Walk a mile with my shoehorn

[Dave Birch] There’s a wonderful variety of new payment systems out there, one of the reasons why I love this business so much. A good example is FaceCash: the payment is made using a barcode on a mobile screen (yet another case of innovators not waiting for operators to get their NFC act together) and the POS displays the picture of the payer so that the merchant can authenticate them. And it’s cheap.

That was enough for the Indochine restaurant in Palo Alto to adopt FaceCash. Owner Don Stewart told me he was fed up with credit-card processing fees, and that he was willing to try out FaceCash even if it means he has to install a second payment system in addition to the one he already uses.

[From Will FaceCash, the mobile payment application, kill the credit card? | VentureBeat]

I wouldn’t necessarily say that this is the perfect implementation: apart from anything else, studies show that pictures aren’t that helpful in authenticating shoppers and automatic face recognition is nowhere near sophisticated enough to make the system without relying on retail staff to make the decision. And, as an aside, if it was made to work automatically, unless it is military grade then Im sure people will figure out how to spoof the algorithm.

Using off-the-shelf makeup and accessories such as glasses, veils, and artificial hair, Adam Harvey’s master’s thesis combines hipster fashion aesthetics with hardcore reverse engineering of face detection software. The goal: to give individuals a low-cost and visually stimulating means to prevent their likenesses from being detected and cataloged by face-recognition monitors.

[From Reverse-engineering artist busts face detection tech • The Register]

Whether FaceCash is the way forward or not isn’t the point, but it illustrates a point: it is not trying use the existing retail payment infrastructure, but bypassing it because it is cheap to do so.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

They must have been cuckoo

[Dave Birch] Where are we going with authentication? Bruce Schneier made me think about this again with a post about the breaking of the Russian “spy ring” operating in the US.

Ricci said the steganographic program was activated by pressing control-alt-E and then typing in a 27-character password, which the FBI found written down on a piece of paper during one of its searches.

[From Schneier on Security: Cryptography Failure Story]

The Russian equivalent of “M” must be furious! “Doh! — if it wasn’t for those darn kids” etc. The idea that making a password 27 characters long (probably a pass phrase, in fact, since there are relatively few 27-letter words even in Russian) makes it secure is hilarious, since any user security expert would have absolutely predicted the scheme’s doom. But this led to muse in another direction, which is about how much time and money must be wasted messing around with these pointlessly long passwords that don’t actually add any real security, that are just another kind of performance art in the great security theatre. I looked back through some of my notes on that topic and came across an actual figure (for the US).

In the paper, Herley describes an admittedly crude economic analysis to determine the value of user time. He calculated that if the approximately 200 million US adults who go online earned twice the minimum wage, a minute of their time each day equals about $16 billion a year. Therefore, for any security measure to be justified, each minute users are asked to spend on it daily should reduce the harm they are exposed to by $16 billion annually. It’s a high hurdle to clear.

[From Boston.com]

So, in other words, if you made a law to stop everyone in the US from using passwords to log in to their bank accounts and insisted that they instead use some kind of 2FA that takes a minute (eg, look up OTP on mobile phone then type it in to web site — which wouldn’t actually protect against MITM attacks) then it would have to save $16 billion per annum to make it worthwhile. According to the FBI, US cyber-bank robbery is running about $100 million per month, or only about $1.2 billion per annum, so we’re better off doing nothing.

What? Hold on, there must be a flaw with this approach, and it must be that the overall cost of having the security must factor in potential losses and costs to rectify as well as user time. Anyway, the point is we need to make some strides in authentication.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Let’s make crime illegal

[Dave Birch] In today’s newspaper, I read that the Blackberry is not, after all, to be banned from Saudi Arabia as it has been from UAE.

The agreement, which involves placing a BlackBerry server inside Saudi Arabia, would allow the government to monitor users’ messages and allay official fears the service could be used for criminal purposes.

[From Saudi Arabia halts plan to ban BlackBerry instant messanging - Telegraph]

I don’t know whether it’s a good thing for messages to be in the clear or not. If I were an investment banker negotiating a deal, I might worry that someone at the Ministry of Snooping might pass my messages on to his brother at a rival investment bank, for example. After all, the idea that only authorised law enforcement officers would have access to my private information is absolutely no comfort at all.

A drugs squad detective, Philip Berry, sold a valuable contacts book containing the personal details of the criminal underworld to pay off his credit card debt, a court heard.

[From Corrupt drugs detective 'sold underworld secrets to pay debt' - Telegraph]

The idea that law enforcement would be helpless to stem the tide of international crime unless they can tap every call, read every email, open every letter, is (if you ask me) suspect. If I am sending text messages to a known criminal, you do not need to be able to read those message to decide that you might want to obtain a warrant to find out who I am calling or where I am. The fact that I am using a prepaid phone does not, by itself, render me immune to law enforcement activity.

Beyene’s role in the heist was to buy so-called dirty telephones and hire a van to use as a blocking vehicle,

[From Gunman jailed for 23 years over Britain's biggest jewellery robbery - Telegraph]

In fact this gang was caught because the police found one of the mobile phones they had been using. It contained four anonymous numbers, and from these the police were able to track down the gang members. It wasn’t revealed how, but there at least two rather obvious ways to go about it: get a warrant to track the phones and correlate their movements with known criminals or get a warrant to find out which numbers those other phones have been calling and follow the chain until you get to a known number. Yes, this might require some police work, which is more expensive than having everything tracked automatically on a PC, but it is better for society. This reminds of a recent discussion about anonymous prepaid phones. I’m in favour of them, but plenty of people are against them. (Same for prepaid cards.) Ah, but you and the authorities in some countries might ask: how can you catch criminals who use anonymous prepaid phones? Forcing people to

Earlier this month, the FBI revealed that the suspected Times Square bomber had used an anonymous prepaid cell phone to purchase the Nissan Pathfinder and M-88 fireworks used in the bomb attempt.

[From Senators call for end to anonymous, prepaid cell phones]

Setting aside the fact that this guy was caught (despite the dreaded “anonymous prepaid call phone”) and had been allowed on a flight despite being on the no-fly list, the politicians are, I’m sure, spot on with their informed and intelligent policy. In fact, one of them said:

“We caught a break in catching the Times Square terrorist, but usually a prepaid cell phone is a dead end for law enforcement”.

[From Senators call for end to anonymous, prepaid cell phones]

Amazingly, the very same issue of the newspaper that reports on the captured UK armed robbers contains a story about a Mafia boss caught by… well, I’ll let you read for yourself:

One of Italy’s most wanted mafia godfathers has been arrested after seven years on the run after police traced him to his wife’s mobile registered in the name of Winnie the Pooh

[From Winnie the Pooh leads to gangster's arrest - Telegraph]

So, basically, if you require people to register prepaid mobile phones then you raise the cost and inconvenience for the public but the criminals still get them (because they bribe, cheat and steal: that’s criminals for you). I imagine that in the Naples branch of Carphone Warehouse the name “Winnie the Pooh” on a UK identity card looks perfectly plausible: they would have no more chance of knowing whether it’s real or not than the Woking Carphone Warehouse would when looking at an Italian driving licence in the name of Gepetto Paparazzo. Again it’s not clear exactly what the police did, but from elements of the story it appears to be something like: the police discovered (through intelligence) that the godfather’s wife was calling an apparently random mobile phone number at exactly the same time every two weeks. From this they determined which phone was hers (the “Winnie the Pooh” phone) and they tracked it to Brussels. But suppose some foolproof method for obtaining the correct identities of purchasers were to be found. Would this then stop crime in, say, Italy? Of course not.

In an attempt to combat the cartel-related violence, Mexico enacted a law requiring cell phone users to register their identity with the carrier. Nearly 30 million subscribers didn’t do this because of a lack of knowledge or a distrust of what could happen to that information if it fell into the wrong hands. Unfortunately, the doubters were proven right, as the confidential data of millions of people leaked to the black market for a few thousand dollars, according to the Los Angeles Times.

[From Did Mexico's cell phone registration plans backfire?]

The law just isn’t a solution. It might even make things worse.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Points should mean prizes

[Dave Birch] I was in another conversation about mobile payments yesterday — pitching for work with a company that is looking to extend their payment services through the use of mobile phones — and shortly afterwards I got a note from a journalist asking me why there was so much attention on the topic. In both cases, my focus was not on using mobile phones as card substitutes but as using them as both card and POS substitutes. In other words, payment devices.

“Because 30% to 50% of new phones being sold are smart phones, why not use them as a payment device?”

[From Considering Mobile Payments? Some Hard And Soft Answers - American Banker Article]

Absolutely. And this is one of the key reasons why I think the mobile payment market here in Europe will follow a different trajectory to Japan, where there are sixty million phones capable of mobile proximity payments in circulation already and more than a million retail outlets capable of accepting them.

Celent’s Gillen estimates there are 28 million registered mobile-payment accounts in Japan. Of those, roughly 20 million are “active,” which Gillen loosely defines as an account the subscriber uses at least once a month. A single subscriber could have multiple payment accounts on his phone.

[From Report: Japan’s M-Payment Players Discover That Points Count | NFC Times – Near Field Communication and all contactless technology.]

But all of these millions of phones are used to make payments, none to take payments. And it is the ability to accept payments that makes mobile phones disruptive in the e-payments world. Back to Japan though: as I’ve mentioned before, most of the Japanese mobile proximity phones are live with pre-paid “e-money” accounts, but NTT DoCoMo have been very active in growing the credit account business as well.

As of March, there were 14.2 million subscribers registered for iD, of which 11.3 million were DCMX customers. And most of those were DCMX mini subscribers, who only require a quick opt-in to sign up for the service. They can then spend up to 10,000 yen (US$109) per month tapping their phones at iD terminals, with the transactions appearing on their phone bills.

[From Report: Japan’s M-Payment Players Discover That Points Count | NFC Times – Near Field Communication and all contactless technology.]

Even though customers can extend the line of credit beyond the initial 10,000 Yen, they are still using mobile “tap and go” for the smaller purchases, which tends to reinforce the view and the speed and convenience of contactless makes it a cash replacement technology, whether on a card or a phone.

DoCoMo’s Tamano told NFC Times the telco’s payment service is capturing enough low-value transactions, including purchases at the scores of convenience stores that accept iD and other contactless-payment brands. But mid- to high-value transactions were lagging. “It’s not the number of transactions; the amount used for each transaction is not up to our expectations,” he said.

[From Report: Japan’s M-Payment Players Discover That Points Count | NFC Times – Near Field Communication and all contactless technology.]

The main point of that article is that it is the value-added applications around payments, such as loyalty points and coupons, that seem to be driving the market rather than the payments themselves, which is to be expected because payments are commodity. The most interesting new thing to happen around the actual payments themselves is the agreement between Japan and Korea to work on interoperability. Japanese mobile proximity payments are to be accepted at Korean merchants and vice versa.

When the NFC- based payment system roll-out is completed, NFC phone users in Korea and Japan will be able to make mobile transactions after a simple downloading of a mobile payment application to their phones. As of late May, 3.3 million SK Telecom customers are using handsets equipped with the financial USIM.

[From SK Telecom-KDDI-SOFTBANK MOBILE Agree to cooperate on Mobile NFC Service | Korea IT Times]

What makes this interesting is that it is an agreement between telecommunications operators to deliver regional interoperability in a financial service. Will Asia lead the way in extending the use of mobile proximity payments through cross-border interoperability? Not necessarily. In China, there may not even be interoperability between the country’s two main operators, let alone with other regional operators.

China’s No. 2 mobile operator, China Unicom, and the country’s large bank-card network, China UnionPay, will launch a mobile-payment project with NFC phones at the world Expo 2010 in Shanghai–a direct challenge to plans by China Mobile to debut its RF-SIM technology at the Expo… In a not-so-subtle jab at China Mobile’s approach to mobile payment, which cuts out banks, UnionPay in its announcement said it will “adhere to the concept of “cooperative innovation” and “win-win results.” The bank-card network also said it will follow principles of “open-platform diversified technology and standardized development”.

[From China Unicom and UnionPay Take NFC Battle to Rival’s RF-SIM Turf | NFC Times – Near Field Communication and all contactless technology.]

Who knows how this will pan out. What is clear, though, is that

competition between telecom operators and banks for a dominant role in the new industry may also thwart the development of mobile payments in China.

[From Mobile payment market hurt by weak demand - People's Daily Online]

Just as it appears to have done in Europe. Where there isn’t such competition — because the mobile operators have just done it themselves (eg, Korea, Kenya, Japan) — mobile payments seem to be developing nicely.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Who to trust?

[Dave Birch] I’ve been involved in some involved discussions about an involved topic: trust (again). It happens that a number of the projects that Consult Hyperion is currently working on include implementing trust infrastructures in both private and public sectors. Now, we’re not alone in thinking that this is a big deal.

Newmark called some form of distributed trust system “the killingest of killer apps” for the web over the next decade (he said he wasn’t sure that was the best way to describe it, but was trying out to see how it sounded). He talked about “reputation and trust ruling the web, just the way it does in real life,”

[From Craig Newmark on the Web’s Next Big Problem – GigaOM]

Do they rule real life? Consider the transactions that I’ve made so far today. I took a bus — no trust required, I paid with cash — and then bought a train ticket — chip and PIN, so no trust in me required — and went to a couple of meetings — we’ll come back to this in a minute — took the train home — no trust in me required since I had a ticket — and then took the bus home — no trust in me required since I had a ticket.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Contactless experiences

[Dave Birch] Well, I’ve been using my contactless products for a while now. In practice, most of my transactions have been using my splendid Barclays OnePulse Visa PayWave product (I don’t understand why you don’t see more of these in London, since they include Oyster functionality and will auto-topup your Oyster stored-value from your Barclaycard) and my splendid pre-paid MasterCard PayPass sticker that is on the back of my iPhone. I do see more contactless terminals beginning to appear, which is good, but I’m getting more and more frustrated with the customer experience because of the way that these terminals have been configured and connected to the POS.

Here’s why.

Consider the example of (and I’m not picking on them: they’re just the last place I used contactless) Pret a Manger, which has forward-facing contactless readers conveniently located at a comfortable height in front of each POS. The payment experience is this…

  • Thirsty Coffee Addict Desperate for a Latte (eg, me), or TCA for short: “Large latte please”.
  • Helpful Pret a Manger Serving Assistant, or PMS for short: “£1.99 please”.
  • TCA taps contactless card against reader. Nothing happens.
  • TCA: “Can I pay with the new fast contactless technology please?”
  • PMS: “Yes of course”.
  • PMS goes back to POS and presses a button or two.
  • A few seconds later, the terminal display comes to life and the screen displays “£1.99″.
  • TCA taps contactless card against reader and it beeps and flashes green lights.
  • Payment is instant, but it takes another 30 seconds to print out a paper receipt that I don’t want.

Here’s how it should work.

  • TCA: “Large coffee please”.
  • PMS: “£1.99 please”.
  • TCA taps contactless card on terminal and it beeps and flashes green lights.
  • Receipt is e-mailed to me.

Simple.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Let’s put the future behind us

[Dave Birch] I happened to be looking through some old notes about mobile payments recently looking for some information about one or two ancient, sales, mobile payment systems. I came across an article called “Why banks and telecoms must merge to surge” from the Booz Allen Hamilton strategy+business magazine that I’d filed away back in 2001. It was a very good article, which is presumably why I’d snipped it and scribbled all over it, looking at the imperatives around telecommunications operators and financial services companies and concluding that some form of merger would be a good way forwward. The article pointed out that while banks have a strong hold over payment systems, mobile network operators would be challengers.

Today, banks are at another competitive crossroads. This time the new contenders in financial services are telephone companies, specifically wireless telecoms.

[From Why Banks and Telecoms Must Merge to Surge]

So while the pressures to form alliances, mergers and joint ventures of all kinds was strong, the article noted that the cultural and psychological barriers around cooperation between these two industries would need to be overcome. Which I don’t think they have been. I suppose that it’s in the nature of these things that I’ve underlined and highlighted the points that I agreed with at the time and one of them that stands out is the suggestion that of all of the stakeholders it would be card companies rather than banks who would have the most to fear from a combined mobile financial services sector. The assumption of course was that banks would continue to provide the line of credit but to new, third-party transaction services rather than to conventional card schemes. This could still happen. The article finishes up by saying that it would be logical for “mega players” such as Vodafone and Citi to combine. This hasn’t happened and I can’t help but observe that Vodafone’s most successful mobile payment service, in fact, probably the world’s most successful mobile payment service, M-PESA, doesn’t involve banks at all except as a secure repositories of funds. All of my experience over the last few years has served to reinforce my opinion from those ancient times that it’s much harder for banks and operators to work together than either of them might think. So perhaps this part of the 2001 vision for 2010 may never become reality.

I also thought it was interesting that the article correctly forecast that regulators would push for more competition in the payments arena, which has certainly happened in Europe through the adoption of the Payment Services Directive (PSD), and that this would open the door for mobile operators. In the first wave of e-money regulation, though, the mobile operators fought hard to be excluded from the provisions of the ELMI directive. With the wisdom of hindsight, I think this may well have been a mistake. Post-PSD, when the new ELMI directive comes out, I think that there is a real opportunity for the operators to combine PSD and ELMI licences to offer their own payment schemes without the involvement of banks at all.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Joe Bloggs

[Dave Birch] Having just come from a meeting about the management of multiple identities and the potential commercial structure of a proposition based on pseudonyms, I found myself reading some excellent and thought-provoking comment on the issue of anonymity vs. pseudonymity vs. absonymity starting with a US perspective over at Public Citizen.

The First Amendment protects the right to speak anonymously, and if the bar to such discovery is set too low, much citizen and consumer discussion about the important issues of our day, including the doings of corporations and politicians, will be chilled and hence lost to the marketplace of ideas. If it is set too high, valid claims may be lost. We at Public Citizen have litigated many cases devoted to setting this balance correctly.

[From CL&P Blog: Two new cases on Internet Anonymity]

I can’t say I understood everything (or, indeed, anything) in the legal argument, but I think I agree with the conclusion (applied by the US courts in the examples given) that “commercial” speech is not the same as “political” speech. Companies bashing each others’ products via “astroturf” blogs are not (and should not) be subject to the same privileges as political opponents questioning policies. But, naturally, it is a very fuzzy boundary, and one of the key issues is anonymity. If you are allowed to post anonymously, then it’s hard to

If you read through both stories you see that judges basically seem to be making it up as they go along as to what standards to use in deciding whether or not online anonymity is protectable

[From More Mixed Rulings On The Right To Be Anonymous Online | Techdirt]

Now, I would have thought that one of the reasons why we have judges is precisely so that they can make things up as they go along. If the law was written by people like me, it would be in XML and given the facts of the case as a set of propositions would be capable of delivering justice through an algorithm that would decide the outcome in polynomial time. But it isn’t, so we need judges. Sometimes they come up with odd rulings — look at the fuss about the UK judge who recently ruled that it’s not against the law to smash stuff up if it belongs to people you really don’t like — but, generally speaking, they combine law and common sense.

Unfortunately, as I have constantly complained, common sense is a bad guide to what to do about identity.

We don’t want paedophiles and nazis to be able to groom unsuspecting, innocent children online. Who could disagree with that? In the UK, this “common sense” drove a furore about Facebook that has led to an completely pointless resolution (along the lines of “something must be done, this is something, so let’s do it”).

how can the police help with every teen who is struggling with the wide range of bullying implied, from teasing to harassment? Even if every teen in the UK were to seriously add this and take it seriously, there’s no way that the UK police have a fraction of the resources to help teens manage challenging social dynamics. As a result, what false promises are getting made?

[From danah boyd | apophenia » Facebook’s Panic Button: Who’s panicking? And who’s listening?]

I would be utterly shocked if the presence of this button makes even the slightest difference. The kids who are smart enough to press it when they are approached are presumably smart enough to know that they are being approached, if you see what I mean, and the kids who press it because they are being bullied by their peers in some way are not going to get any help, so what’s the point? The “Facebook murder” that Danah refers to might just as well have been called the “Ford Mondeo” murder, since both technologies were crucial to the crime, and as she points out having this button would not have averted the tragedy.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.