A channel challenge

[Dave Birch] Writing in E-Finance & Payments Law & Policy (volume 4, number 9), Dan Schutzer (the Executive Director of the Financial Services Technology Consortium, FSTC) writes on “Challenges of the US banking and finance channels”. He notes that innovation in the US seems to be centred on the mobile phone and can be divided into three categories: innovations that mean new payment networks, innovations that use existing networks but bypass banks (note that both Visa and MasterCard have followed PayPal in opening up their APIs) and innovations (often targeted at merchants) that use existing networks and issuers.

If mobile is the key new channel (and I’m sure Dan’s right about that), then it’s reasonable to ask to what extent innovation is possible in the latter case: that is, given the well-known provisions of the “innovator’s dilemma”, how can (in the specific example of mobile) banks and schemes develop great propositions? Patrick Gauthier highlights three key roadblocks.

  1. The economic buyers – i.e. the Mobile Operators and Issuers – have not solved their rivalry: Behind the scene a furious battle has raged on the ownership of the secure element used to secure transactions, a proxy for the question of who will own the customer relationship.
  2. Consumers have good enough methods of payments as it is: Without prejudice for the vision behind NFC, the need for a new method of payment delivery based on handsets is tenuous… Absent a reason for consumers to want it and a business case for Issuers to support, standalone payments is an unlikely “killer application.”
  3. No good path has been proposed to reach a critical mass of users: If I had a penny for every time I have heard about “the-chicken-and-egg” problem, I would be retired by now.

[From NFC: Past, Present and Future - pymnts.com]

Patrick’s analysis explains the paralysis in the operator-handset-bank domain. Yet the truth is that customers like NFC and they want it: hence the action is shifting from a consensual evolution at the interface between the mobile industry and the financial industry to a “screw you” revolution where more aggresive service providers (not only in payments) are using stickers (Bling Nation), microSD (Visa) and other technologies (China Mobile) to simply bypass Nokia and Telefonica, Apple and AT&T, RIM and Vodafone.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Front end

[Dave Birch] We’ve often looked at the natural strategy of using identity infrastructure as the “front end” to payment infrastructure. To put it simply, if you have an id card in your pocket (or, more likely, your phone) wherever you go, then what’s the point of carrying other cards around? Well, one reason is that if you only have one ring to rule them all, and that ring is lost, you’re in schtuck (I think there’s an idea for a book there somewhere). This is a valid concern.

A junior, who wishes to remain anonymous to protect her identity, had her ID card number stolen.

[From Identification card theft becomes a documented issue on campus - News]

Now, of course, in a developed nation (such as Germany, for example) this shouldn’t matter, since there is nothing remotely secret about ID card numbers and they cannot be used to effect any transactions — you need the smart ID card for that. But when the ID number is attached to something that has no inherent security, like a piece of cardboard, then it can be the root of mischief.

A week later, she decided to check her account balance at the Help Desk. The help desk printed her receipts, and she realized her laundry money account had decreased from $21 to $2.

“I saw a lot of Marvin’s, but I hadn’t ordered from Marvin’s at all this year,” the student said.

“I looked at the transactions to compare them,” she said. “When I was in Chicago, my card was being used here, and once of my receipts said that I had charged for Marvin’s at 6:46 p.m., when I had also bought food at the Hub at 6:48 p.m.”

[From Identification card theft becomes a documented issue on campus - News]

This is the inevitable consequence of 1-factor authentication, just like magnetic stripes on credit cards. Fortunately, the story has a modern, happy ending.

Public Safety, who traced the Marvin’s orders to a cell phone number, caught the perpetrator.

[From Identification card theft becomes a documented issue on campus - News]

Too funny: the master criminal who copied the ID card number down used his own mobile phone to order food using the number. Still, it’s a serious point, and it has been discussed with relation to some of the national smart ID schemes that we have advised on: there’s a reasonable concern that ID cards might be a target for crime if they can be used for payments, which is true, if the ID cards have no security. But suppose the ID cards have not only a chip on to prevent counterfeiting, but also a biometric cardholder verification method.

The much talked about Unique Identity Project (UID) is not just about providing citizens with biometric cards. In fact, the new identity cards can be used for multiple purposes and can even replace the debit or credit cards one day.

[From UID cards can replace bank cards - CIOL News Reports]

So, once again, let’s be clear about these implications. An effective digital identity infrastructure sitting on top of a standardised “payments cloud” will completely reshape the sector. It will substantially reduce the cost and complexity of starting a new payment scheme, and will further substantially reduce the cost and complexity of running a new payment scheme.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Maple leaf rage

[Dave Birch] I was pottering off to Canada and thought that perhaps I ought to pick up some Canadian dollars. After all, I figured, it’s an advanced nation so I can probably pay by card everywhere, but just in case I’d better get a couple of hundred dollars. I went to Travelex at Heathrow, and the clerk pointed me toward a new product: they had an EMV prepaid MasterCard denominated in Canadian dollars. Hurrah! As a rule, I much prefer to carry prepaid cards rather than cash and I already have a prepaid US dollar Visa, a prepaid UK pound Visa and a prepaid Euro MasterCard. So I got myself one of these new-fangled Canadian dollar cash passports.

When I got to Toronto, the first two places I tried it, it didn’t work. The luggage cart at the airport wouldn’t even recognise it, and the taxi driver wouldn’t accept it because it didn’t have embossing. He had one of those zip-zap machines that you sometimes still see in the third world (it turned out, ironically, that I’d been travelling to a meeting about the future of payments in a moving payments museum). Then it didn’t work at the restaurant, chip or stripe. It did work in the hotel bar, by stripe, and it also worked on Canadian railways, by chip. It worked at the lunch place, but it didn’t work to buy a bus ticket. Whatever happened to the brand promise of universal acceptance?

On balance, I give the Travelex Canadian Dollar MasterCard… 4/10 (must try harder).

Remember, I do this so you don’t have to.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

My multiples

[Dave Birch] I watched a strange TV show on a plane back from the US. I was about a woman with “Multiple Personality Disorder” (remember that book Sybil — not the one by Benjamin Disraeli — from years ago). I make no comment about whether the disorder is real or not (the TV show wasn’t that interesting) but there’s no doubt in my mind that when it comes to the virtual world, multiple personalities are not only real, but desirable.

Here’s a good reason for not having your Facebook account in your real name (as I don’t):

Five interviewees who traveled to Iran in recent months said they were forced by police at Tehran’s airport to log in to their Facebook accounts. Several reported having their passports confiscated because of harsh criticism they had posted online about the way the Iranian government had handled its controversial elections earlier this year.

[From Emergent Chaos: Fingerprinted and Facebooked at the Border]

I’ve already created a new Facebook identity and posted a paen to Iran’s spiritual leaders just in case I am ever detained by revolutionary guards and forced to log in. But will this be enough? Remember what happened to film maker David Bond when he made his documentary about trying to disappear? The private detectives that he had hired to try and find him simply went through Facebook:

Pretending to be Bond, they set up a new Facebook page, using the alias Phileas Fogg, and sent messages to his friends, suggesting that this was a way to keep in touch now that he was on the run. Two thirds of them got in contact.

[From Can you disappear in surveillance Britain? - Times Online]

So even if you are careful with your Facebook personalities, your friends will blab. As far as I can tell, there’s no technological way around this: so long as someone knows which pseudonym is connect to which real identity, the link may be uncovered. Probably the best we can do is to make sure that the link is held by someone who will demand a warrant before opening the box.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

What would you toss?

[Dave Birch] In some European countries — Finland and the Netherlands are good examples — both retailers and consumers have spontaneously abandoned low-value coins. Transactions are automatically-rounded (by custom and practice, not by law) to the nearest five euro cents and the one- and two-cent coins are just thrown away. In my house, we throw coppers into an old wooden bowl in the kitchen, and we are not alone.

Research revealed yesterday that up to one in five people suffers from “penny rage” – we chuck out 1p and 2p coins because we get fed up carrying them.

[From Express.co.uk - Home of the Daily and Sunday Express | UK News :: We really do throw away cash]

I'd never heard of "penny rage" before, and I'm not sure that "rage" is the right description, but I too find low-value coins nothing more than shrapnel. When was the last time you bought anything for a penny? Every day I take them out of my pocket, every night I come home with more (although my efforts to have cashless days have gone much better recently since Arriva introduced its iPhone application and mobile bus tickets in Woking — last week I didn't have to find cash for the bus even once!).

The 18bn British copper coins in circulation weigh the same as 213 fully loaded jumbo jets. Many of them – along with a further 6.5bn pennies the Royal Mint believes are “missing” – line the bottom of sock drawers and fill fridge-top jars. This mass of idle shrapnel indicates that many Britons stopped bothering with the stuff long ago. So it is surprising that the UK – along with G8 peers US and Japan – still continues to circulate their most basic unit of coinage, while countries such as Australia, the Netherlands, Brazil and Israel have all phased out their low-value change in the past 20 years.

[From FT.com / Lex / Financial services & property - Small change]

Yet in the UK, instead of doing something sensible such as melting down "copper" coins (they are not, of course, made out of copper at all) to make something more useful in these times of austerity, we are focusing on the higher-value coins.

Random sampling tests carried out by the Mint last May found that 2.58 per cent of £1 coins were counterfeit-compared with 2.06 per cent seven months earlier in October 2007 – or one in 50. This had doubled since 2002, when one in 100 £1 coins was counterfeit.

[From £1 fakers are quids in: Counterfeit coins surge to a record high | Mail Online]

Perhaps it's time to call in the £1 coins and remint a more counterfeit-resistant alternative? No: we're going to remint the small "silver".

Britain's 5p and 10p coins are to be substantially changed next year, causing potential chaos for the millions of people using vending machines and parking meters.

[From New steel 5p and 10p coins a 'disaster' - Telegraph]

Actually, this could be a blessing in disguise. Hopefully, some of the people who are complaining that enormous amounts of their money is going to be wasted (people who sell things through kiosks and the like) are going to take the opportunity to simply give up on coins completely: why replace the coin unit in a drinks machine with another coin unit when you could replace it with a contactless card reader and at the same time put the vending machine online through a built-in GPRS unit? (Answer in Europe: because under the current EMV scheme, you must install a contact reader and a PIN pad as well.) A good place to start would be with the vending machines in the London Underground, where every single person has a contactless-only card already.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Recognising the problem

[Dave Birch] An interesting series of talks at Biometrics 2010 reminded me how quickly face recognition software is improving. The current state of the art can be illustrated with some of the examples given by NIST in their presentation on testing.

  • A 1:1.6m search on 16-core 192Gb blade (about $40k machine) takes less than one second, and the speed of search continues to improve. So if you have a database of a million people, and you’re checking a picture against that database, you can do it in less than second.
  • The false non-match rate (in other words, what proportion of searches return the wrong picture) best performance is accelerating: in 2002 it was 20%, by 2006 it was 3% and by 2010 it had fallen to 0.3%. This is an order of magnitude fall every four years and there’s no reason to suspect that it will not continue.
  • The results seem to degrade by the log of population size (so that a 10 times bigger database delivers only twice the miss rate). Rather fascinatingly, no-one seems to know why, but I suppose it must be some inherent property of the algorithms used.

We’re still some way from Hollywood-style biometrics where the FBI security camera can spot the assassin in the Superbowl crowd.

What is often overlooked is that biometric systems used to regulate access of one form or another do not provide binary yes/no answers like conventional data systems. Instead, by their very nature, they generate results that are “probabilistic”. That is what makes them inherently fallible. The chance of producing an error can be made small but never eliminated. Therefore, confidence in the results has to be tempered by a proper appreciation of the uncertainties in the system.

[From Biometrics: The Difference Engine: Dubious security | The Economist]

So when you put all of this together, you can see that we are heading into some new territory. Even consumer software such as iPhoto has this stuff built in to it.

face-rec

It’s not perfect, but it’s pretty good. Consumers (and suppliers) do, though, have an unrealistic idea about what biometrics can do as components of a bigger system.

But Microsoft’s new gaming weapon uses “facial and biometric recognition” that creates a 3D model of a player. “It recognises a 3D model that has walked into the room and automatically logs that player in,” Mr Hinton said… “It knows when they are sneakily trying to log into their older brother’s account and trying to cheat the system… You can’t do it. Your face is the ultimate detection for the device.”

[From Game console 'rejects' under-age players | Herald Sun]

This sounds sort of fun. Why doesn’t my bank build this into its branches so that when I walk in?

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

With my peers

[Dave Birch] I went over to the FS Club to hear Forum friend Giles Andrews of Zopa give an update on their progress. He explained that one way of thinking about Zopa is as a bond market for consumers, but one that allows people to get a social return as well as a financial one. What an interesting description. And it was an interesting meeting. I won’t quote anyone, because the meeting was held under the Chatham House rule, but rather I will give some general impressions of the discussion…

We all know Zopa as P2P lending, a marketplace for money. It’s not that hard to set up a web site, though, so there must be more to it. What makes it work, seeing as their numbers have steadily climbed? Giles gave a few insights: he said, for example, that the core of Zopa’s business is their sophisticated credit rating model. I deduce it must be working tolerably well, since their bad debts over the last five years have averaged 70bp.

What I found particularly interesting was the relationship between Zopa and retail banks. In an odd way, the credit crunch came along at the right time for Zopa. Their lending went from £15 million in 2008 to £35 million in 2009 to £75 million this year. It seems to me that as public trust in banks collapsed (along with the interest rates) so more and more people turned to Zopa.

Recently Zopa have been lobbying for regulation of P2P Lending in UK.

[From New Datamonitor report on P2P Lending in the UK has some interesting analysis points « The Bankwatch]

This is true. In fact Giles has said that Zopa think they should be highly regulated and properly supervised. This would be good for them for two reasons: first of all it would create a structure for more competition, and more competition is good for innovation and excellence, and secondly it would further legitimise the P2P sector, thus bringing in more borrowers and lenders. It would also, presumably, bring in more competitors, which would be good for competition.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.