Security matters, but why?

[Dave Birch] At the M-Payments and M-Banking conference in Madrid there was a super presentation by Karin Huber on Mobicom’s experiences with mobile payments, ticketing and related value-added services in Austria. One thing that Karin mentioned in passing was that, in the Austrian market, it seemed as if consumers were using fears about security as a means to rationalise their concerns about mobile in general: they didn’t like registration and other aspects of the service. In a way, they weren’t really concerned about security at all. This factors in with something else I’d been thinking, which is that consumers don’t really understand security and they certainly don’t understand risk (all poll evidence confirms this in spades). Therefore, what consumers want is for their bank, payments providers and merchant to give the appearance of security, which is something different.

I had to phone up to activate a credit card recently, and when I called the activation “hotline” advertised by the sticker on the card, I was put through to someone who tried to sell me identity theft insurance. “Are you concerned about identity theft” they asked me. I said that I wasn’t, and the reason that I wanted a credit card was precisely so that if anything went wrong, it was the bank’s problem and not mine. This, incidentally, is why I never use my debit card except at ATMs. But after I hung up, I wondered if that is the right image to deliver to credit card customers. Isn’t reminding them that card fraud is massive going to drive them away from using their cards rather than reassuring them? Are there any psychologists out there who can help? If people don’t, indeed, understand security but are using it is a placeholder for all sorts of other concerns, then it is possible that the payments industry may be making some bad decisions about how much security to implement and how to implement it. Perhaps people might feel more comfortable using their mobile phones (which are perceived as personal devices) rather than dongles, widgets, passwords and PINs and so even if the actual security might be lower than in another device, the overall security of the system goes up because more people use them rather than wholly insecure means such as passwords.

As an aside, for m-payment nerds, Karin also said some very interesting things about Mobilcom’s decision to fold TSM functionality into the infrastructure. But that’s another story.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Born on the 4th of July

[Dave Birch] Appropriately for today I’m reading Jason Goodwin’s Greenback. It reminds me just how much the birth of America and the birth of modern money (ie, paper) are intertwined. Regarding the most famous document of 1776, he says

There is a niggling list of grievances right at the beginning of the Declaration of Independence which seemed, at the time, crucially important, though few people nowadays read or remember these. The first two blame parliament for ignoring laws passed by colonial assemblies, and what they actually mean is: we agreed to have paper money, and you simply shut us down.

Remember Patrick Henry’s impassioned denunciation of King George as a tyrant? It was about paper money, the latest in the series of experiments — starting with wampum — that helped America to develop as an economy in its own right, despite the British mercantilism prevalent at the time. In Britain, money was about custom and generations of practice, implicit in the structures of society. In America, money was invented: a creature of the law, whether seashells, tobacco or paper. As Goodwin so nicely puts it

Paper money cost nothing to produce; it was just a promise, like America.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Really filthy lucre

[Dave Birch] Here’s another good reason for replacing paper money with electronic money: it’s filthy and contaminated. Apparently there’s not that much real money laundering going on!

public health authorities say these tests show that paper money is dirty – and an effective vehicle for the spread of germs through the population. While minute amounts of cocaine might be harmless, bacteria, viruses and spores clinging to banknotes passed from hand to hand might not be.

[From Paper money makes the germs go 'round]

The mention of cocaine is almost mandatory in these reports, since almost all banknotes in Western countries are contaminated by the drug. I wonder if we might discover something about our societies by delving into the statistics?

German Euros contained levels of cocaine that were five times lower than the Spanish ones. For Irish bank notes, one statistic suggested that of 48 notes studied the highest concentration found was 0.5 micrograms. The chemists found U.S. bills contained an average of between 2.9 and 28.8 micrograms of cocaine depending on the year and city, with a maximum of more than 1,300 micrograms found on some 1996 bills. One study based on 356 notes showed just 6 percent of Swiss francs were contaminated with cocaine at levels above one nanogram per note… between 40 percent and about 50 percent of British pounds were contaminated with cocaine at levels of about 0.0011 micrograms per note.

[From U.S. money contains highest traces of cocaine - LiveScience- msnbc.com]

This looks like scientific proof that drug dealers prefer U.S. dollars but money launderers prefer Swiss Francs. It seems a shame to lose this rich ecosystem by replacing it all with mobile phones and chip cards!! (I do remember though that I once met a chap who had a business cleaning disinfecting mobile phones that had been returned for repair under warranty before they could be refurbished and sold, and he told me that mobile phones were covered in germs too.)

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Interdisciplinary ideas

[Dave Birch] Someone mentioned iris biometrics over coffee which reminded me again that, a couple of weeks ago, I had stimulating day out at the 2nd interdisciplinary workshop on Identity in the Information Society at the LSE. Many thanks to James Backhouse and the team for putting together such a great programme. I really enjoyed Kevin Bowyer’s keynote on iris biometrics and wanted to highlight one or two of the points that he made. You can read the paper for yourself, but a few key findings were that:

  • Pupil dilation has an impact;
  • Contact lenses have an impact;
  • Sensor changes (ie, someone has been enrolled on one system and is being matched on another) have a significant impact (even when using the same software);
  • Irises change over time more than had been anticipated. The effect on false reject rates is small, but measurable,

In all of the cases, it is the match distribution that is changing: in other words, it’s “fail safe” in that the system behaviour is such that false rejects go up but false accepts do not. So not too bad. But at population scale, the number of false rejects will still be enough be noticeable and dealing with the false rejects effectively (which might mean different things in different environments) will be central to the success of schemes.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.