Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

So what you’re suggesting is Uber has an actionable fraud threshold and if an intelligent actor wanted to float beneath that with fake accounts and identities they could extract even more?


Yes. Same for all the big tech companies. I guarantee you people are already doing this in every way you can imagine and many you can't. Source: Worked on bad actor detection at FB.


Reminds me of the guy who scammed Google and Facebook of $123 million via fake invoices.

https://www.cnbc.com/amp/2019/03/28/how-to-avoid-invoice-the...


That article doesn’t make any sense. At big companies like this you can’t just send money to someone who even convincingly looks like a vendor or partner. You need to have a PO created with the vendor as the recipient, and there are entire purchasing departments who vet recipients and make sure things like the legal name of the entity matches the wire instructions and so on.

I’d imagine that medium sized companies without much process might be vulnerable to this, but FAANGs?? No way.

If KNOWN_PARTNER simply emails an invoice and wire instructions to an employee of one of these larger companies, there is no way in hell that’s getting paid without multiple people in the paying company simultaneously screwing up.


Yes. Enforcement action requires cash and man-hours, so its logical that you only go after fraud past a certain threshold.


Uber is so big that they cannot attend to every possible discrepancy .


You mean they are too small compared to their customer base to attend to every discrepancy?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: