#tealou-WooCommerce

1 messages · Page 1 of 1 (latest)

frigid rune
#

You can always write to our Support to have tailored support. Before that can you provide your account id? I will take a look

scenic rain
#

Thanks - acct_18qCsIDhCRZzstLS

frigid rune
#

Disabling secret keys normally won't stop the attack vector because they just spam your front end calls. You would want to disabling publishable key and roll a new one. Publishable key is what your client side uses

scenic rain
#

I thought I had fixed it yesterday but it resumed again.... ah ok I thought that might be the case.

frigid rune
#

What I can recommend is

#
  1. Reroll publishable key
  2. Change your URL temporary
  3. Write into Stripe Support
#

(looking at the account)

scenic rain
#

Are you familiar with whether it is the domain or IP? I can roll a new server IP now I am hidden behind Cloudflare, and move to the other Stripe account as well...

#

sorry I meant whether they tend to attack the IP or the domain? I know this is Stripe support haha

frigid rune
#

You are under Card Testing. Our Support folks would be able to help you

#

I am seeing Card Testing

#

This is common scenario. Stripe do our best to help merchant combat with these kind of attack vector

#

I think disabling old Publishable key would be easiest and fastest to temporary stop them. But after you populate the new Publishable key they can continue again. So

  1. Disable old Publishable key
  2. Write to Stripe Support
  3. Try to change both your IP and domain
scenic rain
#

Yeah this is the odd thing, I have rate limiting on, Recaptcha on every possible field...

#

Ah ok, can't change the domain but will move IP and Cloudflare should conceal it

frigid rune
scenic rain
#

Do I need Stripe support to change something?

#

Yeah reading that now, thanks. Didn't know what the term was for it... other client checkouts have never had this issue

#

thanks

frigid rune
#

good luck 🙂 Always write to Support and they might be able to help you more

scenic rain
#

I appreciate the help, truly. Thanks. One more question... do you find that requiring user to login before purchase helps much, in terms of trade-off with User Experience?

frigid rune
#

Well it depends on your business. Many business do allow customer to guest-purchase. Like when you order, for example on ecommerce, the site will prompt to either "Login/Register to continue buying" or "buying without register"

#

It comes down to metrics. You can actively monitor 2 patterns and decide which works best for your business