Announcement

Collapse
No announcement yet.

WolfPaw Fraud Protection

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    WolfPaw Fraud Protection

    Anyone out there still using Wolfpaw Anti-fraud module? I have been using Wolfpaw since 2010 when I purchased the module directly from Miva. There are some changes that I needed to make on the Wolfpaw Configuration Page, specifically update the server URL due to changes being made by Maxmind. The configuration page is no longer available on my Payment Setting Tab. Instead, Wolfpaw module wants me to enter a license key, and when I do, it indicates that it is in use. When I contacted Miva support, they say that Wolfpaw is no longer supported and that I should reach out to Wolfpaw support. When I reach out to Wolfpaw support, they believe that Miva has taken down their Wolfpaw license server and there is not anything else they can do. Just wondering if any one else has encountered this issue. Thanks in advance for your assistance.

    #2
    The license server they're referring to was a third party's license server on the domain mvcool.com, which was a module store similar to our app store, dating back to the early 2000's twenty years ago. The owner of that site ultimately closed the business, and while he did turn it over to us at that time, the site code was written with dependencies on software that went end of life about fifteen years ago. We patched it together for a few years to try to keep it functional but that ultimately became impossible and it was turned off. This particular module was not updated to make use of our license server, which has been available for more than a decade.

    That module should not be used in an active store at this point, not only due to the above issue, but it has other problems from its date of release, particularly its inability to work with a type of internet address called an IPv6 address. This incompatibility means stores that use the module are prevented from receiving certain optimizations from our side.

    Many payment gateways support an equivalent type of screening, or even the use of Cloudflare (free) to challenge browsers from certain origins can be a replacement, if the module is simply being used to prevent certain geographic purchases.
    David Hubbard
    CIO
    Miva
    [email protected]
    http://www.miva.com

    Comment


      #3
      Is there any way to continue integrating Maxmind fraud scores and evaluations without the Wolfpaw module? Or is there a good alternative? Maxmind's Minfraud is very useful.
      Barry

      Comment


        #4
        Running into the same thing today. The new license number is 40 characters and the current module only allows 25. Still waiting for a response from Wolfpaw to see if I can get it to work.

        Comment


          #5
          When I reached out to WolfPaw about if it was possible to get this to work again:
          "The short answer is no. We help out where we can but the module is not compatible with Miva 10 or the MaxMind changes and once Miva shutdown it's Miva Central licensing server you cannot install or re-install the module.

          In your case you can try to insert the new license key directly into that field in the miva database. You might need to alter the table structure to support a longer key but I don't know if the longer key might crash something else in the module."

          and then, from MIVA


          "It's worth exploring migrating to something else since the wolfpaw module hasn't been updated years and they don't have much support for it. The developer that wrote module hasn't worked for them for a long time, probably over a decade. Some of larger clients use Signifyd. There are others but I can't recall which ones are popular."

          What else are people using? Signifyd?

          Comment


            #6
            What payment processor do you use? Most gateways these days include velocity screening tools (which is what the MaxMind module mostly assisted with). We also support Kount.

            I think the first step though is to see what your gateway supports?
            Thanks,

            Rick Wilson
            CEO
            Miva, Inc.
            [email protected]
            https://www.miva.com

            Comment


              #7
              Originally posted by Rick Wilson View Post
              We also support Kount.
              Kount is ridiculously expensive. Out of reach for smaller retailers.
              We are also driving without seatbelt here.
              We use Square and Paypal and while they have some fraud scanning ability, most of the fraud prevention on my sites is just me and my gut feeling that something is off.
              pat
              http://lockitt.com

              Comment


                #8
                Originally posted by Patd265 View Post
                Kount is ridiculously expensive. Out of reach for smaller retailers.
                We are also driving without seatbelt here.
                We use Square and Paypal and while they have some fraud scanning ability, most of the fraud prevention on my sites is just me and my gut feeling that something is off.
                I've also been a long time wolfpaw user and since disabling it have seen a large climb in fraudulent orders in just the last two months of doing so. Wolfpaw had a nice ability to just block those orders from proxy's etc.

                I'm only using paypal and the big step for me and that was worth every penny was to enable chargeback protection. The catch is on those orders that have your hair standing up is to make sure you manually upload the tracking number to paypal. (Hopefully Miva will fix it so that orders in paypal can automatically get those tracking numbers and I believe it's on their very soon roadmap. We have at least been able to recover 90% of the money from those fraudulent orders.
                Mark Hood
                Vermont Gear

                Comment


                  #9
                  Mark,

                  Just curious. Any idea why you see a large number of fraudulent orders? I ask cause with over 50 web sites we work with, we get very few actual fraudulent orders? Granted, most are using fraud protection in both native miva settings and their authorizing agency. (And a few require both shipping and billing to be the same--that said, those obviously do not ship 'gifts' and a couple do have a white list of customers who can use different addresses (i.e., using a custom customer field) and they are B2B.
                  Bruce Golub
                  Phosphor Media - "Your Success is our Business"

                  Improve Your Customer Service | Get MORE Customers | Edit CSS/Javascript/HTML Easily | Make Your Site Faster | Get Indexed by Google | Free Modules | Follow Us on Facebook
                  phosphormedia.com

                  Comment


                    #10
                    I believe a fair amount comes from the nature of our items. High end camo clothing, snowshoes & $1k coats with fur on them seem to be like candy for fraudsters. We do allow multiple addresses as long as the billing address matches the card. We are using Miva settings coupled with paypal. Wolfpaw was great at blocking people using a proxy address. With every order we received an email letting us know great information similar to this below and I've removed most of it. Basically even orders that did go through added some easy access to helpful information for deciding whether or not somebody really could be ordering 3 of those coats with fur on them for a reason and have it be legit.

                    This order has been DECLINED because it has a 65.82% probability of fraud which is GREATER than your risk threshold of 30%
                    Fraud Analysis Details
                    Maxmind Response:
                    distance=11409
                    countryMatch=No
                    countryCode=CN
                    freeMail=Yes
                    anonymousProxy=No
                    binMatch=NA
                    binCountry=
                    err=
                    proxyScore=0.00
                    ip_region=GD
                    ip_city=Jieyang
                    ip_latitude=I removed this
                    ip_longitude=I removed this
                    binName=
                    ip_isp=China Telecom
                    ip_org=China Telecom
                    Mark Hood
                    Vermont Gear

                    Comment


                      #11
                      Mark
                      I'm not sure if you get a lot of orders from China but have you thought about blocking by geo.ip (country=CN,SG) at the Cloudflare level?

                      My business model is not set up for international commerce so I block traffic by country code of the biggest hackers (CN,IN,RU,SG,ID,NG,BR)

                      http://www.alphabetsigns.com/

                      Comment


                        #12
                        Originally posted by alphabet View Post
                        Mark
                        I'm not sure if you get a lot of orders from China but have you thought about blocking by geo.ip (country=CN,SG) at the Cloudflare level?

                        My business model is not set up for international commerce so I block traffic by country code of the biggest hackers (CN,IN,RU,SG,ID,NG,BR)
                        Not something I had thought about but that could very well help! Thank you for the idea.
                        Mark Hood
                        Vermont Gear

                        Comment

                        Working...
                        X