• Latest
Device Fingerprinting Technology Alone Will Not Secure AJAX Websites

Device Fingerprinting Technology Alone Will Not Secure AJAX Websites

July 10, 2019
Veeam Releases Kasten for Kubernetes v7.5, Elevating its #1 Data Resilience Market Position with Enhanced Security and Modern Virtualization

Veeam Releases Kasten for Kubernetes v7.5, Elevating its #1 Data Resilience Market Position with Enhanced Security and Modern Virtualization

February 28, 2025
Major Milestone for PDX Beam as Crypto-to-Fiat App Is Now Available in Apple App Store and Google Play

Major Milestone for PDX Beam as Crypto-to-Fiat App Is Now Available in Apple App Store and Google Play

February 20, 2025
Sardine AI Raises $70M to Make Fraud and Compliance Teams More Productive

Sardine AI Raises $70M to Make Fraud and Compliance Teams More Productive

February 18, 2025
Swap and Signifyd Partner to Empower Brands With Secure, Seamless Global Commerce

Swap and Signifyd Partner to Empower Brands With Secure, Seamless Global Commerce

February 13, 2025
Worldpay to Acquire Ravelin, a Leading AI-Native Fraud Prevention Platform

Worldpay to Acquire Ravelin, a Leading AI-Native Fraud Prevention Platform

February 12, 2025
Socure Verifies Over 2.7 Billion Identity Requests in 2024, Achieves Market-Leading Performance Amidst Increasing AI and Fraud Threats

Socure Verifies Over 2.7 Billion Identity Requests in 2024, Achieves Market-Leading Performance Amidst Increasing AI and Fraud Threats

February 10, 2025
NVISIONx Unveils Nx+RexAI: Redefining Data Security Posture Management with GenAI-Powered Contextual Classification

NVISIONx Unveils Nx+RexAI: Redefining Data Security Posture Management with GenAI-Powered Contextual Classification

February 5, 2025
AuthenticID Annual Report Reveals Surge in Identity-Based Fraud Across Businesses

AuthenticID Annual Report Reveals Surge in Identity-Based Fraud Across Businesses

February 3, 2025
N-able Furthers Open Ecoverse Vision with Launch of AI-Powered Developer Portal—Accelerating API Integrations for Faster, Seamless IT and Security Services Delivery

N-able Furthers Open Ecoverse Vision with Launch of AI-Powered Developer Portal—Accelerating API Integrations for Faster, Seamless IT and Security Services Delivery

January 30, 2025
Zest AI to Deliver First Seamless AI Application Fraud Detection for MeridianLink Clients

Zest AI to Deliver First Seamless AI Application Fraud Detection for MeridianLink Clients

January 29, 2025
Hiya Launches First AI Call Assistant That Stops Live and Deepfake Scams in Real-Time

Hiya Launches First AI Call Assistant That Stops Live and Deepfake Scams in Real-Time

January 28, 2025
Deep Instinct Expands DSX for Cloud Protection to Amazon FSx NetApp

Deep Instinct Expands DSX for Cloud Protection to Amazon FSx NetApp

January 24, 2025
  • Contribute
  • Contact Us
  • About
  • Join Us
  • Advertise
Saturday, June 21, 2025
Merchant Fraud Journal
ADVERTISEMENT
  • Home
  • Articles
    • Chargebacks
    • Fraud Prevention
    • Influencer Insights
  • Resources
    • Recorded Webinars
    • Podcasts
    • Vendor Directory
    • eCommerce Fraud Reports
    • Training and Certifications
    • Jobs Board
    • Associations and Non-Profits
  • News
No Result
View All Result
  • Home
  • Articles
    • Chargebacks
    • Fraud Prevention
    • Influencer Insights
  • Resources
    • Recorded Webinars
    • Podcasts
    • Vendor Directory
    • eCommerce Fraud Reports
    • Training and Certifications
    • Jobs Board
    • Associations and Non-Profits
  • News
No Result
View All Result
Merchant Fraud Journal
No Result
View All Result

Device Fingerprinting Technology Alone Will Not Secure AJAX Websites

Starting in 1990 with the first web browsers, device fingerprint technology has helped industries and companies around the world fight fraudsters online as well as know their customers better. Nevertheless, despite its importance and constant updates, the application of device fingerprinting technologies remain controversial.

This is a shame, because the technology gives merchants a powerful tool to fight chargebacks and improve risk assessment.

How Secure Is Device Fingerprinting Technology on AJAX?

One example of how device fingerprinting technology can fail to prevent chargebacks is in the race to simplify UI/UX.

Companies eager to win more clients and to be truly “customer-oriented” now prioritize the simplification of their UI/UX. As a result, there is a tendency to create one-page websites and applications that do not require a standard client-server application, and that use AJAX. In fact, the majority of social media companies, payment service providers, and online banks use AJAX in this way today.

In addition, companies often combine Asynchronous JavaScript and XML web browser technologies separate from the web server software itself. This is because these technologies allow companies’ sites to send or receive data from corporate servers without requiring users to refresh the page.

Overall, the intent of these approaches is to streamline the customer journey, shorten the response time, and by extension increase customer lifetime value and satisfaction rates. However, this means companies usually implement device fingerprinting technology into the whole webpage, and not to the exact form/point of the page.

In other words, AJAX websites usually only require device fingerprints on the first user step. This is not an effective way to prevent chargebacks or fraud because it creates vulnerabilities fraudsters can exploit.

How? Fraudsters simply generate the first device fingerprint on an AJAX website using the proper browser, country, IP, ID, email, language, screen resolution, etc., allowing their fraudulent behavior in subsequent steps to fly under the radar. Ultimately, this vulnerability renders most device fingerprint solutions completely useless when it comes to preventing eCommerce fraud on sites using AJAX.

How to Use Device Fingerprinting Properly to Fight Fraud

In addition to these technical flaws, fingerprint security information is not complex enough to provide adequate protection when used on single page websites. In fact, in the vast majority of cases it’s almost impossible to determine if an order is fraudulent based on fingerprint scans alone. By extension, using fingerprints alone as criteria for eCommerce fraud prevention actually leads to high chargeback rates, many false positive declines, and by extension, revenue loss.

Is it possible to achieve a balance between rule-based decision making and an ML approach?🤔

Piece of 🍰. Understanding the strengths and weaknesses of both approaches supports their connection in risk management and fraud prevention.🤞🔗https://t.co/jb4HGNEXZk

— Covery.ai (@CoveryAi) July 8, 2019

To solve this problem, companies should support device fingerprinting with other fraud prevention technologies. For example, the results of AML, KYC checks, rule-based scenarios, and machine learning evaluations should augment fingerprint analysis.

This way, if a fraudster uses an emulated device to create a false device fingerprint result, the supporting technologies can use discrepancies in browsers, device types, screen resolution, geolocation variance, keyboard languages, etc. to detect the fraud and fight chargebacks.

Streamlining a Multi-Layered Fraud Prevention Strategy to Fight Chargebacks

Of course, this approach comes with its own problems. Rules-based systems are often unwieldy, and machine learning algorithms take time to get up and running. However, merchants can choose between different types of machine learning depending on their tolerance for complexity: supervised and unsupervised learning.

Pavel Gnatenko from Covery by @maxpay_ltd makes known the power of supervised and unsupervised #machinelearning in solving fraud and minimising risk https://t.co/gB2wpbeOs1 pic.twitter.com/2PUdLb0dYY

— The Paypers (@ThePaypers) April 17, 2019

In a supervised learning approach, a data scientist first uses historical data to create the machine learning model. Then, an algorithm combines old and new data to create profiles for fraudulent and non-fraudulent orders. Finally, the algorithm runs in a live environment and the data scientist makes adjustments as results require. In other words, a human is always behind the process. This is the most common approach.

In an unsupervised learning approach, algorithms derive patterns from a data set without taking the final result (i.e.: if the data set resulted in a chargeback) into account. This allows for pattern recognition independent of results. It also enables feedback from the data set without knowing the exact impact of the variables. In other words, feedback is not based on a correct prediction. Instead, risk analysis receive an algorithmically generated model they can use to approach data sets that show the same pattern in the future.

Ultimately, the most suitable approach to fight chargebacks on AJAX websites and apps is to use device fingerprinting technology with supervised machine learning. The combination of biometric security and rules-based risk logic will help keep risk managers one step ahead of fraudsters.


 

Contributor: Pavel Gnatenko, Product Owner at Covery, Head of Risk at Maxpay

Covery is a global risk management platform helping online companies solve fraud and minimize risk. We focus on the universality of our product and its adaptation to any type of business, based on the individual characteristics and customer needs using both rule-based and machine learning approaches.

Tags: AJAXDevice Fingerprinting
TweetShareSend
Previous Post

Orvibo IoT Devices Suffer Massive Data Breach

Next Post

ICO Fines British Airways £183.39m for Data Breach

Next Post

ICO Fines British Airways £183.39m for Data Breach

Download our latest report:

Our Latest Reports

2024 Fraud Trends Report

2023 Consumer Payments Survey Report

2023 Fraud Trends Report

2022 Chargeback Consumer Survey Report

Fraud Prevention Tactics that Enable Exceptional Customer Experience

Addressing Payment Fraud and The Customer Experience in 2022

2022 Fraud Trends Report

ATO Fraud In Retail Report

2022 Customer Experience Report

3 Ways a Unified Chargeback Management and Fraud Platform Increases Revenue

Digital Trust And Safety Report: Combating the Evolving Complexities of Payment Fraud

On-Demand Webinars

New Trends in The Payments Ecosystem

Balancing Customer Experience and Fraud Prevention: What’s the Secret?

Stopping Fraud Across the Customer Lifecycle

Addressing Payment Fraud and the Customer Experience in 2022

 

Featured Directory Listings

  • Signifyd
  • TransUnion
  • PayRetailers
  • Spotrisk
  • CB-ALERT
  • Chargeflow
  • Corepay
  • AtData

Get the 2024 Fraud Trends Report

Search Our Site

No Result
View All Result

Our Sponsors

Fraud Industry News

Veeam Releases Kasten for Kubernetes v7.5, Elevating its #1 Data Resilience Market Position with Enhanced Security and Modern Virtualization

Veeam Releases Kasten for Kubernetes v7.5, Elevating its #1 Data Resilience Market Position with Enhanced Security and Modern Virtualization

February 28, 2025
Major Milestone for PDX Beam as Crypto-to-Fiat App Is Now Available in Apple App Store and Google Play

Major Milestone for PDX Beam as Crypto-to-Fiat App Is Now Available in Apple App Store and Google Play

February 20, 2025
Sardine AI Raises $70M to Make Fraud and Compliance Teams More Productive

Sardine AI Raises $70M to Make Fraud and Compliance Teams More Productive

February 18, 2025

Connect With Us

Quick Navigation

  • Home
  • News
  • Join Us
  • About Us
  • Contact Us
  • Advertise
  • Contribute
  • Privacy Policy

The Payments Media Network

Merchant Fraud Journal
Payments Review

Privacy Policy

Our Privacy Policy
Our Terms of Use

Resources

  • Articles
  • eCommerce Fraud Reports
  • eCommerce Fraud Webinars
  • Training and Certifications
  • Jobs Board
  • Associations and Non-Profits
  • Podcasts
  • Vendor Directory

Popular Posts

  • What Is a Chargeback: A Primer for Merchants

    What Is a Chargeback: A Primer for Merchants

    0 shares
    Share 0 Tweet 0
  • Understanding “Close Case – No Issuer Response” and Its Importance

    0 shares
    Share 0 Tweet 0
  • Twitch Chargebacks for Streamers: Prevention and Recovery Opportunities

    0 shares
    Share 0 Tweet 0
  • Top eCommerce Fraud Prevention Companies

    0 shares
    Share 0 Tweet 0

Featured Vendors

  • Signifyd
  • TransUnion
  • PayRetailers
  • Spotrisk
  • CB-ALERT
  • Chargeflow
  • Corepay
  • AtData

Download the 2023 Fraud Trends Report

No Result
View All Result
  • About Merchant Fraud Journal
    • Interested in Contributing or Guest Posting to Merchant Fraud Journal?
    • Merchant Fraud Journal Editorial Guidelines
  • Advertise on Merchant Fraud Journal
  • Articles
    • Chargebacks
    • Fraud Prevention
    • Influencer Insights
  • Contact Us
  • Download Addressing Payment Fraud and Customer Experience Report
  • Download Chargebacks Consumer Survey Report 2022
  • Download Evolving Complexities of Payment Fraud Report
  • Download Fraud Prevention Tactics that Enable Exceptional Customer Experiences Report
  • Download Merchant Fraud Journal 2023 Fraud Trends Report
  • Download Merchant Fraud Journal 2024 Fraud Trends Report
  • Download Merchant Fraud Journal Generative AI Fraud Prevention Checklist for SMBs
  • Download Quantifying the Challenge of Friendly Fraud: Your Post-purchase Strategy for the Future
  • Download the 2020 Chargeback and Representment Report
  • Download the 2020 Merchant Fraud Journal Vendor Guide
  • Download the 2021 Fraud Trends Report
  • Download the 2022 Fraud Trends Report
  • Download the 2023 Consumer Payment Trends Report
  • Download the 3 Ways a Unified Chargeback Management and Fraud Platform Increases Revenue Report
  • Download the MFJ 2022 Customer Experience Report
  • Download the MFJ ATO in Retail Report
  • Home
  • Home Elementor
  • Job Dashboard
  • Join The Merchant Fraud Journal Community
  • Merchant Fraud Journal Advertising Agreement
  • Merchant Fraud Journal Advertising Agreement – Signifyd
  • MFJ Fraud Trends Report Giveaway
  • News
  • Post a Job
  • Privacy Policy
  • Resources
    • #9978 (no title)
    • 2020 Chargeback Representment Guide for Merchants
    • 2020 Vendor Guide
    • 2023 Consumer Payments Survey Report
    • 3 Ways a Unified Chargeback Management and Fraud Platform Increases Revenue
    • Addressing Payment Fraud and the Customer Experience in 2022
    • Associations and Non-Profits
    • ATO Fraud In Retail Report
    • Balancing Customer Experience and Fraud Prevention: What’s the Secret?
    • Chargebacks Consumer Survey Report 2022
    • Digital Trust & Safety: Combating the Evolving Complexities of Payment Fraud
    • eCommerce Fraud Reports
    • eCommerce Fraud Webinars
    • Fraud Prevention Tactics that Enable Exceptional Customer Experiences
    • Fraud Prevention Training and Certifications
    • How to Build a Recession Proof Chargeback Prevention Strategy
    • How to Reduce Customer Friction During Holiday Sales Season
    • How to Stop Fraud During the 2022 Holiday Season
    • Jobs Board
    • Merchant Fraud Journal 2023 Fraud Trends Report
    • Merchant Fraud Journal’s Fraud Trends 2020 Report
    • Merchant Fraud Journal’s Generative AI Fraud Prevention Report: A Checklist for SMB Companies
    • Merchant Fraud Journal’s Fraud Trends 2021 Report
    • Merchant Fraud Journal’s Fraud Trends 2022 Report
    • MFJ’s 2022 Customer Experience Report
    • Podcasts
    • Prevent High-Velocity Fraud Attacks During the 2021 Holiday Season
    • Quantifying the Challenge of Friendly Fraud: Your Post-purchase Strategy for the Future
    • Stopping Fraud Across the Customer Lifecycle
    • The surprisingly easy way to secure your payment data, reduce your risk, and win the war on ecommerce fraud
    • Vendor Directory
    • Webinar – Addressing Payment Fraud and the Customer Experience in 2022
    • Webinar – Mitigating Fraud and Risk on the ACH Network
    • Win January Chargeback Disputes
  • Subscribed
  • Terms and Conditions

© 2021 Payments Media Solutions Canada Inc.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?