Red army

[Dave Birch] Oh no! According to tonight’s news reports, the UK is bracing itself for cyberattack from the “hackers” supporting Julian Assange and Wikileaks. Apparently vital government services are at risk from the group called “Anonymous” launching distributed denial-of-service (DDOS) attacks. A bit like this guy, from the group “Not Anonymous At All”:

A 17-year-old from Manchester has been arrested by the Metropolitan Police’s e-crime unit (PCeU) on suspicion of being behind a denial of service attack against the online game Call of Duty.

[From Call of Duty DDoS attack police arrest teen • The Register]

He was, of course, traced from his IP address. I thought it was funny, in a way, that journalists and politicians refer to the LOIC kids as “hackers” when they are anything but. What’s more, as I said when Charles Arthur was kind enough to invite me on to The Guardian’s Technology Podcast, they have chosen a particularly funny way to join the Anonymous group of internet vigilantes: software that isn’t anonymous in the least and that delivers their IP addresses to their intended victims, thus making it easy for them to be traced and arrested. This is, in fact, precisely what has happened.

A 16-year-old boy was arrested in the Netherlands in connection with a series of cyber attacks on Visa, MasterCard

[From Dutch teen arrested over cyber attacks on Visa, MasterCard]

My personal views about Wikileaks and the “Cable Gate” DDOS attacks are irrelevant. (I will say this: that if you don’t like MasterCard then cancel your card and leave mine out of it). But they will certainly have an impact on thinking and the calls for “something to be done” mean change. Since there’s no way to stop people from copying data (as the music industry has discovered), that’s probably not a fruitful line of thinking. So what will happen?

What technology may lead to are “red” and “blue” internets. (Note that “blue and red” are here allusions to the military labelling of secure and insecure networks, they are nothing to do with blue and red pills in The Matrix.) Essentially, there will be secure and insecure internets both running over the same IP networks.

On the red, open, internet people and organisations will exchange encrypted data across an untrusted network. Some people may choose not to connect to the red internet at all and only crazy people (and organisations) will send unencrypted data to unauthenticated counterparties.

On the blue, closed, internet you will need to authenticate yourself before you are allowed to access anything and a digital identity infrastructure will deliver privacy (and in some cases anonymity) through cryptography, not through data protection registrars or privacy ombudsmen. In order to connect to the government, or Facebook, or Amazon, you will have to use the blue internet: they simply won’t be connected to the red internet any more. At home, I will probably set my internet connection to blue only.

Now, some of you may be concerned that, as The Daily Telegraph told us, the Chinese government have a master key that can decrypt everything on the Internet, in which case the entire Internet will be — very literally indeed — red forever.

While sensitive data such as emails are generally encrypted before being transmitted, the Chinese government holds a copy of an encryption master key which could be used to break into redirected traffic.

[From China 'hijacks' 15 per cent of world's internet traffic - Telegraph]

But look on the bright side: since the Chinese have “a copy” of this mythical master key, someone else must have the original, and they will be able to read all of the Chinese government’s e-mail and put that on Wikileaks too.

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Soft and hard SIMs

To understand why the fuss, and why this is of relevance to the digital money world, you need to understand a couple of technical architectures relating to mobile phones and the role of the Secure Element (SE). The SE doesn't exist in phones yet, but it's important because if we want to implement anything important (such as payments) inside a phone, we need somewhere to store cryptographic keys, and that somewhere needs to be tamper-resistant to a great degree. Thus we need a handset to have an SE. Ah! You might say: but handsets already have a tamper-resistant thingumy inside them, why not use that?

That's a good point. In the modern way of things, the tamper-resistant chip thingumy the handset is more properly called the UICC:

The UICC (Universal Integrated Circuit Card) is the smart card used in mobile terminals in GSM and UMTS networks. The UICC ensures the integrity and security of all kinds of personal data, and it typically holds a few hundred kilobytes. With the advent of more services, the storage space will need to be larger.

[From UICC - Wikipedia, the free encyclopedia]

Historically, we've tended to associate the UICC (in the form of a removable smart card) with one application only, and that application is the Subscriber Identification Module (SIM) that allows the phone to connect to a mobile network and refer to the combination as "the SIM". But…

A UICC may contain several applications, making it possible for the same smart card to give access to both GSM and UMTS networks, and also provide storage of a phone book and other applications

[From UICC - Wikipedia, the free encyclopedia]

It can also contain more than one of each. Thus, you could have multiple "soft SIMS" inside one UICC (that special case where the UICC contains only one application, and that is a SIM, we will refer to henceforth as the "hard SIM"). Now let's consider what happens when Apple add an NFC interface to their devices and therefore need an SE.

The filing also points to the inclusion of near-field communication (NFC) technology in upcoming iPhones — and, for that matter, in Macs and media devices such as the Apple TV.

[From Apple patent seeks to reinvent retail • The Register]

Where can the SE that makes the NFC interface useful go? Either we can plug in an SE (eg, a DeviceFidelity microSD) or we can add an SE to the UICC (the e GSM Association, GSMA, preferred option) or we can build an SE into the device by adding it to the motherboard. The GSMA want to put the applications that control the NFC interfaces to be on the UICC, which kind of makes sense because if you take your UICC out of one phone and put it in another, then you'd want your SE applications (eg, your MasterCard, Oyster etc) to go with it. But not everyone thinks that the SIM is the key to this picture.

Suppose that instead of adding an SE, Apple add a UICC and put the SE in that? What this means in practice is that the UICC will be inside the iPhone or iPad or Mac, on the motherboard. But the SE need not be the only contents of the UICC. Why not put soft SIMs in there as well and do away with fiddly microSIMs? If I walk into the Apple Store in London and buy a 3G iPad, say, then the UICC could come with a default SIM application. Let's say this is O2. When I take the iPad to France, instead of paying outrageous 3G roaming charges (and therefore leaving my iPad at home), my iPad will download a French operator's SIM application and start using that. I won't choose the operator — in fact I won't even know this is going on, because Apple will simply negotiate with mobile operators to provide commodity service.

In other words, perhaps we move to a world in which the operators' SIM connectivity function becomes just software running on someone else's physical card.

[From Dean Bubley's Disruptive Wireless: Apple, embedded SIMs, NFC and mobile payments - some speculation]

Dean is spot on. And you can see plenty of positives in this architecture. If you're not a mobile operator, that is. If you're a mobile operator, this is another step towards being nothing more than a pipe. As a customer, I think I'd be quite happy with the mobile operators as a pipe, selected purely on a cost/QoS basis (and competing with each other on that basis). After all, they haven't (in Europe) got very far with "smart pipe" services such as, just to name two examples, digital money and digital identity. So the Apple UICC containing soft SIMs and an SE may not be such a bad architectural option for consumers. But…

The operators are privately saying they could refuse to subsidise the iPhone if Apple inserts an embedded subscriber identity module, or Sim card.

[From FT.com / Telecoms - Apple warned over built-in Sim cards]

There are other people in this value chain too, such as smart card manufacturer Gemalto who were rumoured to be making the Apple UICC.

Gemalto explained to us why such a deal, which involved a significant amount of devolution from the mobile phone operators to the mobile phone manufacturers, is unlikely to happen without the tacit approval of network carriers themselves.

Gemalto has been a strategic partner for mobile phone operators for more than a decade now (the company is the biggest SIM manufacturer in the world) and gets the majority of its revenue (more than 60 per cent of last year's 1.654 billion Euros).

[From Gemalto : No Apple iPhone 5 Deal On The Table Yet | ITProPortal.com]

Quite. But let's just go back over another main point: in order to provide payments, or other useful services, via NFC it is not necessary to have the co-operation of the carriers.

Visa's approach "shows that basically there's nothing that the carriers can do that the [payment] networks can't do without them," McPherson said.

[From Mobile Payments Set for Surge, But Who ll Set the Pace? - American Banker Article]

The mobile operators have no acceptance at retail POS so they have to work with payment scheme partners to reach scale, but other payments players don't need the operators. They can put stickers on the back of phones, plug microSD into handsets or use the NFC interfaces that will be built in by Google, Apple and RIM. Since customers will come to expect these services, they will eventually get built in to all handsets. Unless the operators can launch highly functional NFC platforms quickly (which they probably should have started doing a couple of years ago) then they will be out of the loop.

Issuing hard SIMs is expensive, so if the operator's connection with the customer is downgraded, there is no point in doing it and the operators would save money by providing soft SIMs to any UICC that they can bill to. So I think the situation is this: in the future, many devices will a UICC built-in. This UICC will function as an SE for NFC interfaces. The UICC will store a number of soft SIMs, not only for mobile phone communications but for future 4G and 5G communications. The UICC will also hold standard digital money and digital identity applications. And instead of Vodafone and Telefonica controlling the matrix, Apple and Google will.

These are personal opinions and should not be misunderstood as representing the opinions of
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

iPown

To understand why the fuss, and why this is of relevance to the digital money world, you need to understand a couple of technical architectures relating to mobile phones and the role of the Secure Element (SE). The SE doesn’t exist in phones yet, but it’s important because if we want to implement anything important (such as payments) inside a phone, we need somewhere to store cryptographic keys, and that somewhere needs to be tamper-resistant to a great degree. Thus we need a handset to have an SE. Ah! You might say: but handsets already have a tamper-resistant thingumy inside them, why not use that?

That’s a good point. In the modern way of things, the tamper-resistant chip thingumy the handset is more properly called the UICC:

The UICC (Universal Integrated Circuit Card) is the smart card used in mobile terminals in GSM and UMTS networks. The UICC ensures the integrity and security of all kinds of personal data, and it typically holds a few hundred kilobytes. With the advent of more services, the storage space will need to be larger.

[From UICC - Wikipedia, the free encyclopedia]

Historically, we’ve tended to associate the UICC (in the form of a removable smart card) with one application only, and that application is the Subscriber Identification Module (SIM) that allows the phone to connect to a mobile network and refer to the combination as “the SIM”. But…

A UICC may contain several applications, making it possible for the same smart card to give access to both GSM and UMTS networks, and also provide storage of a phone book and other applications

[From UICC - Wikipedia, the free encyclopedia]

It can also contain more than one of each. Thus, you could have multiple “soft SIMS” inside one UICC (that special case where the UICC contains only one application, and that is a SIM, we will refer to henceforth as the “hard SIM”). Now let’s consider what happens when Apple add an NFC interface to their devices and therefore need an SE.

The filing also points to the inclusion of near-field communication (NFC) technology in upcoming iPhones — and, for that matter, in Macs and media devices such as the Apple TV.

[From Apple patent seeks to reinvent retail • The Register]

Where can the SE that makes the NFC interface useful go? Either we can plug in an SE (eg, a DeviceFidelity microSD) or we can add an SE to the UICC (the e GSM Association, GSMA, preferred option) or we can build an SE into the device by adding it to the motherboard. The GSMA want to put the applications that control the NFC interfaces to be on the UICC, which kind of makes sense because if you take your UICC out of one phone and put it in another, then you’d want your SE applications (eg, your MasterCard, Oyster etc) to go with it. But not everyone thinks that the SIM is the key to this picture.

Suppose that instead of adding an SE, Apple add a UICC and put the SE in that? What this means in practice is that the UICC will be inside the iPhone or iPad or Mac, on the motherboard. But the SE need not be the only contents of the UICC. Why not put soft SIMs in there as well and do away with fiddly microSIMs? If I walk into the Apple Store in London and buy a 3G iPad, say, then the UICC could come with a default SIM application. Let’s say this is O2. When I take the iPad to France, instead of paying outrageous 3G roaming charges (and therefore leaving my iPad at home), my iPad will download a French operator’s SIM application and start using that. I won’t choose the operator — in fact I won’t even know this is going on, because Apple will simply negotiate with mobile operators to provide commodity service.

In other words, perhaps we move to a world in which the operators’ SIM connectivity function becomes just software running on someone else’s physical card.

[From Dean Bubley's Disruptive Wireless: Apple, embedded SIMs, NFC and mobile payments - some speculation]

Dean is spot on. And you can see plenty of positives in this architecture. If you’re not a mobile operator, that is. If you’re a mobile operator, this is another step towards being nothing more than a pipe. As a customer, I think I’d be quite happy with the mobile operators as a pipe, selected purely on a cost/QoS basis (and competing with each other on that basis). After all, they haven’t (in Europe) got very far with “smart pipe” services such as, just to name two examples, digital money and digital identity. So the Apple UICC containing soft SIMs and an SE may not be such a bad architectural option for consumers. But…

The operators are privately saying they could refuse to subsidise the iPhone if Apple inserts an embedded subscriber identity module, or Sim card.

[From FT.com / Telecoms - Apple warned over built-in Sim cards]

There are other people in this value chain too, such as smart card manufacturer Gemalto who were rumoured to be making the Apple UICC.

Gemalto explained to us why such a deal, which involved a significant amount of devolution from the mobile phone operators to the mobile phone manufacturers, is unlikely to happen without the tacit approval of network carriers themselves.

Gemalto has been a strategic partner for mobile phone operators for more than a decade now (the company is the biggest SIM manufacturer in the world) and gets the majority of its revenue (more than 60 per cent of last year’s 1.654 billion Euros).

[From Gemalto : No Apple iPhone 5 Deal On The Table Yet | ITProPortal.com]

Quite. But let’s just go back over another main point: in order to provide payments, or other useful services, via NFC it is not necessary to have the co-operation of the carriers.

Visa’s approach “shows that basically there’s nothing that the carriers can do that the [payment] networks can’t do without them,” McPherson said.

[From Mobile Payments Set for Surge, But Who ll Set the Pace? - American Banker Article]

The mobile operators have no acceptance at retail POS so they have to work with payment scheme partners to reach scale, but other payments players don’t need the operators. They can put stickers on the back of phones, plug microSD into handsets or use the NFC interfaces that will be built in by Google, Apple and RIM. Since customers will come to expect these services, they will eventually get built in to all handsets. Unless the operators can launch highly functional NFC platforms quickly (which they probably should have started doing a couple of years ago) then they will be out of the loop.

Issuing hard SIMs is expensive, so if the operator’s connection with the customer is downgraded, there is no point in doing it and the operators would save money by providing soft SIMs to any UICC that they can bill to. So I think the situation is this: in the future, many devices will a UICC built-in. This UICC will function as an SE for NFC interfaces. The UICC will store a number of soft SIMs, not only for mobile phone communications but for future 4G and 5G communications. The UICC will also hold standard digital money and digital identity applications. And instead of Vodafone and Telefonica controlling the matrix, Apple and Google will.

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Dry

[Dave Birch] Having said that I couldn’t see any circumstances in which I’d use a contactless card at my dry cleaners, I just did.

I went in with some dry cleaning which came to £11 or so. I took out my MasterCard and put it in the terminal, punched in my PIN and then waited a while for it to dial up and authorise. While this was going on, I noticed that the terminal was a new Ingenico i-series terminal with contactless interface. So, as an experiment, I bought £7 of shoe polish: the chap keyed in the transaction and sure enough the contactless interface lit up: I paid with my Visa contactless card which, since it was offline DDA, was instant. Excellent.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Dry

I asked the chap if many people used the new contactless cards and he said no. I asked him why not — like he would know — and he said he thought it might be because they are worried about security. That is, and this is the scenario that he put forward, if you don't notice your card missing for a while then people might be able to go and buy things with it. But as I pointed out to him, the UK issuers have already said that customers are covered.

There is a risk of fraud with any form of card transaction, and contactless transactions are no different. But risk is limited by the security measures put in place. Banks are also required to refund any losses incurred by cardholders unless the bank can prove that the cardholder actually made the transaction themselves.

[From Are contactless payments safe? | This is Money]

But it seems that the reassurances from the banking sector have less impact on the public than the scare stories about contactless security that are becoming tediously regular. Here's a typical example from the US, which ought to be called "man demonstrates that contactless payment cards work as per specification".

Using just an off-the-shelf card reader he bought online for less than $100 and a Netbook computer, Augustinowicz explained, he could swipe credit card numbers, expiration dates, and in some cases, even people's names. People who thought there was no way their pocket could be picked without laying a hand on them, soon learned they were wrong.

[From Credit Cards At Risk from High-Tech Pickpockets? - CBS News]

But later on in the article, we read that

Experts at the San Diego-based Identity Theft Resource Center told WREG that they've never seen a case of RFID skimming used to steal information.

[From Credit Cards At Risk from High-Tech Pickpockets? - CBS News]

Well, quite. It's hardly "pickpocketing" since all you can do is send the money to a merchant acquiring account by setting up a bogus POS terminal. Pointless, since you'll get caught. A marginally better crime would be to scan the cards using your bogus POS terminal and use the data to carry out some other fraud. But that doesn't work either. If you scan my Barclays debit card, the data that you get from the contactless interface is not sufficient to create a cloned EMV card (contact or contactless) because it's a DDA (dynamic data authentication) card and you need the private key to forge it. The data isn't sufficient to create a cloned magnetic stripe card because it gives up the ICVV and not the CVV. The data isn't sufficient to use the card online because it doesn't give up the CV2. So all you can get, even if I don't notice you waving a POS terminal an inch from my arse, is the name, card number and expiry date (none of which are secret).

Personally, I think issuers should go even further and remove the name from both the contact and contactless interfaces, and what's more I think they should do what American Express does and have the contactless interface deliver an alias PAN as an additional safety mechanism.

The BBC "Moneybox" programme recently had a report on contactless cards, and it invited the public to comment. Now, I don't care what the public think about anything, least of all contactless cards (don't forget that a quarter of them think that Sherlock Holmes was a real person) but I thought it might be mildly amusing to read through the comments. One of them caught my eye:

This is just the thin end of the wedge. It is the first step towards abolishing cash. Once these pin-less cards have got rid of cash, we will be totally at the mercy of the bankers and financiers. To say nothing of all sorts of petty officials. Once there is no cash, your ability to function in the world is at their discretion. Cards? Well, ultimately the chip will probably be implanted in your wrist

[From BBC News - Have Your Say: Contactless Cards]

Lyn from Glastonbury clearly doesn't understand that cash is less than 3% of the UK money supply and that we are tragically already at the mercy of bankers and financiers. But it was her comment about implanting the chip in your wrist that got me thinking. Why? (I asked this on the Moneybox web site but I'm afraid they didn't publish any of my questions). The only thing I can think of is that Lyn thinks that contactless cards are the mark of the beast from the Book of Revelations, in which case nothing that the industry says will matter to her. On another point: one of the other public comments was that

I have a Barclaycard One Plus Oyster which I use when visiting London and use by 'swiping' my wallet. Whilst I would find a contactless debit card useful how will the machine discriminate between which one I am using. Will my debit card be Oyster compatible?

[From BBC News - Have Your Say: Contactless Cards]

I thought this was a fascinating comment, given the money that was spent on marketing and communications. The Barclaycard OnePulse (which is what the person is talking) is an excellent product but the Visa credit contactless interface is is distinct from the Oyster interface: the terminal has no need to discriminate between the two because POS terminals only see the Visa interface and the TfL terminals only see the Oyster interface (although, as I blogged recently, the TfL terminals will soon be able to accept contactless payment cards).

One key point that I think is missed in the current reporting of contactless is that contactless is not an end in itself but a stepping stone to non-card form factors, of which the most immediate and probably most important is not bionic wrist implants but… well, let's back up….

Among a number of other readers to contact Your Money is Paul Adkins, who researched electronic payment systems when he worked for electronics' giant Philips in the early 80s. "We discovered the best security would be offered by giving people a calculator-like device where the user had control over the keypad for entering the PIN," he says. "But this was perceived to be too expensive, and we ended up with chip cards. But who knows what is happening behind the keypad and the display? We have to take it on trust that the terminal is not compromised."

[From Contactless cards: the pros and cons of new payment technology - Spend & Save , Money - The Independent]

Mr. Adkins is, as it happens, entirely correct. It would be much more secure to have customers enter their PINs into their own devices, since one of the major sources of fraud at the moment is bogus terminals that steal PINs. Anyway, the "calculator-like device" that Mr. Adkins foresaw is now with us — we call it the mobile phone — and represents a step-change in the security of payments. It won't be as good as it could be until mobile phones are more secure, but going contactless isn't only about low-value cash replacement, speed and convenience: it's about building the rails for a new generation of payment devices to run on.

These are personal opinions and should not be misunderstood as representing the opinions of
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

London buses show us the way

[Dave Birch] The Mayor of London, Boris Johnson, has been talking about the next major revolution to come in London transit ticketing.

Public transport travellers will be able to swipe credit or debit cards in the same way as Oyster cards by 2012, Boris Johnson revealed. The Mayor said the phased scheme will start on buses in the run-up to the Olympics and then move on to the Tube. Prices will be the same as with Oyster. Mr Johnson has also pledged that a “next generation” Oyster card will be released by 2014.

[From Commuters will soon be able to use credit cards like Oyster by 2012 | News]

What this all means is that visitors to London — and, indeed, Londoners — will no longer need to get prepaid Oyster cards. They will be able to use their bank cards (such as, for example, the one of the ten million cards that Barclays has already issued with contactless interfaces) to tap-and-go their way around town.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

London buses show us the way

Another option might be to use Oyster cards in shops. It does seem odd to me that when I'm on an Underground platform and dying of thirst, the Coke machine doesn't take the one currency that every single person on the platform actually has: Oyster. In other regions, this is seen as being a natural development of widespread mass transit contactless systems. Taiwan is following Hong Kong and Singapore in allowing the transit e-purse to be extended out into retail.

The EasyCard, a contactless smartcard system for use on the Taipei MRT system, will soon become an electronic purse that can be used to purchase small-value items… The new payment system, which will allow up to NT$10,000 (US$312.50) to be stored in the card, will be put in place a year after the Legislative Yuan passed an amendment to the Act Governing the Issuance of Electronic Stored Value Cards that paved the way for the new payment vehicle.

[From Electronic purse expected to become operational in March - Taiwan News Online]

It's clear that, as we all know, transit is the vanguard for electronic money and therefore it provides a unique opportunity to drive cashlessness. But that doesn't necessarily mean that transport operators should get in to retail payments: the alternative path is to let retail payments systems operate in transport. This is the path that London has chosen, as noted above, and is true in many cities around the world. Transit operators see ticketing as not part of their core business, which is running public transport. If other people can provide the ticketing solution, then fine.

Toronto transit officials are not the only ones keen to get out of the business of collecting fares and phase out closed payment schemes. Their counterparts in London, New York, Chicago and some other cities are moving at varying speeds toward open-loop payment.

[From Canadian Transit Card Operator: Not So Fast to Open-Loop Payment | NFC Times – Near Field Communication and all contactless technology.]

There's another reason, though, why I think that this trend is gathering momentum. It costs money to stay in the security arms race: the ticketing systems (especially as they move into the world of mobile phones) need to be sure that the activities of fraudsters do not impact revenue. When the transport operator has to spend money on continually upgrading and enhancing systems for revenue protection purposes, that's money that could be better spent. It's not always about counterfeiters and criminals, by the way, sometimes it's just people gaming the system.

Determined token hoarders will have to buy their tokens one by one, at token vending machines, and that’s not the only step the Toronto transit bosses are taking to fight stockpiling. The Toronto Transit Commission (TTC) has now introduced adult paper tickets with an expiry date on them. “The TTC won this,” said Angela Leung, an Ontario College of Art and Design student who amassed over 100 tokens during the 2007 fare increase and had the same game plan for the new year.

[From Excalibur Web edition - Extinct bus tickets temporarily reappear to combat token hoarders]

If payment systems spend the money to develop fast, secure new payment mechanisms (using contactless cards, phones, stickers and who knows what else) then the transit operator doesn't have to. This will be the sort of thing that will be discussed at the excellent Transport Ticketing 2011 conference in London on 25-27th Janaury 2011. I thought this was an excellent event back in January 2010 and so I was very happy to be invited to chair the panel on mobile devices at next year's event.

These are personal opinions and should not be misunderstood as representing the opinions of
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Put your game face on

[Dave Birch] Who are you? That’s an easy question to answer in cyberspace, because no-one knows you’re a dog, so you can be anyone you want to be. This means that you can do bad things, doesn’t it? Surely it would be better to make people disclose their “real” identities online.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Playing the Treasury game

[Dave Birch] Like many of you, I imagine, I’ve been reading through the H.M. Treasury document on “Laying of regulations to implement the new E-Money Directive” (October 2010). It’s written for lawyers, not for normal people, but as far as I can make out, the issues that are worth thinking about are things like the “ring-fencing” of electronic money funds — discussed by John Casanova and William Long from Sidley & Austin in the September issue of E-Finance & Payments Law & Policy — as well as the exemption for small issuers, the meaning of the “limited network” exemption. I rather liked the mention of the idea of introducing the test for “fit and proper” persons to run electronic money schemes, the same definition that has proved so successful for banks, football clubs and so forth.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Game face

I was thinking about online identity — again — because I was working on a report for a client of ours and I was thinking about some issues around multiple identities. In cyberspace, multiple identities make sense in a way that has no analogue in the analogue world, if you see what I mean. Now, a fundamental objection to letting people have multiple identities is that it will enable them to get up to no good. And it is certainly true that there are people out there getting up to no go. When I was writing a post about virtual commerce over on Digital Money, I came across this interesting piece about the activities of fraudsters after virtual gold.

Operationally, gold frauding is much cheaper than gold farming as you don't need to spend time building up characters, farming assets, and waiting to be banned. Since you are hitting accounts and looting them on a one-time basis, you are not going to trigger traditional gold farming detectors…. and if you get banned, on to the next victim.

[From World of Warcraft under stress from Gold Frauders via Phishing and Key Loggers - PlayNoEvil - Game Security, IT Security, and Secure Game Design Services]

While the theft of virtual gold may well be a serious problem, in the great scheme of things it's probably not the no.1 priority of law enforcement (which is why kids use two-factor authentication for these kinds of games). But we have to recognise that there are much more serious problems.

Michigan resident and twice-married mother-of-five has been charged with “using the Internet to entice a minor into sexual activity”, after she seduced a 15-year-old boy while playing World of Warcraft. 35-year-old Angie L. Jenkins told the teenager she was 21, while he swore he was 20.

[From 35-year-old woman charged with seducing minor on World of Warcraft]

Without minimising the seriousness, I do find this example particularly useful: both participants in an online exchange were lying! What can we do about this? Well, to continue with the World of Warcraft (WoW) theme, let's looks at what Blizzard actually tried to do: they decided to introduce a "RealID" system (not to be confused with the US government's "RealID" system because the WoW system was intended to be secure).

the RealID system also identifies you by your real name instead of a character name or alternate identity. Friends who may have previously known you by your character name will now know you by your real name, whether you've ever told them or not. This is information pulled straight from Blizzard's account information and billing system – information that was previously private.

[From Player Perspectives - A Pain in the RealID - MMORPG.com]

How on earth could anyone have imagined that this was a good idea? Apart from anything else, the "real name" associated with the account that my kids use is me, not them, because it's my card that's used to pay for their subscription. I'm very uncomfortable with them using their own debit cards online precisely because I don't want them to give out their real name. But the story gets even more crazy.

Another enhanced feature of RealID is the ability to see friends of friends. Once you're on a friend's RealID list, you can now see the (real) names of anyone they have added to their RealID. The idea behind this function is to allow players to easily add mutual friends without having to ask a dozen people for their e-mail address. The potential use behind it to find out more information about someone that trusts you with their RealID is far worse.

[From Player Perspectives - A Pain in the RealID - MMORPG.com]

This is so wrong. I spoke about the "chatroom paradox" (an example I often use to illustrate this point) at the BCS ISSG "Privacy Day" recently. The point is that people seem to want the "real" identity of counterparties but don't want to disclose their "real" identity in case the counterparty misuses it. Blizzard really misjudged what people want and so they had to abandon their plan.

Sidney Eve Matrix, a film and media professor at Queen's University in Kingston, Ont., who studies cyberculture. "They know the culture requires to some extent an online persona. … It was a cultural misstep, really."

[From CBC News - Technology & Science - Battle to preserve online anonymity rages in video game community]

It isn't just about having a persona, it's about having a persona that can demonstrate certain credentaials (eg, I am over 18, I live in the UK, whatever). In fact, it's about having a number of persona and, I would argue, it's about having persona that are relevant to transactions.

“Who are you?” equates narrowly to Identity. It is only Identity at a sufficient level of trust the meet the requirements of a specific entitlement. In the simplest case, the person can be completely anonymous; in a municipal car park, only the ability to pay makes sense. However, they may keep a record of your car registration number. Requests for Housing Benefits are at the other end of the scale. The identity offered does not need a unique code.

[From Idiotic Identity Fallacy – No2UID « Quarkside]

I prefer to see these issues separated: I think that you do need a unique identifier, but that that identifier should not be part of transactions, and I think that there should be privacy rather than anonymity for low-value payments, but the central point is correct. I wonder if the attitudes forged by WoW and such like mean that the next generation will be far more tuned-in to what identity means in cyberspace: we have to stop forcing our "cardboard age" notions of identity on to them or we'll never make any progress in solving real problems.

Incidentally, if you are interested in the idea that WoW and the like are more than just games, I happen to have on my desk a spare copy of the excellent "Fun, Inc." signed by the author Tom Chatfield. I will cheerfully send this interesting book free to the first person to respond to this post with the name of the WoW character, who became popular due to a video of the game that circulated around the Internet, who famously led his friends to their doom because he wasn't listening to the other players plotting their moves. The phenomenon has since spread beyond the boundaries of the gaming community into other online and mainstream media, so that the name has become a byword for a team member whose reckless enthusiasm and inattention to plans leads to disaster.

These are personal opinions and should not be misunderstood as representing the opinions of
Consult Hyperion or any of its clients or suppliers

 

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.