Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

AVS and CVV do not do much to detect fraud. Anyone that's bought a stolen credit card has the address and CVV code too. Square isn't keeping any money either -- that money is going back to the account it was stolen from (the owner of the stolen credit card). It left Square's bank account before Square was even notified of the chargeback; that's how the system works. The fact that they don't immediately deduct the funds from the merchant, as a merchant account would, is actually a nicety, as their own books are missing money until that chargeback is resolved.


>Anyone that's bought a stolen credit card has the address and CVV code too

Yeah, but for a shipped physical good, only being able to ship to the original cardholder's address doesn't do you much good. That $1800 package isn't going to you, unless you are physically close enough to steal it off their doorstep which is pretty risky.

So either it's the correct address, which points to the cardholder defrauding, or it's a different address, which should be caught by the processor. Or they shipped to a different address than the billing address, which would be totally the fault of the seller.


I bought a camera and tried to have it shipped to my father's house. It was understandably difficult with them actually looking up my home phone and calling me to verify the information before shipping. They called my Dad too to make sure he was ok with it.

These are/ should be normal precautions when shipping expensive equipment


Different shipping addresses from billing addresses are absolutely standard practice. I don't know why you'd think that a seller would disallow shipping to something other than the billing address.


Back in the days when I worked at Newegg, average order values were in the thousands from all of the custom gaming rig builds so fraud was taken very seriously. Newegg did not allow shipping to an address that was different than the one on file with your credit card company so the only way to do that was for the customer to call the credit card company and add the new shipping address. I'm sure they lost some customers who didn't want to deal with that but they also severely limited their exposure.


It's a high risk practice. For instance, PayPal won't protect you if you do it, unless the person has verified the shipping address also.

If I had a small business with large dollar amount purchases, it certainly doesn't seem worth the risk to allow it. One bad transaction and you are out a lot of money.


The one time my card number was stolen was to purchase computers that were shipped to my house and taken from there.


Was that easy to dispute? I wonder if you were placed on a red-flag list after that, like how UPS treats people who have packages that they show as delivered but that went missing.


My bank noticed before I did, but apparently never told Dell. I haven't had any issues since then. I just got a new credit card in the mail a few days later.

One thing I learned is that I should also contact the vendor next time. I am not sure who lost in my case, but after the information I heard today I think it is Dell.

Dell still thinks I am a good customer. I can't get them to stop sending promotional junk mail since the incident.


Maybe with that merchant. There's no reason for banks or other card issuers to keep a "red flag list" for payment disputes, as payment disputes don't cost them anything. They can even be a revenue generator, as not only do reversed funds come right back out of the seller's account, but also a chargeback fee that covers the cost of someone being on the phone with the card holder for a few minutes.


AVS does at least allow you to manually hold orders billed to a totally different zip than the shipping address. I haven't used Square's web store solution so I'm not sure if they provide this data.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: