Stolen Money on Gittip, Part 1
blog.gittip.com
blog.gittip.com
As it turns out, the CEO of BalancedPayments is (there is just no nice way to put this) an unethical bag of scum. He recently went on some kind of insane power trip, completely disregarding the needs of his customers, putting me on unpaid leave for ... reporting an incident of fraud to a bank. I reported an incident exactly like the one Chad discusses here, but the dollar amount stolen was much higher, and the fraudster a repeat offender.
Anyway, after that last meeting where he was sneering and enjoying way too much the power trip of getting to "fire" somebody, I can confidently exhort that Balanced should not be trusted.
It's important that any company a marketplace entrusts its financial data with is an ethical one. So, yeah, looks like I'm on the job market; ping me : http://lnkd.in/NuBGDY
Saying what you think about someone is not, in and of itself, a vindictive act.
However, that really doesn't excuse the behavior: just because you can find someone worse than you, making you look good in comparison, doesn't mean that you are actually doing well... "have you seen Steve? he failed that class; in comparison, my C is great! if you really can't see the difference, you don't deserve to be a teacher" <- this statement isn't even false, as a C really is massively different than an F... at least you tried... but is it really something we should be happy about? Seriously?
I would be hesitant to hire OP because I wouldn't want my name unfairly tarnished in public like this.
This is very dangerous ground, and could be a case of libel if the "unethical" CEO catches this.
This is certainly not a stretch for civil court, nor would it be inexpensive for either party involved.
Being a statement on the internet, I believe this case could be tried in the UK, hence the tourism aspect.
[1] http://en.wikipedia.org/wiki/English_defamation_law#Burden_o...
Ridiculous libel judgements in the UK will not be enforced in the US if the judgements violate the First Amendment.
I'm just waiting for day when libel tourism results in no one visiting the UK -- actual tourism -- because everyone has UK libel judgements against them.
On the other hand, the world would be a better place if we didn't all have to make nice-nice and pretend, so rock on!
What libel? You mean his opinion of the CEO? Which statement do you find to be factual and a lie?
That said I am not sure how BalancedPayments is built. By that I mean how much risk they are taking in being part of this payment ecosystem. It looks like they hold the money in their own bank account so BalancedPayments themselves uses another processor to do their payment processing. The other alternative is that they are big enough to communicate directly with the backend network like IPPay, First Data Omaha, or FNBO...but they don't seem that large.
First off, strictly speaking, this is most likely to be a stolen credit card (i.e., fraud) rather than money laundering. You do NOT benefit from fraud, because when the cardholder notices the charges, they'll call up their bank and issue a chargeback. The $488.15 in your account will actually be removed and given back to the original cardholders. In addition, each fraudulent charge carries a $15-$25 fee, which you're liable for. https://www.balancedpayments.com/docs/testing#chargebacks---...
What's worse, chargebacks can take 60-120 days to reach you, since there's delay at every step: the customer's bank, the credit card networks, your payment gateway, and the acquiring bank (your bank). Unfortunately, that means you won't know how much fraud you have today until February (!). It's a broken system, but that's how all the major card networks work, so it's something that everybody who sells online has to deal with.
If your fraud rate is higher than about 2% for two months in a six month period, Visa and Mastercard reserve the right to block payments entirely to your (or Balanced's) account unless you prove you can get the chargeback rate down. This is called an "excessive chargeback program."
In terms of heuristics, fraudsters adapt rapidly to whatever counter-measures you use. The half-life of a good heuristic is maybe a couple of months. The best approach is to evaluate hundreds of different signals, using a machine learning algorithm to constantly adapt to changing fraud patterns. My company is running a private beta of exactly this technology and we're happy to help: http://siftscience.com. Even if you don't use us, I can recommend other services or give you general pointers.
Hope that helps! Let me know if you have any questions: brandon@siftscience.com.
http://blog.gittip.com/post/28351995405/open-partnerships
I'd welcome a conversation with Sift Science along the same lines.
"use a fraud detection service"
Companies that have high transaction amounts often use the machine learning system to detect likely fraudsters, but then have a human review each one and make the final decision to approve/deny. We have a visualization "widget" that shows the reviewers which signals made a particular user look suspicious. The advantage of using machine learning is then that you: a) catch fraudsters you wouldn't have noticed otherwise, b) don't have to review every single transaction, just the subset that are most suspicious, c) make it faster for your staff to review transactions since the visualization tools will help point them at what to look at.
Does that make sense?
Before selling stolen credit cards, bad guys have to verify them. This is often done with small (<$10) donations to charities or small purchases of intangible goods that are considered low risk merchants.
With Gittip they found a way to get the low dollar amounts to come back to them, but since this wasn't really the goal to start with, you'll likely see donations to random leaderboard members that are unaffiliated with the fraud itself in the future.
https://github.com/whit537/www.gittip.com/issues/329
The desire to verify stolen cards with the added benefit of recovering that waste seems to explain the motive for using Gittip.
I'd say the proper term is fraud. But I don't really like semantic arguments, so I'd say it's not a huge deal either way :)
edit: I should add, the reason I don't think it's stealing is because the money often gets returned; the illicit transfers can be reversed. When the real stealing will be going on the fraudsters will be taking lots of money and running.
edit2: I feel bad for even objecting, it's really not a big deal. 'Stealing money' is close enough to what's going on.
edit2: :^)
That is common law theft. Property taken, no consent, deprives legitimate owner of use of it. The thief gaining value from the property is not an element of the crime.
They also verified them on SoundCloud without any purchase. Don't know if it's still possible.
Or just verify that the credit card number is potentially a legitimate one?
Because if it's the latter, that's just the Luhn algorithm (http://en.wikipedia.org/wiki/Luhn_algorithm) and no transactions are required to perform the verification.
If it's the former, until you make a transaction there's no way to verify in advance whether or not a card has a still valid account attached to the backside of it.
I know you're saying "without any purchase", but maybe it was just for a vanishingly small amount.
It's possible, with most credit card processors, to perform a $0 authorization to confirm that a credit card number is linked to an active account. It doesn't guarantee that any charges against the card will go through -- the card may be at its limit, for instance -- but it will correctly reject numbers that are structurally valid (e.g, pass Luhn) but which don't correspond to any account.
I've supported a number of different online credit card donation forms for various charitable and other causes, and you see this behavior of card testing whenever you set the minimum allowed donation too low, and adopt too few of the necessary precautions.
I wrote a post on the approach to raising the bar I took - it really doesn't require much to get the credit card testers to go away, and if you don't get rid of them rapidly, you'll be dealing with chargebacks from here until eternity:
http://www.exratione.com/2010/10/three-necessary-defenses-fo...
https://github.com/whit537/www.gittip.com/issues/345
Even then, I'm not sure I would trust this approach. I feel much more comfortable white-listing accounts, and for the time being that's not too onerous.
You could hash the IP address, with some suitable salt. Then compare against that.
The purpose of storing IP addresses isn't to find out "the IP address of the user submitting the form", but instead to answer "How many other credit card numbers have come from this address?", something that can be done with sha512("salt_mc_salty_$IP")
No, with IP logging it's all-or-nothing. You might as well store them as uint32/uint128.
From a security / data privacy angle, things are rarely 100% perfect or 100% broken. Just because an approach is not 100% perfect, doesn't mean that it is worthless. It can still offer protection of sensitive data.
Storing IPs in the clear in a DB means that if anyone gets any access to it (e.g. SQL injection type attack), they can have the whole lot. With salted IPs it's harder and much longer before they have any decent data.
If you tweaked a hashing algorithm to take circa 100 milliseconds to hash an IP, then "brute forcing" would be much less of a problem because it would take about 13 years to hash the whole lot.
Or $31,000 on EC2. Are these logs per-request or per-transaction? The former could get awfully expensive.
Of course, checking a single target IP address would be trivial. Whether that matters depends on their threat model.
I would also, advise against your plan to just white list givers. There are already too many barriers to contributing. I would suggest just charging and holding onto money when the transactions seem dubious. Do you also get charged the cost of fraud? because if you don't I would just charge the credit cards and forget about it and let your provider do their job.
Could you run them off by just always displaying success for any sane-looking small value donation, without leaking the result from your payment processor?
Alternately (or in addition to this), you could rate-limit form submissions from the same address.
Most small online businesses do not store credit card data locally, but that doesn't stop you from using salted hashes of credit card numbers to compare.
Storing a "salted hash" of a credit card number in the manner you describe is only fractionally better than storing the credit card number itself. This is because credit card numbers have very little entropy - less than 36 bits per issuer code, so bruteforcing these hashes can be done very quickly.
Depending on where you're based you'll have legal obligations that'll define what you should be doing at this point. This may well involve lawyers, your regulators and the police.
Some countries make it a criminal offence if you let a criminal know that you suspect them of money laundering or similar offences (this is known as "tipping off") so you should be very very careful about what you're disclosing both to your users and the general public.
You should still pull this post and talk to lawyers.
This is one of the reasons that PayPal will lock accounts without giving a reason why--it's potentially criminal for them to tell you why!
What to do? Some options to reduce your fraud are - outsource the problem by using an indemnified payments system (a payment processor who do their own fraud checks and don't pass on any chargebacks to you). Pros: easy. Cons: expensive and lots of valid payments will be refused.
- Use an e-wallet that usually has few/no chargebacks, eg Skrill & Neteller. Pros. Easy, not too expensive. Cons: more difficult for people to make payments as they need to create an account with the e-wallet first.
- Use services to help with your fraud detection. Eg. Iovation. Pros: you can keep it easy for your customers to make payments. Cons. a lot of work to implement (relatively speaking).
- Use bitcoin, eg bitcoin247.com. Pros. no chargebacks ever. Cons. about 0.00001% of your customers use Bitcoin.
Edit: I forgot to add: - require 3D Secure / Verified by Visa payments. This removes the chargeback liability from the merchant in most cases and shifts it to the card owners bank. Pros. much fewer chargebacks. Customers can still deposit directly on your site using their card (apart from the 3D redirect). Cons: entering 3DS details another barrier to making payments so will reduce payments. Plus I'm not sure of the penetration of 3DS cards in the US.
And yeah, you could also kiss goodbye to chargeback, fraud etc problems. These are not a problem in a "hard" currency like bitcoin.
There are others working on similar projects, see fundhub.org
Credit card companies will, some time later, probably notice the fraud. At that point, you'll get a chargeback: you'll have to pay back the money you charged in addition to a fixed penalty per fraudulent charge (usually $15.) Especially if you're enabling a marketplace, like gittip does, these fees can be devastating. Regardless, if chargebacks become too common, your merchant account may be suspended.
I've written some about my company's experiences with fraud, if it's of interest:
http://davepeck.org/2011/11/17/fraudsters-gonna-fraud/
http://davepeck.org/2011/12/01/dealing-with-credit-card-frau...
use a fraud detection service: https://github.com/whit537/www.gittip.com/issues/357
detect and prevent botnets: https://github.com/whit537/www.gittip.com/issues/358
detect and prevent scripting: https://github.com/whit537/www.gittip.com/issues/359
Information assymetry is probably your only advantage against credit card fraudsters, because there is no security hole, rather they are exploiting your core business flow.
What are your thoughts on the value of the social graph in spotting suspicious accounts? It seems to me that we should be able to whitelist new accounts based on a review of GitHub or Twitter profiles, and perhaps for flagged accounts we "authorize without capturing," as dangrossman suggests above.
My experience is that there is no such thing as preventing fraud in the absolute sense. It's not a binary proposition—maybe general security isn't either, but it's a hell of a lot less gray than credit card fraud. So while I think it's good for general fraud prevention techniques and information to be widely disseminated, I can't in good conscience discuss specifics of techniques that I've employed because those would be easily traceable to companies I've worked for, and thus would impose an undue cost on them. A lot of people who have worked on these issues are probably in similar position where we'd be happy to go into details over a beer but not on public record.
Obscurity of process/information can definitely be a benefit to the security of a system but it should not be the solution. The system should be designed for the absolute worst case scenario where this process/information could be exposed.
I realize this can only go so far until at some point there is going to be some sort of secret that needs to be kept (i.e. physical hardware key, encryption codes, etc) where if this is cracked your system is exposed and at that point you need to have some sort of plan B to regain control and minimize damage.
The difference between publishing your techniques (even with specific variables hidden) and often the difference between attackers being able to iteratively determine the minimum work around to get desired results and having to dedicate orders of magnitude more effort than necessary to ensure they are flying under the radar.
There is a reason people don't go around wearing their credit card numbers and SIN on their clothes. The system to protect them should be setup to work its best in the scenario this information is completely exposed but our attempts to hide his information does add a tangible benefit.
After all, hidden passwords are security through obscurity, and that's "just the wrong way".
It does make me wonder, did the bad agent happen across Gittip independently or are they active within Tech communities?
Essentially, this is standard practice.
Just kidding, but it is funny how outsiders might not understand why you are surprised to find criminals in the "hacking" world.
Even so, a significant proportion of the people who go to something like DefCon have done some low-level fraud with credit cards, and some have done much more than that.
Their first round of chargebacks are going to be insane, and if they're this far behind they're going to be eaten alive by fraud.
Any good payment gateway should be managing the risk of stolen credit cards, but it's likely that because Gittip works with small recurrent payments instead of big upfront payments, it doesn't trigger any red alerts.
To take this to the next step, this is also why I believe Paypal is one of the very few companies that has been able to scale online payments. I'd love to see anyone challenge their ability to balance customer service with fraud prevention at scale.
Gittip should work with a party that is already in the possession of the required knowledge or they'll be shutting down. This post raised their visibility as rookies considerably and you can expect the sharks to move in now that there is blood in the water.
For what it's worth, a little bit of fraud is a good thing. It means people are using your system and it's growing. Too much fraud and people will lose confidence and your payment processors will punish you. Too little fraud and your system is probably too complicated to be useful to anyone, including fraudsters.
In the end, I think we (Balanced) should have done a better job here, and we'll work hard to do so in the future.
So that's that for that heuristic. They will adapt now.
> The uncomfortable truth is that Gittip, Balanced, and our legitimate users are financially incentivized to turn a blind eye to laundering, because we have benefitted and are benefitting from it.
That's only true until you start getting chargebacks.
Phew. I'm saved from the moral burden by the financial burden. :^)
There are compliance ramifications of permitting money laundering, but collusion isn't always money laundering. Here's a few different scenarios:
1. Legitimate money laundering where someone is trying to obfuscate the origin of the money for some illicit reason. The ramifications of permitting or not having strong enough systems to prevent money laundering results in being shutdown. That's a bigger incentive than financial loss
2. Fraud where someone is trying to get cash off of someone else's card. This is the number one form of fraud on a marketplace and, by far, the hardest to catch. This is where the incentive is financial due to chargebacks
3. Cash advance where a marketplace has set their fees low (sometimes even lower than the fees Balanced charges) and someone is incentivized to get money off their card or simply get miles/points. Venmo and a lot of similar services experienced would get targeted by this form of collusion when they didn't charge any fees. This should be prevented due to card network (Amex, Visa, MC, Discover) policies, but they generally won't result in a chargeback
You didn't get money laundering, but if your volumes would be larger, you would get also money launderers.
https://en.wikipedia.org/wiki/Money_laundering
I changed the blog post and GitHub issue to not refer to money laundering anymore.
None have been as open and ethical about this as you, though, so it's very comforting to know that gittip won't be a free-for-all bonanza for asshats.
https://github.com/whit537/www.gittip.com/issues/search?q=bi...
Haha! That's why i'm never gonna use Tumblr! :P