Hacker News new | ask | show | jobs
by xyzzy123 3741 days ago
It is likely that they are processing a risk score for your transaction, based on browser fingerprint, referer, ip, time of day and so on. That is, the "bounce" may not be entirely useless.

If the risk score exceeds a certain threshold then they can then require additional security. While this may seem very weak, in practice a lot of fraud has pretty obvious signatures.

1 comments

Fair enough. Just having a .nz bank direct me to a .uk domain is a huge red flag for anyone that bothers looking at this sort of thing