upvote
Your rate limits on adding and removing credit cards? Your input sanitization? Designing your system to not just disclose details around anything but that relevant to a logged in/authenticated user?

There are many practical ways to handle that sort of thing that isn't Cloudflare. It just requires thinking and a bit of dev time.

t. Been there, done that, cartels used an app to try to launder money through loyalty programs. Management was deadset against doing the one single thing that would make it impossible to do that at scale.

Ulterior motives abound everywhere but especially behind people claiming X is the only answer. Fingerprinting is far more intrusive than just only allowing one to add at max 2 cards a day per user.

reply
The people who downvote could propose how to solve the fraudster problem instead of shooting the messenger.
reply