BarCampBank biometrics

[Dave Birch] I’d never been to a BankCarCamp before so I wasn’t sure what to expect at the BarCampBank London last week. I needn’t have worried: as well as Forum friends such as Chris Skinner, Stephen Mason and James Gardner, there were both old pals and new acquaintances. The discussions were open and fluid and the combination of views did its job in generating new thinking. I was only sorry that I had to leave at lunch time to get over to OpenTech. One of the groups that I took part in was looking at the use of biometrics at retail POS and I tried to write up some notes to report on the key issues, as I thought blog readers would find them interesting. The discussion ranged over three fairly distinct areas: the drivers for biometrics at POS, the technologies and the business case. So far as the drivers go, the CHYP position has been reported before:

Biometrics work well in controlled environments such as ATMs, it’s true. But it’s not clear — despite a number of roll-outs — whether they offer a realistic alternative to cards at POS because, as we have consistently advised our clients, biometrics at POS are driven by convenience, not by security.

[From Digital Money Forum: Fingering suspects]

I think it’s fair to say that most people felt the same way, although there was some discussion on whether POS fraud is high enough to demand more security but the consensus was that it was not. As for the issue of technology, framed by the debate about convenience, it was not clear to me that the example often used, the fingerprint, has much role to play going forward. It doesn’t provide a particularly good trade-off between convenience and security, for one thing, and to many people it has connotations of criminality. Nevertheless, the technology is moving along and standardisation will help it:

“I think that ISO 19092:2008 will certainly be the kick start that biometric security needs, as it will provide the financial industry with some fantastic guidelines to enable them to implement both the architectural and policy/procedural changes required,” says Jason Pearce, director of sales engineering in Asia-Pacific for RSA, the security division of EMC.

[From Vendor Articles: 4/7/2008 Biometrics usage to pick up with new ISO standard?]

There are plenty of other biometrics to choose from, but surely we will end up using voice, for the straightforward reason that it can function in both local and remote environment, unlike biometrics such as fingerprints (because a remote service provider couldn’t tell if you were really putting your finger on the reader or replaying someone else’s. But for the purposes of the discussion, we can assume that the technology is there (provided it’s main purpose is convenience rather than security). A couple of people mentioned the combination of biometrics and mobile phones as being a promising avenue for exploration and I must agree. The mobile phone is clearly going to be the key device in the consumer space, so for biometrics to go with the grain they have to embrace the mobile from the start.

The business case discussion naturally focused on fraud and the relationship between biometrics and other technologies (eg, contactless) at point of sale. I can’t say that this part of the discussion came to any particular conclusions (if it did, they’re not in my notes) but the fact is that the chip and PIN migration has led to substantial reductions in POS fraud (and substantial increases in CNP fraud) so there’s no desperate need for another technology at POS, especially when the retailers and banks are already engaged in rolling out contactless.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The future of the future of cash

[Dave Birch] I’ve just read a very good report on the future of cash by AGIS Consulting. The report, by Guillame Lepecq, looks at the dynamics of the European cash market in some detail. Starting by noting that there were nearly 700 billion euros in “circulation” at the beginning of this year (compared to 750 billion U.S. dollars) and that euro notes and coins still account for four in five retail transactions in the eurozone, the report looks at the evoluation of the “cash cycle” and develops an informed perspective on the future of cash by looking at different scenarios for cash replacement. Guillame concludes that the growth of cash (ie, the increase in M0) has been driven by three factors: These are hoarding, internationalisation and low-value transactions, each of which is discussed in more detail below.

Hoarding. Only a small amount of cash is actual in circulation (being used for transactions). As Ian Grigg has previously pointed out on this blog, most euros are actually being used as a store of value, with their economic imperative being more about competition than efficiency.

Internationalisation. The euro has become a global currency, in the sense that 500 euro notes are under mattresses in Eastern Europe, the Baltics, Russia, Africa and so on. You can fit much more in a suitcase in euros than in dollars, and they’re acceptable around the world.

Low-value transactions. Cash remains the most effective mechanism for low-value payments, and will remain so until POS infrastructure is built out to orders of magnitude more points (in essence, until it reaches the individual, which will be achieved through the use of mobile phones). Of course, the reason why it remains most cost-effective at retail POS is because retailers do not pay the full cost. That’s why they like it so much…

The BRC’s Cost of Collection survey includes results from 17,000 shops, large and small, multiples and independents, with a sales turnover of £131bn a year, over half of total UK retail sales. It shows cash is the most cost effective way for retailers to accept payments and highlights the huge extra costs card companies impose on retailers for processing card transactions.

The BRC says customers do not realise how much retailers are charged for processing card payments. On average, a retailer is charged two pence for processing a cash transaction while the charge for a credit card is 34 pence and, for a debit card, eight pence. These costs are too high for retailers to absorb and are inevitably passed on to customers in the form of higher prices.

[From - British Retail Consortium - - News ]

When I have to find cash to pay the bus, it’s me that has to drive to the ATM, get money out and then buy something I don’t want in order to get the change I need. No wonder the bus company prefers it.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Keeping an eye on the competition

[Dave Birch] The Digital Money Forum is really all about retail electronic payments, but I’m always keen to see how the competition (ie, notes and coins, cheques) are getting along. Hence it’s hard not to be fascinated by what is going on in Zimbabwe. Inflation there has passed the gazillion (it’s a technical term) per cent level, which is almost impossible to imagine. There’s no point even trying to calculate the figures, because they are meaningless. The Zimbabwean dollar has no value whatsoever.

Comparing Old Mutual’s share price in London and Harare, Josh Giersch concludes that there are now 35 billion Zimbabwean dollars to one US dollar – up from a mere 17 billion on Friday. Which would put annualized inflation, he says (I haven’t checked his math) at 430,000,000,000,000,000,000,000,000,000,000,000,000%.

[From Zimbabwe Datapoints of the Day - Finance Blog - Felix Salmon - Market Movers - Portfolio.com]

This must mean that there is yet another interesting case of negative added-value here: paper is being made into banknotes that are by the end of the week worth less than the paper that was used to make them. This makes the U.S. government’s own 7.7 cents per dime look like quite a bargain in comparison. Why would anyone use expensive banknote paper to make scrap paper? Well, apparently, they won’t any longer, as yesterday I read that:

The Management Board of Giesecke & Devrient GmbH, Munich, today decided to cease delivering banknote paper to the Reserve Bank of Zimbabwe with immediate effect.

[From Zimbabwe deliveries stopped]

Oh dear. No more banknotes: people will have to go back to something that worked in the past, such as cowrie shells or tobacco. (Money fact of the day: tobacco notes were a currency in the colonies and the U.S. was on a tobacco standard for twice as long as it was on a gold standard!)

the crop [served] as legal tender in Virginia and Maryland for almost two hundred years

[From Chapter Two of the Ecology of Money: People-Produced Money]

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

UK Confidential

[Dave Birch] The excellent DEMOS report on privacy “UK Confidential” contains contributions from many of the people i regard as thought leaders in the field and has ideas aplenty. It was supported by BT “in the interests of furthering public debate”, which it certainly does. I’m curious about the extent to which the “tag line” on the report is true or not. It says “an open society depends on individuals rediscovering the social value of privacy”. Is it really for individuals? It seems to me that it is something that needs to be woven into the fabric of society — partly through the technological implementation of identity, the kind of thing that interests me greatly — because it’s a social good.

Anyway, in the introduction, Charlie Edwards and Catherine Fieschi say that “We lack the language to discuss privacy holistically. We use outdated frames of reference that are no longer adequate to discuss the contemporary landscape of privacy concerns or re-frame complex issues about data protection and vulnerability in other terms”. I couldn’t agree more — I’ve been writing a magazine article arguing, similarly, that both the government and its critics on identity management share this outdated frame of reference (which I’ve labelled “Orwellian”) — and there’s no doubt that it is a major impediment, a contributing factor to the privacy logjam we’re now stuck in, where privacy and security are seen as opposites that we have to balance in some way. I don’t want to dip into the “what is privacy” discussion here, except to note that it is important not to make the mistake of conflating a brief period of essentially urban anonymity with privacy and therefore make privacy something we can return to or get back in some way: Most people, throughout most of history, have had no privacy whatsoever.
The essential core of privacy in a modern context, I think, must be built around choice and consent (this is why I’m looking forward to our participation in a couple of Technology Strategy Board projects on Privacy & Consent later in the year). I tend to see these as important components of future consumer propositions and therefore viable if chosen carefully — there’s no point coming with great privacy plans that business will never implement. They call the privacy component of an exchange an “invisible transaction”, which is nice way of putting it. If companies can find privacy-enhancing processes that go with the grain of business, then surely they will promote them (much as they have begun to promote “green” elements of their operations).
In the conclusion Charlie and Catherine say that “our collective ignorance means that we get the privacy we deserve” but I’m not sure I’d be so negative. People are ignorant about lots of things, but they expect professionals (eg, us, I hope) to make good decisions for them. I’m happy to contribute to that debate.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Aussie rules

[Dave Birch] Card schemes point to Australia as a place where attempts to regulate interchange fees have resulted in no beneficial change for the consumer. In essence, as the Australian Consumer Competition Commission (ACCC) implies when it says that “nothing real has happened”, the card issuers were forced to halve interchange but the merchants did not pass the saving on to consumers. So was the regulatory intervention a good idea? Aneace thinks not:

Mandated reductions in interchange fees in Australia were supposed to cause retail prices to drop, directly benefiting consumers. The whole idea is that interchange is a “hidden fee” that retailers bundle into their prices, and that a reduction in fees charged to merchants would benefit customers. Sounds like basic, logical thinking that you would find in a high school economics and civics class, doesn’t it? As it turns out, the regulatory experiment resembles a high school lab experiment gone wrong.

[From Aneace's Blog: Has interchange regulation in Australia redistributed wealth in favour of merchants?]

This makes me wonder why we expect any different outcome in Europe. It’s certainly true that IT suppliers are confident in their predictions of jam tomorrow:

The report is produced by Cap Gemini, and shows that SEPA might create “net benefits to payment markets” of €123 billion in six years.

[From The FinanSer: SEPA today, SAPA tomorrow]

Of course, it “might” create none at all, so it’s difficult to pass judgement on the specifics of the SEPA provisions, but it’s hard to argue about the benefits of anything actions that create a more efficient market (in which domestic debit schemes with 0.1 percent interchange have been scrapped and replaced with fr more expensive international schemes… oh wait…).

If we’re going to discuss the best way to improve the lot of European consumers, then there are two fundamental options: competition or regulation. This brings us back to the general point: if we want to improve the payments system (by which I mean reduce the social cost of payments, thereby increasing the net welfare) should we expect regulation to be the best way to achieve this?

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

RUSI and all that

[Dave Birch] One (!) of the conferences I spoke at last week was the Royal United Service’s Institute’s conference on Science and Technology for Homeland Security and Resilience. I decided to put my original presentation about ID card technology to one side and go with my new psychic ID card slides. If you’re at all curious, the slides are here…

There were a couple of tough questions — mostly around “why bother with an ID card at all” — but on the whole the people there were very nice to me, and prepared to listen to what I suppose must seem like a fairly radical idea if you are from a conventional security background.

As the comments on the original blog post seem to indicate, I think I’ve stumbled on a useful way of describing an alternative form of identity card. I’ve been writing it up in more detail for a journal, so hopefully I can address some of those issues as I go along with the “psychic rewrite”, by which I mean that I’d already prepared a paper on how to use smart cards, mobile phones and so on to create new kind of identity card, but I’m currently rewriting it to use the Dr. Who framing as it does seem to speak to people far more effectively than any of my previous attempts.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.