Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I am blaming Apple for:

* the fact they "allow the purchase first" and "warn later." * their warning email has no fraud or dispute mechanism * I've never purchased a game like this so they my usage pattern should be a red flag

Apple should have fraud systems as powerful and convenient as VISAs.



I have a problem with most these arguments. You're suggesting that they should not have allowed the purchase. I would be highly annoyed if Apple didn't allow me to purchase from a different device. I see no reason for Apple to outright refuse this.

The same goes for purchasing something like you've never purchased before. Hell, one of the commercial strengths of the App Store/iTunes concept is that it gets people to do exactly that. There's nothing particularly suspicious about that.

We don't implement such paranoid measures either in other web-services or in real live, so I find it rather overblown to demand Apple does this.

The one thing I agree with is that there should be a better fraud reporting mechanism.


What's utterly silly about not having a "purchase first, warn later" system in Apple's case is that that of unlike credit cards, Apple can literally undo the purchase. Apple has done a great job of making the App Store's FairPlay DRM invisible to users, but in the case of a fraudulent purchase, I would imagine it trivial to make that DRM quite plainly visible to the fraudulent purchaser.


We don't implement such paranoid measures either in other web-services

Yes "we" do. Steam doesn't let you authenticate, let alone buy stuff, from a new computer without entering a code that they'll email to you. Takes all of ten seconds--start up Steam, go to my email client, paste the code in, done.

And it works great. So what's the complaint?


Steam is the only service that I've tried to use that won't accept any of my credit card... I'm not in a common situation living in China with a French credit card registered with my chinese address but still, I only could pay two times successfully (after a lot of tries) and now I can't anymore (and one would think that it should have become easier since they didn't get any chargebacks when I did buy)

So, in a world where customers can easily chargeback fraudulent charges, I think having security measures that are too paranoid is a great way to lose customers for no real advantages to the customer security.


Oh man, I've tried numerous time to buy something using Steam and was never able. If you have a card issued in a country and you are traveling abroad, good luck making a purchase. Even if you change the billing address registered with the credit card to the same country you're traveling to and making a purchase from, it won't go through.

I would not give Steam as an example of a successful payment system implementation.


I don't seen the downside to verifying your account on a new device before being able to use it. If you have access to the appstore then you have access to Gmail and one simple email to say "Yeah, go ahead and let my friend's iPad buy this app on my account for 24 hours/7days/forever" is all it takes to prevent this sort of thing.

> We don't implement such paranoid measures either in other web-services or in real live, so I find it rather overblown to demand Apple does this.

Google Two-Factor Authentication, Facebook emails you when someone logs on using an unknown computer, Steam does the same, and I'm sure there are more examples.

It's only paranoia until something happens.


As I mentioned in another comment, you don't have to go as far as verifying before usage (although in some cases you should), but at the very least alert the user of any new device, just like Facebook does.


I can sympathize with you. But even suspect credit fraud is also "purchase first" "warn later". Refusing to let a new device purchase anything without a thorough check is a ridiculous idea.

But I do agree that as the iTunes store grows, the anti-fraud mechanism should be vastly improved along the way. IIRC Apple just began to send those emails out to remind costumers of suspicious activity due to rampant credit card theft. Clearly Apple hasn't done enough to minimize users effort and loss. I'm skeptical of utilizing usage pattern though, App Store genius recommendation is laughable.


even suspect credit fraud is also "purchase first" "warn later"

Not necessarily. My credit card was refused just two days ago because the purchase seemed unfamiliar to Chase. And it's common (and often annoying) for cards to be blocked when you travel abroad.

I think it'd be fair for a new device from a different location to be blocked. Not a thorough check, but an email would work. But in that domain you can never find a compromise that works with everyone.


I can sympathize with you. But even suspect credit fraud is also "purchase first" "warn later". Refusing to let a new device purchase anything without a thorough check is a ridiculous idea.

They could always do something like what Steam does - the first time you try to buy something with a new device, you must enable it by typing in a code that is emailed to you.

Apple's new-device-detection algorithm doesn't seem to be perfect - I was vacationing and bought an app, and it was flagged as a new device (I got the mail for my purchase), despite it being the same one I've been using for a few years.


> Apple's new-device-detection algorithm doesn't seem to be perfect - I was vacationing and bought an app, and it was flagged as a new device (I got the mail for my purchase), despite it being the same one I've been using for a few years.

I have had this happen with Steam countless times, it's made me hate the Steam Guard system. I have a long complex password for Steam and I don't play online so my account isn't high risk at all.

However I use a number of different browsers on different machines and reset them frequently. As a result, almost every purchase I've made through a browser from Steam since that system was implemented has required me re-authenticating the "new device".

Personally, I'm not a fan. I'm positive it would get an even worse reception from the general public, too. Steam users aren't necessarily savvy but they are typically willing to jump through technical hoops for a particular endgame. I wouldn't say the same for iOS users, by and large.

This is a tricky one. Increasing security without adding complexity or alienating users that have grown used to the current system is very difficult. I'm not ready to jump all over Apple for this, it's not a problem with an obvious & popular solution that they are just choosing to ignore, this is something every company in the world is struggling with right now and they all have a different way of combatting it, each with their own unique pros and cons.


FWIW, you can disable Steam Guard for your account in the preferences.


Thanks. I can't believe I didn't notice that.


Fraudulent charges happen all the time on credit cards. The only difference here is that you can call up your CC company and get the charges refunded immediately.


Put differently, purchase first, warn later IS the way VISA and credit cards in general work. Step 2 after warning is telling the card company those aren't your purchases, and then they void them out.


> I am blaming Apple for the fact they allow the purchase first and warn later.

Really? So you'd like to be actively prevented from purchasing your first app on any new device you purchase in the future?


Of course. A simple email with a confirm link would solve this.


Email to what, your @me.com email that the attacker may very well have access to?


Preferably my Google Apps account, for which I have two factor auth enabled. Or perhaps my SmartCard enabled work email. Or even my SMS 2-factor Facebook email.


It's a numbers game; it would help people without an @me.com account or with a secondary email address.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: