Making a silk e-purse

[Dave Birch] Throwing out some old papers, I came across a Datamonitor report from 1996. It was projecting the use of online payments through to 2002 and suggested that credit cards would account for about half of the market (a small decrease) whereas digital cash would account for something like a quarter of the market. Now, as we all know, this didn’t happen. But like many other people at the time I thought it would. Why were we so wrong? In my case the reason for the utterly wrong prediction was transaction cost calculations. Like many other people I sat down with a spreadsheet and worked out that it would be a lot cheaper to pay for things on the Internet using e-cash rather than conventional banking infrastructure. For example…

  • Conventional means to pay gas bill. Phone up with credit card (3%), debit card (10p) or direct debit (4p).
  • New means to pay gas bill. Insert Mondex card in reader. Click to download UKP23.45 from bank account to Mondex card. Go to British Gas web site. Click to transfer UKP23.45 from Mondex card to British Gas. Total transaction cost: zero.

Of course, the cost of issuing Mondex cards and smart card readers is amortised to near-zero here. But it doesn’t matter, since none of it ever happened. It turned out that the transaction costs were irrelevant, because getting people to plug a smart card reader into a PC was a huge barrier on the acceptance side and getting banks to put a Mondex application on a smart card was a huge barrier on the issuing side. Customers, however, rather liked the idea of e-cash, and many would still prefer to pay this way.

Research this week from Prepaid Services (that operates Cash-ticket) found that around a third of shoppers would prefer to use cash rather than a credit card when paying for goods online.

[From Untitled]

It has to be easy, and it has to work. But it’s an interesting point to consider with hindsight: why did we make systems such as Danmont, Mondex, VisaCash and use them to compete with cash in the physical world rather than use them in the virtual world where there was no cash? I suppose at the time the world of the Internet was considered a novelty, not central to the world of banking and payments, so the idea of creating an e-cash system specifically for the Internet was considered the province of technology startups rather than banks. That’s not to say that people didn’t try: DigiCash, remember, and there were a variety of other ideas floating around such as Millicent, Hashcash and all the others. At the time, I was on the hardware side of the debate: that is, I couldn’t see how such a system would work in software and assumed that it would be the bank who would provide the tamper-resistant hardware (correct: the chip card) and the interface to the PC. These interfaces never materialised in the mass market, so that they never got a foothold before the falling cost of chips and telecommunications combined with massive economies of scale to give debit cards and unassailable lead at retail POS.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Magic bullet it’s not

[Dave Birch] I was in a meeting recently, the context is not relevant, where some of the Consult Hyperion team were helping a customer to develop a roadmap that included in a future transition to biometrics, and a discussion began about whether biometrics in certain kinds of mass market systems are about security or convenience (I’m convinced that they are about convenience, but that’s another discussion) and, if they are about security, whether existing biometrics are “secure enough”. “Secure enough”, though, is a complicated assertion — I’m glad to say, otherwise our risk analysis business wouldn’t be around for long — and this reminded about about a story from the Gulf about a woman who had been deported and then re-entered because her biometrics didn’t match the ones of hers on the “already been deported” register.

Although there were glitches in the system when it started, “for the past three or four years, we have not heard of a single case of someone getting around this”, the representative said.

[From Iris scan fails to stop returning deportee - The National Newspaper]

But this is illogical, isn’t it? If there were glitches in the system that allowed people to get through, then the bad guys would learn about this pretty quickly. People who are getting through on forged passports and not being recognised by the iris-recognition system are not going to report the system’s failure. So how would anyone know? It’s only when a failure comes to light through some other route that the failure is “logged”. So while the system is apparently working perfectly, in reality it isn’t. Let’s hope that a more detailed investigation in the UAE reveals that this woman’s irises were not scanned on re-entry or it will be back to drawing board for many people.

As readers will know, I like the idea of a “gold standard” biometric database, comprising iris, face and finger biometrics, to ensure the uniqueness of identity numbers (and that’s all). Adding biometrics to any identity system isn’t a “magic bullet”, but having a system that is founded on guaranteed uniqueness achieved through the use of biometrics might just be.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Throwing good zinc after bad

[Dave Birch] Well, it looks as if the e-money boosters such as yours truly have suffered a setback because of the great financial crisis.

About 42% of consumers are using more cash than they were a year ago, according to the survey, due out today from the consulting firm Market Strategies International. (Thirty-nine percent of the 1,000 respondents polled in January said they were using less cash than a year earlier, and 19% said they do not use cash.)

[From Back to the Greenback? Consumers Turn on Cards - US Banker]

So almost a fifth of Americans say that they do not use cash? I guess we’re making some progress. But not everyone is happy with the Yankee dollars.

The US is the laughing stock of the world when it comes to our money. Our bills all look and feel the same, and only last in circulation for a few years. We have coins that can buy literally nothing, and cost far more to make than what they are worth. The time might be right to put currency reform on the table with any financial reform package.

[From Time For Change To Change | NEWS JUNKIE POST]

It costs them nearly two cents to make a penny: if that was your business, you’d get out of it. But the Feds have decided to make cheaper pennies instead.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The parable of Woking

[Dave Birch] Many years ago, as I was reminiscing to a bored audience today, when I was involved with the Mondex project, I can remember writing some enthusiastic pieces about cashless payments. I used the car park at my local train station, Woking, as the exemplar. This is where I, and a great many other commuters, came face to face with the cash menace on a daily basis. I used to drive to the ATM to get cash, then go to the petrol station to buy a newspaper that I didn’t want in order to get some change, and then go to the car park and use the change to buy a ticket. It was a couple of quid for the ticket, and I can remember standing up at conferences and enthusing that the car park would be the ideal place to demonstrate the value of digital money to the Great British Public.

It never happened.

In the short term, Woking Borough Council fixed the problem by putting the cost of parking up to eight quid and installing ticket machines that took credit cards. Indeed, Consult Hyperion worked for a couple of the service providers in this area, helping with chip and PIN business models and migration plans for the unattended terminals.

Over the last four or five years, I never once paid at the car park with cash. I always used a card, except for the one time I can recall when the card machines were out of service (I bet it was a software upgrade that went wrong, otherwise why would they have all gone down at the same time?). I can well remember being totally pissed off that I couldn’t use a card and had no cash, so I just left a note on the dashboard saying something like “sorry no cash, fix the machine and I’ll pay when I get back”. I fully expected to get a fine, but the wardens were clearly sympathetic that day.

A couple of years ago, I began to wonder if the transition to contactless might be an opportunity to enhance the parking experience still further: quicker and more convenient for the customer, less fraud (there was a certain amount of fraud at the machines because they didn’t use PINs) and the potential for robust, maintenance-free contactless-only outdoor units. Like many other hapless commuters, I also wondered if our good friends at TfL might extend the remit of the Oyster — which 99% of commuter using the car park have in their wallets — so that you could zoom up, tap your Oyster card, grab the ticket and go.

Once again, the leading edge of retail payments remained tantalisingly out of reach of the Woking station car park. No contactless interface of any kind, either EMV or Oyster, arrived.

Now, however, the next chapter in the Woking payments story has been opened. The card slots have been taped shut, and you can no longer pay with cards of any description, contactless or otherwise. Why? Because 40% of the parking sessions are now paid for by mobile phone using RingGo.

RingGo, which we discussed in a podcast a year ago, gets you to open an account and register a payment card. Then when you want to park, you call them and punch a couple of keys on your mobile phone. That’s it.

The typical user experience is now…

I drive to Woking train station and park the car, go and get on the train. Either on the platform waiting for the train, or on the train, I call RingGo. The IVR says “do you want to park the same car at the same place as last time, punch 1 for yes” or something like that. I punch 1, then I punch 1 again to park for one day. Then I punch in my CVV, and hang up. A second or two later a text message arrives confirming the session.

The parking wardens have PDAs that list the registration numbers of the cars legally parked, so that’s how they check whether you’ve paid or not. If they don’t see a ticket on the dashboard, they punch the number in to the PDA.

Having registered with RingGo at my local car park, it is of course now my first choice at other car parks. I stopped in at PayPal in Richmond the other day, and was delighted to see that the car park opposite them takes RingGo. What a relief: no more scrabbling around under the car seats to find change.

Having allowed mobile to get a toehold, it’s really not clear to me how contactless cards, or bank mobile payments, can fight back. I can well imagine that in a year or two, there will be car park levels that are RingGo only so that they council can take out the ticket and coin machines completely and cut their maintenance costs to zero.

After that, RingGo will get fed up paying for card payments so they will come to regular customers like me and offer me a discount for signing up to a monthly direct debit or for loading a prepaid account instead of billing to a payment account.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

On the money

[Dave Birch] As I blogged before, Consult Hyperion has joined forces with Identrust to sponsor the Digital Identity Forum track on “Identity is the new money” at this year’s European e-Identity Management conference in London on 9th-10th June 2010. Having been through the usual juggling as people drop in and out, get called away to meetings and mess up their calendars, the final line-up is now as fixed as it can possibly be:

The Digital Identity Forum: Identity is the New Money
Sponsored by Consult Hyperion and Identrust

Session 1: Chaired by John Bullard, Identrust

13:15 John Skipper, PA Consulting
13:45 Vincent Jansen, Innopay
14:15 Sonia Rossetti, RBS
14:45 Giles Sergant, Touch2ID

15:15 Tea

Session 2: Chaired by David Birch, Consult Hyperion

15:45 Expert Panel on the Identity Business

Joe Norburn, Identrust
Robin WIlton, FutureIdentity
Jan Dart, Bell ID
Todd Facemire, Barclays

16:45 Expert Panel on Identity and the Consumer

Peter Bradwell, DEMOS
Henry Potts, UCL
Marc Dautlich, Olswang
William Heath, MyDex

17:45 Close.

Look forward to seeing you there. By the way, the promotional code EID10DIF will give your delegates 20% OFF of one or two day passes.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Spot the looney

[Dave Birch] I happened to be chatting to our friend Tony Poulos from the Telecommunications Manager’s Forum about new service possibilities for mobile operators facing commoditisation and declining ARPUs, and one of the areas he got me to brainstorm was identity services.

One of the world’s leading experts in this field, David Birch, spent some time with me explaining how mobile operators, in particular, could actually become ‘smart pipes’ with financial transactions. The ‘secret sauce’ according to Birch, lies in the ability for operators to provide secure identification linked to the SIM providing private and public keys for multiple providers.

[From The 'secret sauce'? | Poulos Ponderings]

The mobile phone is the obvious “remote control” for identity, and I’m surprised that operators haven’t moved into this space more aggressively (there are some exceptions, of course, such as Turkcell). This led me to think, again, about the nature of the value-added identity infrastructure that might be built.

One thing, I think, is clear: the goal shouldn’t be to build a virtual version of the current identity “system”. At the moment, the online world has a dynsfunctional identity layer: it’s not really anonymous but it’s not really absonymous either.

Implementing an Internet without anonymity is very difficult, and causes its own problems. In order to have perfect attribution, we’d need agencies — real-world organizations — to provide Internet identity credentials based on other identification systems: passports, national identity cards, driver’s licenses, whatever. Sloppier identification systems, based on things such as credit cards, are simply too easy to subvert.

[From Schneier on Security: Anonymity and the Internet]

Bruce goes on to note that in the real world, half-baked identity management schemes actually make matters worse, not better. You can’t argue that having people sort-of-identified is better than having them not identified at all. It isn’t.

We have nothing that comes close to this global identification infrastructure. Moreover, centralizing information like this actually hurts security because it makes identity theft that much more profitable a crime.

[From Schneier on Security: Anonymity and the Internet]

This is why I am naturally somewhat suspicious of attempts to slap identity on the ends of the network rather than having identity management as a value-added service that is part of the network infrastructure and quite distinct from the issue of which identities will be managed (in other words, the web server has PKI built in, but it doesn’t provide the identities, it facilitates identity providers to do so). Simple solutions to this difficult problem — along the lines of the Chinese attempts to have “real-name registration” of Internet access by decreeing that everyone has to present their ID number when connecting — don’t work.

Mundie and other experts have said there is a growing need to police the internet to clampdown on fraud, espionage and the spread of viruses. “People don’t understand the scale of criminal activity on the internet. Whether criminal, individual or nation states, the community is growing more sophisticated,” the Microsoft executive said… He also called for a “driver’s license” for internet users. “If you want to drive a car you have to have a license to say that you are capable of driving a car, the car has to pass a test to say it is fit to drive and you have to have insurance.”

[From UN agency calls for global cyberwarfare treaty, ‘driver’s license’ for Web users | Raw Story]

It’s a bad analogy for a start, because cars are covered by product liability laws and Microsoft’s software isn’t, but the law on driving licences doesn’t stop cars from being stolen, used in crimes and being in accidents. If there were an Internet driver’s license, the 419 scammer wouldn’t apply for one, he’d make a fraudulent one just as he would in the physical world, and then use it to open bank accounts and so forth.

Many of the forgeries are “know your customer” documents such as utility bills and driving licences, which are then used to open bank accounts under false names.

[From Police war on fake ID factories as fraudsters net millions | News]

Ah, you might say, but in the Internet world we can use cryptography and similar geek tools to stop people from forging licences. In which case, the scammers will still get their licences.

An Irvington, N.J., man who operated a driving school pleaded guilty yesterday in federal court to bribing Pennsylvania driver’s license examiners to obtain phony licenses for his customers… Authorities said Lominy began paying bribes to a PennDOT driver’s license examiner, Alexander Steele, in early 2009 in exchange for Steele issuing licenses to his customers even though they weren’t Pennsylvania residents and hadn’t passed a written test or driving exam.

[From He admits bribing PennDOT examiners to issue fake licenses | Philadelphia Daily News | 04/02/2010]

I see reports of people being convicted for taking other people’s tests for them for money in the UK from time to time as well. So, an Internet driving licence? I don’t think this is a way to improve security. I might go further and say that compared to this, the Monster Raving Looney Party’s manifesto commitment to ban envelopes and force everyone to communicate via postcards looks more practical.

All sealed private letters to be banned – we propose that all letters must be written on postcards, and emails to be routed through police stations. (After all honest citizens have nothing to hide)

[From Official Monster Raving Loony Party - manifesto proposals]

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.