Price in practice

When I was checking in to a hotel the other day, I saw a sign on the counter advising that there would be a £2.50 surcharge for paying by credit card. Naturally, I asked the receptionist about the impact of explicit pricing of payment instruments on customer preferences (remember, I do this so you don’t have to). I’m interested in both why retailers do this and what impact it has on their customers.

She told me that it made no difference to business customers, because they aren’t paying the bill and they always pay with credit cards anyway, and many of them pay with corporate credit cards and there are no corporate debit cards. For personal customers, most of them paid by debit card anyway, but the surcharge had pushed even more of them in that direction, to the point where probably four-fifths of personal customers paid with debit cards. Of the remainder, most paid with credit cards but some paid with cash. I thought it would be impolite to enquire further as to whether the cash payers were predominantly drug dealers, prostitutes or (given the location of the hotel) politicians.

Are these results typical? To what extent pricing drives payment choices is uncertain. In some cases (remember the case study of IKEA steering customers to debit in the UK) it clearly does, in other cases — such as my favourite case study of the parking at Woking station, where it costs 40p extra to pay by mobile, and half the customers do it — it doesn’t. In theory, though, there’s nothing wrong with the idea of making the costs explicit and then letting the market choose. Except… A little while back, Deborah Baxley of Capgemini (talking about the US environment) wondered if the appearance of explicit pricing for payment instruments (in itself, a good thing) might lead to a perverse outcome as merchants seek to externalise the cost of payments.

Merchants benefit from lower acceptance costs for debit cards. In a surprising twist, incentives and steering could have the perverse result of driving consumers toward cash and checks.

[From Changing the Game in Cards - pymnts.com]

I think this is a realistic projection, especially given that merchants don’t care about the costs they impose on the rest of society by driving up the use of cash and because customers simply do not pay the real cost of cash or checks. I would love for this to change, but it’s not going to. It’s reasonable to wonder, in response, whether banks can use EMV, NFC, SMS or some other TLA (three letter acronym) to generate added-value around payment transactions and thus stem the shift to cash. In the case of NFC, I think they probably can. Since NFC is now entering the consumer market, it might be time to firm up on some value-adding plans. This has been clear, I think, for some time.

Last week Google confirmed that Android 2.3 will support Near Field Communication, as will Nokia and RIM smartphones, starting next year. And judging from Apple’s recent hiring of an NFC expert, and patent filings for a probably-NFC-powered iTravel app, the iPhone 5 will boast NFC too.

[From I Have Seen The Future, And It Looks A Lot Like Bump (Without The Bump)]

But just because the idea has been around for some time, that doesn’t mean that finding genuinely value-adding applications around technologies such as NFC is easy. But I digress: the clear problem is that when you make the pricing of things explicit, then that pricing appears in the first instance to show an increase. Hence the perverse thinking that emerges.

Banks have never lost out because of their gracious generosity in allowing customers to use cheque books, debit cards or cash machines for free.

[From The end of free banking would be another slap in the face | Chris Leslie | Comment is free | guardian.co.uk]

This is what people in the UK genuinely believe. I have no idea who they think pays for all of this stuff (hint: you do) but it does make it very difficult to introduce “real” pricing that allows consumers to make informed choices. This real pricing would take offline prepaid debit as the benchmark and then price everything else from there: debit, then probably cash, then credit, then cheques, that sort of thing. Then the consumer preferences would be meaningful.

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Why is card fraud in the UK apparently so much worse than elsewhere?

Our good friends at� ACI Worldwide have just released their annual Global Card Fraud Survey, which contains some rather bad news: the UK has more card fraud than many other countries. We’re up there with the US, with three times as many people affected than in Germany and the Netherlands. So a third of us have been victims of card fraud compared to only a tenth in Netherlands. Why? Are the Dutch more honest than Brits? Are their cards more sophisticated? No. I think there are two main reasons for this discrepancy.

First of all, while chip and PIN has cut fraud on the high street, card-not-present fraud is still a big problem. In the UK, cards still account for a big portion of online payments. In the Netherlands, and some other countries, they don’t. More than two-thirds of Dutch e-commerce purchases are made with iDeal, a bank-based scheme that has no equivalent in the UK (or the US, or pretty much anywhere else for that matter).

Second, UK credit cards have high limits. In the last couple of weeks, both of my main card issuers have written to me raising credit limits (I didn’t ask for this in either case). If you’re going to steal some card details, you’d go for cards that are likely to be some way from their limit.

The survey wasn’t all bad news, by any means. I found it interesting that the proportion of people who had been victims of card fraud but were satisfied with the response of their issuer had actually increased slightly, to almost four-fifths, which isn’t bad. Personally, like the majority of people surveyed, the last time there was a strange charge on my card, the bank took off the charge then cancelled and reissued the card.

The agent informed me that new cards for me and my wife would be Fed-Ex’d, to arrive today or tomorrow. What followed were a series of texts from merchants that have my credit card on file for automatic billing, delighting me with the knowledge that I won’t be able to use such services as the Bay’s FasTrak toll lanes or uninterrupted cable service until I update my records.

[From� I’m a five-time ID Fraud victim; How crazy is that? - Javelin Strategy & Research Blog]

Think how expensive this all this though: cancelling and re-issuing cards, call centre seats, letters and whatever else. So we still need to do better. Only around a third of people (fewer than before) said that they would switch financial institutions because of card fraud, which is bad news for people trying to sell anti-card fraud solutions to high street banks.

The poll of 970 UK adults, part of the bi-annual global Unisys Security Index, reveals that cyber-security is the public’s chief concern, with 85% of respondents worried, and over 50% “seriously concerned”, about bank card fraud and identity theft.

[From� Finextra: Brits switching banks over security and privacy concerns - Unisys]

This is odd, I think. I couldn’t care less about bank card fraud, since it’s the banks’ problem and not mine. I never use a debit card for anything, offline or online, so I’m totally protected by the legislation around credit cards. I’m more worried about identity theft, because it’s more time consuming to put right, but that’s a different issue (being discussed at the CSFI yesterday, as it happens).

The press release also noted that 81% of people have confidence in their issuer protecting them from fraud. I think that this may be a little simplistic, for that very reason: had I been asked for the survey, I would have said that I don’t really care about Barclays’ ability to prevent fraud on my splendid OnePulse credit card because it’s their problem.

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with� ecto]

These are personal opinions and should not be misunderstood as representing the opinions of
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Why us?

Our good friends at ACI Worldwide have just released their annual Global Card Fraud Survey, which contains some rather bad news: the UK has more card fraud than many other countries. We’re up there with the US, with three times as many people affected than in Germany and the Netherlands. So a third of us have been victims of card fraud compared to only a tenth in Netherlands. Why? Are the Dutch more honest than Brits? Are their cards more sophisticated? No. I think there are two main reasons for this discrepancy.

First of all, while chip and PIN has cut fraud on the high street, card-not-present fraud is still a big problem. In the UK, cards still account for a big portion of online payments. In the Netherlands, and some other countries, they don’t. More than two-thirds of Dutch e-commerce purchases are made with iDeal, a bank-based scheme that has no equivalent in the UK (or the US, or pretty much anywhere else for that matter).

Second, UK credit cards have high limits. In the last couple of weeks, both of my main card issuers have written to me raising credit limits (I didn’t ask for this in either case). If you’re going to steal some card details, you’d go for cards that are likely to be some way from their limit.

The survey wasn’t all bad news, by any means. I found it interesting that the proportion of people who had been victims of card fraud but were satisfied with the response of their issuer had actually increased slightly, to almost four-fifths, which isn’t bad. Personally, like the majority of people surveyed, the last time there was a strange charge on my card, the bank took off the charge then cancelled and reissued the card.

The agent informed me that new cards for me and my wife would be Fed-Ex’d, to arrive today or tomorrow. What followed were a series of texts from merchants that have my credit card on file for automatic billing, delighting me with the knowledge that I won’t be able to use such services as the Bay’s FasTrak toll lanes or uninterrupted cable service until I update my records.

[From I’m a five-time ID Fraud victim; How crazy is that? - Javelin Strategy & Research Blog]

Think how expensive this all this though: cancelling and re-issuing cards, call centre seats, letters and whatever else. So we still need to do better. Only around a third of people (fewer than before) said that they would switch financial institutions because of card fraud, which is bad news for people trying to sell anti-card fraud solutions to high street banks.

The poll of 970 UK adults, part of the bi-annual global Unisys Security Index, reveals that cyber-security is the public’s chief concern, with 85% of respondents worried, and over 50% “seriously concerned”, about bank card fraud and identity theft.

[From Finextra: Brits switching banks over security and privacy concerns - Unisys]

This is odd, I think. I couldn’t care less about bank card fraud, since it’s the banks’ problem and not mine. I never use a debit card for anything, offline or online, so I’m totally protected by the legislation around credit cards. I’m more worried about identity theft, because it’s more time consuming to put right, but that’s a different issue (being discussed at the CSFI yesterday, as it happens).

The press release also noted that 81% of people have confidence in their issuer protecting them from fraud. I think that this may be a little simplistic, for that very reason: had I been asked for the survey, I would have said that I don’t really care about Barclays’ ability to prevent fraud on my splendid OnePulse credit card because it’s their problem.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

A theory of privacy to help technologists

The� Institute for Advanced Legal Studies hosted an excellent seminar by� Professor Michael Birnhack from the Faculty of Law at Tel Aviv University who was talking about “A Quest for a Theory of Privacy”.

He pointed out that while we’re all very worried about privacy, we’re not really sure what should be done. It might be better to pause and review the legal “mess” around privacy and then try to find an intellectually-consistent way forward. This seems like a reasonable course of action to me, so I listened with interest as Michael explained that for most people, privacy issues are becoming more noticeable with Facebook, Google Buzz, Airport “nudatrons”, Street View, CCTV everywhere (particularly in the UK) and so on. (I’m particularly curious about the intersection between new technologies—such as RFID tags and biometrics—and public perceptions of those technologies, so I found some of the discussion very interesting indeed.)

Michael is part of the� EU PRACTIS research group that has been forecasting technologies that will have an impact on privacy (good and bad: PETs and threats, so to speak). They use a roadmapping technique that is similar to the one we use at Consult Hyperion to help our clients to plan their strategies for exploiting new transaction technologies and is reasonably accurate within a 20 year horizon. Note that for our work for commercial clients, we use a 1-2 year, 2-5 year, and 5+ year roadmap. No-one in a bank or a telco cares about the 20 year view, even if we could predict it with any accuracy—and given that I’ve just read the BBC correspondents informed predictions for 2011 and they don’t mention, for example, what’s been going on in Tunisia and Egypt, I’d say that’s pretty difficult.

One key focus that Michael rather scarily picked out is omnipresent surveillance, particularly of the body (data about ourselves, that is, rather than data about our activities), with data acted upon immediately, but perhaps it’s best not go into that sort of thing right now!

He struck a definite chord when he said that it might be the new business models enabled by new technologies that are the real threat to privacy, not the technologies themselves. These mean that we need to approach a number of balances in new ways: privacy versus law enforcement, privacy versus efficiency, privacy versus freedom of expression. Moving to try and set these balances, via the courts, without first trying to understand what privacy is may take us in the wrong direction.

His idea for working towards a solution was plausible and understandable. Noting that privacy is a vague, elusive and contingent concept, but nevertheless a fundamental human right, he said that we need a useful model to start with. We can make a simple model by bounding a triangle with technology, law and values: this gives three sets of tensions to explore.

Law-Technology. It isn’t a simple as saying that law lags technology. In some cases, law attempts to regulate technology directly, sometimes indirectly. Sometimes technology responds against the law (eg, anonymity tools) and sometimes it co-operates (eg, PETs—a point that I thought I might disagree with Michael about until I realised that he doesn’t quite mean the same thing as I do by PETs).

Technology-Values. Technological determinism is wrong, because technology embodies certain values. (with reference to Social Construction of Technology, SCOT). Thus (as I think repressive regimes around the world are showing) it’s not enough to just have a network.

Law-Values, or in other words, jurisprudence, finds courts choosing between different interpretations. This is where Michael got into the interesting stuff from my point of view, because I’m not a lawyer and so I don’t know the background of previous efforts to resolve tensions on this line.

Focusing on that third set of tensions, then, in summary: From� Warren and Brandeis’ 1890 definition of privacy as the right to be let alone, there have been more attempts to pick out a particular bundle of rights and call them privacy.� Alan Westin‘s 1967 definition was privacy as control: the claims of individuals or groups or institutions to determine for themselves when, how and to what extent information about them is communicated to others.

This is a much better approach than the property right approach, where disclosing or not disclosing, “private” and “public” are the states of data. Think about the example of smart meters, where data outside the home provides information about how many people are in the home, what time they are there and so on. This shows that the public/private, in/out, home/work barriers are not useful for formulating a theory. The alternative that he put forward considers the person, their relationships, their community and their state. I’m not a lawyer so I probably didn’t understand the nuances, but this didn’t seem quite right to me, because there are other dimensions around context, persona, transaction and so on.

The idea of managing the decontextualisation of self seemed solid to my untrained ear and eye and I could see how this fitted with the Westin definition of control, taking on board the point that privacy isn’t property and it isn’t static (because it is technology-dependent). I do think that choices about identity ought, in principle, to be made on a transaction-by-transaction basis even if we set defaults and delegate some of the decisions to our technology and the idea that different persona, or avatars, might bundle some of these choices seems practical.

Michael’s essential point is, then, that a theory of privacy that is formulated by examining definitions, classsifications, threats, descriptions, justifications and concepts around privacy from scratch will be based on the central notion of privacy as control rather than secrecy or obscurity. As a technologist, I’m used to the idea that privacy isn’t about hiding data or not hiding it, but about controlling who can use it. Therefore Michael’s conclusions from jurisprudence connect nicely connect with my observations from technology.

An argument that I introduced in support of his position during the questions draws on previous discussions around the real and virtual boundary, noting that the lack of control in physical space means the end of privacy there, whereas in virtual space it may thrive. If I’m walking down the street, I have no control over whether I am captured by CCTV or not. But in virtual space, I can choose which persona to launch into which environment, which set of relationships and which business deals. I found Michael’s thoughts on the theory behind this fascinating, and I’m sure I’l be returning to them in the future.

These are personal opinions and should not be misunderstood as representing the opinions of
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Theoretically private

The Institute for Advanced Legal Studies hosted an excellent seminar by Professor Michael Birnhack from the Faculty of Law at Tel Aviv University who was talking about “A Quest for a Theory of Privacy”.

He pointed out that while we’re all very worried about privacy, we’re not really sure what should be done. It might be better to pause and review the legal “mess” around privacy and then try to find an intellectually-consistent way forward. This seems like a reasonable course of action to me, so I listened with interest as Michael explained that for most people, privacy issues are becoming more noticeable with Facebook, Google Buzz, Airport “nudatrons”, Street View, CCTV everywhere (particularly in the UK) and so on. (I’m particularly curious about the intersection between new technologies — such as RFID tags and biometrics — and public perceptions of those technologies, so I found some of the discussion very interesting indeed.)

Michael is part of the EU PRACTIS research group that has been forecasting technologies that will have an impact on privacy (good and bad: PETs and threats, so to speak). They use a roadmapping technique that is similar to the one we use at Consult Hyperion to help our clients to plan their strategies for exploiting new transaction technologies and is reasonably accurate within a 20 year horizon. Note that for our work for commercial clients, we use a 1-2 year, 2-5 year, and 5+ year roadmap. No-one in a bank or a telco cares about the 20 year view, even if we could predict it with any accuracy — and given that I’ve just read the BBC correspondents informed predictions for 2011 and they don’t mention, for example, what’s been going on in Tunisia and Egypt, I’d say that’s pretty difficult.

One key focus that Michael rather scarily picked out is omnipresent surveillance, particularly of the body (data about ourselves, that is, rather than data about our activities), with data acted upon immediately, but perhaps it’s best not go into that sort of thing right now!

He struck a definite chord when he said that it might be the new business models enabled by new technologies that are the real threat to privacy, not the technologies themselves. These mean that we need to approach a number of balances in new ways: privacy versus law enforcement, privacy versus efficiency, privacy versus freedom of expression. Moving to try and set these balances, via the courts, without first trying to understand what privacy is may take us in the wrong direction.

His idea for working towards a solution was plausible and understandable. Noting that privacy is a vague, elusive and contingent concept, but nevertheless a fundamental human right, he said that we need a useful model to start with. We can make a simple model by bounding a triangle with technology, law and values: this gives three sets of tensions to explore.

Law-Technology. It isn’t a simple as saying that law lags technology. In some cases, law attempts to regulate technology directly, sometimes indirectly. Sometimes technology responds against the law (eg, anonymity tools) and sometimes it co-operates (eg, PETs — a point that I thought I might disagree with Michael about until I realised that he doesn’t quite mean the same thing as I do by PETs).

Technology-Values. Technological determinism is wrong, because technology embodies certain values. (with reference to Social Construction of Technology, SCOT). Thus (as I think repressive regimes around the world are showing) it’s not enough to just have a network.

Law-Values, or in other words, jurisprudence, finds courts choosing between different interpretations. This is where Michael got into the interesting stuff from my point of view, because I’m not a lawyer and so I don’t know the background of previous efforts to resolve tensions on this line.

Focusing on that third set of tensions, then, in summary: From Warren and Brandeis’ 1890 definition of privacy as the right to be let alone, there have been more attempts to pick out a particular bundle of rights and call them privacy. Alan Westin‘s 1967 definition was privacy as control: the claims of individuals or groups or institutions to determine for themselves when, how and to what extent information about them is communicated to others.

This is a much better approach than the property right approach, where disclosing or not disclosing, “private” and “public” are the states of data. Think about the example of smart meters, where data outside the home provides information about how many people are in the home, what time they are there and so on. This shows that the public/private, in/out, home/work barriers are not useful for formulating a theory. The alternative that he put forward considers the person, their relationships, their community and their state. I’m not a lawyer so I probably didn’t understand the nuances, but this didn’t seem quite right to me, because there are other dimensions around context, persona, transaction and so on.

The idea of managing the decontextualisation of self seemed solid to my untrained ear and eye and I could see how this fitted with the Westin definition of control, taking on board the point that privacy isn’t property and it isn’t static (because it is technology-dependent). I do think that choices about identity ought, in principle, to be made on a transaction-by-transaction basis even if we set defaults and delegate some of the decisions to our technology and the idea that different persona, or avatars, might bundle some of these choices seems practical.

Michael’s essential point is, then, that a theory of privacy that is formulated by examining definitions, classsifications, threats, descriptions, justifications and concepts around privacy from scratch will be based on the central notion of privacy as control rather than secrecy or obscurity. As a technologist, I’m used to the idea that privacy isn’t about hiding data or not hiding it, but about controlling who can use it. Therefore Michael’s conclusions from jurisprudence connect nicely connect with my observations from technology.

An argument that I introduced in support of his position during the questions draws on previous discussions around the real and virtual boundary, noting that the lack of control in physical space means the end of privacy there, whereas in virtual space it may thrive. If I’m walking down the street, I have no control over whether I am captured by CCTV or not. But in virtual space, I can choose which persona to launch into which environment, which set of relationships and which business deals. I found Michael’s thoughts on the theory behind this fascinating, and I’m sure I’l be returning to them in the future.

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Time to experiment with new ATMs

There has been another spate of cash machine fraud, near where I live, entirely coincidentally. The police have instructed us to… well, let them tell you.

Officers have advised members of the public that if possible they should not leave the scene if their card is retained

[From� BBC News - Cash machine users in Woking warned over thefts]

So, essentially, if an ATM keeps your card (this has never, ever, happened to me) then you should stay by the machine and call for help. Who you are supposed to call is not made clear, but I will call one of� our local police stations. These are open from 8am to 10pm. As an aside, when I last went to one of our local police stations, I was ushered into a small room with a telephone, from where you are connected to the same call centre as if you had just stayed at home and phoned them, so come to think of it I may just as well call the call centre directly. Perhaps it’s time to rethink the “hello 1966” card plus 4-digit PIN system and either get rid of ATMs completely or improve their security.

Perhaps we should look further afield for ideas for new ATMs.

The Intelligent ATM comes equipped with a camera that recognises the customer’s face and sends details of the facial dimensions to a database for verification… Its use could also reduce the now common incidents where carjackers force their victims to empty their accounts at gunpoint, often taking the card and the personal identification number (PIN).

[From� Daily Nation: - News |Your face is all you’ll need at an ATM]

I think this is unlikely: it would simply replace customers being forced to hand over their ATM card at gunpoint with customers being forced to go to an ATM at gunpoint, which strikes me as being more dangerous! Relatively few people are carjacked and shot dead in Woking at the moment—this generally happens up the A3 in South London—- but it could all change. Mind you, you’ve got to be pretty brave to use an ATM at all in the UK.

‘We were surprised by our results because the ATM machines were shown to be heavily contaminated with bacteria; to the same level as nearby public toilets… In addition the bacteria we detected on ATMs were similar to those from the toilet, which are well known as causes of common human illnesses.’

[From� Cash machines ‘as dirty as public toilets’ | Mail Online]

Yuk. It’s time to stop the silly 1960s fashion for putting things in slots and touching filthy keypads. This might help prevent fraud as well as the propagation of intestinal disorders.

The future may lie with RFID chips and mobile phones. If a mobile phone replaced the ATM card and withdrawals could be performed only by placing an RFID phone near an ATM then cell site analysis (plus E911 and E112 compliance) would greatly limit the scope of fraud against banks. But such a secure deployment needs investment – and in these difficult times this looks doubtful.

[From� Forensic Computing Expert and Barrister - Automated Teller Machines]

Maybe Barclays, who have issued millions of contactless debit cards in the UK, might want to start experimenting with ATM de nos jours. After all, I want to leave home without a wallet, with only a phone, but there are still backward and underdeveloped parts of the world (eg, Woking) where many retailers do not yet have contactless terminals and so there is the need for occasional recourse to the hole in the wall, but it’s difficult to get my iPhone in the slot, especially when it is fitted with anti-fraud devices. Consider this appealing alternative: take splendid new Barclaycard/Orange mobile phone with NFC, open card application and enter numerical passcode and amount of money required. Then hold phone next to ATM and wait for the money to come out.

These are personal opinions and should not be misunderstood as representing the opinions of
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Time to do something about ATMs

There has been another spate of cash machine fraud, near where I live, entirely coincidentally. The police have instructed us to… well, let them tell you.

Officers have advised members of the public that if possible they should not leave the scene if their card is retained

[From BBC News - Cash machine users in Woking warned over thefts]

So, essentially, if an ATM keeps your card (this has never, ever, happened to me) then you should stay by the machine and call for help. Who you are supposed to call is not made clear, but I will call one of our local police stations. These are open from 8am to 10pm. As an aside, when I last went to one of our local police stations, I was ushered into a small room with a telephone, from where you are connected to the same call centre as if you had just stayed at home and phoned them, so come to think of it I may just as well call the call centre directly. Perhaps it’s time to rethink the “hello 1966″ card plus 4-digit PIN system and either get rid of ATMs completely or improve their security.

Perhaps we should look further afield for ideas for new ATMs.

The Intelligent ATM comes equipped with a camera that recognises the customer’s face and sends details of the facial dimensions to a database for verification… Its use could also reduce the now common incidents where carjackers force their victims to empty their accounts at gunpoint, often taking the card and the personal identification number (PIN).

[From Daily Nation: - News |Your face is all you’ll need at an ATM]

I think this is unlikely: it would simply replace customers being forced to hand over their ATM card at gunpoint with customers being forced to go to an ATM at gunpoint, which strikes me as being more dangerous! Relatively few people are carjacked and shot dead in Woking at the moment — this generally happens up the A3 in South London — but it could all change. Mind you, you’ve got to be pretty brave to use an ATM at all in the UK.

‘We were surprised by our results because the ATM machines were shown to be heavily contaminated with bacteria; to the same level as nearby public toilets… In addition the bacteria we detected on ATMs were similar to those from the toilet, which are well known as causes of common human illnesses.’

[From Cash machines 'as dirty as public toilets' | Mail Online]

Yuk. It’s time to stop the silly 1960s fashion for putting things in slots and touching filthy keypads. This might help prevent fraud as well as the propagation of intestinal disorders.

The future may lie with RFID chips and mobile phones. If a mobile phone replaced the ATM card and withdrawals could be performed only by placing an RFID phone near an ATM then cell site analysis (plus E911 and E112 compliance) would greatly limit the scope of fraud against banks. But such a secure deployment needs investment – and in these difficult times this looks doubtful.

[From Forensic Computing Expert and Barrister - Automated Teller Machines]

Maybe Barclays, who have issued millions of contactless debit cards in the UK, might want to start experimenting with ATM de nos jours. After all, I want to leave home without a wallet, with only a phone, but there are still backward and underdeveloped parts of the world (eg, Woking) where many retailers do not yet have contactless terminals and so there is the need for occasional recourse to the hole in the wall, but it’s difficult to get my iPhone in the slot, especially when it is fitted with anti-fraud devices. Consider this appealing alternative: take splendid new Barclaycard/Orange mobile phone with NFC, open card application and enter numerical passcode and amount of money required. Then hold phone next to ATM and wait for the money to come out.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

New approaches to National ID

The UK’s last attempt to introduce a national identity infrastructure, the national ID card, failed pretty badly and left everyone involved under a cloud (except for the management consultancies who billed tens of millions of pounds to the project).

The Home Office slipped out the final report of the Independent Scheme Advisory Panel (ISAP) this week, more than a year after it was written. The ostensibly independent report, which reveals how the ID system had been compromised by poor design and management, was submitted to the Home Office in December 2009.

[From� Henry Porter - Home Office suppressed embarrassing ID cards report]

The report says that there are no specifications for usage or verification (which we knew – this was one of my constant complaints at the time) and, revealingly, that (in section 3.3) that “it is likely that European travel” will emerge as the key consumer benefit. This, I think, is an interesting comment. As I have pointed before in tedious detail, what the Identity & Passport Service (IPS) built was, well, a passport. It had no other functionality and, given the heritage, was never going to have. Hence my idea of renaming it “Passport Plus” and selling it to frequent travellers (eg, me) as a convenience.

As an aside, the report also says (in section 5.5) the “significant” number of change requests after the contracts had been awarded would likely increase risk, cost and timescale. Again, while this is a predictable comment, it is a reflection on the outdated consultation, specification and procurement processes used. Instead of a flagship government project heralding a new economy, we ended up with the usual fare: incomplete specifications, huge management consultant bills, massive and inflexible supply contracts.

The report repeated the same warnings ISAP had given the Home Office every year since the system blueprint was published in December 2006 by Liam Byrne and Joan Ryan, then Home Office Ministers, and James Hall, then head of the Identity and Passport Service (IPS).

[From� Home Office suppressed embarrassing ID cards report - 1/7/2011 - Computer Weekly]

How did it all go do wrong? Liam Byrne should have known something about IT as he used to work for Accenture, as did James Hall (Joan Ryan was a sociology teacher who later became famous for having claimed for more than £1,000,000 in MP’s expenses). Yet somehow the “vision” that emerged was profoundly untechnological, backward-looking and lacking in inspiration. What’s different now?

Well, a key change is that the new administration is heading more along the lines of the US (with USTIC) and the Nordics, where people use their bank IDs to access public services. We’re working on a project with Visa Europe and our good friend Fred Piper at Royal Holloway to develop a pilot implementation right now.

Consult Hyperion, working with Visa Europe and Codes & Ciphers, is the industry lead for a Technology Strategy Board funded research project;� Sure Identity, for Secure Authentication of Online Government Services. This innovative pilot scheme will investigate the security and cost benefits of consumers using new bank-issued electronic Visa debit cards to securely access online government services

[From� Digital Systems - DS KTN Member receives funding from Trusted Services Competition for research into the secure authentication of online Government Services - Articles - Technology Strategy Board]

It’s possible to at least imagine some form of “UKTIC” that is interoperable with the US version, certainly to the extent that an American with a US bank account might be able to open a UK bank account, things like that. And it’s possible to imagine a kind of EUTIC that sets certain minimums in place so that UKTIC can interoperate with France TIC and Germany TIC and so on. I already have one or two ideas about where UKTIC may differ from USTIC. Let’s go back to the EFF’s comments on USTIC.

A National Academies study,� Who Goes There?: Authentication Through the Lens of Privacy, warned that multiple, separate, unlinkable credentials are better for both security and privacy. Yet the draft NSTIC doesn’t discuss in any depth how to prevent or minimize linkage of our online IDs, which would seem much easier online than offline, and fails to discuss or refer to academic work on unlinkable credentials (such as that of Stefan Brands, or Jan Camenisch and Anna Lysyanskaya).

[From� Real ID Online? New Federal Online Identity Plan Raises Privacy and Free Speech Concerns | Electronic Frontier Foundation]

If we were to make UKTIC something like USTIC but with the addition of a class of unlinkable credentials that might be mandated for certain uses, then we could take a really important step forward: instead of a physical national identity card, the administration could trumpet and virtual national privacy card. (Actually, I’d be tempted call it a Big Society Card in order to get funding!)

These are personal opinions and should not be misunderstood as representing the opinions of
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Positive changes in e-money regulation

William Long and Kai Zhang, from our friends at Sidley & Austin, present a typically good summary of the main issues raised in the consultations preceding the implementation of the new E-Money Directive (EMD) in the UK in the recent issue of� E-Finance & Payments Law & Policy (December 2010).

Generally speaking, things look very positive. The capital requirements are being relaxed so that anyone who wants to provide e-money services probably can do with too much trouble, so I predict that you’ll see some major companies moving in now. The prime candidates to offer services are probably telecommunications operators and retailers, but transit operators, event managers, corporate “campus” suppliers and others will surely seize the opportunity. Some have already declared their intentions.

O2 will apply for an e-money licence this year, signalling its commitment to support contactless payments in the UK in the near future.

[From� O2 to apply for e-money licence to support NFC payments - 2/2/2011 - Computer Weekly]

The French operators announced a similar move this week. I can’t resist noting that this is precisely the strategy that we recommended to mobile operators a couple of years ago (that is, use the upcoming PSD/ELMI changes to start their own payment businesses). Competition is good for innovation, and bringing these new players into the payments business will be very positive for all of us.

The interest of mobile operators is natural, and they have to move quickly to avoid being cut out of the loop by handset-based secure element providers (eg, Apple) who may move quicker than the UICC-based secure element providers (eg, mobile operators). The interest of the transit operators is also natural, since they have the cards out there in peoples’ pockets. I still think that we’ve yet to see the really big plays yet: these will come from the retailers, just as they are in the US.

Kmart has begun testing check cashing, money transfers and prepaid cards in stores in Illinois, California and Puerto Rico, with plans to roll out the services nationally later this year. Best Buy has installed kiosks in its stores for shoppers to pay utility, cable and phone bills. Wal-Mart has opened roughly 1,500 MoneyCenters that process as many as 5 million transactions each week.

[From� Retailers offer financial services to ‘unbanked’]

The use of retailer-issued e-money pre-paid products as a low-cost alternative to bank accounts for the excluded is a win-win. It takes unprofitable customers away from the banks and gives those customers more convenient services. And the retailers could steer customers to use these products at POS, thus saving on their payment processing costs. Personally, I think the prepaid market is not competitive enough (the charges are still too high) but new entrants enabled by the ELMI, new entrants with economies of scale (such as high street retailers), could open up the market and drive down costs very quickly.

Finally, I was also very excited to note in the article that the Treasury is considering my idea of making the balance limit for simplified due diligence (under the Third Anti-Money Laundering Directive) for low-value electronic money “accounts” the same as the value of the largest banknote: in this case, €500. Although they are only looking at this for non-reloadable devices, I think this should be the guiding principle for reloadable devices as well. The link between the two, the “magic number”, is entirely symbolic: it doesn’t mean anything at all, but it’s a good way to focus debate and discussion about the regulatory balance between cash and cash alternatives.

These are personal opinions and should not be misunderstood as representing the opinions of
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Having another go

The UK’s last attempt to introduce a national identity infrastructure, the national ID card, failed pretty badly and left everyone involved under a cloud (except for the management consultancies who billed tens of millions of pounds to the project).

The Home Office slipped out the final report of the Independent Scheme Advisory Panel (ISAP) this week, more than a year after it was written. The ostensibly independent report, which reveals how the ID system had been compromised by poor design and management, was submitted to the Home Office in December 2009.

[From Henry Porter - Home Office suppressed embarrassing ID cards report]

The report says that there are no specifications for usage or verification (which we knew – this was one of my constant complaints at the time) and, revealingly, that (in section 3.3) that “it is likely that European travel” will emerge as the key consumer benefit. This, I think, is an interesting comment. As I have pointed before in tedious detail, what the Identity & Passport Service (IPS) built was, well, a passport. It had no other functionality and, given the heritage, was never going to have. Hence my idea of renaming it “Passport Plus” and selling it to frequent travellers (eg, me) as a convenience.

As an aside, the report also says (in section 5.5) the “significant” number of change requests after the contracts had been awarded would likely increase risk, cost and timescale. Again, while this is a predictable comment, it is a reflection on the outdated consultation, specification and procurement processes used. Instead of a flagship government project heralding a new economy, we ended up with the usual fare: incomplete specifications, huge management consultant bills, massive and inflexible supply contracts.

The report repeated the same warnings ISAP had given the Home Office every year since the system blueprint was published in December 2006 by Liam Byrne and Joan Ryan, then Home Office Ministers, and James Hall, then head of the Identity and Passport Service (IPS).

[From Home Office suppressed embarrassing ID cards report - 1/7/2011 - Computer Weekly]

How did it all go do wrong? Liam Byrne should have known something about IT as he used to work for Accenture, as did James Hall (Joan Ryan was a sociology teacher who later became famous for having claimed for more than £1,000,000 in MP’s expenses). Yet somehow the “vision” that emerged was profoundly untechnological, backward-looking and lacking in inspiration. What’s different now?

Well, a key change is that the new administration is heading more along the lines of the US (with USTIC) and the Nordics, where people use their bank IDs to access public services. We’re working on a project with Visa Europe and our good friend Fred Piper at Royal Holloway to develop a pilot implementation right now.

Consult Hyperion, working with Visa Europe and Codes & Ciphers, is the industry lead for a Technology Strategy Board funded research project; Sure Identity, for Secure Authentication of Online Government Services. This innovative pilot scheme will investigate the security and cost benefits of consumers using new bank-issued electronic Visa debit cards to securely access online government services

[From Digital Systems - DS KTN Member receives funding from Trusted Services Competition for research into the secure authentication of online Government Services - Articles - Technology Strategy Board]

It’s possible to at least imagine some form of “UKTIC” that is interoperable with the US version, certainly to the extent that an American with a US bank account might be able to open a UK bank account, things like that. And it’s possible to imagine a kind of EUTIC that sets certain minimums in place so that UKTIC can interoperate with France TIC and Germany TIC and so on. I already have one or two ideas about where UKTIC may differ from USTIC. Let’s go back to the EFF’s comments on USTIC.

A National Academies study, Who Goes There?: Authentication Through the Lens of Privacy, warned that multiple, separate, unlinkable credentials are better for both security and privacy. Yet the draft NSTIC doesn’t discuss in any depth how to prevent or minimize linkage of our online IDs, which would seem much easier online than offline, and fails to discuss or refer to academic work on unlinkable credentials (such as that of Stefan Brands, or Jan Camenisch and Anna Lysyanskaya).

[From Real ID Online? New Federal Online Identity Plan Raises Privacy and Free Speech Concerns | Electronic Frontier Foundation]

If we were to make UKTIC something like USTIC but with the addition of a class of unlinkable credentials that might be mandated for certain uses, then we could take a really important step forward: instead of a physical national identity card, the administration could trumpet and virtual national privacy card. (Actually, I’d be tempted call it a Big Society Card in order to get funding!)

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.