Front line

[Dave Birch] I was been out pounding the beat, trying all sorts of payment experiments during my last few days in California. I have to say that the results were pretty mixed. At the airport, while being harassed by traffic cops, I couldn't find a single UK-issued card that would work in the rip-off $4 cart machines and was reduced to feeding in crumpled dollar bills (it wouldn't take dollar coins), much as my ancestors would have done. At BART, I couldn't get any of my Visa or MasterCard pre-paid cards to work (and I got an odd error message a couple of times: "bank not on file"). I did get my UK prepaid Visa card to work in a couple of shops (I discovered that when asked "credit or debit", always reply "credit" even though it's not a credit card, because if you reply debit it doesn't work). I couldn't use it in one shop because the assistant insisted I present ID, which I didn't have. Later in the day, my wife bought something with her UK MasterCard and was asked for ID so she presented her British driving licence, which was dutifully accepted even though the assistant couldn't possibly have known whether it was real or not. Come to that, they probably wouldn't have been able to tell whether her US driving licence was real or not either.

Interestingly, my prepaid MasterCard contactless sticker worked perfectly in 7-Eleven, and I have an independent witness and photos to prove it (thanks to our good friends at Glenbrook). But my UK contactless Visa cards were not recognised in any US terminals. Why? Because the sticker is MSD and the cards are EMV and the US terminals aren't reading EMV contactless (although terminals here in Singapore do).

The result of all this is, essentially, that when I walked into a shop, I had no idea which cards would work properly or not. The whole system is beginning to annoy customers, and I just can't see how it can continue this way, with US customers having their stripe cards refused in the UK and UK customers having their cards refused in the US. Time for some change.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Market failure

[Dave Birch] I was in a meeting today discussing some ideas for introducing a sort of trust service, that could fit in a framework along the lines of NSTIC but as a commercial proposition. You know the general idea: a private-sector, for-profit issuer of trust identities. The customer and the segment aren’t relevant (and I wouldn’t tell anyway), but I wanted to reflect back something I was thinking about the market. The idea that I was involved in exploring assumes, as do many similar ideas, a “two-sided market”.

In this market paradigm users and relying parties both interact with each other with the help of a platform. The platform (e.g. single players like Facebook/Google/ Paypal/etc or a network of cooperating parties) optimizes both the proposition towards users and the relying parties. The relying parties are business (including banks) and governments, all with clear business needs: relying parties achieve better e-services for their customers and lower cost of operation… If there is value, a market can come and the growth will come by itself when the trust is organized properly. It’s just a matter of getting the industry act together.

[From Innopay - Payment Consultants - home]

The problems that “e-identity” businesses might try and solve fall into the this two-sided (aka “chicken and egg”) structure, and this has so far proved a barrier. This isn’t because there aren’t problems to solve: here’s some examples of how straightforward the business problems are.

  1. I wanted a new credit card from a UK card issuer and I couldn’t use my Barclays Bank “identity” to get it. Surely this should be one of the simplest problems to solve? I just called John Lewis to find out why a chip and PIN transaction in Waitrose had been declined (a problem with the network apparently) and it took me longer to “log in” than to deal with the issue: I had to punch in my card number, date of birth, last 4 digits of phone number and then when I got through to person I had to give my name and the first two letters of my secret word. Surely card number followed by CAP/DPA OTP is all that is required?
  2. I can’t use my Barclays identity to log in to Barclaycard.
  3. The British government presumably trust Barclays, since they regulate them, but when I log on to sort out taxes or get my car tax I have to use completely different username/password combinations (ie, no security) instead of just linking my government “identities” to my Barclays identity for authentication purposes.

So despite having all of the technology already in place and deployed, there is no functioning two-sided market. I wonder if it’s because it’s just too complicated to either explain to senior management or make it accessible to the general public?

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Is more e-crime actually identity crime?

[Dave Birch] I was kindly invited along to a breakfast briefing on e-crime by the folks at International Business Wales. They are trying to develop the financial services business in Wales by bringing together business, academia and government to create a more effective infrastructure. Obviously, financial e-crime threatens this sort of development, so I can see why they would be interested in finding ways to avoid it. Naturally, I was mainly interested in the payments-related parts aspects of the discussion, but I was generally curious about the topic as a whole. Before I reflect on the presentation, an aside on the topic of financial e-crime. There's no doubt that financial e-crime is on the rise the world over: here is one just one case chosen almost completely at random:

Criminals have stolen more than $479,000 from a Pennsylvania housing development authority after infecting its computer system with the notorious Clampi Trojan. The crime is the latest in a rash of heists from small business banking users in the US, which has led some industry bodies to suggest radical lock-down procedures for companies banking online.

According to local press reports, the Trojan was installed through a fake Web site purporting to belong to Cumberland County Redevelopment Authority's bank, M&T.

Once installed, Clampi stole passcodes which were used to transfer the money to bank accounts set up by the hackers at 11 different financial institutions. About $109,000 has been recovered since the money was taken on 22 September.

[From Finextra: $479,000 heist from small business bank account lends weight to calls for online banking 'lock-down']

This is clearly recognisable e-crime, but there are many other forms. In the UK, the probably biggest single category of business fraud is VAT carousel fraud. Is this an e-crime or not? Even though the crime is perpetrated using computers, I wouldn't call it an e-crime, since exactly the same crime could be carried out in exactly the same way without computers. What about credit card fraud? That clearly needs computers to execute at scale, but again I wouldn't really call cloning magnetic stripes "e-crime". I'd give card fraud its own category.

Police in 12 countries have arrested 178 people accused of involvement in an international credit card cloning ring that is believed to have netted crooks around EUR20 million. According to the Spanish Interior ministry, the arrests come after a two-year investigation that culminated in 84 raids in Spain, Italy, Romania, France, Germany, Ireland, Sweden, Greece, Finland, Hungary, the US and Australia.

The raids turned up 11 cloning 'laboratories' with around 120,000 card numbers and 5000 fake cards found in Spain alone.

[From Finextra: Card cloning raids net 178 arrests]

What? $20m? That's peanuts. Some guy was just indicted for a fraud fifty times bigger than that.

Former South Florida lawyer Scott Rothstein was sentenced to 50 years in prison for using his law firm to run a $1.2 billion Ponzi scheme that financed a lavish lifestyle, bankrolled his firm and bought political influence.

[From Rothstein Gets 50 Years for $1.2 Billion Fraud (Update3) - BusinessWeek]

Card fraud is so last year. But on to the report.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Big bills

[Dave Birch] Having started to fill out my online tax return, and having read a lot about tax in the newspapers over the weekend…

HMRC admitted last week that 4.3 million people were in line for tax rebates because they overpaid a total of £1.8 billion in tax between 2008 and April this year. A further 1.4 million face demands for repayment because they paid too little.

[From 10 million in line for rebate after tax fiasco - Telegraph]

..it reminded me that not everyone is paying their share. The European Central Bank (ECB) is making some decent money from cash, but it may be at other peoples’ expense.

Gangsters, drug dealers and money launderers appear to be playing their part in helping shore up the financial stability of the euro zone. That’s thanks to their demand, according to European authorities, for high-denomination euro bank notes, in particular the €200 and €500 bills. The European Central Bank issues these notes for a hefty profit that is welcome at a time when its response to the financial crisis has called its financial strength into question.

[From Drug Dealer's Bill of Choice Boosts the Euro Zone - WSJ.com]

Well, I suppose in these difficult economic times then every little helps as far as the central bank is concerned, but I wonder if the morality of this operation isn’t a tiny bit suspect?

The high-value bills are increasingly “making the euro the currency of choice for underground and black economies, and for all those who value anonymity in their financial transactions and investments,” wrote Willem Buiter, chief economist at Citigroup, in a recent research report.

[From Drug Dealer's Bill of Choice Boosts the Euro Zone - WSJ.com]

When I interviewed Willem for our Tomorrow’s Transactions podcast series, he said that no €500 has ever been used for an honest transaction! You would think that there would be considerable pressure from cash-strapped European governments to start removing high-value banknotes from circulation in an attempt to reduce crime and fraud, or at least increase its cost. Never mind drug dealing, plain old fraud is a massive problem, and it means that honest taxpayers such as me end up having pay more to cover for the fraudsters.

VAT fraud is a serious problem in the EU; losses in VAT receipts from fraud are estimated to be around 10% every year.

[From Combating tax fraud and harmful tax practices: Commissioner Šemeta welcomes two important agreements in ECOFIN]

The fraudsters, by the way, are having a field day. Any new system introduces new opportunities for fraud, and the EU is not short of new systems.

European authorities believe the EU has lost at least €5bn to carbon-trading VAT fraud in the last 18 months. Europol, the EU’s law-­enforcement operation, fears the fraud will be used in other areas, especially gas and electricity trading markets, after criminals found VAT fraud was one of the most lucrative financial frauds… The fraud occurs when carbon credits are bought and imported tax-free from other EU countries, then sold to domestic buyers, charging them VAT… The three Britons allegedly set up a firm in Tournai, in west Belgium, which bought the credits in Britain and sold them on to banks via an intermediary, pocketing the 21% VAT charged in Belgium.

[From Three Britons charged over €3m carbon-trading 'carousel fraud' | Business | guardian.co.uk]

As national treasuries deplete, surely someone is going to eventually start wondering if the cash itself (in the form of high-value notes), rather than the rules about tax, that is the problem. All around the world, monetary authorities issue high-value banknotes to earn seigniorage and then lose far more than that seigniorage to crime and fraud. I understand that in Korea the new 50,000 Won bills introduced last year have made their way out of circulation and are primarily used for gambling, and I’m sure that’s not the only example of banknotes that are simply never used as a circulating medium of exchange but only as a store of value outside the formal economy.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Fail safe

[Dave Birch] A correspondent writes

We had an earthquake. Yes, we have them every day and this one was not very bad as quakes go, but it starts the news folks doing the "are YOU ready for the Big One" stories, complete with lists of things you should have on hand should local services be unavailable after a quake. One thing to have, say the experts, is some cash because, the wisdom goes, electricity will likely be out for an extended time ( and in 1994, in many parts of LA, it was) and so ATM's and retail cash registers won't work.

This is a good point, isn't it? If there's no electricity, no mobile phones, no internet, then we'll need cash to get by? But if there's no cash, then how will we get by? I discussed this before with the case study of the Irish bank strike:

For several months, almost a year from start to finish, the Irish did it all with their own paper and no banks.

[From kashklash:: exchanging the future » Blog Archive » The Irish answer]

The case study notes that about four-fifths of the money supply disappeared because of the bank strikes, so the general public were left with the notes and coins in their pockets and nothing else. How did this society function? Since people could not go to the bank and draw out more money, they developed their own currency substitutes: some people began to use Sterling instead, but it was the cheque that stepped in to keep the economy going. People began to accept cheques from each other, and these cheques began to circulate.

In summary a highly personalised credit system without any definite time horizon for the eventual clearance of debits and credits substituted for the existing institutionalised banking system.

My conclusion: in "local" transactions, business can work perfectly well with no currency and no banks. But if there's no electricity, no mobiles, no internet and no banks for more than a few days, I'd suggest we have a lot more to worry about than a lack of a circulating medium of exchange.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.