I suffered from Amex's fraud detection algorithm recently when trying to book a discount airfare. There was 1 ticket left, I tried paying for it, and Amex blocked the charge, and by the time I tried it again (90 seconds or so), the ticket was gone.
I was on call with many service reps, and no one was able to cover the differential between the cheapest new flight and the discount fare that I missed due to the 'false positive' fraud block.
Why should the customer suffer penalties for false positives? Considering that fraudulent charges themselves do not accrue liability for the customer, why should false positives do so?
It seems worse than that. Now there will be 2 layers of possible false positives - your card and your merchant's payment processor. I can understand a merchant opting in to a sift science like service, but having it built into the processor seems like a bad idea.
Stripe has no relationship with the end user, and should not. A legitimate buyer can't possibly be expected to call into Stripe to verify a transaction before or after a purchase attempt like they could to their own credit card or bank.
(I work at Stripe) Buyers won't have to contact Stripe directly, just as they would not contact a third-party fraud detection service directly. They'll contact businesses, who can use the dashboard or API to mark the charge as safe and retry it without Stripe intervening. In our experience, card networks don't catch much fraud, and not all businesses have the time or resources to integrate a third-party solution—we don’t want them to be unprotected.
And, to be clear, the fact that Stripe is doing fraud protection isn't new—we've always blocked some fraudulent payments, as does every other major payment company. What we're launching is a much better system and, especially, one that businesses using Stripe can train so that there are fewer false positives over time.
Sure they can. A low false positive rate is almost a given. Low false positive rates are acceptable everywhere else, even in medicine, and when the "cost" is a minor inconvenience for perhaps millions in time/energy saved, its an acceptable business choice, even for me as a consumer.
(You note that Stripe has no business with the consumer. Well, then, this doesn't affect your relationship with Stripe, because there is none. It affects your relationship with your card's fraud prevention, which has and will always be there...)
I don't mind the false positive. It's just that people should be compensated for it, especially if the rate is low. It's just good business sense. If the bank can eat up actual fraud charges, why should it not eat false positives?
For online transactions, least in my business, it's not the banks that eat the fraud charges it's the business. If someone uses your card to purchases services, and then later there is a charge back due to you reporting fraud, my business would lose the money that was paid from the card and would be fined $25 dollars. So for example say someone signed up for a VoIP service, made a bunch of calls through that service that were charged. You later check your credit card, see some fraudulent charges and then do a charge back. Well the bank/credit card company gets the money from the VoIP service and fines them.
It would probably be abused all the time and the claims would be for larger amounts than the difference between two similar plane tickets. There would be people claiming they had to buy a car for $2,000 more just because they missed some kind of window where the price was cheaper (even though that doesn't make sense). I don't think any bank would open themselves up to that kind of liability. Even if they would, I think they'd cap it to a low amount that was close to the cost of eating chargebacks.
That sucks. I had a somewhat similar experience trying to buy about $2k of stuff in person in a shop I hadn't been to before, Amex blocked it and I instantly got a ping on my iPhone app. The process to unblock it was stupid - I had to call in - but I think they're making headway. It would be nice if you could just TouchID a "yes, please authorize this transaction".
Yes if the transaction was 'on hold' it may have been fine. The problem occurred because the transaction went thru on the sales page, but was then blocked by Amex before the airline could send a confirmation, and then there was no confirmation as the payment had not been approved.
So, infact, if the card was refused AT the submission form, the website would've held onto the ticket, and waited for re-submission.
I ditched Wells Fargo after getting lots of repeated calls at anytime of the day or night to verify the last transactions on my account. Based on the same transactions, they could figure out my most recent location and develop something that's a little more careful about the time/day of the week this automated calls were placed.
The weird part was that I was booking the flight sitting at home from my personal laptop. In short, my modal usage of the credit card for online shopping.
Comments
I suffered from Amex's fraud detection algorithm recently when trying to book a discount airfare. There was 1 ticket left, I tried paying for it, and Amex blocked the charge, and by the time I tried it again (90 seconds or so), the ticket was gone. I was on call with many service reps, and no one was able to cover the differential between the cheapest new flight and the discount fare that I missed due to the 'false positive' fraud block. Why should the customer suffer penalties for false positives? Considering that fraudulent charges themselves do not accrue liability for the customer, why should false positives do so?
It seems worse than that. Now there will be 2 layers of possible false positives - your card and your merchant's payment processor. I can understand a merchant opting in to a sift science like service, but having it built into the processor seems like a bad idea.
Stripe has no relationship with the end user, and should not. A legitimate buyer can't possibly be expected to call into Stripe to verify a transaction before or after a purchase attempt like they could to their own credit card or bank.
(I work at Stripe) Buyers won't have to contact Stripe directly, just as they would not contact a third-party fraud detection service directly. They'll contact businesses, who can use the dashboard or API to mark the charge as safe and retry it without Stripe intervening. In our experience, card networks don't catch much fraud, and not all businesses have the time or resources to integrate a third-party solution—we don’t want them to be unprotected.
And, to be clear, the fact that Stripe is doing fraud protection isn't new—we've always blocked some fraudulent payments, as does every other major payment company. What we're launching is a much better system and, especially, one that businesses using Stripe can train so that there are fewer false positives over time.
Sure they can. A low false positive rate is almost a given. Low false positive rates are acceptable everywhere else, even in medicine, and when the "cost" is a minor inconvenience for perhaps millions in time/energy saved, its an acceptable business choice, even for me as a consumer.
(You note that Stripe has no business with the consumer. Well, then, this doesn't affect your relationship with Stripe, because there is none. It affects your relationship with your card's fraud prevention, which has and will always be there...)
I don't mind the false positive. It's just that people should be compensated for it, especially if the rate is low. It's just good business sense. If the bank can eat up actual fraud charges, why should it not eat false positives?
For online transactions, least in my business, it's not the banks that eat the fraud charges it's the business. If someone uses your card to purchases services, and then later there is a charge back due to you reporting fraud, my business would lose the money that was paid from the card and would be fined $25 dollars. So for example say someone signed up for a VoIP service, made a bunch of calls through that service that were charged. You later check your credit card, see some fraudulent charges and then do a charge back. Well the bank/credit card company gets the money from the VoIP service and fines them.
It would probably be abused all the time and the claims would be for larger amounts than the difference between two similar plane tickets. There would be people claiming they had to buy a car for $2,000 more just because they missed some kind of window where the price was cheaper (even though that doesn't make sense). I don't think any bank would open themselves up to that kind of liability. Even if they would, I think they'd cap it to a low amount that was close to the cost of eating chargebacks.
It was an actual charge for a specific route (e.g. SFO - JFK). I couldn't later claim that it was for SFO - YYZ.
That sucks. I had a somewhat similar experience trying to buy about $2k of stuff in person in a shop I hadn't been to before, Amex blocked it and I instantly got a ping on my iPhone app. The process to unblock it was stupid - I had to call in - but I think they're making headway. It would be nice if you could just TouchID a "yes, please authorize this transaction".
Yes if the transaction was 'on hold' it may have been fine. The problem occurred because the transaction went thru on the sales page, but was then blocked by Amex before the airline could send a confirmation, and then there was no confirmation as the payment had not been approved. So, infact, if the card was refused AT the submission form, the website would've held onto the ticket, and waited for re-submission.
I ditched Wells Fargo after getting lots of repeated calls at anytime of the day or night to verify the last transactions on my account. Based on the same transactions, they could figure out my most recent location and develop something that's a little more careful about the time/day of the week this automated calls were placed.
The weird part was that I was booking the flight sitting at home from my personal laptop. In short, my modal usage of the credit card for online shopping.