Nine is a magic number

[Dave Birch] I’m going to have to stop using the time-worn vernacular “as bent as a nine-bob note”. Up until decimalisation in 1973, the British shilling of twelve pennies was known as the “bob”. Hence the ten shilling note was the ten bob note. For some odd reason, and I really can’t remember why, I never saw the replacement 5p piece as a bob, nor have I ever referred to a 10p piece as two bob, but for a long time I called a 50p piece a “ten bob piece” (in fact I can distinctly remember once asking my younger brother for ten bob and being genuinely surprised when he had no idea what I was talking about). So ten bob was a sizable amount of coin of the realm whereas nine bob meant something that was clearly fraudulent (as in “the Enron P&L statement was as bent as nine bob note”). But it now transpires that there was in fact at least one nine bob note: the Irish “Newports Bank” issued a nine shilling note in 1799, and a specimen has just been sold at auction in the U.K. for three thousand euros. So what is to be our post-cash alternative: as bent as a… what? As bent as a card with a magnetic stripe on it… no, wait… as bent as an IBAN with an invalid check digit… as bent as an SDA clone with an invalid digital signature… they don’t seem to have the ring to them, do they?

Technorati Tags:

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Cards and costs

[Dave Birch] Retailers just won’t let it lay about the cost of cards and there are new articles about this every day. In the U.S., gas stations are a particular focus of discontent (as they have been for some time, in fact). What bothers the owners is that on a petrol sale, the the card companies make more money than they do. For example, on a $30 sale with petrol at $2.89 per gallon (that’s approximately zero per Imperial gallon, for British readers), the retailer will get 39 cents but (as the retailer sees it) the bank gets 69 cents. I saw a quote from another retailer recently that if a customer wants to buy a pack of gum with a card, he’d prefer them to just steal it because he loses less money that way. Not exactly a devoted customer base. It’s not just in the U.S. though. In Dubai, all petrol stations have banned cards and all Emarat, Enoc and Eppco stations accept only cash or own-brand cards. Denzil Lawson, the General Manager of MasterCard Middle East & Levant, said

We continue to consult with all parties concerned towards finding an effective solution… MasterCard is disappointed with the announcement by the fuel companies in Dubai that they will stop accepting payment cards, denying their customers the convenience and safety of using payment cards.

Technorati Tags: , , ,

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Security on a grand scale

[Dave Birch] It’s really difficult to keep big systems secure when they have lots of users. Especially when those users don’t really care about security. And worse when there’s no identity infrastructure. The textbook case study for years to come will be the “troubled” $25 billion-ish National Health Service “Connecting for Health” (CfH) system. It’s travelling a predictably rocky road. NHS staff (which, from a risk analysis perspective, means everyone in the world — the NHS employs over a million people) have complained they have not been properly consulted, system designers have argued it is foolhardy to keep patient records in one central database and security experts have warned that the system might (!) be vulnerable to unauthorised users. Some of the most stringent security measures in the IT industry have been devised to protect confidential information: staff have been issued with smart cards, for example. Of course, they don’t actually use them to log in: they find the person with the highest level of authorisation, put their smart card into the system and then leave the card in until the end of the shift.

Technorati Tags: , ,

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Cardspace apace

[Dave Birch] It’s been a while since Microsoft’s Cardspace first began to obtain reasonable media attention, and it’s certainly true that it now figures on the potential technology roadmap in many corporate strategies, but it doesn’t yet seem to have crossed the chasm, so to speak. Early business model ideas — such as the scenario in which cardspace-style authentication would reduce fraud rates so that credit card issuers would be able to offer merchants a discount for using — haven’t yet materialised. Yet momentum does seem to be building (see, for example, the ACI presentation from Digital ID World) and I’m sure that some banks will become experimenting or piloting soon — but perhaps they are right to be cautious.

Technorati Tags: , ,

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Turkish delights

[Dave Birch] I’ve been in Istanbul working for a customer in the telecommunications field. As always, I’ve really enjoyed it. I love coming to Istanbul because it’s a dynamic place. There’s a lot going on and people are always trying to launch new products and services. Right now, it’s a really great living case study of the co-evolution of banks and telecommunications operators because of the early adoption of contactless payment technology in Turkey.

Technorati Tags: , , , ,

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

He overshoots, he scores

[Dave Birch] Deloitte, a management consultancy, have published a report called “is the retail payments industry heading for disruption?”. It looks to me as if it is based on the disruptive innovation concepts of Clayton Christensen (our favourite guru). I think this is a very useful way to look at the evolution of the retail payments sector — I have used the same analysis myself for a couple of years ago in a course I teach at the Visa Business School — and it can help with product and service development in very practical ways. Deloitte says that

Credit card companies are showing classic signs of “overshoot,” which makes them vulnerable to disruption, especially disruptive innovation.

I agree, but I think this is only part of the story, and the example of EMV helps to illustrate why.

Technorati Tags: , , , , ,

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Hammer of the gods

[Dave Birch] I read in my Daily Telegraph that there has been a postal strike in the U.K. I can’t say that I noticed, because I never send letters anymore and never receive any except for junk mail and the occasional utility bill (which, since I pay all utility bills by direct debit, I rarely look at anyway). I’m from the same mould as the terrific U.S. stand-up Jim Gaffigan: if I did actually see a hand-addressed envelope drop onto the doormat I’d assume that someone had been kidnapped. But I digress. I further read in the very same newspaper that in an attempt to waste an impressive amount of public money, the Department for Work & Pensions (the DWP) sent out 400,000 pension cheques last week by courier because of the strike. I was really shocked: I had no idea that they sent out cheques at all, let alone sent them out by courier when they would otherwise be delayed. Surely it should be a condition of receiving pension cheques that you get yourself a bank account and end the anachronistic printing, posting, depositing and clearing of bits of paper. If I sound more intemperate than usual about allowing this quaint Georgian payment mechanism to persist, it’s because I’m writing this in Iceland.

Technorati Tags: , ,

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Will they have to write to everyone in the entire country?

[Dave Birch] Some people think that data breach legislation is a useful way to force companies to take their data protection responsibilities seriously. Personally, I’m not entirely convinced but I’d be very happy to hear the arguments from either side. If I got a letter from, say, Tesco saying that one of their systems had been compromised and some people’s personal details had been stolen, then I’d just chuck it in the recycling since — like most other people, I imagine — I don’t really care and I’ve no idea what to do with the information if I did. As it happens, my Tesco loyalty card isn’t in my real name anyway. But suppose — just suppose — that it is the government itself that is compromised? Do then they have to write to every single person in the country?

Technorati Tags: , ,

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

This what virtual identities are for

[Dave Birch] The New York Times published an article based on a concept put forward by Mike Neuenschwander of Burton Group.. This is what he called the “Limited Liability Persona” (or LLP). This persona would be a legally recognized virtual person in which users could “invest” the financial or identity resources of their choosing. Once their individual personas are created, consumers would be able to use them as their legal “alter ego,” even in financial transactions. As Mike says:

My L.L.P. would have its own mailing address, its own tax ID number, and that’s the information I’d give when I’m online.

. The author of the Times article, Denise Caruso quotes Drummond Reed as well:

The myth is that companies have to know all this information about you in order to do business with you … [b]ut from a liability perspective, the less I know about my customers the better.

Or, as Forum friend and former editor of Wired UK John Browning wrote a decade ago (in Wired 5.11)

The true identity of a counterparty may be the least interesting fact about them in a commercial transaction.

Drummond’s point is made form the perspective from the U.S. National Retail Federation open letter to the credit card industry asking them to stop putting retailers on “the horns of a dilemma” by requiring them to store personal data, but then turning around and penalizing them when that data gets compromised. The LLP idea aims to help by giving retailers (and everyone else, of course) help to protect individuals by giving those individuals identities which contain only a limited amount of personal information (I don’t see why companies would have LLPs as well though). If this sounds familiar, and I sound uncritical, that’s because this is one of our PET projects: but we don’t call them LLPs (I prefer to shy away from the word “liability”) but pseudonymous virtual identities, and they solve more problems than PCI-DSS compliance.

Technorati Tags: , , ,

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Chip and PIN mythbusters

[Dave Birch] Chip and PIN has been back in the news again. This time, it’s reported that large numbers of cash withdrawals are being made using cards without a security chip and it is the banks themselves that are allowing it to happen. The newspaper story says that there are more than 140m cards in circulation and every day more than 7m withdrawals are made at cash machines across the U.K., which is true. It goes on to say that if banks rejected every card with a slight fault in its chip they would be inundated with complaints from furious customers — which is true, of course — and therefore fraudsters using cloned bank cards that have no chip can still get their hands on other people’s cash and it gives the lie to industry claims that the system is totally secure. Wow, that sounds terrible: there’s a flaw in chip and PIN. Let’s find out more…

Technorati Tags:

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.