Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I consider myself pretty quick to detect scams, having worked in cybersecurity, though probably no quicker than the average HN commenter. And yet 15 years ago I fell for the “sell products that are no longer available” scam.

There was a keyboard I really wanted but it was no longer being made. However, I found an online shop that had them in stock! I ordered, paid, got my confirmation, and waited about two weeks before complaining that it hadn’t shipped.

Ended up with some dude from the usual geography for this stuff, yelling at me and threatening me over the phone. At which point I realized it was all fake, told him where to stick it and hung up. It was only $100 or so and I was lucky they didn’t do anything creative with my credit card.

The point being, there are lots of circumstances that can make you let your guard down. Thinking you’re too smart to be at risk is probably not the safest position to take.



I let my guard down once, because of a third party survey from actually Apple. Then actually Apple allowed the third party to funnel me onto their third party site. And that's where I suddenly found myself subscribed to a $15 fun recurring weekly quiz. I trusted them, because it's Apple, right? Except it wasn't Apple anymore. And, well, it wasn't fun to me so I un-subbed pretty quickly, but the first $15 were already payed. When I looked into it, they'd hidden themselves through layers of proxies so it wasn't possible to find an office address. And there was ofc no help to get from Apple, because they assured that they were only responsible the third party survey, and not what happened when you where funnelled onwards. I still think this is pretty crappy customer service from Apple, and that cooperating with such a scammy company reflects very poorly on them. Oh, and I still want my $15 back! (Don't worry, it's nothing compare to what I lost on FTX...)


I'm guessing Apple would have investigated more had a reporter asked them.


if you're in the US you can reverse the charge, whether debit or credit card, although with a debit card you'll have to be re-issued a new one.

If enough people do chargebacks the payment processor will drop them because the ACH operator representing them will 100% fine the shit out of them if they don't. It's all contractual.

My point is, if you want to put a dent in stuff like this, do a chargeback. Like a union, the power isn't in your action, it's in the action of many.

---

But also, this is why I'm very picky and have quite often refused to purchase something I wanted. I'll trust Walmart.com in a way I won't trust momandpop.com. Unless they're using a payment process that isn't handled by them (CC via paypal, for example) I just flat won't use them.

What's worse is most people don't even consider the risk to calling in an order from a local restaurant for delivery (chinese, for example). They may or may not save your CC information and you have no idea how well those systems are secured. They're probably using a 3rd party, but you don't know who that 3rd party is so you can't even begin to assess that risk.

I'm not a fan of doordash by any means, but they do offer a service here in terms of risk assessment.


> What's worse is most people don't even consider the risk to calling in an order from a local restaurant for delivery (chinese, for example).

if you review your monthly statement, the "risk" is the possible inconvenience of having your card replaced. I don't let it stop me from ordering my favorite takeout, but you do you.


yeah... because ... you know, they'll only charge once in a first month and do nothing else.


I honestly don't understand your threat model here. from the post I originally replied to, it's clear that you already understand that you can easily reverse unauthorized charges to a credit card. if you're already reviewing your monthly statements (which you really should be, as part of sane budgeting), this is basically a non-issue. you tell your cc issuer you suspect someone has stolen your credit card info, they cancel the card, and you can probably even get them to ship you a new one overnight. it's unlikely things even get to this stage though. card not present with no cvv is already the most highly scrutinized type of cc transaction by the processor.

I guess someone could probably treat themselves to their own monthly takeout order without me noticing for a while, but at least to me, this minuscule risk does not seem worth the mitigations you are taking.


I challenge you to quote me saying I don't order takeout.

Furthermore, many people use debit cards backed by an actual bank account and the vast majority of people can't afford to have those drained in any meaningful fashion without experiencing some severe consequences.

And thirdly, when the equifax breach happened I didn't bother doing anything. Why? Because I do NOT have the attitude that it's ok to be defrauded of money since someone else will pay for it. There was nothing for them to go after.


No but you'll get all of their charges reversed and then get a new card.


How did you pay? Did you let it go because "only $100"? Because if you paid by a non-sketchy method (paypal or credit card) the chargeback should be straightforward.


Good point, but at the time I didn’t think of that. I’ve never done a chargeback, which is probably a testament to my banks’ fraud detection.

For $100-ish, and a good couple weeks since I made the payment, getting my money back wasn’t the main thing on my mind. Which, again, is an example of circumstances clouding your judgement. I was mostly just pissed I wouldn’t be getting the keyboard.

I did try a complaint to the BBB since the shop was (probably not really) listed there… from which I learned how useless the BBB is, so I guess in the end I got something for my money after all.


usual geography being india?


It’s not really relevant other than that it’s anywhere beyond the reach of the law right?


It's relevant as a red flag alongside other information that should raise one's level of suspicion.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: