Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Or the connection in between, unless SSL is satisfying that part of our threat model.

From my original comment: "With HTTPS."

> A nice idea, let me know when you get that implemented.

It's part of a service I'm currently previewing privately.

One of the projects I worked on was a sophisticated fraud-detection framework which was deployed to one of the largest banks and acquired by a top security company. Stuff like this is not easy to implement and work never ends but then that's why we get paid.



I could see it working well enough for banks. But banks are an unusual scenario. They (and maybe insurance companies) are the only businesses that have become accustomed to having so much loss due to fraud that they can handle it as aggregate risk and a cost of business.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: