←back to thread

1134 points mtlynch | 2 comments | | HN request time: 0.522s | source
Show context
cordite ◴[] No.22937547[source]
This is kinda common. Events with other anti-fraud providers are similar, it's a black box to the outside world that figures out what's normal and what is risky.
replies(1): >>22939591 #
notRobot ◴[] No.22939591[source]
It being common practice doesn't make it okay.
replies(1): >>22940378 #
1. cordite ◴[] No.22940378[source]
To defend against credit card fraud in an automated world, it’s kinda the only thing we got: an automated risk assessment.
replies(1): >>22940948 #
2. frei ◴[] No.22940948[source]
That's true, but the data collection doesn't have to be this automated. It's a tradeoff for ease-of-use.

Everyone used to use Paypal, right? That doesn't track anything on your site in the default flow, but it requires sending the user to paypal.com, where they will have to enter even more information. But at least it doesn't collect mouse movements on all users on non-payment pages.