Industrial-scale identity theft

[Dave Birch] Well, not really identity theft at all, but stealing credit card details on a massive scale then using them to obtain goods or services fraudulently. These ones got caught.

Federal prosecutors have charged 11 people with stealing more than 41 million credit and debit card numbers, cracking what officials said on Tuesday appeared to be the largest hacking and identity theft ring ever exposed.

[From 11 Charged in Theft of 41 Million Card Numbers - NYTimes.com]

Judging by the ever escalating figures for credit card fraud, however, plenty of others are still getting away with it. Are the figures telling us something very specific about authentication: that online PINs and passwords are not only not a particularly good authentication mechanism but may actually make matters worse? The prosecutors allege that the criminals stole card details and PINs as they were passing (apparently unencrypted) over wireless networks and then used the fake card to details to manufacture cards and then used the PINs with the cards to withdraw cash from ATMs. No PINs, no cash out of the ATM.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Not really a classic

[Dave Birch] The ramifications of the MiFare classic shenanigans that we have discussed here before continue to widen.

NXP said that the decision meant that affected parties such as system integrators and operators using MIFARE chips would likely want to review their systems, but that October was not long enough to deal with the problem properly.

[From Oyster card ‘free travel’ hack to be released | IT PRO]

NXP were right to point out that not every single card everywhere in the world needs to be replaced instantly, but our original conclusion that many schemes would need to start planning their upgrade route right away has turned out to be entirely justified. The story is a salutary parable about the benefits of “open” versus “closed” security, with a dash of hubris thrown in, and the need for long-term planning with these kinds of secure transaction systems. You might, by the way, be interested in this Channel 4 News segment on the Oyster card in London, which includes interviews with our friends from Royal Holloway and The Smart Card Group.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Micropayments and revealed preferences

[Dave Birch] Once again I’ve been thinking about micropayments. As part of some research I was doing for one of our customers, I noticed a very, very interesting result just in from the real world. In the Apple iPhone applications store (which I myself have used a number of times since my splendid new iPhone 3G arrived), “free” is no longer the most popular price point as it was at the launch. In fact

$0.99 is the most popular price point

[From Pinch Media » Percentage of free applications decreasing]

I think this adds something to the micropayments discussion that was revived here last month. Thinking about the psychology, it seems to me that since the price of something is an important subset of the total information about that something, then a price of “free” sends out mixed signals. If I’m browsing through the iTunes Store to try and find a nice business expense collection and reporting application (any recommendations?), then I probably won’t choose something that’s free. I’d wonder if it’s any good, or if the developer will support it in the future. On the other hand, I won’t pay £10 for something I’ve not had a chance to try out. I don’t mind paying £10 for something that I know works and will make my life easier, but it’s too much for a leap of faith. This makes 59p a good choice of price: it’s so low that I don’t mind paying it (the mental transaction costs are minimised) and I can buy it with one click. So I do.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

U.K. government research

[Dave Birch] The British Government is to invest in three new research projects that will help to develop the next generation of secure identity management systems. The Technology Strategy Board, Engineering and Physical Sciences Research Council (EPSRC) and Economic and Social Research Council (ESRC) have joined forces to back the three projects with an investment of over £5.5 million. The three projects are:

  • Encore, which will focus on the issue of providing more rigorous means for individuals to grant and revoke their consent for the use, storage and sharing of personal data, bringing together technological, procedural and regulatory developments.
  • VOME, a research project that will reveal and utilise end users’ ideas and concepts regarding privacy and consent, facilitating a clearer requirement of the hardware and software required to meet end users’ expectations.
  • Privacy Value Networks (pvnets), will generate a detailed understanding of individuals’ and organisations’ conceptions of privacy and identity across a range of contexts and timeframes – using a range of techniques including in-depth privacy value and devalue chains analysis to model the impact of the personal information.

Consult Hyperion are contributing to the VOME project (with Royal Holloway University of London, Cranfield University, Salford University and Sunderland City Council) and the pvnets project (with University of Oxford, University of St Andrew’s, University College London and University of Bath), so I hope to be able to share some interesting results with blog readers in the future!

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Economical summit

[Dave Birch] I’m very proud to say that the Digital Money Forum has become an associate of Economist Conferences and we’ve been helping them to put together The Digital Money Summit at The Dorchester in London on 25th November 2008. The folks there have kindly invited a number of Forum friends — including Sandra Alzetta, Jack Selby, Susie Lonie and Diane Coyle — to come along and address a business audience on the state of the digital money marketplace now that more and more consumers are experiencing new ways to pay.

Naturally, there are some obvious areas for them to focus on: The arrival of contactless and mobile payments in the mainstream and the potential for the two them to transform retail payments through the magic of NFC. They’ve asked me to present a reasonably strategic overview of the topic to kick the conference off and I’ve started to put together a few ideas (based on the Digital Money 3.0 discussion we had before). The conference will chaired by Tom Standage of The Economist. You may remember that we gave out a copy of Tom’s excellent book the Victorian Internet to delegates at the Forum a few years ago so it will be real pleasure to meet him and learn from his perspective.

We’re hoping it will become an annual cycle, with the 2-day Digital Money Forum that you know and love in the spring and the 1-day Digital Money Summit targeting a narrower selection of content at a wider business audience in the autumn. I look forward to seeing you there in November and getting your feedback on how we can work most effectively with the Economist guys in the future to deliver a great service to the digital money community.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Pass this one up

[Dave Birch] The newspapers here are having a fine time with the very latest Dutch chip shenanigans: A Dutch researcher has shown The Times how easy it is to clone e-passport chips and change the details.

The Home Office has always argued that faked chips would be spotted at border checkpoints because they would not match key codes when checked against an international data-base. But only ten of the forty-five countries with e-passports have signed up to the Public Key Directory (PKD) code system, and only five are using it. Britain is a member but will not use the directory before next year. Even then, the system will be fully secure only if every e-passport country has joined.

[From ‘Fakeproof’ e-passport is cloned in minutes - Times Online]

Nearly right. It’s digital signatures that “would not match” and the international database contains the public keys that allow you to check the signatures. I doubt it’s much of a threat to be honest, because you’d have to forge the paper part of the passport to match the cloned chip, and that strikes me as a little harder. The only people who read the chips, or at least attempt to read the chips, are immigration officers. My bank doesn’t have any readers, nor does my airline and nor does Eurostar or anyone else. Anyway, as the journalist points out, digital signatures are pretty useless if no-one implements them. I’m not sure why it’s in the new today, since it’s a recycling of a story that’s a couple of years old

A German computer security consultant has shown that he can clone the electronic passports that the United States and other countries are beginning to distribute this year.

[From Hackers Clone E-Passports]

It may be a symptom of a general collapse in public trust of any kind of government IT rather than a specific reflection on anything to do with e-passports.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Opentech and the manifesto

[Dave Birch] When I went over to OpenTech to give a talk about Digital Money, I had no idea what to say. I had a few slides about cashlessness that I could have used, but by the time I was on stage it was getting a bit late in the day so I thought it would be more fun to just talk because the audience must have been pretty sick of Powerpoint by then. (I meant Powerpoint generically, which was a bit lazy, since I haven’t seen such a high Mac/PC ratio for some time, even if most of them were running OpenOffice under Ubuntu.)

I wanted to talk about what was wrong with payment systems and suggest a few ideas for further investigation, hoping that the geeks would pick up on one of these and knock up a revolutionary new payment system in the bar afterwards. I started by remembering the three key points that I discussed in this context a few years. These were written up in “E-Money and Payment Systems Review” (Central Banking Publications) back in 2002: payment systems are too slow and too expensive, they are opaque and they are not suited to e-commerce. These seemed like a reasonable starting point but for some reason I was sure that they weren’t going to connect with the audience and I felt that I need some more context.

When I was chatting at the coffee break, I had the idea of trying to explain to the assembled geekhood why they should be interested in digital money but re-interpreting the key issues in a more social context, and I ended up with a quick three-point manifesto that seem to go down quite well. Are you with me!

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Public transports

[Dave Birch] Stuart Kwan, Director identity and Access at Microsoft, kicked off something a while back by talking about the need for some sort of "identity bus" that can allow different systems, components, applications to tap into an effective digital identity infrastructure. It doesn’t exist as an architecture, let alone products, but people do understand what he means.

 

The "identity bus" is, of course, still just a vision, but at least it is a beginning. Understanding and building toward an identity industry that is "the identity bus" should be the mission of every serious identity vendor out there.

[From Identity Bus: More than meets the eye | CSO Blogs]

Kim has been talking about this as well. There’s a lot to commend this way of thinking. From the technical side, we all understand what a bus implies: standards and interfaces, "plug and play", commodity units. Whether this is realistic in the identity space needs further discussion, because the industry may not be yet know enough about what is wanted, what the real requirements are, in order to be able to come up with some building blocks of lasting value. Yet in a discussion this afternoon, in connection with the use of mobile phones in the identity infrastructure, I did start to think that perhaps instead of endless industry bodies, government studies and new experiments, it might be better to just start plugging a few bits and piece together.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The reduced interchange world

[Dave Birch] The Revolution card seems to be gaining an amount of traction in the US:

Since being launched 9 months ago, the card has already garnered acceptant 150,000 merchants with plans to reach 1 million by the end of the year.

[From National ACH: Revolution Card Acceptance Rising]

Their essential tactic is, as we’ve discussed before, to provide a more merchant-friendly payment card scheme (although I still don’t really understand why merchants don’t just do this for themselves if payment cards, as they claim, are taking such a big chunk out of their profits) that is geared up for the reduced-interchange world of the future:

The main advantage to merchants is that accepting the card costs only 0.5% of each purchase amount, significantly less than the discount rates merchants pay to accept credit cards. In addition, the company recruits merchants as distribution partners and rewards them to provide an incentive to promote usage of the card. Merchants have the option of co-branding the card.

[From National ACH: Revolution Card Acceptance Rising]

Price and promotion are only part of the future reduced-interchange world, because one might hope that the kind of new technologies that we are always talking about here will provide platforms for new value-added services to benefit all of the stakeholders. Falling interchange might even stimulate some new developments:

This strategy is especially relevant if interchange gets cut. Merchants will be paying less, so there is an opportunity for the merchant’s acquirer to offer new value added services that are paid with a portion of the money freed up by lower merchant discount fees.

[From Aneace's Blog: Are some banks already preparing for lower interchange fees?]

There’s a great deal of scope here, because the “narcotic” of interchange (to use Steve Mott’s provocative description) has meant that such value-added services (loyalty, coupons, rewards,, management, control, folio, groups and so on and so on) are still in their infancy. Retailers pay large amounts in interchange for (as they see it) very little.

He also notes that IKEA pays some €90 million annually and Tesco pays about €128 million in fees to the banks for processing credit and debit cards – that’s more than €210m p.a., between these two firms alone.

[From Retailers count the cost of interchange]

it therefore ought to be easy to co-opt retailers into using a deploying value-added services and charging them for the “something” of these services rather than the “nothing” of interchange.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.