Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's not IP based, it's billing address based.

Amazon has a UK presence so it's only natural they accept payments from there. But it's very myopic to insist all other vendors do the same since many don't have the resources to pursue fraud cases overseas. They barely manage to get through locally.

I used to work at a fashion house that didn't ship outside the U.S. simply due to our AVS not being able to valiate addresses outside the 50 states. Losing thousands of dollars to fraud during a bleak economy isn't how people stay in business.



I wasn't talking about shipping stuff outside of the US.

Amazon UK has nothing to do with the transaction. It is all through Amazon (US/.Com).


I wasn't either. I'm talking about the billing address, which for most vendors must be in the U.S. for their AVS to work.

Edit: Let me clarify further...

U.S. Businesses rent services here that let their AVS take advantage of anti-fraud measures. Many of these services don't even bother looking at the shipping address, but do look at the billing to make sure the card number matches the account holder information. These services often times have no information on overseas card holders so they have no means to verify whether the actual card holder made the purchase.

Now you also have some vendors who make sure the billing address == shipping address as that's a cheap way to prevent fraud (or at least reduce it). That's not what I was talking about.


What you're saying makes no sense.

If someone uses a stolen credit card with a working address then the AVS has done nothing to mitigate the fraud, if they use a non-working address then it bounces up-stream and the AVS has done nothing, and if there is no fraud then the AVS has done nothing...

So explain to me exactly what the AVS's point is? And how it saves companies money? Isn't it up to the bank to decide what is and is not a valid address for usage with the card?

All you're doing is hitting real customers (including international ones).


You need to read up on what AVS actually does :

http://en.wikipedia.org/wiki/Address_Verification_System

AVS doesn't work all that well outside the U.S. (Amex declines it outright) And services that do work outside are often value added (read: expensive) and for businesses that primarily cater to U.S. customers, isn't worth the price. AVS isn't just a "bank service". It's only available to merchants that use a gateway that supports it (same for CVV/2) : https://support.mivamerchant.com/supportsuite/index.php?/Kno...

And of those gateways, some don't support AVS outside mainland U.S. or only partially.

Those businesses aren't "losing money" by not catering to you. On the contrary, they're saving quite a bit by focusing on local customers.


If your shipping a physical good then it works well, different billing and shipping address can be a red flag. Depending on where the billing address is then it can be easy to stop fraud.

If the causes us to miss out on a few sales it is small price to pay compared to getting hit with chargebacks.

Also AVS works fine in the UK as well as the US.


> Now you also have some vendors who make sure the billing address == shipping address as that's a cheap way to prevent fraud (or at least reduce it).

I use a PO box as my billing address. I never have anything shipped to my billing address. Also, my PO box shows up nowhere in my wallet, so, if it gets stolen, at least the thief won't have a valid billing address to use with my cards. And merchants who check billing address will decline his order when it comes through with my driver's license address.

I've never had a problem with an online merchant using the tactic you advocate. However, if I did, I would be royally pissed and bad-mouth the vendor online. Far from reducing fraud, your tactic would serve to increase it!


Refusing to ship a physical product to a first-time customer at anything other than the address where their card is registered seems a sensible practice, and it is certainly in fairly common use here in the UK.

If you tried to order from one of those companies and failed their check, sure, they might lose your order, but it's a game of probabilities and you're making yourself a statistical outlier.

As for going on-line and bad-mouthing a vendor who uses this technique to reduce fraud, that's between you and your conscience, but if you in any way claimed that they were insecure and cost them business, don't be surprised if it becomes between you and their lawyers.


Perhaps you should think about the number of times you've entered a new shop to find some present for someone. Refusing the first sale because the shipping address is different equals to saying FU to most gift orders in my opinion.

As a side note, the most heavy handed and dumb fraud detection processes I ever saw where fom very small shops who would for instance try to hand mail or phone you to have you fax them some doc.

It's a real PITA, but since someone taje time to communicate with you in a people to people level, usually I wouldn't just cancel, and try to make it work out.


>Refusing to ship a physical product to a first-time customer at anything other than the address where their card is registered seems a sensible practice

Knowledge of the billing address is a means of authentication, as is knowledge of the expiration date and the CVV2. A different billing address enhances security, since a typical thief would be expecting the billing address to match whatever fleeting knowledge of the customer he gleaned during the theft. I've done many transactions using a PO box billing address and a street shipping address, all without a problem.

> As for going on-line and bad-mouthing a vendor who uses this technique to reduce fraud, that's between you and your conscience, but if you in any way claimed that they were insecure and cost them business, don't be surprised if it becomes between you and their lawyers.

My conscience says, you inconvenience me, I tell others!

As they say in Texas, Bring It On. In the United States of America, truth is an absolute defense! That means, even if you go out of business because your story was told, you've got no case unless you can prove the story teller lied deliberately while knowing the truth.


Knowledge of the billing address is a means of authentication, as is knowledge of the expiration date and the CVV2.

Right, but requiring that physical products are only ever sent to an address that is known to be associated directly with the card holder, at least the first time when you don't "know" the card holder yet, reduces the likely gain from fraud to near zero for third parties. That is a far more effective deterrent than any minor hurdle in the authentication process.

As they say in Texas, Bring It On. In the United States of America, truth is an absolute defense!

And which truth would that be? If you caused serious damage to a business by claiming this practice made them less secure, I expect they would have no difficulty at all lining up expert witnesses who say they have a very different idea of what makes things more secure. They would have the added advantage that this is a field where lots of people look very carefully at real numbers, so they could probably bring a mountain of statistical data in support of their position.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: