Rover van Mierlo, Shuitema

[Dave Birch] Rover van Mierlo is Director Central Logistics and Innovation of Schuitema NV. Schuitema is the second largest retail organisation in The Netherlands with 450 C1000 stores (it has just been acquired by private equity). Before that, Rover was the supply chain manager of Akzo Nobel Twaron Products, Practice Leader Industrial Consulting at KPMG Management Consulting and a project leader at Philips International. In this podcast, he talks about the results of the C1000 NFC trial.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Location layer

[Dave Birch] I recently gave a talk about the using mobile phones as carriers of identity "cards", pointing out the kind of functionality that such an implementation could deliver into the hands of citizens and consumers. I'd used Neil McEvoy's "identity as utility" as the paradigm and demonstrated, I think, that the mobile phone is (for the time being) the most logical means to implement national-scale solutions. Caspar Bowden of Microsoft was in the audience and — as I always genuinely appreciate — asked me a couple of tough questions that I've been reflecting on. One of them concerned the relationship between security and privacy in an environment where the connection layer not only knows who the users are, but where they are at all times. This, Caspar reasoned, means that any implementation that tries to use privacy-enhancing technologies at a higher layer will necessarily be confounded, since trivial data matching in mobile phone records or ISP records will deliver an accurate record of both where you were and who you were talking to. This is, of course, correct. As Ben Laurie has so clearly pointed out, unless the connection layer is anonymous, nothing else matters. Uh oh…

A United Nations agency is quietly drafting technical standards, proposed by the Chinese government, to define methods of tracing the original source of Internet communications and potentially curbing the ability of users to remain anonymous. The U.S. National Security Agency is also participating in the "IP Traceback" drafting group, named Q6/17, which is meeting next week in Geneva to work on the traceback proposal. Members of Q6/17 have declined to release key documents, and meetings are closed to the public.

[From U.N. agency eyes curbs on Internet anonymity | Politics and Law - CNET News]

Shouldn't there be some kind of informed public debate about this kind of thing? (If you want to read up, start with the document that Robin Wilton pointed me to at the ITU.) This isn't a bit of irrelevant geekery on the margins of society, it's a fundamental issue, a fundamental bound on the development of communications.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Delivering for the unbanked

[Dave Birch] Professor Steve Worthington has a piece in the current Journal of Financial Transformation looking at financial services for the unbanked in the U.S. It contains some very useful figures and statistics — noting, for example, that half of the unbanked have college educations and that a quarter of them have prime credit ratings, which implies that they have opted out of the banking system rather than been excluded — that reinforce the point that the unbanked are an underserved segment. If the financial sector could develop appropriate products, they could make money from a socially beneficial enterprise (ie, reducing transaction costs).

The headline conclusion, for me, was that a fifth of U.S. households are either unbanked or underbanked and that some of them have already begun to turn to non-banks to deliver financial services to them. An example used in the article is the Wal-Mart Money card, exemplifying the point that simple, transaction-oriented financial services are well-suited to the core skills and competitive approach of mass-market retailers. With the growth of, in particular, government use of prepaid card products to provide better and more cost-effective services to the unbanked, it seems plausible that non-banks might do rather well in this space. Leave the “lending money” part of banking to banks (who seem hopeless at it, but there you go) and treat the “moving money” part of it as a business up for competition just like any other business.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

NFC drivers

[Dave Birch] I’ve been looking at some NFC-related business cases for customers in different countries and noticing — without giving away anything confidential — how different they are: some are focussed on retail, some on transit, some on operators etc. Yet they are all founded on what I think is a reasonable consensus on the narrative to date: that is, customers like NFC (a lot), operators aren’t sure how to cash in and banks aren’t sure whether the operators are on their side or not. One thing they all agree on though is that handset availability shapes the critical path. This is because it seems highly unlikely that consumers will hammer down the doors of mobile phone shops to get NFC handsets to use for boring things like payments. Once they have the handsets I’m sure they will use them for payments, but payments isn’t interesting enough to drive them down to the mall. What consumers will want in the first instance is the simple stuff — smart posters, exchanging numbers, that sort of thing — and above all (in certain urban markets) for transit.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Update from the frontline

[Dave Birch] I’m at Mobile Payments World Asia, where I’ve been hearing some interesting projections about what might happen in the future. Everyone is fairly bullish, as they have every right to be given the very positive consumer research on the topic. According to the GSMA, who conducted a 17 country market research survey of 2500 consumers, something like three-quarters of consumers would be happy to use their mobile to buy train tickets as well as pay for their shopping at a supermarket. The excellent case study of the Philippines apart, though, a lot of people were still talking about pilots and trials. It’s a little disappointing, I think, that the convoluted dance between banks and operators is taking so long to deliver useful services to customers.

Meanwhile, the latest figures from my favourite mobile payments scheme, M-PESA in Kenya, continue to amaze. Safaricom added 870,000 new mobile subscribers in the first quarter of the fiscal year to reach 11.1 million by the end of June (a considerable increase in the subscriber base since the introduction of M-PESA). M-PESA itself is still growing and the registered user base increased 50 percent over the quarter from 2 million at 31 March. New registrations continue to exceed an average of 10,000 per day and by the end of July the total registered user base exceeded 3.3 million. Total person-to-person transfers reached KES 6.88 billion in July (about $100 million), representing a growth rate of 220 percent over the March figure. The total value of all transactions during July exceeded KES 21 billion (about $300 million), and the average transaction per user has continued to increase over the last 6 month.

Wow. I guess that the increase in average transaction size has two obvious drivers. First of all, when people come to a new payment system they may initially be uncomfortable with committing large amounts of money to it. So they being by making small payments, but send large payments through existing systems that they know work, even if they are much more expensive (eg, interpersonal money transfer via physical offices. In time, their confidence grows and the larger payments move to the new system as well. The more important driver, though, might be the adoption of new systems by business. Just as PayPal “proved” itself to consumers sending each other the occasional few bucks and then they began to use it for person-to-business payments (through eBay as first), so mobile payments systems that have proved themselves easy, reliable and cost-effective for interpersonal payments (and microfinance payments in the M-PESA case) will soon be adopted by businesses. With more than three million M-PESA users out there, what Kenyan business wouldn’t want to accept mobile payments?

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Visualisation

[Dave Birch] There’s no real point to this post, except I thought you’d find it mildly diverting. As part of one of the projects we’ve been working on in the telecommunications sector, the guys and gals in Hyperlab (Consult Hyperion’s research and development team) had to build some kit to measure and map the electromagnetic fields around contactless payment terminals to help the terminal and card designers improve the performance of payment and transit cards in operational environments. Since one of the terminals that I’m interested in is the Nokia 6131 NFC phone, they put that in the rig. So this is what a Nokia 6131 looks like to a person:

6131_blank

And this is what it looks like to a Visa card:

6131-with-overlay-pic

Cool.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Jonathan Craymer and Stephen Howes, GrIDsure

[Dave Birch] Jonathan Craymer and Stephen Howes are the inventors of the GrIDsure system and founders of GrIDsure Limited. GrIDsure is a “visual PIN” system, which replaces a simple numeric PIN with a pattern-based alternative. In this podcast, they tell us where the idea came from and where they hope it might go.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Losing contact with reality

[Dave Birch] When I first heard about the government’s “Children’s Index” project, I was quite scathing about it (perhaps a little over the top in one or two places) because I felt that the basic concept was so transparently flawed that the management consultants should have been sent away with a flea in their before it ever got near a gateway review. It looks as if it’s turn out to be an even bigger waste of a quarter of a billion pounds than even I had suspected. It’s been delayed yet again and who knows when, and it what cut-down form, it will ever be used. If it isn’t delayed indefinitely until it is quietly scrapped.

A fundamental flaw with the scheme (now known as ContactPoint) is the idea that you can give upwards of a third of a million people access to a system and expect its contents to remain secret in any kind of cost-effective way. And, of course, any sensible person would reason similarly:

If you allow large numbers of people access to sensitive data it’s never going to be secure. You can’t protect it. ContactPoint should simply never have been built.”

[From Database delayed: Critics fear children may be in danger | Education | The Guardian]

The dangers inherent in this kind of system, that collects sensitive data and then opens it up, do not need to be repeated. Nor are the restricted to the public sector. In today’s Korea Times I read that:

Two CDs, containing the private information of more than 11 million people (including politicians and government ministers) were found in pile of rubbish in Seoul. GS Caltex, the oil company from where the data had leaked, said that they took private information very seriously and only 12 employees were authorised to access the database.

They can’t keep the stuff safe with only 12 authorised users, so goodness knows how ContactPoint is going to keep it safe with 300,000 of them. It would only be a matter of time before some minor functionary in local government left a laptop on a train, or a management consultant analysing the data lost a USB key, or whatever, and the whole database would be exposed.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Privacy expectations

[Dave Birch] Interviewed in New Scientist, Jacques Stern, the head of the Laboratory of Computer Science at the Ecole Normale Superieure in Paris (called the “high priest of French cryptography” in the article), says that “In future, people will look to cryptograpghers to protect their privacy”. I couldn’t agree more that this should be true, but it’s not clear to me at all that it is true. We’ve got to find new ways to communicate the rich and diverse world of digital identity to the public, to the public sector and to their management consultants. If we can’t, they’ll never be in a position to demand privacy or expect it to be implemented as part of the systems that they interact with.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Moving target

[Dave Birch] The GSMA’s NFC Technical Guidelines [PDF] point to the connectivity of mobile phones as an important countermeasure against fraud. If someone steals your phone you would certainly notice before you would notice if they stole your wallet, and once you have reported it stolen then the banks, transit operators and others can remotely disable or block the applications. Whether this statistic is true or not, the advantage of the mobile is clear:

‘The average time it takes before a person realises they have lost their mobile is around 25 minutes compared to the average time it takes for a person to realise they have lost their wallet which is around 1 day’

[From Ponderings of The Orange Cow.....: Mobile Payments - Are they Secure?]

What’s more, of course, when someone steals your credit card you have no idea where it is, but if someone steals your phone then the phone company knows exactly where it is. So there’s nothing inherently less secure about using a phone to pay. However, as a corollary, the payments guys need to understand the levels of security available on the mobile platform and the inter-relationship between the security of payment system and that platform. We can’t afford to have anything fall through the cracks.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.