7 ms·
I work in fraud prevention with vendors such as this. Let me be the devil's advocate here: trust and risk scores such as these are often very useful for identif
by velavar 3y ago
I work in fraud prevention with vendors such as this. Let me be the devil's advocate here: trust and risk scores such as these are often very useful for identifying account takeovers and stolen identities in the financial and telecom worlds. We often see folks on HN complaining about how banks don't protect them from fraud losses - companies like this are how there is any hope left for some modicum of consumer protection.
You may ask: Then why do banks not protect me from losses better?
I say: They're already doing something (invisible as it may be). They can definitely do a better job. But without companies such as Telesign, fraud losses would far, far worse.
You may ask: What if my data gathered is used for nefarious purposes?
I say: In my experience, data such as this is not allowed to be used for marketing purposes but strictly for consumer protection. I'm not specifically speaking about TeleSign but similar vendors. The worst that should happen is that you get a transaction declined, or get denied for a credit card etc. But no marketing or any other manipulative practice is allowed, in theory.
Happy to answer any questions you may have :)
- sharikous 3y ago>> worst that should happen is that you get a transaction declined, or get denied for a credit card Which, in a cashless society, can mean you have no money since you can't spend it
- Andrex 3y agoHow confident are we Telesign will never ever be the victim of a data breach?
- zie 3y agoSince the NSA has shown they can't do it, I'd venture to guess the likelihood of Telesign or any other company being breached is approaching a 100% chance.
- velavar 3y agoAhh that's a great question - it's a very real risk. In my mind, most of the data these companies have is sourced from other companies so all that these vendors do is increase the surface area for the attack vectors. And the (probably naive) hope is that the attackers can't do much with data such as trust scores and the underlying factors.
- tpxl 3y ago> They're already doing something (invisible as it may be). They can definitely do a better job. But without companies such as Telesign, fraud losses would far, far worse. Until banks accept that they got defrauded, not you, whatever they do will be too little.
- velavar 3y ago> Until banks accept that they got defrauded, not you, whatever they do will be too little. True. Regardless of accepting responsibility, I think they're spending a good bit of money in preventing fraud from happening [1]. Maybe some regulation around banks taking fraud losses would do the trick but the flipside would be that simple financial flows of legitimate customers would become full of friction as banks race to lock down fraud losses. Fraud detection is a really hard fraud problem for even a human, let alone models. [1] https://bankingjournal.aba.com/2022/01/study-banks-see-rise-in-fraud-attempts-associated-costs-in-2021/ https://bankingjournal.aba.com/2022/01/study-banks-see-rise-...
- slt2021 3y agoNo-one is actually breaking into a bank and stealing $$ from your account. Virtually most of the fraud is happening due to customer's own fault, not strictly bank's fault: 1. installed malware and got all saved CC data stolen 2. website you ordered your widgets got hacked and your CC stolen 3. clicked phish linked and lost your online bank credentials 4. got scammed and sent zelle to a scammer 5. used shady website to order deeply discounted electronics / signed up for adult membership website - and gave your CC data right into hands of fraudsters 6. used shady third party ATM in tourist place like Cancun and got your card skimmed etc 7. used same user/pass credentials for online banking, as your email account, and your online bank got taken over
- velavar 3y agoSo true and something I see everyday on my job! it's no wonder then that financial companies have to resort to using data from companies like Telesign to view these red flags and attempt to detect fraud.
- jopsen 3y agoWhy not start by supporting webauthn (Yubikeys)? How come all online VISA transactions don't have to completed through a redirect to visa.com or master.com (or may bank website), but instead we're typing card numbers into sketchy websites? (I guess EU 2FA requirements are pushing the boundary, but very slowly and often in ways that still appear remarkably sketchy). Trust scores of IPs and phones numbers is a tool, but when physically hardened security tokens aren't widely supported, I'd argue the essential tools simply aren't available to users.
- kmoser 3y agoIt would be trivial for sketchy websites to have fake (but real looking) "official" Visa/MC forms, or even for multiple fake "official" sites to be set up. So redirecting everyone to the One True Payment System is no solution to fraudulent websites.
- lokar 3y agoWebauthN solves that problem
- graftak 3y agoIt is when a bank phone app is being used as a second factor (or, when on your phone, it redirects to it). This has been used in the Netherlands for almost 2 decades[1] for online payments (iDeal) and card fraud is basically a non-issue. [1] Before smartphones a hardware token that requires your physical card was used.
- velavar 3y agoWhat kmoser said :) I support your argument about Yubikeys - I myself use them for any financial site that allows it. A lot of companies do use them to check for fraudulent logins. But the friction of it is high enough that companies would much rather take the loss than force their customers to authenticate every time a transaction has to be made. Also, I think until it is normalized in the industry, there is a consumer perception of physical keys being too technically difficult to obtain, set up and manage. Not to mention, all the Yubikeys in the world still don't help if one goes and gets phished/socially engineered :)
- bragr 3y ago>Let me be the devil's advocate here: The question here isn't (primarily at least) whether this is a good or bad thing, the important question is if this arrangement is legal under EU law. It can be the most beneficial thing in the world and still be illegal.
- velavar 3y agoThat's very true. I think my comment was more in response to other comments talking about "surveillance" and "trust", but you're right that if the data collection itself is illegal, there are no two sides about it :)
- kmoser 3y agoWhat I want to know is how "the regularity of completed calls, call duration, long-term inactivity, range activity, or successful incoming traffic" translates to a trust score. Do less trustworthy people tend to make longer or shorter phone calls than more trustworthy people? And what even is range activity, not to mention how does it relate to trustworthiness?
- velavar 3y agoI haven't worked with Telesign data but I can attempt a guess. Think of how a fraudster uses a phone versus how a legitimate customer uses a phone: 1. The former is likely using a throwaway phone number, the latter is using an established phone number. You can tell the difference with the number of completed calls over time, call duration etc. Burner phones will have bursts of high intensity activity to several different phone numbers whereas legitimate phones will have lots of successfully completed phone calls over a long period of time to repeating phone numbers. 2. The former will likely place calls all over the country or world as they attempt to raid several bank accounts digitally. The latter will probably have more local calls since they're calling their doctors, schools, etc. This is probably where range activity plays a role. I'm not defending Telesign or how they collect data - I'm merely saying this data has value in account protection.