frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Can anti-fraud make large-scale attacks unprofitable?

2•jezzwar•1h ago
I’m interested in feedback from people who have experience with fraud prevention, security, ad-tech, or abuse systems.

Let’s assume a platform where users receive some form of benefit based on verified real activity. A major concern is whether organized fraud operations can scale profitably.

A common assumption is that attackers will always find a way around individual defenses. So instead of trying to make abuse impossible, the approach is to increase the cost of abuse:

device reputation and fingerprinting; IP/network reputation; VPN/proxy/datacenter detection; behavioral analysis; account reputation over time; graph analysis to detect connected accounts; risk-based limits and delayed payouts; manual review and feedback loops.

The idea is that a fraudster might be able to create accounts, but maintaining profitable accounts at scale becomes difficult.

The question:

Does this actually change the economics of fraud, or will sophisticated operators always find a way to stay profitable?

For example, attackers can theoretically use virtual machines, proxies, automation, and other infrastructure. But they also have ongoing costs:

infrastructure; acquiring and maintaining identities/accounts; operational overhead; adapting to detection systems; losing accounts and reputation.

At what point does the cost of running the operation exceed the expected return?

I’m especially interested in perspectives from people who have worked on the offensive or defensive side of fraud. What weaknesses would you expect in this approach? Which signals are actually valuable, and which are mostly security theater?

Looking for criticism, not validation.

Comments

DamonHD•54m ago
It's always about costs - cost to run the service, cost to abuse the service.

I was founder/CTO of a UK small e-money issuer, and while I am no fan of Musk, at PayPal he made a good observation that while the money handling bit is not so hard, the anti-fraud part is.

I also created/ran an early UK ISP, helped moderate a busy (US) forum, etc, etc, and I observe that while you generally cannot eliminate bad behaviour, you can make it costly enough that you stop being the easy target and attention goes elsewhere...

And you should have a range of broad signals to evaluate with.

Hugging Face is being used to easily undress women and children

https://www.theverge.com/ai-artificial-intelligence/971723/hugging-face-nudify-deepfake-undress-w...
1•sbulaev•38s ago•0 comments

Show HN: How many people live within an hour walk of you?

https://blockatlas.com/tools/radius/walk
2•NameError•2m ago•0 comments

Show HN: Vivari – Open-Source WebContainer for Node, Bun, and Python

https://vivari.jamesisme.com
2•maitrungduc•3m ago•0 comments

Colour Drained from Our Furniture

https://europeancorrespondent.com/en/r/how-colour-drained-from-our-furniture
2•donohoe•4m ago•0 comments

Animating the Odyssey unabridged, from Palmer's 1891 prose translation

https://www.youtube.com/playlist?list=PLZo1QBAphXPM
2•lschneider•4m ago•0 comments

I'm a doctor. Here's why I wear sunblock indoors

https://www.washingtonpost.com/wellness/2026/07/27/doctor-heres-why-i-wear-sunblock-indoors/
2•bookofjoe•4m ago•1 comments

Fast Remediation Is the New Trust Model (JFrog and OpenAI Zero-Day Findings)

https://jfrog.com/blog/jfrog-and-openai-collaboration-on-zero-day-security-findings/
2•882542F3884314B•4m ago•0 comments

The Ten Commandments for C Programmers from Henry Spencer (Unix/Plan 9 – 1987)

https://doc.cat-v.org/henry_spencer/ten-commandments
2•pjmlp•6m ago•0 comments

Homework for SMTM-6941: Lithium Problem Sets

https://slimemoldtimemold.com/2026/07/21/homework-for-smtm-6941-lithium-problem-sets/
2•surprisetalk•7m ago•0 comments

My Secret AI Bookmark That Hypercharged My Comms

https://grokimage.ai/
1•RustyArmor•7m ago•0 comments

What a Reddit Buying Question Looks Like: I Read All 148 Highest-Intent Threads

https://cuescout.com/blog/what-a-reddit-buying-question-actually-looks-like
1•weeklyrunner•8m ago•0 comments

The AI risk is inside the labs

https://www.antirez.com/news/172
1•craigmart•9m ago•0 comments

An autonomous agent that researches, writes and publishes a news site

https://distillation.technology/alembic.html
1•bgalvan•9m ago•0 comments

How Nvidia Builds Open Models for the Age of AI

https://blog.bytebytego.com/p/how-nvidia-builds-open-models-for
1•svobodamartin•10m ago•0 comments

Kernel accepts wrong-structure projections, allowing axiom-free proof of False

https://github.com/leanprover/lean4/issues/14576
1•gopiandcode•10m ago•0 comments

Identifying the Actors: What a Byline Certifies

https://bytecode.news/posts/2026/07/identifying-the-actors-what-a-byline-actually-certifies
7•jottinger•11m ago•0 comments

TikZ

https://en.wikipedia.org/wiki/PGF/TikZ
2•tosh•12m ago•0 comments

Excel Never Dies (2021)

https://www.notboring.co/p/excel-never-dies
1•downbad_•12m ago•0 comments

The Robocall Geography Tax: Why Your Zip Code Determines Your Spam Reality (2025)

https://www.karmacall.com/blog/southeast-spam-call-geography-tax/
2•dredmorbius•13m ago•0 comments

A computer can never be held accountable

https://jola.dev/posts/a-computer-can-never-be-held-accountable
2•shintoist•13m ago•0 comments

Chinese CXMT DRAM doesn't look like the budget savior many were expecting

https://www.tomshardware.com/pc-components/dram/chinese-cxmt-dram-doesnt-look-like-the-budget-sav...
2•elorant•18m ago•0 comments

Apple Apps Are Rubbish

https://www.gordonmclean.co.uk/2026/07/28/apple-apps-are-rubbish/
2•ExMachina73•20m ago•0 comments

Yamaha DX1

https://en.wikipedia.org/wiki/Yamaha_DX1
1•tosh•21m ago•0 comments

What Is Flash Attention?

https://modal.com/blog/flash-attention-article
1•ronfriedhaber•22m ago•0 comments

The Rise of Software Factories

https://newsletter.alexlazar.dev/p/the-rise-of-software-factories
1•sirnicolaz•23m ago•0 comments

Show HN: The mentor setup I've run for months, now as a Claude Code plugin

https://github.com/hcsum/dont-let-me
1•sumtsui•24m ago•0 comments

Let Your Software Write Its Own Code

https://cymerys.com/w/let-your-software-write-its-own-code
3•rcymerys•26m ago•0 comments

ASRock 4U16X-GNR2 packs 8 B300 GPUs, demands liquid cooling

https://windowsforum.com/windows-news.4/asrock-4u16x-gnr2-packs-8-b300-gpus-demands-liquid-coolin...
2•teleforce•27m ago•0 comments

Show HN: Zenly – Investment research platform built around a quality/value score

https://zenlyfinancial.com/
1•juliiii•28m ago•0 comments

Collabora Online 26.04: Your Documents, Your AI, Your Decade of Data Sovereignty

https://www.collaboraonline.com/blog/cool-26-04-release/
1•maxloh•29m ago•0 comments