your customer gets caught up in a terrorism investigation, and you didn’t flag/block those transactions.
Most regulation deals with something far more mundane, money laundering. It’s mostly to prevent organised crime groups being able to launder their cash, that either cash generated from the “traditional” crimes, but more often it’s cash generated from socially engineering normal people into handing over bank details, or simply convincing them to send their life savings to a fraudster. Something that’s far more common than people expect, and far more effective than people expect.
Eh, I assume you also want your bank to block fraudulent transactions on your card. Somehow I doubt you would react kindly to someone buying half a dozen MacBooks on your card without your knowledge.
Of course I want fraudulent transactions to be reversed, but more than that, I want to use a system that makes fraud hard, rather than an everyday occurrence.
Although one of my banks has recently sent me a new bank card with a credit card number on the outside, and that worries me a bit, because I don't have or want a credit card from that bank, and I certainly don't want to expose myself to that kind of security hole.
But as you've noticed, Maestro is being phased out by Mastercard, to be replaced by Mastercard Debit, and that one will be usable online using its 16-digit card number just like a credit card.
If you don't want to use the online payment feature of it, some banks let you disable it. Otherwise, the worst that can happen is that you're short the money until your bank refunds you in case of fraud – still very frustrating if it does happen, but it's very revocable.
But that's a massive step back. We should be getting rid of payment information on the outside of cards to share with merchants. We should be introducing protocols for secure online payment through your own bank. Which Netherland has (iDeal), but it's not universally internationally supported. (Steam supports it, Lego does not.)
What we need is an international version of iDeal, not turning everything into the insecure system that credit cards use.
> the worst that can happen is that you're short the money until your bank refunds you in case of fraud – still very frustrating if it does happen, but it's very revocable.
Yes, but that introduces fraud into a system that doesn't need it, which will drive up the cost for everybody. It's a step backwards.
Seen purely from a security point of view, I agree.
But so many people have only exactly one debit card and currently can't use it for online payments abroad at all. Adding that feature to a bank's standard card seems like a good idea from that point of view, especially given that it doesn't add any additional liability. I also think it should be possible to be deactivated, but "on" seems like a reasonable default to me.
> We should be introducing protocols for secure online payment through your own bank.
This exists for credit and debit cards: 3DS! It's even mandatory for many intra-EU payments. If it's not used, chargebacks are mostly trivial to win for banks.
> What we need is an international version of iDeal, not turning everything into the insecure system that credit cards use.
Realistically, that's not going to happen anytime soon. Visa and Mastercard have had many decades to grow their international footprint.
Domestic alternatives have started showing up (e.g. UPI in India, WeChat and Alipay in China) with significant success, though, and I could see some of these eventually expanding to a competing global system. I don't see that happening for an individual EU country's scheme, though; it would have to be something pan-European like the proposed "digital Euro".
Not if users aren't aware of the fact that their bank account suddenly has a massive new vulnerability they have to be looking out for.
> 3DS!
Another system by Visa and Mastercard. I'd really like our payment systems to be independent from that duopoly.
But also: it still has the fundamental problem that credit cards have: you still enter your card number into the merchant's website. From what I understand, only if merchant and customer agree to the extra security, does it actually offer that extra security.
The big advantage of iDeal is that the only thing the merchant has to know, is which bank I use. Merchant redirects me to my bank, sends the payment details to the bank, I authorise the payment on my bank's site with the best security my bank offers, and the bank sends me and the approval back to the merchant.
Many webshops kinda do something like that by handing payment off to their payment provider, but their payment provider isn't my payment provider yet still needs a credit card number. And what if a merchant uses a shady payment provider? But if those payment providers were to support a safer system, and international version of iDeal, that's really all we need. (In fact, I think some of them do support iDeal, which is great.)
But I want to get rid of typing large supposedly-secret-but-not-really numbers from my card into a stranger's webform.
Nothing would prevent you from strapping 3D onto any other payment system of your choice.
Merchants have to choose to perform 3DS, but EU Strong Customer Authentication rules make it mostly mandatory for EU merchants to use 3DS. They can only really opt-out if they can consistently demonstrate they’re capable of detecting and preventing fraud, keeping it at levels that are basically equivalent to fraud seen on 3DS transactions.
The card number alone is not enough to perform a card transaction. There are some merchants out there that are capable of performing card transactions with only the 16-digit number, such as Amazon, but you need to be a very large merchant, and demonstrate you’ve got effective fraud controls in place to prevent abuse. Any smaller merchant attempting something similar will find their merchant accounts quickly closed, and all transactions automatically refunded.
> Many webshops kinda do something like that by handing payment off to their payment provider, but their payment provider isn't my payment provider yet still needs a credit card number. And what if a merchant uses a shady payment provider?
They mostly don’t exist. Becoming a payment provider on the Visa and Mastercard networks is expensive, difficult and very time consuming. Additionally Visa and Mastercard monitor all network participants, if they’re seen to be misbehaving then they get disconnected from the network, and their collateral payment is seized. So running a shady payment processor isn’t profitable.
The system isn’t perfect, but most of things you’re concerned about don’t happen in the EU. They happen a lot in the U.S., but the U.S. has a very different culture around money to the EU, and their payment systems are a bit more bonkers. Which is why EU banks tend to get a bit trigger happy with their fraud rules when customers travel to the U.S.
With 3DS2 why is this even a thing?
These sites are not cancelling your orders. The card-issuing bank is.
If you have persistent trouble, switch banks.
Most likely the stores are cancelling the orders because of billing/delivery address mismatch or (if you didn't set a different billing address) that it doesn't verify against your card.
The site was clear upfront that everything had to match EXACTLY or they would cancel the order. I logged in to my online banking and copy and pasted my debit card details to make sure there were no issues.
The one thing I didn't think to copy and paste was my own name because, I mean, I know my own name, right?
Apparently not as I'd entered "John Public" and to my surprise my debit card was issued to "John Q Public".
When my bank card expired Schwab even overnighted a new card to Peru for me. I order from Amazon a fair amount and don’t have any issues.
Maybe you are in this weird algorithmic grey zone where you don’t travel enough so everything gets flagged. Where for me I have been traveling for so long that nothing gets flagged.
Also I don't have issues with classic eCommerce stores like Amazon, Newegg, B&H, ebay. It's only the new wave of eCommerce stores trying to enter the market this decade, like all the big box stores. It's like they all got sold the same crap anti-fraud software/service.
For example, when building a road, there is a certain chance that an accident will happen, that some people will die, and that could have been prevented. For example, by installing a guard rail, enforcing speed limits, or by taking a different path.
But installing that guard rail for a one in a million chance that something bad happens is money better spent elsewhere, like improving safety where it matters more, and people tend to dislike the resulting taxes. Enforcing speed limits have a cost too, that can be recovered from the fines that result from it. But the goal is not to bankrupt your citizens with fines, and constant surveillance is not very popular. And the different path you are planning may go though people homes, relocating people is also expensive, and usually not very popular for the people in question.
So, we tolerate a few accidents and deaths over a dystopian society.
Just for clarity -- guard rails, where we choose to place them, probably cost $500k to $2M per life saved over their lifetime, while the value of a statistical life in the US is >$10M. This comparison ignores costs of non-fatal outcomes (injuries, disability).
It seems like we should be deploying more guardrails, even though their marginal return would be less than our current average.
In the above metaphor, it's more like guard rails are already in place, the speed limit is 1/10th a reasonably safe velocity, and the only way you can stop the remaining death-every-decade is to make everyone walk the road instead of driving it, and guarded so that you don't encounter any strangers along the way either. Very safe. But now nobody even wants to take this road. But it's so safe! Zero deaths, no injuries, ever.
Sure, the expenses/value argument can be made, too, but that's not ultimately what makes it nonzero. Even if you had limitless resources to apply to the anti-fraud, the only way you're getting nonzero fraud is if a large amount of legitimate customers are inconvenienced or outright denied as well. This is due to how easily fraudsters can still find processes and marks to make it worth their time, and regulations + policies are ever evolving to keep up, but a lot of it comes down to a cost/benefit analysis by the business. The internet just scales this up by several orders of magnitude too.
Take the wealthiest top 10,000 Americans out of the equation, and what’s the value of a statistical life in the US?
$10M seems to be a weird number in my mind.
Edit: Well that was a fascinating rabbit hole: https://en.m.wikipedia.org/wiki/Value_of_life#:~:text=In%20W....
They are much less likely to be the recipient of all the money spent on entitlements, no? A giant bucket of money is spent on regular Americans.
[0] https://fiscaldata.treasury.gov/americas-finance-guide/feder...
What's the value provided to citizens by spending 67B on health in the USA in terms of value provided? 10B in a country where prices are not the result of insurance companies colluding with the government?
> Government money is a direct pipe to transnational corporations and the billionaires that run it. Welfare payments are peanuts compared to it.
I don't see the point in hypotheticals. You're restating the politics you've absorbed over years of consuming a certain slant of media. There's no point in that, and no point in me doing the same.
That's not true. It assumes that there is an objective, known price for a life. Since you can't have e.g. 0.1 deaths, there's no guarantee that the optimal amount is at least 1. It's more that it's the outcome of haggling, politics, and the willingness to turn a blind eye to the consequences of stupidity.
[0] https://www.tandfonline.com/doi/full/10.1080/14737167.2017.1...
nit: pretty sure that should be £30k * QALY.
So, in relation to airplanes, we can't choose zero deaths in the real world. We have to choose some imperfect trade off, otherwise we'll cause more deaths.
True, but you can have 0.1 deaths per year, by having 1 death per 10 years.
Of course, I agree there are some things that don't work well for that - nobody's going to be happy accepting "1 nuclear meltdown per 30 years" even if statistically it'd mean fewer deaths than coal.
> But the goal is not to bankrupt your citizens with fines,
There is this one crazy trick to avoid speeding tickets. Cops hate it.
While this is technically true (the devices themselves are cheap and effective), the data required for them to work well doesn't exist. If the data exists at all, it is usually horribly out of date. So in practice there will be many cases where these devices limit you to the 30mph from last year's big construction project. Then you get rear-ended because nobody expects you to slow down 50mph for no reason at all.
Maybe let's start with residential streets only, using the residential speed limit. And let's say only those residential streets that are at least 100m away from a faster street.
I'm sure it will be possible to find a solution that eliminates false positives.
And in the worst case - it's just about acceleration. It's not like the car would abruptly break.
Even in this rare fictional scenario, I don't agree that the costs outweigh the benefits. There are many vehicles that cannot go above 30 kmh and somehow they don't get rear-ended either. Plus, mid-term, the other cars will also have the speed limiter installed.
Which is to say, if you were to build out a system that limits speed based on some authoritative database of speed limits, then suddenly there's an incentive to make sure that database is actually correct (where there was no such incentive before).
Seems like the same point we have with security in computer systems and ease of use.
For example, the USA's lack of a national ID (and the resulting adoption of realldy ba substitues like SSNs, driver's licenses and "two photo IDs") has made a plethora of fraud techniques ridiculously easy. In many other countries, "identity theft" so rare there is not even an established term for it.
Passkeys will hopefully turn into a similar case regarding computer security.
(For what it's worth, I actually liked the national identity card, and didn't hear too much about identity theft - I'm just curious).
For most ID-requiring processes people undergo training to identify these security features, to the level of fraud that it's worth detecting for said process.
When the post office asks for your ID to retrieve a package, they won't check much, but I don't think it's unusual for banks to pass your card through the RFID reader and have a high res picture of your face on screen even if only to recognize you properly (btw you have apps to read such data).
The certificates themselves in the DNI are used only occasionally, but it's mostly your decision: you can stick to using the certificates and not activate other means and then you can't access a bunch of things unless you use the certificates.
But still, this is mostly for the public administrations. Private entities, such as banks or whatever, don't really make use of it and build their own systems (most of the time quite stupid ones [0]).
--
[0] Fortunately they changed it, but for about a year or so my bank decided that instead of sending a 4-digit code through SMS -which you then typed to verify whatever transaction you were doing- it was "more secure" to just show 5, 10, or 20 4-digit codes on the transaction site and then send you a single number through SMS, say "7", to select the code from the list.
And somehow this was applauded and got them some newspaper headlines as the bank investing the most in advanced security in the country or some shit like that.
Having a better national ID than SSNs would have effectively no negative impact while being a huge benefit for security and fraud prevention. It would also, if implemented well, be hugely beneficial for privacy. For instance things like Signal could move from requiring phone numbers to a ZKP using a national ID.
There's tons of issues like this, where there's a clear technical right answer, but the only people who are foaming at the mouth over it are on the crazy side, so it doesn't happen.
The way you can tell this article is crazy is by noticing lines like this:
> When a police officer or security guard scans your ID card with his pocket bar-code reader, for example, will a permanent record be created of that check, including the time and your location?
This is already what happens. The police officer logs your interaction alongside your drivers license (or non-driver ID) number. Transposing a nationally-unified ID scheme for the current state-based scheme doesn't increase the amount of logging, it substitutes one log for another.
Error-prone-ness is a feature for people who want the state to be less powerful.
Personally I think that for purely practical reasons national ids are good infrastructure.
I don't think in 2023 a "weak" national identity system offers much protection against an adversarial government.
Right now the way we verify identity is "dumb" in the sense that we prove identity using document ids or photos. This is "too strong" - to prove I am over 18 or just "the account holder" I must present valuable document IDs or scans which disclose other things about me such as my exact date of birth or my legal name. It is also "too weak" in that any verifier who receives these things can present them to someone else and impersonate me.
Today, every entity we deal with who verifies our identity can also impersonate us. There are billions of ID scans absolutely everywhere, in realtor's offices and lawyer's cabinets, at car rental agencies, etc ad nauseum.
A good "digital id" scheme allows for cryptographic proofs of identity which are non-transferable between verifiers. It allows things like proving that I am John Smith who is over 18 and holds a driver's license in a way that does not allow the verifier to then present those to someone else and impersonate me. It can allow for proofs of uniqueness, e.g. I can prove that I'm a person you've seen before with id xxxyyy in your database without disclosing my name (if the verifier chooses not to collect that). It can allow "blinding", e.g. I can hand over a token to someone who doesn't need to "see" my actual identity details unless they initiate legal process (say car rental scenario) and then I can be notified if that happens.
It is likely that a lot of verifiers might choose to "over collect" (say, request up-front proof of my legal name when strictly speaking they don't need that to rent me a car) but this can at least be discouraged by measures like tuning service charges so that more invasive verifications cost them more and ensuring that verifiers are subject to different regulation tiers based on the scope of data they collect. Even if the entity loses my PII e.g. my name, DOB, phone number, the systems are designed to not allow anyone accessing that information to impersonate me.
Strictly speaking digital id schemes / properties are orthogonal to "national ids". There are centralised, de-centralised and more or less anarchic (p2p) "versions" of digital identity. However, a government operated scheme at the national level could reduce a lot of commercial capture and the kind of "waste" that happens when you need to stitch together many disparate data sources.
This is especially true given that for many applications, I can already use my passport as an ID.
An attacker who pops my bank’s network doesn’t need to look for ID photocopies: my identifying info is in the database in an already parsed format.
You can get ID scanners for nightclubs which check dates, parse dozens of different designs of ID correctly, detect some types of fake IDs, and record banned patrons. That's a thing you can get in Europe as well as America.
But only in America are they allowed to save the patron's address and use it for marketing purposes.
That is a huge advantadge if the federal governments ever gets taken over by totalitarians. Surely at least some states will refuse to authenticate their ID cards when requested by the feds, some may even issue fake IDs to resistance members. If the feds have a centralized database with updated information on residences etc, they can quietly disappear people.
Not to mention before this there was almost no way to get a new drivers license number, so if it got stolen good luck, a new license is issued under the same number.
As two amusing anecdotes:
A while back, I went to buy some beer in a state other than where I lived. I was asked for my ID, and provided my drivers license. The employee pulled out this comically thick three ring binder, flipped to the page for my state, and had to read through a list of compiled identifying factors for a legitimate ID from my state.
Even further back, I worked at a company where a small slice of my job was verifying ID for new signups flagged as high-risk. Except... we were an online business. Our users were global. So if somebody happened to upload a passport or US DL, I could at least eyeball it. But if somebody uploaded an ID issued by basically any other country on Earth... I guess that's what IDs from The Confederacy of Independent Systems look like? The only surefire way to get rejected was either not uploading anything, or the many, many bots that uploaded random pictures of flowers or trains or random nonsense.
The issue here is the license number is the one used for most verification, and that one is static. The card number changes every time the card is re-issued.
Examples of them are here: https://www.mygovid.gov.au/verifying-your-drivers-licence
A funny anecdote along the same lines:
A friend of mine recently moved from WA to NSW. If you move state, you have to apply for a new license within three to six months depending on the state. So he got a NSW license, it's a trivial process to convert your license thankfully.
He came back to WA to visit for a while, and tried to go clubbing. One bouncer read the post code from the address (like a ZIP code, only 4 digits instead) as his birth year because he had no clue what he was looking at... NSW post codes start at 2000, so you can see how this mistake could come up. WA post codes start with 6000 so there's no possible confusion there, until we reach the year 6000 at least!
Of course, the Date of Birth is still clearly labeled on every states driver licenses so this bouncer may also have been a bit daft.
This is literally the core gameplay of Papers, Please, a game designed to make you feel bad. (A great game, I hasten to add, and surprisingly enjoyable -- though allowing yourself to enjoy it means turning off empathy more consciously than in anything I've played before.)
US federal government provides passports with passport numbers. All the infrastructure is already in place, it’s just a question of political will to implement an API to use this for identity verification.
Yes, you're
> you should welcome greater than zero fraud. You can think of it as a necessary expense, just like rent or salary or advertising is.
You don't WELCOME costs just because they're necessary. Similarly, you wouldn't welcome fraud just because it's too costly to get rid of it.
And if you add a tiny bit of morality into the mix, your too clever "fraud welcome!" message becomes even more invisible
(also, it could very well be that some fraud types can be reduced to literal 0 without bringing the whole system down, but then the parts of the system that can make it happen aren't incentivized to do so because they've passed all the costs to other parts of the system)
My interpretation was something like and efficient frontier model between multiple variables where “zero fraud” isn’t actually a position on that frontier. So, if you find a place with zero fraud, you can possibly increase the total utility of the system by aiming for slightly less than perfect but being back on the efficient frontier.
Arguably zero of anything is a great ideal but not maximally efficient.
Morally, the situation is more in favour of getting to zero.
Non-zero fraud is useful for political point-scoring, but zero fraud is a terrible goal on its own. You also need to be measuring false positive cost, and drive that to zero too. The moral argument has to be for the efficiency frontier itself, I can't see any other way this works.
And what's you moral argument for the level of fraud at the frontier? Is the same efficiency better with lower levels of fraud or higher or indeterminate?
When would this be the case? I'm having trouble picturing it.
> And what's you moral argument for the level of fraud at the frontier?
The frontier is exactly the point at which you cannot reduce the amount of fraud without it costing genuine users (and you) more than you gain. So if you're at the frontier and you want to reduce the amount of fraud further, you are acknowledging that harms to users are less important to you than losses from fraud, and doing so would be immoral. The efficient frontier should be the point of least moral harm, almost by definition - at least, as long as all the relevant externalities are priced in.
> Is the same efficiency better with lower levels of fraud or higher or indeterminate?
That's a trolley problem question. Higher levels of fraud at the same level of efficiency would mean there's a corresponding rise in value delivered from genuine usage of the service, so cost/benefit is the same and preference boils down to personal choice. But it sidesteps the more difficult question, which is how taking action to reduce the level of fraud actually plays out: there'll be diminishing returns as you take more and more extreme steps. Each step will likely have an incrementally more harmful effect on the genuine users, so efficiency won't remain the same.
It's less about "allowing fraud" and more about managing false positives in the fraud detection subsystem: it should ideally detect fraud, and only fraud. The false positives need to be low enough for the system to work, without also having so much fraud that the system stops working. Ideally there are no false positives at all, but at some point the effort to reduce this further exceeds the returns. Like with fraud.
But that's also not connected to the main critique - I get how you'd welcome more efficiency (at higher costs), but do you get to welcoming costs outside of trying to do counterintuitive rhetoric?
I think most people understand that a risk-free society is a poor society. Take driving: the safest way to drive is to not get in the car at all. Similarly, the best way to save yourself from credit card fraud is not to have a credit card. But does this justify driving like a maniac, or being careless with your personal information? Of course not.
In other words, the article simply points out that categorical thinking (1 or 0) is useless in this context (as it is in most contexts, to be honest). The meaningful question is what degree of fraud we should be willing to accept, and in what contexts.
Eventually, they started forcing 3DS (which shifts liability from you to the card issuer, and apparently card issuers don’t like paying!). Revenue didn’t decline, but fraud rates did go indeed to zero.
>> The optimal frequency of disasters is not zero. This graceful formulation is due to Prof. Richard Portes, who used to say it about emerging market financial crises. However, it’s a fundamental principle of risk management and one of entirely general application. Most dangers can be absolutely eliminated for all practical purposes, but only at unacceptable cost.
Indeed.
You could make the same counterintuitive and clever point about any bad thing, pointing out that there are things one might do to reduce that thing, which have other costs, and aren't worth it, but for many bad things that would not sound counterintuitive and clever, but deranged.
Consider the following statement:
> The optimal amount of salt in food is non-zero.
That's true, and it's not clever at all, we need salt. It's not that trying to remove all salt from food would be too expensive.
But consider also:
> The optimal amount of radioactive material in food is non-zero.
We might defend this in a similar clever counter-intuitive sense. But it's a completely different statement, and it's wrong.
EDIT: The three replies making the same point about bananas are a great illustration of the desire (and failure) to be clever and counter-intuitive that's also evident in the article. We don't eat bananas for their radioactive material. We don't need to eat radioactive material.
Well, then I have some bad news for you regarding bananas.
Which is funny, because it proves the point of the article: The optimal amount of [bad] is usually nonzero because otherwise you have give up too much of [good].
The world is naturally awash with unstable isotopes and low level cosmic radiation.
But this is true! Everything except lead is radioactive in some capacity. Pretty sure us humans cannot live on lead alone.
Incidentally, astute readers that have picked up on the fact that Pb has Z=82 which is larger than 66 should pat themselves on the back and note that the 4 isotopes all have a yet-to-be-observed decay to mercury, with half life of >1.4×10^20 years for 204 and experimental lower bounds of >10^21 for the other 3. Theoretically, 208 takes >10^124, which means 207 is "more" stable.
The law can place liability anywhere. In a situation where transaction costs are zero, it doesn't actually matter where liability is placed, because the participants will contract in the most economically efficient manner to share the burden.
That means liability choices can reduce to reducing transaction costs. For credit, the $50 is to avoid the adverse incentive of the cardholder permitting fraud, but otherwise the cost and mitigation is better shared among the big players at scale that reduces overhead. (Conversely, shifting liability via forced arbitration and legal disclaimers monetizes market power.)
As a policy matter, ask yourself: so why then do debit cards not come with the same limitation of fraud liability to $50, since the same economies of scale apply?
https://mattlakeman.org/2020/04/27/explaining-blaming-and-be...
He makes the point that although Enron was clearly doing shady things, it's possible for a legitimate business to do many of the same stuff ("mark-to-market" accounting, tricky SPEs, and so on). Try to categorically eliminate Enron-style fraud and you might take down the next Google in the crossfire.
The author is trying to make it sound deep and meaningful with statements like "you should welcome some fraud", as though fraud is actually required for the system to function (clever counterintuitive point made, cue huge dopamine spike). But no, we simply tolerate a certain amount of fraud because eliminating it isn't worth it. Yawn.
You could make an argument that you need some level of fraud to keep the anti-fraud dept on its toes. It’s like war. If you have an army that has never fought a war in a century, you should have no confidence you have an army at all. That’s a problem the day a real war or in this case a real fraud, happens.
The framing is also relevant for another reason: choosing a conscious trade-off point means that you can choose to move it as circumstances dictate, which can be very non-obvious. There's currently a lot of noise in the UK media about dodgy PPE contracts issued during COVID, and for my money most of the coverage misses the point.
The coverage focuses on who the contracts went to, and how much they cost. There is only scant consideration given to whether the contracts were fulfilled (and they weren't - the PPE was no good and couldn't be used).
This is precisely backwards: in an emergency situation where you don't have enough of a thing, and the existing systems to provide the thing are very much tuned to preventing fraud, you absolutely want to be able to throw money at the problem and accept that more of it than usual will be going places you wouldn't ordinarily tolerate. That's a lever we should definitely be able to pull, by making a conscious choice to relax . But that's only true if you do actually get what you paid for.
Yes, you want to be able to follow up any dodgy procurement after the fact, but in the moment what you need is the critical resource.
The scandal should be that none of it worked, not how it was bought.
I was only dismissing the way the article presented fraud tolerance as something deeper than a trade-off. I did acknowledge that the trade-off exists and in my other comment stated explicitly that I think discussion of how one finds the right trade-off is interesting.
On your COVID example, I agree that in an emergency it's worth pulling the lever as you put it, i.e. grease the wheels and get the stuff we need. But I wouldn't expect the extra spending to be directed disproportionately at cronies of the government, fraudulent or not.
Similarly, there's no reason in principle why certain classes of fraud couldn't be rendered practically impossible by an advance in technology, which would undermine the whole "you should welcome some fraud" argument.
I discovered this book through another great post by Patrick McKenzie, "The fraud supply chain" [2] where he heartily recommend it, and I haven't been disappointed. On top of being informative, the book is very entertaining to read.
[1] https://www.amazon.com/Lying-Money-Legendary-Frauds-Workings...
[2] https://www.bitsaboutmoney.com/archive/the-fraud-supply-chai...
The most desirable amount of fraud, corruption or tax evasion is zero.
In the real world we don’t get what we desire. The closest we can came is to the optimal amount, where the marginal cost has to equal the marginal benefit.
But this logic is only applicable for things that on both ends measure in money.
As long as it's in a competitor's operation and not mine, I'll do fine.
The monetary system doesn't care about fraud. Banks, credit card companies, and the rest of the financial sector make money from transactions, with no regard for who spends the money, who owns it, or if the transaction was legitimate. Bad actors need banking too, and their transactions are just as valuable as the ones your grandmother makes.
Here we find the sharp divide that fraud controls try to bridge. The social cost of fraud is extremely high. Yet the proportional value, defined in a capitalist sense, of fraud is close to 1. A transaction that happens to be fraud is almost if not as valuable as a transaction that happens to be legitimate. For a bank, the optimal amount of fraud is not just non-zero, it's basically as much as possible.
I want to launch a business which requires investing a lot of resources per customer. Think, the users pay 100$ and I spend 80$ in resources straight away, transform the resources in a peculiar way and provide it to the customer.
I have already tried this and failed due to occasional credit card fraud and sneaky chargebacks from users AFTER having used resources.
Now, being a small business (zero employees) I can't afford to stomach losses for months, invest into marketing and then wait until 100x growth bring me some profits.
Just because of fraud being the problem of the seller and not of the cardholder, my choices are:
1. Go to parasitic VCs and convince them to give me money, in the hope I'll be profitable in a few years
2. Sell 1 on 1 to trusted companies - which doesn't work if you're selling B2C, increase your sales cost and bar you from a typical SaaS paths with random customers
3. Accept only crypto-currency payments - but nobody will bother to convert money to purchase something when they are used to just use their credit card
Of course the optimal amount of fraud for a business is zero. A world with zero fraud would be optimal for them.
And (also of course) given that combating fraud has costs, there is a level at which investing more money and effort into anti-fraud has diminishing returns.
Therefore it is not worth it to go all in into the fight against fraud, but accept that some amount of it happens.
Surely none of this is surprising.
It has ramifications for the kinds of discussions we have on HN, because the primary stimuli we get are news anecdotes, and anecdotes about fraud can be galling but still under some sane noise floor that organizations don't bother to stop.
The concept of diminishing returns applies to everything any living thing does. I think it's very natural, even in the 'our brains are wired for this' sense.
The optimal amount of pollution is non-zero.
The optimal amount of [insert almost anything bad] is non-zero.
The ideal amount of anything bad, is zero. But the optimal amount is going to be higher than that, given we don't have unlimited resources to spend.
The optimal amount of airline catastrophes is zero. It is also impossible.
Should all humans spend all of their effort and all of their resources to lower the amount of airline catastrophes? I believe that pretty much everyone finds it reasonable to say no.
Would you take a $10 10,000 mile flight across the world with a 1% chance of dying? How about a $100 flight with a .1% chance of dying?
The optimum is non-zero only if there are enough costs associated with making it zero.
That's why asking for optimum amount of fraud is misleading. It omits the costs. Once the costs are taken into account (i.e. it is clarified what the question means) the answer is obviously above zero.
You are conflating optimum (highest value outcome for all variables) and ideal (highest value outcome for one variable). The ideal number of any bad thing is zero. I can't, off the top of my head, think of any bad thing for which the optimum number is zero. Extinction level events, perhaps.
"You can't put a price on human life" is one common occurrence of this. I thought it was just a throwaway phrase, or a wish of how things could be, but I've regularly run into people who don't understand why we would ever fail to spend absurdly large amounts of money to save a single life.
I have had people say "Is the only reason we aren't doing something about X money" for various forms of X. I personally spent over an hour walking one such person through the concept of opportunity costs, the fact that money is representative of value, &c. with the conversation ending with them still certain that the US Government could just print a trillion dollars and solve the problem.
I have talked to people who honestly think that every person with depression should be forcibly committed to prevent them from committing suicide and respond to the "but only a fraction of those people have suicidal ideation, and only a fraction of those commit suicide" with a "if it saves just one life, it's worth it!" So forcibly committing 8% of the adult population is not too high a cost in their minds.
some kind of bald man once quoted someone: "With the first link, a chain is forged..."
The flip side, of course, being the folks who believe they somehow have no responsibility for how they use their rights to impact others.
Society can only function with at least some balance between these two extremes. Some of us need a little bit of chain.
Societally, we've largely decided we're all better off without a pile of frozen bodies at our door.
Eh, I know lots of people who are neither anarchists nor totalitarians, so I'm not sure this is true.
"Red cars are more involved in traffic accidents, I therefore think you must be a murderous lunatic if you get a red car, and we cant have that, so lets forbid it"
How much "earth is sterilized" risk is reasonable per year?
It's the edge cases-- the things where it's really hard to get rid of and we get some useful benefit from the related activity-- where it's nonzero.
Of course, those edge cases are our biggest world problems-- for example, pollution, because pollution abatement is hard and the industry and commerce that produces pollution is beneficial... or fraud, because fraud protection is hard and the industry and commerce that provides opportunity for fraud is beneficial.
One of the key factors is that a large part of the cost is opportunity cost. People tend to get all tangled up when thinking about such counterfactuals. We want to have our cake and eat it too. And if we can't, we persist in trying to find ways to believe that we can, and are surprised that the world continues not working that way.
Yes when we look at it from both an individual level and a societal level. There's a very very strong aversion to loss and many decisions (including my own) are based on the concept of not losing something. Many times these decisions lead to making decisions that are sub-optimal (for the thing that's being optimized for).
By extension, many people apply this thinking to businesses and higher levels as well.
Maybe people have gotten worse at intuitively understanding that tradeoffs need to be made in anything, and that the questions that define systems are never choices as much as what the tradeoff should be.
All you can do is try to realize it early and hit the back button before you waste too much time on it.
Only if the business doesn’t have to pay to avert fraud.
> A world with zero fraud would be optimal for them.
You are misunderstanding the statement. We are not imagining which hypothetical world we wish to live in. We are making a claim about fraud levels in this world and how they feed into profits.
In this world, every reduction in fraud costs money or time or opportunity. Therefore, optimizing your profit means choosing a non-zero (often higher than you’d think) level of fraud.
This is how we end up going back and forth between "the optimal amount of fraud is non-zero" and "it would be optimal to have no fraud". Economics has to live with the world that exists, and there is no plausible combo of variables where people who are about to attempt fraud are instantly evaporated into dust.
Then the question should be stated clearly:
"How much effort and resources should be spent to combat fraud?"
The answer is very obviously not "all of the effort and all of the money". Therefore the matter is trivial.
Also, it fails to consider that corporations (or any entity which operates at the kind of scale suggested by the author) may not be optimal economic constructs for a society to begin with. Society worked fine before corporations and arguably was far more efficient given technological shortcomings. Think of how much human time was wasted on data entry, physically searching for documents in large archives, travelling between home and work on foot or by horse, doing accounting with pen and paper, manual farming, primitive irrigation systems, no synthetic fertilizer, etc, etc... Now that we've freed up people from all that work, how come everyone is busier than ever and yet there are so many poor people?
I think it doesn't make sense to look at our modern economic system as a model of efficiency, instead, I think it should be studied as a model of economic parasitism.
We shouldn't conflate efficiency driven by technology with other aspects of the socio-economic system which are canceling out much of that efficiency.