Skynet merchant services

[Dave Birch] Forum friend Leo van Hove pointed me to what may well turn out to be my favourite digital money web story of all time, a story that has literally everything: payments, POS terminals, innovation, mobile phones, Japan, contactless interfaces, biometrics and GIANT KILLER ROBOTS. OK, perhaps I’m, letting my imagination get ahead on that last point, but who can resist when you see a picture like this…

Yes, it’s The Terminator, APACS 30/40/50 version, otherwise known as the NEC iExpo 2008 prototype.

NEC’s payment terminal is modeled after a life-size android. Its torso has a touch screen panel where you can choose the e-money icon you need… the company hopes it will sell to establishments that need a reader for FeLiCa-enabled cell phones. The machines are also equipped with cameras for face recognition.

[From NEC Designs FeLiCa Payment Terminal Robot - Gearlog]

Please enter your PIN now… you have twenty seconds to comply. Given the recent discussions about POS-based card crime in the UK, perhaps there’s a breakthrough product here. Hey, bad fraud guys, try tampering with this…

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

It was 20 years ago today, again

[Dave Birch] You’ve probably already read about Visa Europe’s new trial with “PIN cards”.

The Visa PIN card features an alpha-numeric display and a 12-button keypad built into the back of a conventional credit, debit or prepaid card. The card, developed using technology from Australia-based Emue technologies, promises a three-year battery life, overcoming a potential stumbling block to such schemes in the past.

[From Finextra: Four banks to trial Visa PIN code cards]

I was playing around with one of these cards a few weeks ago, and I can tell you that they are as far as I can tell exactly the same thickness as “normal” chip cards and fit in a wallet properly (a key factor, if you ask me). Could I imagine using them? Yes, and clearly people at MBNA in the UK, Cornèr Bank in Switzerland, Cal in Israel and IW Bank in Italy are assuming that their customers will think the same, since each is to begin pilots of the PIN card in the next few months.

The cards contain two microprocessors, one of them containing the standard EMV application to support “chip and PIN” transactions, the other implementing a one-time-password (OTP) application that takes in the PIN from a keypad on the cards itself and presents the OTP on the screen that is also built in to the card itself. Thus, you can use the card to provide 2FA through the 3DS interface: instead of registering a password and then trying to remember it, you use the OTP from the card.

This isn’t a perfectly secure solution — it doesn’t defend against certain kinds of man-in-the-middle attacks — but it’s certainly considerably more secure than using phisable passwords. If the banks could offer the OTP infrastructure as a cost-effective option to third parties (including their own internet banking services), it would be even better, as I’d much rather log on to the Inland Revenue and Barclays internet banking using a debit card that worked this way than passwords buried and at the bottom of draws or dongles that I always forget!

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Mobile eye-D

[Dave Birch] OK, so I’ve been thinking about mobile phones in the identity space again, because I’ve been considering a problem around remote identification in connection with a project we’re working on. The mobile phone is an obvious focus for a solution, because everyone has one and (generally speaking ) they know how to use them. Therefore, if you have to use your mobile phone in some way to identify or authenticate yourself on the web, you probably won’t mind that much. And not having to buy some kind of dongle makes it cheaper. We have to be careful with this thinking though. As we discussed recently, we must thoughtful and not tomake unwarranted assumptions about the security of the mobile handset, applications, network and systems. People think that mobile is more secure than it actually is, and not because master criminals are planting trojan horse viruses

Though he’s seen cases in which customers were sent SMS messages that tricked them into giving up passwords or other key information, he hasn’t yet seen any cases in which losses were caused by key logging programs or other malware that infiltrated cell phones.

[From Mobile Insecurity: Reality or Just hype? - 11..2008 - Bank Technology News Article]

What we need is for end-to-end security to become standard on mobile phones and, to my mind, what that really means as a first step is a digital identity infrastructure that is rooted in the SIM. This, in itself, is not that hard. A SIM Toolkit (STK) application for creating and verifying digital signatures together with a key pair is all that is needed to get started. But so long as the handset itself remains insecure, there will always be the possibility of viruses capturing PINs and so on. If the manufacturers could get together to add some kind of trusted processing to the handset (which, incidentally, would mean that mobile phones could become approved PEDs and become part of PCI-DSS solutions) it would open up a whole new field of value-added business.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

2.5D Secure

[Dave Birch] The 3D Secure (3DS) schemes — Visa’s Verified by Visa and MasterCard’s SecureCode — have come in for a lot of criticism (from, eg, me) and it’s been getting worse recently. Card-not-present (CNP) fraud continues to climb

According to the latest statistics from banking association APACS late last month, more than 25 million UK-issued credit and debit cards are registered with either Verified by Visa or MasterCard SecureCode,

[From Merchants and punters cry foul over Verified by Visa • The Register]

I have to say that, personally, I’ve never bothered to register either of my credit cards, but plenty of people have. Here’s the issue, from my perspective as a rational consumer. I’m protected from fraud by my credit card issuer, so I have no incentive to use 3DS of any kind. Any 3DS means more hassle for me for no return. The people who do benefit from 3DS — merchants, since merchants are protected against fraud by offering me 3DS even if I don’t use it — don’t insist on it and, crucially in my opinion, don’t incentivise me to use it. If I got air miles for using 3DS, I’d use it.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Is mesopayment a useful word?

[Dave Birch] I was at Ian Harris’ Gresham College lecture on commercial ethics, and whether teleological approaches can be reconciled with deonological processes in a procurement process, when I saw him use a word that had never occurred to me before in a payments context but I desperately needed. Ian was talking about the scale of decisions and used the simple categorisation of micro, meso, macro. Aha! Now it all makes sense. A payment of less than $1 is a micropayment, a payment of less than $10 is a mesopayment and a payment of over $10 is a macropayment and a payment of over $10,000 is a megapayment. Does my new classification scheme work?

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The numbers game

[Dave Birch] I was privileged to be invited along to the Home Secretary's talk on the roll-out of ID cards (not, sadly, because she reads this blog but because I'm a member of the IPS advisory forum). It was basically an update on the development plan outlined earlier in the year, explaining where the procurement is and what happens next. I imagine the focus of the media coverage will be the announcement that the original plan for all airport "airside" workers to get ID cards in the near future has been revised to an experimental 18-month trial of ID cards at two airports (London City and Manchester) and the confirmation that cards for foreign nationals will start on 25th of this month.

She also talked a little about a potential competitive market for enrollment services, which I think is management consulting fantasy (there's no reason to do anything other than enroll at certain post offices, which would provide a convenient income — Jacqui estimated £200m per annum — for a network threatened with politically unpopular closures and go with the grain of public expectation), and mentioned that a trial enrollment of 15,000 people had successfully detected duplicates and had no failed enrollments at all.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Small change we can believe in

[Dave Birch] You can’t accuse this blog of not keeping up with change in current events. For example, I notice in my Daily Telegraph that there has been an election in the United States and there’s going to be a change of President. At these times of great change, I turn to economists to inform us as to the key monetary and fiscal changes that the new leader of the free world should adopt. I heartily endorse these two important policies concerning change:

# Get rid of pennies.
# Replace the dollar bills by dollar coins.

[From Economic Logic: Change I can believe in]

Hear, hear. I cannot understand the attachment to the dollar bill, even taking on board the inherent conservatism of people towards money. My American wife, who suffers taxation without representation here in the Mother Country, tells me that the issue is psychological. A dollar coin would make people feel that a dollar isn’t worth very much any more. Which it isn’t: it’s worth literally a fraction of what it was worth when it was first issued as a note.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Personal development

[Dave Birch] I was given a useful insight into a different perspective on identity, the developing countries perspective, when I spoke on a panel at the Chatham House conference on Technology and Development. I’d actually been invited along because I know about mobile payments and mobile banking in developing countries, not because I particularly know anything about NGOs, foreign aid or so on, but it gave me the opportunity to sit in on some discussions that I wouldn’t otherwise have heard. For example, one of the audience asked a question about the deployment of mobile phones in the development world, a question that would never have occurred to me. The question was about security and privacy, and I won’t violate Chatham House rules by giving away an identifying information, suffice to say that the core of the question was about the use of mobile phone data, mobile phone location information, call records and billing information. In some countries, where you are and who you call is dangerous information that can have disastrous consequences.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

And now, time for the money forecast

[Dave Birch] One of the functions of banks has already been changed forever by the Internet, and that’s what economists call the information function. People used to rely on banks to provide certain kinds of information into the market (eg, credit ratings) but a combination of technology-enabled business change and vanishing delivery costs has meant that they are themselves consumers of exactly the same information as non-banks. (This is not the same point as the current debates about the privledged role of “agents” and information asymmetry which focuses on the knowledge gap between bank shareholders and bank managers as a contributory factors in the financial crisis.)

This is hardly new thinking — I can remember discussions a decade ago pointing out that some kinds of information were out of bank’s hands and that (given all sorts of constraints to do with data protection, competition law and so on) the operators of payment networks could use the “data exhaust” from their transaction networks to create information to “turbocharge” other businesses (it was the 1990s, remember). Indeed, I worked on a project for SWIFT to look at his kind of thing in (if I remember correctly) the late 1980s.

Now, advances in “web 2.0″ technology mean that this turbocharging is both technically trivial and incredibly powerful, providing ways to create new kinds of information that would never have been generated by banks internally nor made available to the market as a whole. A favourite example of mine, that I originally found thanks to our friends at Payments News, is that courtesy of the New York Fed you can see U.S. bank card delinquency by county, and thus get yourself a real-time map of the credit crunch sweeping across the nation, like bad weather.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.