• cecilkorik@piefed.ca
    link
    fedilink
    English
    arrow-up
    23
    ·
    24 hours ago

    It’s about time we start seriously thinking about how to escape Visa and Mastercard anyway.

    • notabot@piefed.social
      link
      fedilink
      English
      arrow-up
      21
      ·
      1 day ago

      You don’t need to stop them, you just need to make the effort not be worth it compared to using a different site. Things like making sure they have a valid session cookie before they hit the payment flow, and, ideally, require them to be logged in too. That way you can block attacking accounts, and they have to go through the effort of registering a new one, which is, hopefully, well gated against automated attacks.

      • Steve@startrek.website
        link
        fedilink
        English
        arrow-up
        18
        ·
        1 day ago

        Every single attempt registers a new user account, all with fake info. I have been trying all different things to block them but theres no unique data to identify them. I havent had a completed payment from them in a few weeks but I can still see the attempt being made.

        At first, they used valid emails which led to me being banned from gmail because all the order notifications were being reported as spam.

        • InFerNo@lemmy.ml
          link
          fedilink
          English
          arrow-up
          1
          ·
          7 hours ago

          Block Russian IP range. Do the logged ips of the malicious tries originate from the same region?

        • BananaTrifleViolin@piefed.world
          link
          fedilink
          English
          arrow-up
          4
          ·
          23 hours ago

          Do you have basic security like 1 email is a unique account, and the email needs verification before an order can be placed? Because that simple step will be rate limiting for the attackers but normal and expected for real users.

          Also could be worth considering using a dedicated payment processor to handle things. It adds overhead, but so does fraud.

          • Steve@startrek.website
            link
            fedilink
            English
            arrow-up
            1
            arrow-down
            2
            ·
            22 hours ago

            I dont want to add barriers for real orders.

            I use both Stripe and Paypal to process cards.

            • muusemuuse@sh.itjust.works
              link
              fedilink
              English
              arrow-up
              8
              arrow-down
              1
              ·
              22 hours ago

              You don’t want barriers for scammers because they inconvenience real customers. So you choose to enable the scammers. That is exactly why this works.

              Thanks for playing.

              • Steve@startrek.website
                link
                fedilink
                English
                arrow-up
                3
                arrow-down
                1
                ·
                22 hours ago

                I agree. What do you suggest? Just shut it down?

                I guess I could move to SantaFe and do something with turquoise.

                • muusemuuse@sh.itjust.works
                  link
                  fedilink
                  English
                  arrow-up
                  5
                  ·
                  21 hours ago

                  People have already given you options and you repeatedly say “nah, that’s inconvenient”. The inconvenience is the point. You are inconveniencing customers who want to get a thing from you and have a reason to endure it to achieve that goal but you are also inconveniencing the scammers who have no goal at the end so…

                  Fuck it. Have fun in Santa Fe. Save me a seat and some tequila.

  • Retro_unlimited@lemmy.world
    link
    fedilink
    English
    arrow-up
    9
    ·
    23 hours ago

    Way back when AOL was on floppies there was software called AOHELL that would generate fake name, address, and fake CC just to sign up for AOL free 40 hours.

    I’m sure credit cards were always a problem. I think the first 4 or 8 numbers of the card are the issuing bank and location. Something like that. So it’s super predictable.

    • nibbler@discuss.tchncs.de
      link
      fedilink
      English
      arrow-up
      1
      ·
      edit-2
      3 hours ago

      I learned from a friend how to dial in with some terminal to create an account like that manually. There were some magic numbers/strings involved, but I can’t remember details. I just remember the com port had to be set to 7n1, not 8n1 like for all other stuff I did