Some best practices

[Dave Birch] The European Commission’s ePractice.eu is hosting a free workshop on electronic identity in Brussels on February 14th. I’ll be going along to hear three best practice presentations — from Spain, Belgium and Estonia — and to join in the discussion about how to learn from and build on them. See below for more details if you want to come along too.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Lucky, for me anyway

The celebrations for Chinese New Year (it’s going to be the Year of the Rat) are about to begin so I went out last night to join in the fun here in Singapore — and an excellent night out was had by all, I have to add. Wandering through some of the market stalls in the evening, I came across a stall selling “lucky coins”. Naturally, I bought some. It turned out to be lucky for the stall owner (who got $2 for three old coins worth, essentially, nothing) and lucky for me too, because they gave me something to write about on the blog when I couldn’t think of anything else. The coins were cash, in the truest sense of the word.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Dog years

According to one of the U.K. newspapers, the government is thinking about chipping prisoners in order to track them, as they (sort of) do at the moment with ankle bracelets…

But, instead of being contained in bracelets worn around the ankle, the tiny chips would be surgically inserted under the skin of offenders in the community, to help enforce home curfews. The radio frequency identification (RFID) tags, as long as two grains of rice, are able to carry scanable personal information about individuals, including their identities, address and offending record.

[From Prisoners 'to be chipped like dogs' - Independent Online Edition > UK Politics]

They are talking about Verichips here, but a moment’s reflection leads me to the conclusion that the story either cannot be true at all or can only have been leaked to the newspaper by someone who hasn’t the slightest understanding of RFID technology or, for that matter, technology in general. Verichips store only a 16-digit number and they are not re-writable: they can’t store addresses or anything else. But then none of the people in the article seem particularly au fait with the either the technology or its risks:

Consumer privacy expert Liz McIntyre said a colleague had already proved he could “clone” a chip. “He can bump into a chipped person and siphon the chip’s unique signal in a matter of seconds,” she said.

When she says “siphon the chip’s unique signal”, she of course means “read the chip ID as per the specification”. Reading the ID number off of the chip is no different to reading it off of the patients bracelet. It’s just a number. I’m not waving away perfectly valid privacy concerns here. I’m just pointing out that the fact of the matter is that there is no point implanting a chip under the skin of someone who doesn’t want to co-operate. They will simply take it out, or swap it with another chip. The technology has absolutely nothing to offer in this case.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Money museum

[Dave Birch] Wallowing in nostalgia over coffee today — and spurred by Ian Grigg’s comment about innovation and Steve Klebe’s mention of Cybercoin — I was reminded that our good friends at Payments News pointed me to the VisaCash and Mondex testimonial web site, every page of which is laden with memories for many of the Digital Money denizens.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

1% of the way

[Dave Birch] Things haven’t been going terribly well for America’s ambitious Real ID scheme. Government agencies missed the end of October deadline to complete background checks for employees and contractors who have worked for the federal government for 15 years or less and to begin issuing the new identity cards that include employees’ fingerprints as required under Homeland Security Presidential Directive 12, which President Bush issued in 2004. In all, about 1.9 million federal employees and 591,358 contractors require credentials. As of that deadline, 97 percent of federal employees and 79 percent of contractors had completed the required background checks, but federal agencies had issued only 1 percent of the new cards. Now it turns out that some of the other deadlines around driving licenses are being rolled back as well.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Getting cash on the web

[Dave Birch] There are plenty of people out there who want to use cash on the web. Not digital cash, or electronic cash or virtual cash but actual cash. (This shows how the variety of e-cash solutions introduced over the years have failed because of execution and implementation, not because of a lack of consumer demand) There are companies how are trying to find ways to help them to do this, such as Click and Buy in the U.K., for example. Similarly in America. Chase Paymentech and Green Dot Corporation have announced an agreement to offer Chase Paymentech-processed merchants an alternative cash payment solution that gives them the ability to accept cash transactions through their existing online and phone interfaces by accepting Green Dot’s MoneyPak as a form of payment. They say that research from McKinsey shows that cash accounts for more than 60 percent of all consumer transactions. So there’s plenty to play for. GreenDot run one of the largest retail-based cash acceptance networks in the United States, and MoneyPak would be the first cash-based payment solution available for use by Chase Paymentech’s merchants. Available at more than 40,000 retail outlets nationwide, including Wal-Mart, Walgreens, CVS/Pharmacy, Rite Aid, Radio Shack, Kroger, Ralphs, Food4Less and Fred Meyer, consumers can purchase a MoneyPak for $4.95 (suggested retail price) at any Green Dot retailer location and move that money wherever MoneyPak is accepted as a form of payment or funding. I’ve never used it, but I assume that they can reload their Money Pak at the same outlets. Choice is a good thing, and I’m sure that consumers having the ability to choose between pre-paid “open” (ie, Visa/MasterCard) payment cards and non-bank alternatives is a thoroughly good thing.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Time for the one-time signature …

[David Griffiths]  I have recently moved home, and I wanted to tell my bank the new address for my business account.  I logged into the internet business account management centre, with my username, password AND one-time passcode from my whizz-bang security gizmo, but I couldn’t find any option for updating my address.  "Perhaps I have missed it", I said to the lady in the call centre, after she had been through all of the additional security questions and had confirmed that it was indeed me, "No", she said, you have to go into the branch and tell them".  "But I work in London, and can’t get in".  "That’s ok", she said "I’ll contact your branch and they can send you the form".  "And where will they send it?" "Ah!", she said, "You don’t live there anymore, do you?  You’ll have to write to them".  "But if I write to them, how will they know it’s me?"  "You’ll have to write to them", she repeated.  Now I can tell a procedural road block whan I hear one, and I could tell I was hearing one – I considered my best option was to give in before they start quoting the Data Protection Act at me … I sent the letter…

 

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Don’t worry, it still works fine

[Dave Birch] There are lots of fraud stories around today, including the one about the fraudster who managed to con high street bank Barclays out of £10,000 in a credit card scam by posing as the bank’s own chairman, Marcus Agius. It seems as if the card fraud meme has been spreading. I don’t know if you saw this wonderful story in The Guardian back in December, but it was about the English town of Letchworth (the world’s first garden city) and the essence of the story was that card fraud is so out-of-control that a kind of panic has set in. I won’t reproduce all of the details here, but I wanted to pull out a few key quotes from the story in order to make a couple of points and to reflect on the conclusion of the story, which is that whole communities are losing faith in payment cards and are turning back to cash-only transactions. The meme has been spreading through various channels and there are more and more stories about the failure of chip & PIN (ie, failure to eliminate fraud), the rise in ATM fraud, CNP fraud and so forth. But I’m getting ahead. In the Letchworth story, the reporter found many people “boycotting” outdoor cash machines, and, in some cases, abandoning the use of payment cards at retail POS.

Shoppers at the Shell petrol station told us they will never use their bank cards to pay for fuel again, after witnessing the chaos caused to friends who have had bank accounts plundered by fraudsters. Outdoor ATMs are strangely quiet, while inside banks there are queues of customers taking out cash.

The story says — and I’m not questioning it — that in the town (of 33,000 people) virtually everyone the reporter met had either been the victim of card fraud or they knew of someone who has had money illegally taken from their bank account. Usually the illegal withdrawals take place in Australia. This is a novel twist (it’s usually Italy or Bulgaria) suggesting a specific gang at work. Several people said they were now only using cash. Almost all said they would no longer use cash machines unless they were inside the bank. One specific problem identified was — hello 2006 — the petrol station. Card-reading equipment at the Shell garage, on the main road in and out of the town, was compromised. Another was the bank. An ATM at a bank branch had a skimming device fitted The local paper reported the stories with additional coverage when it emerged the problem had spread to another Shell garage in nearby Hitchin. I’m not trivialising the issues: the stories involve real people, such as

Hilary Gibson defaulted on her mortgage because thieves stole the £700 she had deposited to cover the payment the following day. Leisa Virgo from Hitchin was another victim. When the bank called to check a payment, she immediately cancelled the card – but not before £300 had been withdrawn.

Hertfordshire police also reported that CCTV monitoring had foiled another attempt to install a skimming device at another ATM and four people were arrested. Nevertheless, residents such as Peter Merrigan are concerned:

To be honest, I have stopped using bank cards… I now prefer to go into the bank and get out my money the old-fashioned way – I certainly wouldn’t use a cash machine.

The reporter found the ATM outside the Barclays branch with wires hanging out. It had clearly been attacked. The staff were sanguine:

Don’t worry, it still works fine.

I’m not sure that the residents have been doing their risk analysis homework, because (and here I agree with the APACS spokeman) carrying around wads of notes is (I’m sure) more likely to lead to loss than carrying around a card: if I lose a tenner, it’s gone for good, but if my card is skimmed I’ll get the cash back from the bank. Sorted. Since I never, ever, use my debit card except at ATMs, I feel fairly comfortable. But then I don’t live in Bicester, where fraudsters tried to attach a skimming device to every ATM in the town, or Houghton on the Hill, where the local garage was compromised so that everyone’s card details were stolen.

Technorati Tags: , , , ,

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

More Flash than Cash?

[Dave Griffiths] Have the Mobile Operators missed the mobile
payments boat? Time was when the mobile gurus
would have us believe that mobile payments were going to be big, so much so
that they replaced the “e” in “e-commerce” with “m” for mobile. About 10 years ago they were convinced that
people would browse the internet on their WAP phones, and buy fridges (not just
fridges though) on the train on their way home from work. The only thing the mobile operators were
missing was a payment mechanism they could tickle. The same gurus who had thought that buying
fridges on trains was a neat idea, also thought that the mobile operators already
had all of the necessary payment mechanisms in place – because they already
billed their customers monthly, and because they already settled call charges
between themselves both nationally and internationally. However, there was a gap between guru perception
and mobile operator reality: analysis soon showed that the billing systems were
held together with string, the international settlements were based to a large
extent on fingers in the air, and the overall m-commerce proposition was more
pie in the sky than fridge on the train.

The brave new m-commerce dream soon became
little more than a mechanism for ring-tone purchase based on then concept of
the reverse charge SMS (which for consumers, fell into the same perception category
as premium rate telephone calls, along with all the associated mis-charging
grief). The reverse SMS payment
mechanisms did nothing to enhance mainstream mobile telco payment propositions –
and they were also associated with sub-prime businesses, advertised in the back
of tabloids. Other SMS mechanisms were
tried (linked to standard bank accounts as the mobile operators tried to tickle
the transactions by enhancing existing transaction security), but these have
never managed to catch the international imagination.

The mobile operators cannot deny that they
had a flying start. They had
relationships with each other, and they also had a technical infrastructure built
around the GSM chip that had the potential to bridge the card not present
transaction security gap – and since the number of mobile phones in use was
rapidly approaching credit card density, there would be no shortage of adopters. Pay-as-you-go (PAYG) also meant that payments
need not be restricted to the over 18s and the banked. The development of the PAYG infrastructure,
since it dealt primarily with value rather than minutes, could easily have been
enhanced to provide a card scheme type payment infrastructure.

Collectively and, to some degree,
individually, the telcos were in possession of everything necessary to build a
non-bank payment infrastructure – in an area that for the banks was still
pre-roadmap. And the banks were
pre-occupied; at the time they were working hard to put chips on cards, and
chip readers in terminals: they had no immediate interest in mobile payments.

PAYG, and the development of e-top-up vastly
enhanced telco ability to manage the movement of real money. Without a doubt, this gave them the edge; it
especially gave them the edge because the e-top-up cards were ATM compatible
and the transaction switching technology had also been adapted from existing
banking systems. However, PAYG also made
the phones accessible to the youth market, and sexy because of the
accessibility. The more mature phone
users still wanted a phone they could use for talking, and maybe the odd
new-fangled text thing. The younger
user, who by and large had little memory of the old world “dog ‘n’ bone” phones
wanted cameras and videos and mp3 players and radios and television and the
internet and MSN, and Oh! Yes, a phone too, so that their more pedestrian
parents could still communicate with them.

Phones that did stuff that wasn’t
particularly “phoney” inevitably caught the imagination of the designers, and
the marketers. With phone technology
riding the Moore’s Law wave, the designers were ever more able to squeeze ever
more features into ever smaller boxes, and the race was on to provide an
endless supply of phones to satisfy an ever expanding mobile phone market.

Phone manufacturers formed alliances with
multi-media corporations, as each recognised the other as a means of expanding
their individual markets. History has
shown each to have been correct – phone companies sell more phones and media
companies sell more media – and the telcos are still selling bandwidth: a
commodity product with limited ability to add value to the stand-alone telco
proposition. Multi-media corporations
and phone manufacturers are selling their products on the back of the high
availability, high bandwidth, transport medium provided by the telcos, and now
the banks are too. Contactless gizmos
can be attached, or built in, to phones that can talk to merchant terminals,
and congratulations go to RBS for recently achieving this significant
milestone, and thanks for showing it to me. The phone gizmo communicates with the existing bank payment infrastructure,
and the transaction just works! The
gizmo, however, is also in communication with the customer’s bank, and can be
topped up and managed remotely over the phone network – but the telco is still
just selling the data bandwidth and is still not in a position to tickle the
transaction.

The
mobile operators are still selling mobile toys: their market expands (or at
least generates new consumers) as new youth come of phone age every year. There will always, it seems, be a market for
phones that flash. It’s an exciting
world for the designers, for the technologists, for the marketers, for the
accountants, and for the customers; and it’s exciting in a way that mobile
payments aren’t! The mobile operators
had a period of grace from the time that mobile phones became digital to the
time when the banks and the payment schemes would catch up and apply their ever
increasing payment sophistication to the mobile phone. That grace period was probably in the region
of ten years, and it’s over!

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The internet of things 2.0

[Dave Birch] Over on the Digital Money Blog, we’re obsessed with the spread of NFC technology built in to mobile phones because it will have a disruptive impact on the retail e-payments world. But the technology will undoubtedly have an impact on the identity world as well, and not just because the NFC-enabled mobile phone is an ideal personal identity management device, but also because it bridges the local and remote environments to provide infrastructure for the internet of things: in fact, one might argue that bringing mobile into the picture (the internet of things 2.0) turbocharges the whole concept. The Auto-ID guys seem to think this as well. At the St. Gallen/ETH Zurich Auto-ID Lab, for example. They agree that NFC-enabled mobile phones could give consumers access to the EPCglobal Network. This isn’t because NFC phone can read EPC tags — they can’t, because NFC technology, which operates in the high-frequency band, and EPC technology, which operates in the ultrahigh-frequency band, are incompatible — but because they could link local devices that can read tags (Bluetooth-connected pens and that sort of thing) into the savant network needed to make RFID work in a useful way. It’s possible, of course, that UHF EPC readers may be integrated into mobile phones in the future, though it’s technically challenging because the readers drain a lot of energy from the phone’s battery. What’s more likely is that some applications will end up using NFC tags. I tend to favour this NFC direction on the overall roadmap, because it links to the wider demand for NFC phones. While NFC is still in pilot for most operators around the world, this is about to change as an increasing number of commercial launches are due to take place in 2008: while in the short term there still remain important challenges for the development of NFC-enabled devices, analysts are saying that in the long term NFC will be a feature supported on the large majority of the phones sold. This already the case in Japan, where NTT DoCoMo has FeliCa contactless technology embedded in about 80% of the phones they sell. There are no great technological or cost barriers for NFC to be integrated quickly into a wide range of devices, so this must stimulate a tag ecosystem.

Technorati Tags: , ,

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.