“Real” and “virtual”

[Dave Birch] At the 21st European e-Identity Conference, there was a presentation on the regulation of virtual worlds by Bart Schermer from the University of Leiden. I know we’ve discussed it here many times before, but I mention the presentation here because In the Netherlands (where the conference was taking place), the first virtual theft case is now being prosecuted. The case concerns the theft of €4,000 worth of Habbo Hotel furniture stolen by a “phisher” who obtained account passwords. Not only does this confirm that phishing in virtual worlds is going to be just as much of a problem as phishing in the sort-of-real world, it confirms that the virtual world might be a good customer for bank authentication systems. Of course, as a consumer I don’t care if phishers get in to my bank account, because my bank will give me the money back. But I do care if they take over my virtual world avatar: Will I get my magic sword back?

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Zero hour

[Dave Birch] Part of my Bank Holiday reading this year was book dropped on my desk by our head of Software Development. He’d been working with a customer on helping some of their people to develop a better understanding of phishing (and similar threats) by developing a bogus web site to show how easy it is, and had been reading it on the train. The book is Zero Day Threat by Acohido and Swartz. It’s an O.K. read and at the end makes a few sensible suggestions. For example, they say that a priority is to do something about payments.

Jettisoning magnetic stripe payment cards and online authentication systems that rely soley on user names and passwords, and replacing them with technologies that actually hinder counterfeiting and impersonation — not make it mere child’s play — is also a must… In short, the credit-issuing and card-based payment systems are due for a massive overhaul that will take us beyond the current solutions now on the table.

They also go on to say that

One can only hope that political leaders will emerge to champion the greater public good, not be bulldozed by probusiness interests.

What they are saying here is that banks prefer to have payments insecure because it’s cheaper. This is true, but it’s important to see why, and why the goals for the payment system might diverge from public policy goals. The designers of payment systems do not have as a goal the eradication of fraud but the management of fraud down to acceptable (ie, financially acceptable) levels. The few hundred million that goes to card fraud in the U.K. is a tiny fraction of the amount spent on cards. But the money earned through this fraud, while not a big deal to the banks, may well lead to larger social problems that do not figure in the banks’ cost-benefit analysis, which is why we should still try to reduce it even if it doesn’t make business sense for our particular organisations or systems.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Converging world views

[Dave Birch] It looks as if the wider world is finally catching up with the Digital Money Forum’s view of the future. Take a look at these “Top 10 Trends” that I came across while searching for something else. They were put together by market research heavyweights A. C. Neilson, presumably a couple of years ago. Some of these trends may be rather familiar to digital money denizens, but they are still worth surveying…

1. Digital money
According to AC Nielsen, 90% of transactions in the US will be cashless by the year 2020. PayPal already has 63 million accounts, which makes it larger than most national banks,while in Korea during the month of June 2004, 300,000 people purchased cellphones into which you can insert a memory card containing all your financial data. So will physical money soon be a thing of the past? Most observers say yes, but don’t underestimate the power of human nature and tradition.

2. Contactless payment
McDonald’s is testing ‘contactless’ payment technologies in the US (and elsewhere). Just drive-in, grab your goods and drive off. Payment is made automatically by a wireless device on your windscreen linked to your bank account. Mobile phones can and will do much the same thing.

3. Pre-pay and stored value cards
10 million households in the US don’t have bank accounts and many of these use their pay cheques to buy pre-paid credit cards. Around 8.5% of households without bank accounts own pre-paid credit cards but this figure is expected to rise to 25% by the end of 2006. This is one reason why companies like Visa and MasterCard are getting into the act by signing up Rap moguls and singers like Russell Simmons and Usher to put their names on prepaid cards.

4. Private currencies
Pre-pay is a type of private currency in that you can restrict where people spend their money, in some cases to a single brand, outlet or service. This is good news for loyalty and also good (or bad) news for privacy depending on your point of view. For example, parents can give their children pre-paid cards with certain categories or locations locked off. However, the big news in private currencies is what’s happening in the air and in cyberspace. According to the Economist magazine, airmiles are now technically more valuable than the US dollar while over in cyberspace gamers are exchanging cyber dollars for the real thing.

5. Debt
The level of credit card debt in Britain has increased by 73% since 1997. The UK now holds 60% of all credit cards issued in Europe and has 75% of all European credit card debt. Spending on credit cards now represents 11% of GDP and 40% of people say they expect to use their cards more with the advent of new technology. Meanwhile, the amount owed to credit card companies in the UK now stands at GBP £53 billion. Figures for other countries such as the US and Australia are following a broadly similar trend. So what happens if (when) interest rates really go up? Trouble, that’s what.

6. Everyone is a bank
If everyone from supermarkets and search engines to phone companies and airlines offer banking services where does this leave the banks? The answer could be as back office low margin sub-contractors or maybe banks will re-frame themselves as ‘wealthcare’ businesses.

7. Micropayments
Once upon a time people used credit cards for big purchases like holidays. Not any more. Now you can buy a 99cent song on i-Tunes with your credit card or charge your hamburger at McDonald’s to your plastic. In 2004 the average credit card transaction in the US was $67.81. Back in 1999 it was $72.83. Add to this the possibilities created by contactless payment, stored value cards and pre-pay and you have a recipe for radical change in the financial services sector.

8. Proof of identity
With cases of identity theft going through the roof in most countries, there will be a boom for companies and technologies offering electronic and other forms of identity verification. There will also be an increase in products and services aimed at helping people get their identify back after its been stolen.

9. Mobile phones becoming wallets
Have you noticed how fewer people are wearing watches these days? Under the age of 21 a watch is almost a novelty as people use their mobile phones to tell the time instead. And so, the theory goes, phones will replace wallets too as people find it more convenient to carry their cash digitally inside their phones.

10. The death of cheques
Seriously, who under the age of thirty uses cheques these days?

[From What's Next - Top Trends in Money, banking & insurance]

Yes!

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Phorget it

[Dave Birch] I have to write something about tracking and tracing, for unspecified purposes. Broadly speaking, and within some bounds, I want to be tracked and traced because I want a better service, more useful adverts, that sort of thing. I remember someone telling me that in countries with strict laws about the collection of personal information for marketing purposes, you get more junk mail because the originators cannot target the offers. If you know I hate golf, why send me stuff about golfing holidays? The goal is to get to the point where companies are not supply advertising by information relevant to my state and relationships. If I’m in a Forum about writing Dungeons & Dragons adventures, then a post from a company providing some useful tips and a link to their adventure-writing software is not really an advertisement, because it’s something the community is happy to see. But how to get to this harmonious balance: should my information be under the control of the companies or me? You must remember Phorm.

Phorm said it was setting up a new online advertising platform called the Open Internet Exchange, which any Web site will be allowed to join. Proceeds from ads that are shown on these publishers’ sites will be shared with BT, Carphone Warehouse and Virgin Media, which together represent more than two-thirds of the Internet access market in Britain… The three Internet providers have agreed to give Phorm access to customers’ surfing records, letting it track a Web user’s every move.

[From Providers get a piece of ad income - International Herald Tribune]

Is this acceptable? Wouldn’t I prefer to control my my personal browsing habits and partition them, parcelling out the data to people who I think relevant? Or, to put in another way, CRM or VRM? Since the original trials, Phorm have changed the system (remember, it is operated by your ISP, not by Phorm) to provide for an opt out, but I assume that ISPs will incentivise me heavily to opt in because

Phorm could be the future, a future in which targeted advertising is essential to the business model of an ISP.

[From The law of Phorm | OUT-LAW.COM]

This seems reasonable to me, but within some pretty strict bounds. For one thing, if my mobile operators knows that I’m ringing a bank’s mortgage enquires line, can then they bombard me with junk mail about mortgages? I hope not, and I wouldn’t expect the same from my ISP: I they know I’ve been looking at Abbey National’s mortgage offers, can they just sell this information to the highest bidder in a carousel of mortgage companies? Wait, I assert my moral right as the author of that idea…

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Metro-politan

[Dave Birch] Down at the European Technology Standards Institute (ETSI), I saw a good presentation by Jens Kungl from the 64 billion euro METRO Group, which operates 2,400 retail locations in 31 countries. He knows a bit about retail, and Metro have been experimenting with RFID for some time, so his opinions need to be taken seriously. He began by making (strongly) the point that the best way to scupper an RFID project in retail is to begin tracking people instead of goods. In my opinion, one of the dangers here (and there are genuine privacy concerns that need to be addressed) is the regulatory response, which may be over-anxious, mis-targetted or plain wrong. For example

The Washington legislation outlaws the use of RFID “spy technologies” to collect consumer information without the owner’s consent. The only problem is, heavy corporate lobbying narrowed the scope of the law (before Governor Gregoire signed it) to cover only criminal acts such as fraud, identity theft, or “some other illegal purpose” (making it a Class C felony to do so). Collecting information from consumer RFID chips for marketing purposes in Washington—with or without the owner’s consent or even knowledge—is still fair game.

[From Washington State passes RFID privacy law; where's Uncle Sam?]

Surely, collecting information for anything but the purpose for which is was intended is just wrong, and it doesn’t matter why it’s being collected. Anyway, the point of this post is that Jens said that the trigger for item-level tagging is the five euro cent tag and this has arrived sooner than they were planning, so they are going to begin item-level tagging earlier than they had originally planned (they are already rolling out pallet-level tracking). He also said something about two Watts at 868MHz, but he was losing me a bit there…

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Shrinking sweet spot

[Dave Birch] As you may know, the banks have launched contactless cards in the U.K., aiming for a cash replacement “sweet spot” in the range UKP2.50 to UKP10 pounds, where the speed and convenience should work well. So I was thinking of suggesting to the pub over the road from our office that they install a contactless terminal, thus ensuring a steady stream of traffic from Consult Hyperion as we conduct visitors from around the world in their direction for a contactless lunch. But oh dear..

Shrinking Sweet Spot

I’m genuinely beginning to worry.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

There’s going to be a BarCampBank London

[Dave Birch] There’s going to be a BarCampBank in London on 5th July 2008 at Sun Microsystems’ offices in the City. The full details are below. I’ll be there — although I’ll be over at OpenTech later in the afternoon — and look forward to seeing you there to. I’ve been looking forward to BCBL and was really pleased to hear from Frederic that it’s all going ahead.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Supply and demand always win

[Dave Birch] You know those wobbly writing boxes that you have to read when responding to blog posts, signing up for Hotmail, that kind of thing? I’ve always found them really annoying, and so have hackers, spammers and various other ne’erdowells. As a consequence, there’s a substantial demand for software that can read the wobbly writing so that computers can pretend to be people…

 

All of these developments clearly indicate the demand and supply for CAPTCHA breaking services, as well as the potential for abusing the clean domain reputation of the most popular email providers whose continuous emphasis on usability, namely coming up with more user friendly CAPTCHAs, often results in the easy of which the process can be automated.

[From Microsoft’s CAPTCHA successfully broken | Zero Day | ZDNet.com]

But look at the second comment on the story, which makes a point that occurred to me as I was reading the story. I was thinking "hey, can I get some of that software to make life easier for me when I’m posting blog comments?". More than once I’ve had a quick thought while reading someone’s blog post, clicked on "comment", typed in a quick note and then given up when I’ve typed in the wobbly writing incorrectly a couple of times. As the commenter points out, if the cracking software can read the codes better than many people can, so there will be a demand for that software from people who want to use it for legitimate access!

And, by the way, if you authenticate yourself with OpenID, as I just did on Faster Future, why should you need to read the wobbly writing at all? Surely one of the most important attributes that OpenID could share is "is_a_real_person" or something similar.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Not with a bang

[Dave Birch] You probably won’t have noticed, but the paper airline ticket has breathed its last. The International Air Transport Association (IATA) has had a thousand souvenir final tickets printed up for distribution to industry luminaries, and that’s it. The 300+ member airlines have switched to electronic tickets…

Those few paper tickets which were printed in recent months will be honoured – although airlines have said this will also come to an end.

[From Paper airline ticket dies this weekend after 75 years - Telegraph]

So there you go. Total dematerialisation, and in a relatively short time. The airline industry has responded to the new technology: It has scrapped something that is based on paper, has worked for generations, is accepted all over the world etc. Paperless progress. It can happen here…

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Silver lining

[Dave Birch] I happened to be at an IT industry gathering with a question and answer session with someone from the British Bankers Association (BBA). It wasn’t about payments, directly, but about the legislative fallout from the current rash of bank debacles. The session concerned the government’s plans for something called the “The Financial Stability and Deposit Protection Bill” which went out for comment earlier in the year…

Banks have 12 weeks to persuade the Treasury to drop the idea or face a bill that investment bank UBS has estimated at up to £3bn a year for several years.

[From Banking reforms 'to cost £3bn a year' - Telegraph]

The government is proposing that deposits will be safeguarded up to some figure — maybe 50K or 100K for individual personal accounts and half a million or so for small business accounts — but we were discussing yesterday, a limit of £35K would cover almost all depositors (save for very rich people such as M.P.s). So, what has this got to do with payments?

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.