I didn’t want to write about fraud yet again, but…

[Dave Birch] The U.K. remain Europe’s largest exporter of card fraud, and it looks as if this year we’re going to do even better than last year. Total card fraud last year was UKP 535 million (about a billion dollars) but the half-yearly figures for 2008 are predicting a full year well in excess of UKP 600 million. The prospects of fraud reducing remain, I think, slightly gloomy. SDA clones (of French cards, luckily) have already been found in Europe and I would imagine that we’ll begin to see SDA cloning on a large scale over the next twelve months as the ICVV base expands. When you add this to the lack of a mass market solution for EMV in the Internet/MOTO environment, there is no possibility of U.K card fraud falling over the next year. 3D-Secure technology (Verified by Visa and MasterCard SecureCode) has not even dented the problem. Despite the fact that nearly 20 million cards have been registered for 3DS in the U.K., and the fact that a tenth of e-commerce transactions are already 3DS verified, the CNP fraud figures are increasing remorselessly. I have heard some anecdotal evidence that some customers are switching from cards that are 3DS to cards that are not, simply because they can’t be bothered with the 3DS authentication when they’re buying online. And, rationally, why should they even care? Consumers are protected whether the transaction is 3DS or not so unless the retailers the incentivise them to use 3DS instruments, why would they bother?

At some point, I assume, fraud will get so bad that banks will be worried about it. That’s some way away, of course, since in the U.S. fraud is well under 1% in card portfolios that have bad debt well in excess of 6%, so I know which area will be attracting most management attention for the foreseeable future. It’s clear that chip and PIN isn’t going to crack the problem by itself, so we’ll have to start looking around for the next generation of card technology. Since the cards themselves will be disappearing into mobile phones, that would suggest that the banking sector begin ramping up their efforts in mobile. Which, of course, they already are.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The future is another (virtual) country

[Dave Birch] In many countries the banks have begun to issue 2FA tokens of one form or another. In some places, such as Singapore, 2FA is already mandatory for home banking, and everyone is used to carrying around their token. In many companies, people use 2FA tokens of one form or another for intranet and VPN access. Authentication is improved tremendously, hurrah. But the “necklace problem” looms. The necklace problem is that if you need half-a-dozen different tokens to log in to your different bank accounts and corporate systems, not to mention government services, then you will have to carry them around your neck or risk not having the right one by your side when you need to do something. Oddly, despite the existence of (for sake of argument) SAML or OpenID, none of the tokens that I have in my possession are in the least bit interoperable. My Barclays token doesn’t even help me log in to another U.K. bank, let alone the U.K. government or a corporate site.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Rosemarie Wilken, Fundamo

[Dave Birch] Rosemarie is a Regional Executive at Fundamo Limited, and specialises in consulting to and supplying Mobile Banking and Payments solutions globally. She has an MBA (cum laude) with her dissertation being on Prepaid Mobile Telephony in Africa. Currently Rosemarie manages business development and customer relationships for Fundamo’s Global Partnership Programme as well as Resellers in the Latin America and Asia Pacific Regions. Rosemarie’s experience in the Mobile Telephony industry spans over 13 years where her role has varied from consulting and company directorship at mobile operators in Africa to market development and software business development relating to secure mobile transactions internationally. In this podcast, she talks about the growth of mobile payments and mobile banking in emerging markets.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Codpiece

[Dave Birch] Now that Britain has declared the nation of Iceland to be part of the axis of evil…

The freezing order against Landsbanki, which owns failed internet bank Icesave, was issued under the 2001 Anti-Terrorism, Crime and Security Act.

[From Iceland bank freeze 'used anti-terror laws' - politics.co.uk]

…a new Cod War may be just around the corner. Hence it is diverting to remember the previous cod wars and the key contribution of the Icelandic people to the story of cryptography. Implausible as it may sound, I have in front of me a splendid book by Mark Kurlansky called “Cod: Biography of the fish that changed the world“. Within its pages it a lovely story of the neverending struggle between security and new technology.

The Anglo-Danish Convention of 1901 gave the British permission to fish up to three miles from the coast of Iceland, a state of affairs that the volcanic colony was most unhappy about. By the late 1920s, the Icelandic Coast Guard had started to arrest British (and German) trawlers found within its (as it saw) territorial waters. From 1928, the British trawlers were equipped with radio and started passing coded messages between themselves to alert each other when Coast Guard vessels were in and out of harbour. “Grandmother is well” meant that the Coast Guard were in port, for example. In an early example of governments attempting to legislate new technology, the plucky Icelanders made it illegal send to coded wireless messages. This had no impact whatsoever, of course: British seafood companies simply devised new code systems for the trawlers to use. Think about it: how on Earth would an Icelandic wireless operator know whether “Tottenham Hotspur are the pride of North London” was a coded message or gibberish? Then came World War II. Iceland got independence from Denmark in 1944, but more importantly the British trawlers were requisitioned for the war effort, so Iceland found itself with the only fishing fleet in Northern Europe and Britain’s “sole” supplier (tee hee).

Things were quiet for a while, until the First Cod War in 1958 when the might of the Royal Navy (which was recently told not to arrest Somali pirates in case they claim asylum) was deployed against the Icelanders. Then, in 1972, the Cod War started. Iceland extended its territorial waters to 50 miles and the British once again sent the fleet. But in the intervening period, the Icelanders had developed and deployed a secret weapon (literally: it was a closely-guarded secret until first use). The Icelandic Navy could never outgun the British Navy (and in any case didn’t want to actually shoot at us) so they assembled a fiendish weapon: a net cutter. When they found a British trawler, they would sail behind dragging a net cutter and the trawlers net (worth a lot of money) would head for Davy Jones locker while the fish made for the underwater hills. Things did turn nasty — with ships getting rammed and live shells being fired, the Icelandic government refused to allow injured British seamen treatment — until eventually NATO made Britain back down.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Separation, not divorce

[Dave Birch] The European Commission has, admirably in my opinion, been trying to introduce competition into the payments world, hoping that competition can deliver a better payment system. The Electronic Money Directive and the Payment Services Directive have opened up new regulatory categories for non-banks and while these have yet to make much of an impact, recent events may well have persuaded the public that money issued by, let’s say, Vodafone or Virgin is worth a try when compared to the money pouring out of government printing presses to bail out the bankers! Current issues aside, though, anyone looking at long term business trends must be wondering to what extent the payments industry will remain part of the banking industry.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Vox populi

[Dave Birch] An interesting anecdote from one of the contactless payment roll-outs in Europe, as reported to me from a credible source. A student was overhead talking to a friend, saying that he had got up, taken the subway into college, worked all morning, gone out to get a sandwich and juice and lunch time, worked in a lab all afternoon and then taken the subway home. On arriving home, he found his wallet on the kitchen table. Amazing story, I think. And while it certainly has some hard to believe aspects (working all morning — yeah right), the fact that the student was telling someone about this strikes me as an interesting confirmation that pockets, albeit small pockets, of cashlessness are beginning to emerge.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Unscientific

[Dave Birch] The current issue of Scientific American has a special section about privacy (there’s a podcast with the editor here) and it made for a diverting read for me, because I tend to see privacy through the digital identity prism rather than from a wider (albeit still technological) perspective. So instead of thinking about privacy in “mechanical” terms — which digital identities are allowed to validate the credentials of which other digital identities and under what circumstances — I’ve been thinking about privacy in social terms and wondering if this different perspective leads to different conclusions about the way forward.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

We’re from the government and we’re here to help

[Dave Birch] Even if you don’t understand the intricacies of the credit crunch or the precise mechanism by which investment bankers have greatly enriched themselves while beggaring the rest of us, you must be wondering why on earth we spend so much money on regulators and regulations, directives and directors if they couldn’t prevent (or apparently even mitigate) a calamity on this scale. As Chris Skinner asks

With SEPA, the PSD and MiFID all paling into relative insignificance as the major banking markets explode globally, there are questions about whether the European plan will succeed or is even needed now

[From The FinanSer: Are Europe's plans for Banking, MiFID and the PSD irrelevant?]

This is a very good point. If regulation serves only to hamper innovation but fails to deliver any commensurate benefits in stability of security, then what’s the point of it? Right now, it looks as if European initiatives in the finance sector have been a waste of time and money. They certainly haven’t worked as intended, either through a process of watering down (as in the case of the Single Cards Framework, the SCF) or through irrelevance in other cases. The Banker, more charitably, says that the EU is undergoing massive regulatory upheaval and while the goal of a single market in financial services may in principle be worthwhile…

As with all regulatory initiatives, not all the outcomes are exactly what the policymakers intended and The Banker has reported faithfully on a number of significant deviations. There are lessons to be learned from these failures as, no doubt, other parts of the world are planning to adapt the European model for their own uses.

[From The world can learn from EU’s regulatory shake-up mistakes - The Banker]

Still, as The Banker notes, we should take comfort from the fact that some scraps of usefulness might accidentally be left behind as many regulatory initiatives are swept away, saying that

Some of it will eventually come out right and Europe will be left with a half-fixed system.

[From The world can learn from EU’s regulatory shake-up mistakes - The Banker]

Frankly, given the costs of SEPA et al (which are several billions of euros), I think we ought to expect a little more than an almost coincidentally “half-fixed” system. When it comes to payment systems, I’m certain that a further separation between banking and payments is a way to move forward. It’s a combination of inactivity and accident that has led to payments being regulated, managed and delivered within banking and the goals of initiatives such as the Payment Services Directive are hardly coincident with the goals of banks

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Secure opinions

[Dave Birch] At the Mobile Banking Security conference in Vienna — which was very good, by the way — I gave a short introductory talk explaining to the delegates that I felt that security needed to improve at all levels to push the development of the sector: the regulatory level, the business level and the technology level. In his talk, however, Ivan Mortimer-Schutts of BNP Paribas asked a question that I didn’t, and which should frame some of the debate about security at all of these levels: is there a tradeoff between security and innovation in the mobile space and, if there is, is that tradeoff currently positioned correctly. You can see what he means: if we demand complete security at every level, aren’t we going to hold back innovation and stifle competition? And if we are, is that good or bad? After all, you might reasonably argue that some parts of the banking world might have benefited from substantially less innovation over recent times.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Mobile focus

[Dave Birch] At NFC conferences these days (I’ve just got back from NFC World Asia) there tends to be a focus on using the NFC-equipped mobile phone for payments of one form or another, but I am convinced that identity management should be getting just as much attention. The idea that you could leave home with only your phone and no wallet depends on the phone replacing all of things in your wallet, not just a couple of cards.

The point was made that to focus only on speed of transaction though was to miss the areas of convenience, security and the concept that people will leave home without their wallet but not without their phone. I think the latter point is a stretch to think that “mobile commerce will be driven by people without their wallets” – after all they still need their driver’s license to commute in their cars and office badge to get into many buildings. This is cash replacement and not a card or wallet replacement strategy.

[From Glenbrook Partners: Report from CTIA - Mobile Payments Eventually]

Absolutely. But that’s not to say that a wallet replacement strategy is not plausible, if we use the mobile phone as the platform for digital identity infrastructure as well as digital money infrastructure.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.