Ex-Googlers Train Machine Army to Sift Out Crooks
wired.com
wired.com
If siftscience turns out to be significantly more accurate, it may end up being worth it.. but at somewhere between 6 and 20x their competition's price, it will take quite the improvement.
For what it's worth, you can score up to 5000 users per month completely free with Sift Science. So if you run a small site, there's no fee. If you run a large site, you can see for yourself whether we're saving you enough money to justify the price.
In addition, there are discounts from high volume, for pre-payment, and there's the possibility of scoring only high-risk users. If you run a web site, feel free to shoot me an e-mail at brandon@siftscience.com, and we can figure out how to make it work for you.
Just to clarify, we charge 10 cents per unique user that you query in a month, not per query. So, you can query the same user as many times as you like in a month and the cost will not exceed 10 cents for that user.
An ideal customer would be an e-commerce marketplace, I imagine that Sift Science would want to receive as much information about the customer as possible, including credit card / address details. Are you guys completely PCI compliant? You're taking 10 out of 16 credit card digits...
From a quick glance of your website you make no reference to PCI.
There is no requirement in their api to supply CC details... so no requirement to be PCI.
So it would be weird if they did mention PCI...
The first 6 and the last 4 is not enough to make a valid CC... And if you are still guessing the last details then it's the same as just guessing the full number. (just you'll get their quicker)
Perfect timing too, I just started looking at our options for developing something similar internally.
Would love to see the systems that Etsy / Ebay for handling this type of fraud.
We provide a score, and then let our customers decide what to do. The majority of our customers have a human review the user, and sometimes as part of that review, they'll do extra verification such as calling the user up. In other cases, customers will delay charging the credit card until they can verify it's legitimate.
I live in Malaysia, and for the longest time, we didn't have access to the iTunes store. We effectively couldn't buy apps or music online from Apple.
To circumvent this, we could open a fake US account. Problem is, you can only purchase items with a valid US credit card. To circumvent that, some people went to the US, bought a lot of prepaid gift cards, and sold them here at a marked-up price. Then all we have to do is set up a US account with a fake US address (thank you, Beverly Hills 90210!).
One thing to note -- our system analyzes a whole bunch of patterns for each user. So just shopping at 3am by itself won't cause problems, nor will using a prepaid gift card by itself. But if a user matches multiple fraud patterns, then they're likely to get a high fraud score.
In other words: A lot of things can have perfectly legitimate reasons but still strongly suggest that you're up to no good.
The tricky thing is to combine sufficient number of signals to get a high enough confidence to act on it without angering users with legitimate reasons.
Those $label events let us do two really important things.
First, we can learn patterns that are unique to a particular site. Every site is a little different, so that has a big impact. Patterns that catch fraud accurately for an auction site may not work at all on a travel site.
Two, if a user gets banned from one site in our network, we can identify when they attack another site. That means as more sites join the network, the system gets more accurate for everybody.
If there has been no JavaScript activity from a user who makes a transaction on your site, that is a fraud signal in its own right. (You can send us events from your server in addition to adding the JS to your site, so that we know characteristics of your users' transactions that can't be gleaned from the JS. In both cases you set the user ID in the call to Sift.)