Answers like yours kill the little remaining faith I have in people.
This same argument has been used to defend sloppily implemented CAPTCHAS destroying accessibility since what, 20 years.
Happy to share it with you. Using small businesses for credit card testing is one of the most evil things on the Internet, so anything to stop it is worth it.
"Don't shoot the messenger!"
Security can't be a reason for discrimination.
Edit: The downvotes have spoken! This view is simply wrong with no justification!
There are many practical ways to handle that sort of thing that isn't Cloudflare. It just requires thinking and a bit of dev time.
t. Been there, done that, cartels used an app to try to launder money through loyalty programs. Management was deadset against doing the one single thing that would make it impossible to do that at scale.
Ulterior motives abound everywhere but especially behind people claiming X is the only answer. Fingerprinting is far more intrusive than just only allowing one to add at max 2 cards a day per user.
All those requests will appear from different ip's and different browsers, made by someone who can spend months on trying to defraud you. How do you differentiate this from valid customer who happens to try to buy something between 20 tries by bots?
> Your input sanitization?
All those fraud requests will give you valid credit cards which will work perfectly, but then defrauded people or banks will try to chargeback later.
> Designing your system to not just disclose details around anything but that relevant to a logged in/authenticated user?
They can register as normal buyers.
> It just requires thinking and a bit of dev time.
And they can spend months trying to outthink you, then will drain your service in 4 hours when you are asleep.
> Management was deadset against doing the one single thing that would make it impossible to do that at scale.
So, did you actually ever implemented and checked a good solution? Cloudflare isn't perfect, but not everyone has resources to implement their own solution that is better than cloudflare.
> Fingerprinting is far more intrusive than just only allowing one to add at max 2 cards a day per user.
The fraudsters will appear as completely new users each time, adding only one card and making one purchase.
How are they getting pass 3D-S?
If they are able to get past it, then your liability drops off.
Yes it could be designed better, but that is a separate discussion.
Performance optimization for website already is a business. It's just that product managers mostly don't care and optimize for other metrics (eyeball retention, SEO, etc).
Bots and scrapers and hackers also try and avoid being tracked, which is by far a bigger problem for them and most websites than the 15 of us using tons of antifingerprinting techniques. Evil? No, that's silly.
Sufficiently advanced stupidity being indistinguishable from malice is also something to keep in mind.
- stupidity
- stupidity and malice