Hacker News new | ask | show | jobs
by SyneRyder 3164 days ago
It sounds like you've already done this, but have you read about when Candy Japan was hit by massive fraud and how they solved it? (TLDR: don't let fraudsters know the card was declined, make it look valid)

https://www.candyjapan.com/behind-the-scenes/candy-japan-hit...

https://www.candyjapan.com/behind-the-scenes/how-i-got-credi...

I'm more amazed that Stripe hasn't reached out to you if you're getting 33% chargebacks. I thought the industry standard was that if your fraud rates are above 1% they'll flag your account, and above 2% you risk being permabanned by Visa/MC. (Perhaps that's outdated, I think I first heard that 10+ years ago.)

1 comments

It's challenging to find a balance between security and not hindering legitimate customers. Telling them the order went through when they mistyped their card number isn't great. I don't expose the reason the payment was rejected however.

Stripe does warn me about the charge-backs.