Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I can sympathize with you. But even suspect credit fraud is also "purchase first" "warn later". Refusing to let a new device purchase anything without a thorough check is a ridiculous idea.

But I do agree that as the iTunes store grows, the anti-fraud mechanism should be vastly improved along the way. IIRC Apple just began to send those emails out to remind costumers of suspicious activity due to rampant credit card theft. Clearly Apple hasn't done enough to minimize users effort and loss. I'm skeptical of utilizing usage pattern though, App Store genius recommendation is laughable.



even suspect credit fraud is also "purchase first" "warn later"

Not necessarily. My credit card was refused just two days ago because the purchase seemed unfamiliar to Chase. And it's common (and often annoying) for cards to be blocked when you travel abroad.

I think it'd be fair for a new device from a different location to be blocked. Not a thorough check, but an email would work. But in that domain you can never find a compromise that works with everyone.


I can sympathize with you. But even suspect credit fraud is also "purchase first" "warn later". Refusing to let a new device purchase anything without a thorough check is a ridiculous idea.

They could always do something like what Steam does - the first time you try to buy something with a new device, you must enable it by typing in a code that is emailed to you.

Apple's new-device-detection algorithm doesn't seem to be perfect - I was vacationing and bought an app, and it was flagged as a new device (I got the mail for my purchase), despite it being the same one I've been using for a few years.


> Apple's new-device-detection algorithm doesn't seem to be perfect - I was vacationing and bought an app, and it was flagged as a new device (I got the mail for my purchase), despite it being the same one I've been using for a few years.

I have had this happen with Steam countless times, it's made me hate the Steam Guard system. I have a long complex password for Steam and I don't play online so my account isn't high risk at all.

However I use a number of different browsers on different machines and reset them frequently. As a result, almost every purchase I've made through a browser from Steam since that system was implemented has required me re-authenticating the "new device".

Personally, I'm not a fan. I'm positive it would get an even worse reception from the general public, too. Steam users aren't necessarily savvy but they are typically willing to jump through technical hoops for a particular endgame. I wouldn't say the same for iOS users, by and large.

This is a tricky one. Increasing security without adding complexity or alienating users that have grown used to the current system is very difficult. I'm not ready to jump all over Apple for this, it's not a problem with an obvious & popular solution that they are just choosing to ignore, this is something every company in the world is struggling with right now and they all have a different way of combatting it, each with their own unique pros and cons.


FWIW, you can disable Steam Guard for your account in the preferences.


Thanks. I can't believe I didn't notice that.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: