Brian Lovin
/
Hacker News
Daily Digest email

Get the top HN stories in your inbox every day.

etempleton

My approach to detecting fraud is to always assume the worst possible reason why someone did something or why something happened. Always be looking for the angle. You will detect fraud and manipulations and also a bunch of manipulations that aren’t there at all. In psychological circles this is called catastrophic thinking.

It is a hell of a way to live.

swagasaurus-rex

What about just applying that reason only when people want something from you.

Most people don't want anything from you. Some people like just chatting. Salesmen will feel smothering and uncomfortable because they want something from you. Advertisements trigger me because it's so obvious (in my mind) they want something from you. News feels this way too.

How can I tell? The same cues that fool people who focus on the surface-level: flashiness, bravado, loudness, taking the subject matter to things I do not care about. Trying to make me feel emotions (fomo, FUD, even excitement).

You could use it as dating advice: people are turned off when you want something from them too much.

Not all that glitters is gold.

withinboredom

Pickpockets work by just chatting with you while someone else does the work. Stay vigilant!

Johnwbh

Except a smart scammer won't do it as a hard sell and look like they need you. They know as well as anyone that aggressive sales look suspicious. Madoff waited for people to come to him.

ludamad

I was reading some Madoff stuff the other day - I think generally true, but he had his share of "one of a kind offer invest this week"

spywaregorilla

I don't think you're claiming otherwise, but just to be clear, this is generally perceived as a bad thing, psychologically, along the lines of OCD/paranoia/anxiety. This is not a healthy approach, and it's concerning that some responders below seem to think it's a good idea.

etempleton

No, and to be clear, this is not a good approach to life. I was being a bit glib in my comment. I am not advocating for anyone to actually think in this way. I do indeed suffer from OCD/paranoia/anxiety, though it is currently well managed with medication.

For anyone that actually thinks in this way, as I do, I recommend seeking help. It took me half my life to actually get help and I realized after being on medication just how bad my anxiety was. It is good to be cautious, but when you see daggers everywhere it is probably time to get help.

gmadsen

depends if it gives you anxiety. I think the healthy approach is "Prepare for the worst, hope for the best"

I don't need to live in constant fear of the worst, but it helps to be prepared for it

spywaregorilla

That's not catastrophic thinking then. Catastrophic thinking tends to fixate on irrational concerns, like, "Did I run over a person on my drive home and not notice" or "is that stranger planning to kill me?".

"prepare for the worst" is super vague, because the worst is unbounded in implausibility.

saiya-jin

IMHO that's pretty far from OP' description of a viewpoint.

fanzhang

Good point. To add an exception to the original article then, perhaps the only general method to detect fraud is the trivial method: assume everything is fraud.

In practice though for most goals it's probably better to trade off Type 1 vs Type 2 error.

numpad0

Someone said: “people immune to cultist recruitments don’t have friends”

hutzlibu

I get the point, though in reality, the people without any real friends, are the most vulnerable to be dragged into a cult and once they are in - cannot go, because they would then be truly alone again.

fho

I mean ... at some level everything today is some kind of "fraud" ... everything that is sold to you is not sold to you out of altruism, but because somebody else is living of that trade. That person in turn has to maximize the profits, which is why you never buy something at value.

amelius

> My approach to detecting fraud is to always assume the worst possible reason why someone did something or why something happened.

This goes against Hanlon's razor, though.

etempleton

Catastrophic thinking is rarely based in good probabilistic thinking. Logically I know that, but my brain latches on to the worst possible rational outcome as the most likely outcome.

I do not try to think in this way. I wish I didn’t.

dgb23

Human failure and weakness is something we have to accept, the response to it doesn’t need to be entirely negative. Often we can be empathetic in some way or another, which doesn’t exclude tough love.

Also we often underestimate others when thinking too cautiously or fearful. This can often be cured through direct interaction.

Whenever I feel overwhelmed by negative perspective/thinking. I try one of these angles. Sometimes it works, especially if I put effort into engaging with people that are involved.

seoaeu

Hanlon's razor is specifically used by malicious people to conceal their malice, and if you rely on it too heavily you will never detect fraud

jkhdigital

Reminds me of the characterization of Harry Markopolos in Malcolm Gladwell’s book Talking to Strangers.

His takeaway is that society is a pretty bleak place when we all lose our “default to trust” mode of operation.

ngc248

I remember a line from a manga called "Liar's game". The line goes "If you meet someone new, doubt them, question them and then you will understand them better". I think this should be the SOP of when you meet anyone new.

admissionsguy

> My approach to detecting fraud is to always assume the worst possible reason why someone did something or why something happened.

> It is a hell of a way to live.

True, but it is the honest way to live. Especially employment/management relationships are all about manipulating, cajoling, and ultimately threatening (by homelessness and starvation) people into doing things they would not otherwise do. Things are not much better in private/social life, except maybe within some families / friend groups or between lovers during the first year or so. Life is so bleak.

scandox

The solution is worse than the problem if you live with this attitude.

In addition it is too reductive and doesn't represent the very complex (even enjoyably subtle) interactions that go on between humans who do want something from each other.

Life has many illusions and it is up to you which one you pick. The reality you are enduring is just another illusion you've settled on: except it's a crap one.

roenxi

People do things for reasons. That doesn't make life bleak, that just means you should be careful about incentives in your relationships. Shun people who have an incentive to harm you, embrace people who have an incentive to help you and seek out people who think that their best chance at an easy life is making those around them prosper.

tonyedgecombe

Not all relationships are like that. Customers buy my software because it provides some value to them, I sell it because it provides an income. It's a relationship that works to our mutual advantage.

I don't manipulate them, there are no dark patterns on my web site, I don't hold their data hostage or nickel and dime them.

musicale

> A surprising number of employees get duped into accepting part of their pay packet as options in their employers' private (and highly illiquid) stock

I'd not heard this stated so clearly before.

ludamad

Can I get a second opinion on this (from someone here who feels they know, that is)? Say the stock option is at a call at a high valuation, but you know all exits would be higher, is the underlying stock that much more valuable?

umvi

As long as trust exists, fraud will exist. The only way to eliminate fraud is to eliminate trust, and trustless societies are pretty dystopian.

genedan

In my experience working in an insurance claims department, we overlooked a lot of fraud, intentionally. Usually, only the large, extremely obvious cases with plenty of evidence were pursued. I believe a lot of the soft fraud involving slightly inflated claims went undetected.

Part of this is because you have to pay the salaries of the investigators, so there is a cost of detection. It's not worth recovering an amount that is less than the cost of an investigation. Secondly, a company will lose customers if it has a reputation for having too many false positives or a default stance of mistrust of their policyholders.

scotty79

I'm not sure. Reducing necessity for trust is a worthwhile goal.

It's wonderful to not have to trust too much. Instead to rely on evidence and have a contingency if things go horribly south.

lbriner

Is that possible? Every system we use has to be trusted at some point. I don't trust the internet so I use https but that is only really saying that I trust the IETF or my certificate provider and I (personally) have no realistic way of knowing whether either is trustworthy.

Did the IETF miss a vulnerability when they inveted the protocol? Was there someone on the team planted by the NSA? Do the cert authorities provide the means to hack my data in some way?

I don't think they do but that is because I trust them that I don't think it would be in their interest to do this and I think that if the IETF messed with the protocol, someone would have noticed but we have seen OpenSSL bugs that have sat there for years because it was too complex for most people to understand.

It just sounds like turtles all the way down because ultimately you have to trust someone or something even if it is just time and experience.

rocqua

Reducing the amount of places where you have to trust, and then demanding more transparency from those places helps create a society where less trust is needed, and fraud has fewer options.

konschubert

Trust is great and it's enabled by reputation systems.

https://ncase.me/trust/

CharlesW

I'd characterize it this way: Reputation systems don't enable trust, but are an attempt to algorithmically quantify it. To paraphrase the old aphorism, all reputation models are wrong but some are useful. Unfortunately, they're inevitably abused by the untrustworthy that they're supposed to filter. Madoff had increasingly-good reputation signals until he didn't.

dgb23

It’s still trust, just shifted to something else.

marcosdumay

It's actually more trust, because any bad consequence is reduced. It feels like less because it's easier to trust, but the real world impact is of the real thing, that is more.

That's why an effective police, punishment for business crimes, and law enforcement even when the person moves into a different place are important. A more trusting society is a happier and richer one, so we should make it easy to trust.

22c

>By switching, you have a 2/3 chance.

I guess I need to read up on the Monty Hall problem again, because I always thought it was 1/2 chance if you switch (vs 1/3 chance if you don't).

SailingSperm

I find the Monty Hall problem becomes intuitive when scaled.

100 doors, 1 car, 99 goats. Pick a door. All doors open (with goats except 1) ... Do you think you picked the 1/100 door with the car, or that it's the other only one left standing.

Mordisquitos

Exactly. It also helps to emphasise that the eponymous host knows which door contains the prize and will never open the prize door before asking you whether you want to switch.

lovecg

The variants where the host does not know are also worth considering. If they’re just guessing and happened to not open the prize door by chance, you’re back at 50/50. If they have a hangover and you think there’s a 5% chance they forgot where the prize is and still just happened to open the doors correctly, well that makes the math even more interesting.

rho4

Beautiful short explanation. I always struggle getting this point across in discussions.

rho4

My hopes for this explanation were too high. I just tested it on my cooworkers. No luck. I reverted to suggesting to write a short simulation script to convince themselves by experimental data.

HWR_14

It's a 1/3 chance if you pick before the second door is opened and do not switch.

It's a 1/2 chance if you pick after the second door is opened, regardless of switching.

It's a 2/3 chance if you pick before the second door is open and switch after the second door is opened.

I recommend reading again, because I don't want to write up the logic.

Of a bigger concern is that this was not true on "Let's Make a Deal". The problem assumes that Monty always offered the option to switch. In reality, he did not, and the offers were not random. That corrected for the issue to a large degree in practice.

rocqua

That doesn't add up. Literally, 1/3 + 1/2 does not add up to 1. What third option exist that has a 1/6 chance of happening?

The basic argument is. If you don't switch, you have 1/3 chance of winning. So if you do switch you have 1/3 chance of losing. Hence if you switch you have 2/3 chance of winning.

How the door you switched too went from 1/3 chance to double is the hard part to explain. But it must be the case.

aonsager

It's a 1/2 chance at the point where you're considering the switch.

If you start the game with the intention of switching, you have a 2/3 chance of being successful because the winning strategy is to miss the car on your first pick.

cjbest

No, I don’t think this is right.

Regardless of your intended plan, you only had a 1/3 chance of picking correctly the first time, so switching gets you a 2/3 chance.

undefined

[deleted]

Nursie

No, it's a 2/3 chance at that point.

When you choose initially, you have a 1/3 probability of getting the right one, leaving a 2/3 probability that the car is on one of the other two.

The host reveals one of the other two. So that 2/3 probability applies to the remaining door. Here is a short C implementation that made it very clear to me...

  #include <stdio.h>
  #include <stdlib.h>

  int doround () {
    int car = rand() % 3;
    int firstchoice = rand() % 3;

    // host reveals one of the goat doors

    if (car == firstchoice) {
      // you changing to the other door after the reveal is a loss
      return 0;
    }

    if(car != firstchoice) {
      // you changing to the other door after the reveal is a win
      return 1;
    }
  }

  int main(int argc, char** argv) {
    int wins=0;
    for (int round=0; round < 1000; round++){
      wins+=doround();
    }
    printf("Worked in %d of %d rounds\n", wins, rounds);
  }

undefined

[deleted]

anyfoo

It's been a while since I actively thought about the Monty Hall problem, I thought I understood it intuitively back then. I thought it became one of those "oh yeah, that's unintuitive, but once it clicks it's fine" things for me.

I thought through it again, and I'm angry now.

At least I'm not alone (got this link from the article): https://web.archive.org/web/20140413131827/http://www.decisi...

albedoa

That would mean you have a 5/6 chance of finding the car if you were allowed to pick both doors. You can see the problem with that. In reality, it's 2/3 and 1/3 respectively.

22c

If you started with 4 doors, where 3 of them had goats, wouldn't you have a 1/4 chance of picking the car the first time and a 1/3 chance of picking the car the second time?

lmm

1/4 chance if you keep your original door, 3/4 chance if you switch (assuming the host opens two doors to show goats). If the host opened one door (so you have your original door and two other doors to pick from) then it's a 3/8 chance if you switch, if that's what you're asking.

aliceryhl

When using the switch strategy, you win if you choose a goat initially. Since there are two goats and one car, this is a 2/3 chance.

mlboss

Door A | Door B | Door C | —————————————————————————- Car. | Goat. |Goat.|

Goat. | Car. | Goat.|.

Goat. | Goat. | Car.|.

The above tables shows all possible distribution of car and goats. If the initial choice was Door A, then you only have 1/3 probability. But after B/C door is opened the probability increases to 2/3 if switched.

The clue is that the host will always open the door with a goat.

MattGaiser

I have read and own the recommended book at the end, Financial Shenanigans. Anyone who has ever had to measure up to some imperfect KPI will find it relatable.

My way of personally looking for fraud is to look at incentives. What might this person stand to gain if I take this chosen action and do my incentives align in any way with his?

lbriner

This doesn't work in some fraud cases. If Madoff is selling you an investment, it is obvious what you think he gets out of it, he invests your money and keeps a proportion and that is normal business right?

As the article says, his clever angle was not to over-inflate the ROI of the investments which might well make them look implausible.

What is harder to spot is whether an investment is actually taking place.

jimnotgym

Is there any KPI that is perfect? I think you could find a valid criticism of any KPI.

The incentive view is a good one, and one often followed by auditors, starting with the pay of company accountants!

motohagiography

Makes you wonder if having a lottery system for firing people in a company at random would perform better than KPIs, or at least provide a baseline for KPIs to be measured against.

8-12 months severence / perf bonus, glowing reference for taking one for the team, and placement services. It's just like normal attrition, but makes planning a scam and consolidating a lot of anti-patterns way less viable.

It seems psychotic, but compared to the incidence of mendacity, it's a pretty good deal for everyone.

thatfunkymunki

agreed. Who wants to have unlucky employees? Get rid of them by using the RNG!

pnutjam

https://en.wikipedia.org/wiki/Benford%27s_law

This is a good way to detect fraud. Basically, any number set will tend to have more 1,2,3's vs 7,8,9. Fraudsters will use random data that doesn't follow this.

pjc50

> I think confirmation bias afflicts aficionados most of all.

Interesting to link this to https://news.ycombinator.com/item?id=27467999 (hedgehogs/foxes and "one big idea"); the people with one big idea, who are aficionados of that idea, are easier to exploit because they're using the idea to avoid being contingent: that is, they're not looking at what's actually happening, merely whether they can fit the idea to it.

Following this, a lot of modern social media culture war consists of (a) selling you a universal idea that explains everything you see in the media and then (b) recruiting you into a cult which uses your support (money, votes) for their own gain. The ur-example is of course Nazism selling the idea that Jews were the problem to which they had the "solution", but you can see analogies to this all over the political spectrum.

user-the-name

> you can see analogies to this all over the political spectrum.

No, you can see analogies of this specifically on the right, which is just doing the same thing still.

jimnotgym

If you create the right atmosphere, you will find your junior employees will become very adept at keeping a suspicious mind. This is endemic in most accounts staff, but only if you encourage it.

chrisweekly

Mods: Please consider changing the title. It makes it seem like this awesome, grounded, helpful, 100% licit advisory outlining clever examples of hard-to-detect fraud is instead some kind of NSFW nonsense. So glad I RTFA; hope others will too.

calpaterson

Thanks: glad you liked it. he original title is my fault as author because I picked it and it took me a while to realise that it was so terrible. Sorry about that.

buffet_overflow

If it weren't for this comment, I would have missed this one. Thanks for the flag, and a +1 to this being worthwhile.

anyfoo

I agree, this was a fantastic read.

yjftsjthsd-h

And here I was hoping for a tutorial on unusual sexual maneuvers. So yes, it should be fixed so nobody else is disappointed. (I'm actually semi serious, if you're wondering)

grzm

The title is editorialized (and I'd say egregiously so): the title of the article is "No general method to detect fraud"

22c

Seems like the author of TFA submitted it to HN, so they editorialised their own title.

dang

We cut authors some slack about that, but not when the submitted title is clickbait. We've changed it now. (Submitted title was "Slick Tricks for Tricky Dicks". That's one hell of a stretch.)

"Please use the original title, unless it is misleading or linkbait; don't editorialize." https://news.ycombinator.com/newsguidelines.html

The article itself looks good though!

calpaterson

Sorry about that, I changed the title after posting it here, when I realised how terrible it was. It wasn't really intended as clickbait though and in fact it actually functioned as anti-clickbait. As a few people have said, it looked like a "risky click". :|

Glad you liked it though.

undefined

[deleted]

calpaterson

I'm very sorry about that. The submitted title was the one I originally had but it took me a while to realise that it wasn't very good. I changed my mind about it but you can't edit titles on HN submissions after publishing.

modeless

> The best defence against frauds and scams seems to be a kind of "intellectual vaccination" via repeated exposure to benign, non-functional specimens.

Similarly, ransomware is doing us all a favor. Every ransomware hack exposes and closes a vulnerability that could do much more damage in the hands of a truly malicious actor such as an enemy in wartime.

calpaterson

Ransomware isn't a "benign, non-functional specimen" :). It has real harms and they can be quite serious.

I suppose that - always dangerous to extend an analogy - ransomware is more like "intellectual variolation" than vaccination.

I wonder what would happen in wartime though.

modeless

Random, sparse ransomware attacks are absolutely benign compared to what a wartime enemy would do. If you don't think so, you haven't properly imagined the serious, extensive, real world damage that could be done by coordinated simultaneous attacks. Look at Stuxnet's destruction of machinery and then imagine that applied to a wide swath of the economy, including basic infrastructure like water and power, all at once.

Daily Digest email

Get the top HN stories in your inbox every day.