Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Why isn't there a centralized black list of addresses that are known to have received fraudulent orders? Just like with IP addresses that are known to have spammed.


There are but think more deeply about it. If someone uses a vacant house as a drop and then someone moves in, should the new owners / tenants be penalized? What about mailbox services with a shared address? I personally use a UPS Store for all my mail. If it was blacklisted I wouldn't be able to order anything online.


Of course it would be just as problematic as blacklisting IPs, if not worse. But at least it is something.

First of all, you don't block the order if billing and shipping addresses are the same, even if blacklisted. Another important thing would be, an address is blacklisted only in the case of a proven fraud, not just suspected. Next, apartment/house sharing would be problematic for the tenants, well then co-habitants or the landlord will have a good reason to throw the fraudster out.


>well then co-habitants or the landlord will have a good reason to throw the fraudster out.

But how would the landlord or co-inhabitants know? And even if it were proven, it would still not be a straightforward task to deal with such people.

The aggressive self-righteousness described in the article is very typical of criminal types. This makes them very convincing at playing the victim when they are challenged. They can very easily turn the tables on you, even to the point where you are the one facing sanctions, and even paying compensation.


There are many.

However, they're usually curated and distributed for enterprise customers, which means you may be paying a huge subscription fee (6 figures yearly wouldn't be uncommon) for access to that list.

Fraud is such a big problem that companies can easily charge a massive premium for anti-fraud services and software.


It's been a while since I've done an integration with fraud prevention systems, but the credit bureaus do offer functionality like this - for instance, they can give you a red flag back if an address has been used by a number of different identities within a certain time period. This is important because often times a scam artist will have a drop that's been working well for them and they will use it for multiple scams simultaneously.


There are a bunch of services out there which try to help you estimate risk, e.g. http://www.volusion.com/ecommerce-credit-card-fraud-protecti...

They're not perfect though, so you get some false-positives and they'll let through some e.g. Spammers sign up for web hosting in my experience.


You can use Blockscore (YC S14) for this. When you verify a user's identity, the result tells whether the address has a history of high risk activity


Dynamic IPs, proxies, (purposely or accidental) open APs, stolen phones, etc.


He's referring to physical addresses, not "IP" addresses.


So what? Dynamic mailing addresses?




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: