惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

F
Full Disclosure
Recorded Future
Recorded Future
T
Tenable Blog
S
Securelist
C
CERT Recently Published Vulnerability Notes
T
Threatpost
S
Schneier on Security
A
Arctic Wolf
The Hacker News
The Hacker News
C
CXSECURITY Database RSS Feed - CXSecurity.com
Know Your Adversary
Know Your Adversary
P
Privacy International News Feed
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
The Register - Security
The Register - Security
Cisco Talos Blog
Cisco Talos Blog
AWS News Blog
AWS News Blog
K
Kaspersky official blog
T
True Tiger Recordings
T
Threat Research - Cisco Blogs
V
Vulnerabilities – Threatpost
P
Palo Alto Networks Blog
T
The Exploit Database - CXSecurity.com
小众软件
小众软件
B
Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Microsoft Azure Blog
Microsoft Azure Blog
Cyberwarzone
Cyberwarzone
C
Cybersecurity and Infrastructure Security Agency CISA
T
Tor Project blog
Spread Privacy
Spread Privacy
Malwarebytes
Malwarebytes
P
Proofpoint News Feed
F
Fox-IT International blog
F
Fortinet All Blogs
P
Privacy & Cybersecurity Law Blog
G
GRAHAM CLULEY
量子位
Latest news
Latest news
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - 叶小钗
Project Zero
Project Zero
T
Tailwind CSS Blog
N
Netflix TechBlog - Medium
Martin Fowler
Martin Fowler
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
I
Intezer
博客园_首页
腾讯CDC
H
Hackread – Cybersecurity News, Data Breaches, AI and More
D
Darknet – Hacking Tools, Hacker News & Cyber Security

Hacker News: Front Page

Erin Brockovich made a map to track data centers around the country agent memory: an anatomy How Wikipedia Whitewashes Mao Your AI Tools Are Only as Good as Your Judgment — And That's the Point Overview · Cloudflare Flagship docs Xiaomi MiMo API 开放平台 Token Plan 全球上线 Colorado and California Exempt Open Source from Age Attestation From Rust to Ruby Why is the Left No Fun? Big Tech's Anti-Labor Playbook Has Come for Wikipedia More ETFs Than Stocks The worst job interview I ever had DeepSWE Chemistry behind the Garden Grove chemical tank Uber burned through its entire 2026 AI budget in four months. Now its COO is questioning whether it's worth it | Fortune AltTab is introducing a Pro version — and staying open source · lwouis/alt-tab-macos · Discussion #5533 Stop advertising in your commits! | AksDev Xiaomi MiMo Api Open Platform - Token Plan Global Launch Stack Overflow's forum is dead thanks to AI Stack Overflow’s forum is dead thanks to AI, but the company’s still kicking... thanks to AI Founding Software Engineer at Sage Care | Y Combinator The Real Cost of Owning a Home — Eric Turner Is “colorectal cancer” rising in “young people”? What Color is Your Function? – journal.stuffwithstuff.com Uber, Lyft drivers in Massachusetts form first US ride-share union The ballad of TIGIT 'Incredible' milestone reached as Sweden becomes a smoke-free country Minicor | Scalable Desktop Automations Don't Subscribe So Casually Stockholm poised to become leading European geospatial intel player C64 BASIC: Game Map Overhead “Camera View” Dropbox CEO Drew Houston to step down after 19 years at helm of cloud storage pioneer AWS Fired the One Employee Who Gave a Damn Spain blocks prediction markets Polymarket, Kalshi over lack of gambling licence Outsourcing plus LocalAI will soon become more economical vs. Frontier labs EAGLE 3.1: Advancing Speculative Decoding Through Collaboration Between the EAGLE Team, vLLM, and TorchSpec Netherlands blocks US takeover of vital digital supplier GitHub Status Ferrari shares fall after launch of first EV as Jony Ive design proves divisive Incident with Actions and Pages Modern Blu-ray drives can now rip GameCube, Wii, and Xbox 360 games to PC — third-party OmniDrive firmware unlocks game rips from physical media on select players China vs Taiwan: The Geography of an Unfinished War – The Jerusalem Strategic Tribune Daily links from Cory Doctorow I bypassed AWS API Gateway auth with a trailing slash. Got $12K bounty. Uber president says AI spending is getting ‘harder to justify’ Exposing Critical Vulnerabilities in CBSE’s On-Screen Marking Portal: From Authentication Bypass to Full Account Takeover — ni5arga A portentous reunion A reality check on the AI jobs hysteria DynIP — Dynamic DNS that actually works Ask HN: Is anyone working at least 4 hours daily on an Apple Vision Pro? GitHub - andreoliwa/logseq-doctor: Heal your Markdown files: convert to outline, list tasks and more tools to come Ask HN: Pregunta para los devs hispanohablantes Language Models Need Sleep Motorola phones have started hijacking the Amazon app to insert affiliate codes [Video] Earthion: A New Mega Drive-Style Shoot-Em-Up Why The Smart Home Bubble Popped GitHub - redraw/rapel: chunked resumable downloads in unstable networks JSX.lol Sonny Rollins, Jazz’s Saxophone Colossus and Greatest Improvisor, Dead at 95 Encrypt Files in Your Browser — Secvant Vault | AES-256 Designing for and Against the Manufactured Normalcy Field TP–7 Notes on Pope Leo XIV’s encyclical on AI About the security content of macOS Tahoe 26.5 - Apple Support Nobody Cracks Open a Programming Book Anymore · unix.foo Chatbot Has a Long Memory. That Isn't Always a Good Thing I Made 6 Frontier AIs Take the MBTI 600 Times. They All Came Back INTJ. Market Outlook: Canada losing top talent as workers head to the U.S. How Shamir's Secret Sharing Works Overview — Agentic Patterns — Veso Research Taking a walk may lead to more creativity than sitting, study finds (2014) I'm done. I'm f***ing done [video] Show HN: OpenBrief – Local-first video downloader/summarizer Microsoft Copilot Cowork Exfiltrates Files It’s finally here: meet the Ferrari Luce, Maranello’s first ever fully electric car GitHub - ghetea-patrick/riscrithm: Riscrithm is a lightweight, low-boilerplate macro-assembly dialect that compiles straight down to pure, human-readable RISC-V assembly. It bridges the gap between the expressive syntax of high-level languages and the raw, deterministic hardware execution of bare-metal computing. Jony Ive's Ferrari A few interesting modern pixel fonts – Unsung Yoti age checks share facial photos and device fingerprints with third parties Ninth Circuit Panel Goes Out of Its Way to Question Section 230–Doe v. Meta Tidy PSU – PD-64 C64 PSU Brings USB PD to Commodore 64 Norway's 2 petabytes of Huawei flash storage and LLM training Anthropic co-founder Chris Olah's remarks on Pope Leo XIV's encyclical "Magnifica humanitas" GitHub - yugr/rust-slides The bootstrapper's EU stack for under €10 per month Weave (YC W25) is hiring ML, AI, product, & design engineers Exit IP VPN servers mitigation rollout The Revenge of The Measurers The User Is Visibly Frustrated Senior AI/ML Lead at RentFlow | Y Combinator Ubers COO says its getting harder to justify the money spent on AI tokenmaxxing Founder of 7/11 Japan, Toshifumi Suzuki, has died at age 93 Using AI to write better code more slowly Chert | iMessage Infrastructure for Reaching People at Scale California moves to exempt Linux from its upcoming age-verification law after backlash over forcing operating systems to collect users’ ages — amendment proposed by the same lawmaker who wrote the original law Hive (YC S14) is hiring sr back-end developers (CA/US remote OK) The Cost of Safetyism On C extensions, portability, and alternative compilers Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks 2026 HIPAA Security Rule Update: New Requirements Every Healthcare Organization Must Prepare For
Stripe is friendly to “friendly fraud”
2026-05-27 · via Hacker News: Front Page

Friendly fraud is the laundered name for something that the payment system is not really able to prevent. Even though I’m pretty sure they can do way better. Particularly big and sophisticated payment providers like Stripe, with a mountain of signals.

I had a customer buy my product twice. It’s called Ciglue. It’s cigar glue. Not Rolex or iPhone. The first order was shipped with DHL and delivered, with proof of delivery. The customer didn’t contact to request a refund or a re-delivery, but I saw a dispute filed, so I reached out to them.

They said it was the bank’s mistake because the bank bundled this payment with some real fraudulent transactions from the Philippines. They promised to contact their bank and even offered to pay me back via Paypal. I was happy that it’s just a misunderstanding. I submitted the evidence of the delivery, customer communication, website policies, everything by the book.

It turned out the customer was doing it on purpose, and lying to me. They not only didn’t contact the bank to correct the situation, they actually pretended not to have received the product. And the bank, naturally, sided with them. I had no recourse. Dispute granted. Money, product, shipping and dispute fees, all gone. This is annoying, but not exactly unheard of. If you sell online, you probably know the feeling: you send the product, collect the evidence, submit everything properly, and then somehow still lose.

Before the dispute came in, the same customer placed another order, this time with untracked shipping, and a few days after the first dispute, another dispute followed. Once the first dispute was granted, things became clear. The customer emailed me to gloat about their clever scheme. Literally giving me the finger.

I sent the screenshots to Stripe and asked if this could be reported properly. To the bank, to some fraud reporting network, or even just internally inside Stripe.

I wasn’t expecting Stripe to recover the money or reverse a closed dispute. I understand that the customer’s bank makes the final decision, and that card network rules are what they are. But I did expect the report itself to matter. This is a very clear case of “friendly fraud”. The card belonged to the customer, the address was valid etc. The customer appeared to enjoy screwing me over. Pretty sad considering this is a pretty cheap product in a niche hobby. But still.

I would have expected Stripe to use this evidence in some way to feed into the sophisticated machine-learning anti-fraud system. But No.

After quite a bit of back and forth, Stripe’s answer seems to be that it doesn’t really matter beyond my own account.

They told me they don’t use evidence of chargeback abuse from one merchant to create cross-merchant fraud signals, or to take action against the customer’s card, email, or other details for other merchants.

You probably don’t want a system where one annoyed merchant can get someone blocked across the whole Stripe payment system. But there’s a pretty big gap between “automatically block this person everywhere” and “thanks for the screenshots, please consider Radar”, and this is where it gets frustrating.

Stripe sells Radar on the strength of its network: lots of payments, lots of signals, better fraud detection, machine learning, etc. Stripe sees a lot of transactions, so in theory it can spot things that an individual merchant can’t. But when a merchant sends actual evidence that a customer is abusing chargebacks, suddenly it means nothing. The recommended solution is to use Radar rules to block the customer from buying from me again. And I probably have to upgrade and pay Stripe to use this rule anyway. Gee thanks!

The next merchant still starts from zero. This is also not the kind of fraud Radar can easily solve before the payment. The transaction looked fine, checks passed, physical address matched. The abuse happened later, through the dispute process. There is no clever checkout rule for “customer receives the product and later lies to their bank”.

Small merchants already have very little leverage in disputes: the bank decides, Stripe points at the bank, and I lose the money, the product, the dispute fee, and the time spent dealing with it all. If new evidence appears later, it may be too late to submit. If the customer does the same thing elsewhere, and something tells me this isn’t this person’s first rodeo, then the next merchant gets to get suckered.

Nothing friendly about this. Besides perhaps Stripe effectively being friendly with the fraudsters here by not doing anything about it.