Does mass market eID need a liability model or not?

I posted about the silo-style identity and authentication schemes we have in place at the moment and complained that we are making no progress on federation. Steve Wilson posted a thoughtful reply and picked me up on a few points, such as my “idea” (that’s a bit strong – more of a notion, really) of developing an equivalent of creative commons licences, a sort of open source framework. He says

CC licenses wouldn’t ever be enough. Absent new laws to make this kind of grand identity federation happen, we will still need new contracts—brand new contracts of an unusual form—struck between all the parties.

[From comment on� Digital Identity: The sorry state of id and authentication]

But isn’t that what CC licences solve?

It’s complicated by the fact that banks & telcos don’t naturally see themselves as “identity providers”, not in the open anyway

[From comment on� Digital Identity: The sorry state of id and authentication]

Well, I’m doing what I can to change that (see, for example, the� Visa/CSFI Research Fellowship), but on the main point I happened to be reading the notes from the� EURIM Identity Governance Subgroup meeting on 23 February 2011, talking about business cases for population scale identity management systems. The notes say that

It is alleged that the only body with the remit, power and capability needed for assuring and recording a root identity through a secure and reliable registration process is Government.

The notes then go on to talk about case studies such as the Nordic bank-issued eIDs though. These arguments are to some extent circular, of course, because the e-government applications in the Nordics are using bank-issued eIDs, but the only reason that the banks can issue these eIDs is because they are using government ID as the basis for KYC. In the discussion about this at a recent roundtable in that Visa/CSFI “Identity and Financial Services” series, someone made a comment in passing (and I’m embarrassed to say that I can’t remember who said this, because I noted the comment but forgot the commenter) that all of this takes places in a model� absent liability. That is, as far as I understand what was said, the government accepts no liability from the banks, and vice versa. So if the bank opens an account for me Sven Birch, using a government “Sven Birch” identity, but it subsequently transpires that I am actually� Theogenes de Montford, then the bank cannot claim against the government. Similarly, if I used my bank eID “Sven Birch” to access government services, but it subsequently transpires that I am actually Theogenes, then the government has no claim against the bank. (If this isn’t true, by the way, I would appreciate clarification from a knowledgeable correspondent.)

So what is the situation? Must we have a liability model, or can we all agree to get along without one. Or do you have to a have a more consensual society, or perhaps one with fewer lawyers per head of population?

These are personal opinions and should not be misunderstood as representing the opinions of
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

It all comes back to liability

I posted about the silo-style identity and authentication schemes we have in place at the moment and complained that we are making no progress on federation. Steve Wilson posted a thoughtful reply and picked me up on a few points, such as my “idea” (that’s a bit strong – more of a notion, really) of developing an equivalent of creative commons licences, a sort of open source framework. He says

CC licenses wouldn’t ever be enough. Absent new laws to make this kind of grand identity federation happen, we will still need new contracts — brand new contracts of an unusual form — struck between all the parties.

[From comment on Digital Identity: The sorry state of id and authentication]

But isn’t that what CC licences solve?

It’s complicated by the fact that banks & telcos don’t naturally see themselves as “identity providers”, not in the open anyway

[From comment on Digital Identity: The sorry state of id and authentication]

Well, I’m doing what I can to change that (see, for example, the Visa/CSFI Research Fellowship), but on the main point I happened to be reading the notes from the EURIM Identity Governance Subgroup meeting on 23 February 2011, talking about business cases for population scale identity management systems. The notes say that

It is alleged that the only body with the remit, power and capability needed for assuring and recording a root identity through a secure and reliable registration process is Government.

The notes then go on to talk about case studies such as the Nordic bank-issued eIDs though. These arguments are to some extent circular, of course, because the e-government applications in the Nordics are using bank-issued eIDs, but the only reason that the banks can issue these eIDs is because they are using government ID as the basis for KYC. In the discussion about this at a recent roundtable in that Visa/CSFI “Identity and Financial Services” series, someone made a comment in passing (and I’m embarrassed to say that I can’t remember who said this, because I noted the comment but forgot the commenter) that all of this takes places in a model absent liability. That is, as far as I understand what was said, the government accepts no liability from the banks, and vice versa. So if the bank opens an account for me Sven Birch, using a government “Sven Birch” identity, but it subsequently transpires that I am actually Theogenes de Montford, then the bank cannot claim against the government. Similarly, if I used my bank eID “Sven Birch” to access government services, but it subsequently transpires that I am actually Theogenes, then the government has no claim against the bank. (If this isn’t true, by the way, I would appreciate clarification from a knowledgeable correspondent.)

So what is the situation? Must we have a liability model, or can we all agree to get along without one. Or do you have to a have a more consensual society, or perhaps one with fewer lawyers per head of population?

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Hip to be Square

Many years ago, when I was a mere slip of a consultant, I was sent by a client to check out a company called WorldPay, then run by Forum friend Nick Ogden. I reported back to the retail bank I was engaged by that I couldn’t see where WorldPay was going, since it didn’t provide any service that the bank couldn’t provide themselves given a small amount of development effort. Therefore I assumed that the bank, like all other banks, would soon be providing a comprehensive range of services for new internet businesses and that WorldPay’s niche would vanish.

Royal Bank of Scotland Group Plc, the U.K.’s biggest government-owned bank, agreed to sell its credit- card payment processing unit to Advent International Corp. and Bain Capital LLC for 1.7 billion pounds ($2.7 billion).

[From RBS Sells WorldPay to Advent, Bain for $2.7 Billion - Bloomberg]

Please! Don’t listen to me about anything to do with business! I didn’t realise that there is no such thing as a quick and dirty development in a bank, and that starting a new line of business doesn’t happen overnight. There’s a big, big gap between people like me saying that all the bank needs is a simple internet gateway and a merchant acquisition process and these systems and processes actually getting going. Things just don’t work like that, for all of the well-known reasons (focus on core business etc). I was thinking about this when I got into a discussion with someone a few days ago. They said that Square does nothing that existing stakeholders in the card business couldn’t do themselves, so it has no long-term future, the argument being that Barclays or Streamline could just offer a similar service. And Square is reducing its charges, meaning less margin, so they won’t be able to beat the big boys on cost either.

Square’s rates will fall to a flat fee of 2.75 percent per transaction instead of charging 2.75 percent plus an additional 15 cents. (The rate for when a credit card number is keyed in, rather than swiped, will remain the same at 3.5 percent plus 15 cents.)

[From Square Sacrifices Revenues to Ramp Mobile Payment Volumes | Tricia Duryee | eMoney | AllThingsD]

All true. But the reality is that just because other merchant acquirers could do this does not mean that they can do this, and if Square can provide just enough added-value with their app to get traction in the small business sector (they are already processing a million dollars a day), then when new payment technologies come along (eg, NFC phones that can accept payments from contactless cards) the merchants will just expect Square to handle them for them. We have long been advising clients that the key disruptive role of mobile phones in the payments world is the ability to take payments, not to make them.

Incidentally, I can’t resisting commenting on the Square-based debate that sprung up over the last few days. As I’m sure you all know, Verifone wrote an open letter pointing out that Square is not fully PCI compliant, something that has been known since the product was first announced.

iPhone cannot be made PCI compliant without first encrypting the card BEFORE it gets into the iPhone (see the Verifone solution)

[From Square Up update « FinVentures]

Not that interesting, to be honest, but it did stir things up and Square had to respond, which they did by pointing out that the problem is with a payment system built on trivially-copyable magnetic stripes and the like.

In his response, Dorsey said any technology, including “an encrypted card reader, phone camera or plain old pen and paper,” can be used to steal information. “If you provide your credit card to someone who intends to steal from you, they already have everything they need: the information on the front of your card,”

[From Square Responds to VeriFone s Security Claims - American Banker Article]

Will master criminals intent on skimming card numbers sign up with Square and then install a dodgy app? Probably not. There are plenty of better options out there, including the existing magnetic stripe readers that the criminals already use.

Exposing Square’s security vulnerabilities in this manner is an act of outright hostility on VeriFone’s part, and a sign that it’s unnerved by Square’s growth.

[From VeriFone Attacks Rival Square With Ethically-Questionable Security Exploit: Apple News, Tips and Reviews «]

Not that it’s any of my business, but this is why the letter looks like a mistake. If I were Verifone, I would have spent my time making a better iPhone card reader, or something that plugs in to Android phones or EMV chip/contactless readers or whatever, or partnering with people to deliver great merchant service, or something else to compete.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

14th Digital Money Forum a great success

The 14th annual Consult Hyperion� Digital Money Forum was terrific. Here’s some of the feedback we’ve already had:

  • “Excellent! Thank you again”
  • “A most enjoyable event with a variety of speakers”
  • “It was very stimulating”
  • “A very informative conference which didn’t disappoint.”
  • “Very good – as always, so much new stuff”
  • “a terrific #dmf14 session on private vs public money”
  • “I saw the future, the past and, surprisingly, the freedom of cash.”
  • “Very good – as always, so much new stuff!”

First of all, and I can’t say this often enough, a very big thank you to the event sponsors who made it all possible:� Visa Europe and� Monitise. For an event like the Forum it’s really important to have sponsors who share our goals, and both of them were great, giving us the freedom to choose an eclectic mix of speakers and panelist who really helped the delegates (and us) to think in some new ways and to spark off new ideas about where to go next in the world of e-payments. This makes for a special event, unlike the commercial conferences that we attend throughout the year. The economist Diane Coyle, who was kind enough to chair the keynote session on day two, put it very nicely

As ever the Digital Money Forum proved itself a must for anyone interested in the intersection of technology and money

[From� The Enlightened Economist :: Good money, digital or analogue]

And thanks also to our newest supporters,� Olswang, who kindly sponsored to pub quiz (which was great fun) and the drinks that went with it.

I won’t go over everything that was discussed—the� presentations are online if you want to download them—but I will highlight a couple of points that emerged over the two days. First of all, both of the opening sessions, which mixed history and future, worked very well and did, I think, help people to think more imaginatively about the discussions later in the day. The expert panels were popular as always, although I really should keep them to only four people per panel. I’ve had some interesting feedback about the panel on alternative currencies, which I think gave many organisations some unexpected directions to explore.

Mobile was, naturally, a key topic and pervaded many of the discussions. We may have to make it a bigger fraction of the agenda next year if we can find some new angles to approach it from. A lot of the delegates remarked on how juxtaposing lessons being learned in both developed and developing markets worked well, so that’s something to think about.

We’ve already started thinking about 15th Digital Money Forum and what we’re going to do to change things again. I can promise all of you that the event will keep moving forward. Next year will see a new venue (and, yes, there will be free wifi for all), some new ideas for interaction and some changes in the programme structure. One thing that won’t change is the art and design competition: given the outstanding presentations at the end of this years’ Forum, we’ll definitely do that again! If you weren’t there, I urge you to take a� look at the competition winners and appreciate the imagination and invention that went into them.

If I had to highlight one presentation, it was Catherine Eagleton’s keynote. Catherine is the curator of Modern Money at the� British Museum and co-author of the excellent� Money-A History. She asked the delegates to send her examples of anything that should be preserved, particularly the intermediate forms of new payment systems that are forgotten in the long run. I hope some of them will take her up on that. But she also mentioned in passing how difficult it is to think of ways to preserve World of Warcraft gold pieces or Facebook credits for posterity, and I keep thinking about it now. It came up last year when Consult Hyperion were asked to provide a piece on mobile money for the Science Museum. We were enthusiastic, but soon realised that a phone in a glass case (with a dead battery) is not much of an exhibition, and I’m afraid the curators concurred. So if anyone has any ideas on that one, please get in touch (although it does give me an idea for next year’s competition!).

These are personal opinions and should not be misunderstood as representing the opinions of
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Still going strong after 14 years

The 14th annual Consult Hyperion Digital Money Forum was terrific. Here’s some of the feedback we’ve already had:

  • “Excellent! Thank you again”
  • “A most enjoyable event with a variety of speakers”
  • “It was very stimulating”
  • “A very informative conference which didn’t disappoint.”
  • “Very good – as always, so much new stuff”
  • “a terrific #dmf14 session on private vs public money”
  • “I saw the future, the past and, surprisingly, the freedom of cash.”
  • “Very good – as always, so much new stuff!”

First of all, and I can’t say this often enough, a very big thank you to the event sponsors who made it all possible: Visa Europe and Monitise. For an event like the Forum it’s really important to have sponsors who share our goals, and both of them were great, giving us the freedom to choose an eclectic mix of speakers and panelist who really helped the delegates (and us) to think in some new ways and to spark off new ideas about where to go next in the world of e-payments. This makes for a special event, unlike the commercial conferences that we attend throughout the year. The economist Diane Coyle, who was kind enough to chair the keynote session on day two, put it very nicely

As ever the Digital Money Forum proved itself a must for anyone interested in the intersection of technology and money

[From The Enlightened Economist :: Good money, digital or analogue]

And thanks also to our newest supporters, Olswang, who kindly sponsored to pub quiz (which was great fun) and the drinks that went with it.

I won’t go over everything that was discussed — the presentations are online if you want to download them — but I will highlight a couple of points that emerged over the two days. First of all, both of the opening sessions, which mixed history and future, worked very well and did, I think, help people to think more imaginatively about the discussions later in the day. The expert panels were popular as always, although I really should keep them to only four people per panel. I’ve had some interesting feedback about the panel on alternative currencies, which I think gave many organisations some unexpected directions to explore.

Mobile was, naturally, a key topic and pervaded many of the discussions. We may have to make it a bigger fraction of the agenda next year if we can find some new angles to approach it from. A lot of the delegates remarked on how juxtaposing lessons being learned in both developed and developing markets worked well, so that’s something to think about.

We’ve already started thinking about 15th Digital Money Forum and what we’re going to do to change things again. I can promise all of you that the event will keep moving forward. Next year will see a new venue (and, yes, there will be free wifi for all), some new ideas for interaction and some changes in the programme structure. One thing that won’t change is the art and design competition: given the outstanding presentations at the end of this years’ Forum, we’ll definitely do that again! If you weren’t there, I urge you to take a look at the competition winners and appreciate the imagination and invention that went into them.

If I had to highlight one presentation, it was Catherine Eagleton’s keynote. Catherine is the curator of Modern Money at the British Museum and co-author of the excellent Money-A History. She asked the delegates to send her examples of anything that should be preserved, particularly the intermediate forms of new payment systems that are forgotten in the long run. I hope some of them will take her up on that. But she also mentioned in passing how difficult it is to think of ways to preserve World of Warcraft gold pieces or Facebook credits for posterity, and I keep thinking about it now. It came up last year when Consult Hyperion were asked to provide a piece on mobile money for the Science Museum. We were enthusiastic, but soon realised that a phone in a glass case (with a dead battery) is not much of an exhibition, and I’m afraid the curators concurred. So if anyone has any ideas on that one, please get in touch (although it does give me an idea for next year’s competition!).

Oh, and I should finish by saying to everyone who mentioned it (and there were quite a few), yes, the hotel coffee was slop that I wouldn’t have fed to pigs and I swear with my hand on my heart that if we ever serve stuff like that to you again I will personally take all delegates to the nearest Caffe Nero and buy every single one of them a drink there myself.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Identity and authentication for the web is not in a good state

I had a problem with my PayPal account: I used it in China, and it got blocked as the result of some kind of fraud screening.

I ended up having to promise the guys at Bike Beijing that I will sort this out when I get back to the UK and then send them their money.

[From� Digital Money: Holding court]

They still haven’t got their money. In order to unblock the account, you had to log in to your account and then have a code sent via your home telephone number. I clicked, the phone rang, I punched in the number and hung up. Nothing. I clicked again, the phone rang, I punched in the number and waited. Nothing. I clicked again, the phone rang, I punched in the number. After a while, I got an e-mail telling me that the authentication process had failed and so PayPal would send a letter containing some kind of code to my home address and that I could then use this code to unblock my account. It mentioned that the letter might takes six weeks to arrive.

So the nice guys at� Bike Beijing still don’t have their money and I’m still embarrassed.

Now, all the time that this nonsense about codes and letters was going on, I had on my desk a Barclays’ PINSentry (which I can’t even use to log on to Barclaycard, let alone PayPal) and a O2 mobile phone (I’ve been with O2 for two decades and have a billing relationship with them – their system� knew that I was in China) and a keyring OTP generator that we used for our corporate VPN. Any one of these could provide a better solution then messing about typing in code numbers, but they all sit in their own silos and don’t provide the kind of general-purpose services that they should.

What should have happened, of course, is that I should have been able to log in to PayPal using OpenID and then logged in to a 2FA OpenID using my (say) PINSentry. So now PayPal knows that I have been 2FA logged in from an “acceptable” source (ie, Barclays Bank) and we could move on. So why doesn’t this happen? Is it because OpenID has failed?

But if OpenID is a failure, it’s one of the web’s most successful failures. OpenID is available on more than 50,000 websites. There are over a billion OpenID enabled URLs on the web thanks to providers like Google, Yahoo and AOL. Yet, for most people, trying to log in to every website using OpenID remains a difficult task, which means that while thousands of websites support it, hardly anyone uses OpenID.

[From� OpenID: The Web’s Most Successful Failure | Webmonkey | Wired.com]

It can’t be that. OpenID has plenty of support, and even the US government got behind it.

Who would have predicted say, 5 years ago, that you would some day be able to use commercial identities on government websites? Evidently, this raises questions about privacy and security but if these initiatives can garner enough public support, government validation of open identity frameworks could be a boon for the ecosystem of the open, distributed web. Plus, it can make dealing with the government a lot easier for you, too.

[From� US Government To Embrace OpenID, Courtesy Of Google, Yahoo, PayPal Et Al.]

It’s not about the technology. I make no judgement as to whether OpenID is the best technology or not (although it does actually exist, which is a good start), but the truth is that it simply doesn’t matter whether it is or it isn’t.

The unresolved business and legal challenges implicit in federated identity are to blame for the under-delivery of OpenID

[From� OpenID, Successful Failures And New Federated Identity Options | Forrester Blogs]

Indeed they are. So the problem isn’t really anything to do with OpenID, or any other framework that might come along in cyberspace, but the legal framework that it has to sit inside. This is where we need the breakthrough. We need potential identity providers (eg, Barclays, O2) to be able to set up OpenID responders for their customers inside a well-known and well-understood legal framework. Now, you can do this contractually (as� IdenTrust has done), but to scale to the open web, we need something more than that, perhaps an equivalent of the “creative commons” licences that are used for content but for credentials.

Even then, would someone like PayPal rely on them? Or would it only rely on identities from regulated financial institutions in the EU? Or only such institutions that met some minimum authentication standard? We’re a long way from fixing my Chinese problem, despite having all of the technology needed to do so.

These are personal opinions and should not be misunderstood as representing the opinions of
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The sorry state of id and authentication

I had a problem with my PayPal account: I used it in China, and it got blocked as the result of some kind of fraud screening.

I ended up having to promise the guys at Bike Beijing that I will sort this out when I get back to the UK and then send them their money.

[From Digital Money: Holding court]

They still haven’t got their money. In order to unblock the account, you had to log in to your account and then have a code sent via your home telephone number. I clicked, the phone rang, I punched in the number and hung up. Nothing. I clicked again, the phone rang, I punched in the number and waited. Nothing. I clicked again, the phone rang, I punched in the number. After a while, I got an e-mail telling me that the authentication process had failed and so PayPal would send a letter containing some kind of code to my home address and that I could then use this code to unblock my account. It mentioned that the letter might takes six weeks to arrive.

So the nice guys at Bike Beijing still don’t have their money and I’m still embarrassed.

Now, all the time that this nonsense about codes and letters was going on, I had on my desk a Barclays’ PINSentry (which I can’t even use to log on to Barclaycard, let alone PayPal) and a O2 mobile phone (I’ve been with O2 for two decades and have a billing relationship with them – their system knew that I was in China) and a keyring OTP generator that we used for our corporate VPN. Any one of these could provide a better solution then messing about typing in code numbers, but they all sit in their own silos and don’t provide the kind of general-purpose services that they should.

What should have happened, of course, is that I should have been able to log in to PayPal using OpenID and then logged in to a 2FA OpenID using my (say) PINSentry. So now PayPal knows that I have been 2FA logged in from an “acceptable” source (ie, Barclays Bank) and we could move on. So why doesn’t this happen? Is it because OpenID has failed?

But if OpenID is a failure, it’s one of the web’s most successful failures. OpenID is available on more than 50,000 websites. There are over a billion OpenID enabled URLs on the web thanks to providers like Google, Yahoo and AOL. Yet, for most people, trying to log in to every website using OpenID remains a difficult task, which means that while thousands of websites support it, hardly anyone uses OpenID.

[From OpenID: The Web’s Most Successful Failure | Webmonkey | Wired.com]

It can’t be that. OpenID has plenty of support, and even the US government got behind it.

Who would have predicted say, 5 years ago, that you would some day be able to use commercial identities on government websites? Evidently, this raises questions about privacy and security but if these initiatives can garner enough public support, government validation of open identity frameworks could be a boon for the ecosystem of the open, distributed web. Plus, it can make dealing with the government a lot easier for you, too.

[From US Government To Embrace OpenID, Courtesy Of Google, Yahoo, PayPal Et Al.]

It’s not about the technology. I make no judgement as to whether OpenID is the best technology or not (although it does actually exist, which is a good start), but the truth is that it simply doesn’t matter whether it is or it isn’t.

The unresolved business and legal challenges implicit in federated identity are to blame for the under-delivery of OpenID

[From OpenID, Successful Failures And New Federated Identity Options | Forrester Blogs]

Indeed they are. So the problem isn’t really anything to do with OpenID, or any other framework that might come along in cyberspace, but the legal framework that it has to sit inside. This is where we need the breakthrough. We need potential identity providers (eg, Barclays, O2) to be able to set up OpenID responders for their customers inside a well-known and well-understood legal framework. Now, you can do this contractually (as IdenTrust has done), but to scale to the open web, we need something more than that, perhaps an equivalent of the “creative commons” licences that are used for content but for credentials.

Even then, would someone like PayPal rely on them? Or would it only rely on identities from regulated financial institutions in the EU? Or only such institutions that met some minimum authentication standard? We’re a long way from fixing my Chinese problem, despite having all of the technology needed to do so.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Join us at the International Payments Summit on 21st March in London

I really enjoyed the annual International Payments Summit last year, so this year we decided to work with them on a small experiment. On 21st March we’ve helped to put together a 1-day summit on the future of e-transactions, called (somewhat provocatively, I must confess) “cash is dead”.

The idea is to discuss the world of digital transactions (which, of course, in our world means digital money and digital identity) to help organisations who are putting together strategies make some realistic decisions about where future competitive advantage may lay. Naturally, reflecting my own prejudices, there will be plenty of discussion about opportunities for financial services organisations to either provide or exploit the coming range of digital identity services.

As organisers, Consult Hyperion have a couple of complimentary delegate places to give away, so if you plan to be in London on 21st March 2011 and you’d like to come along to the Lancaster London and join in the discussion, please e-mail me ASAP and I will arrange. Don’t pass up this offer as we have a great bunch of people coming along for panels, discussions and networking, see you there.

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The reality of the Japanese retail payments sector

At the 14th annual� Digital Money Forum this week, Michael Salmony from� Equens gave a talk about the reality of retail payments in Japan. Or, as he called it, his holiday snaps! He showed some excellent photos and a video to help us to understand what is really going on. We all know that electronic money of one form and another is huge in Japan, so that’s a good starting point for trying to figure out where they are and what it means for other markets.

Most of the population uses eMoney on a daily basis with mobile FeliCa RFID wallet phones to purchase train/bus fare, a beverage at a vending machine, a meal at a local restaurant or a snack at a convenience store. Many local business and convenience stores have their own chargeable eMoney cards as well as loyalty cards.

[From� What the U.S. Can Learn from Japan’s eCommerce Ecosystems - pymnts.com]

As Michael noted, contactless e-money (ie, prepaid) cards are widely used. There are vending machines everywhere and contactless payments are used for them, in convenience stores, for buying tickets and in many other ways. No wonder that the basic numbers are bullish.

During the first half of 2010, the number of electronic money transactions swelled by 39%

[From� E-money - Big, and Getting Bigger in Japan - Japan Real Time - WSJ]

Note, though, that most electronic money transactions are still made with these cards. I tried to find the most up-to-date statistics that I could to match them to what Michael was saying and they do confirm his impressions.

In December 2010, 9.8 million mobile users in Japan made a purchase using their mobile as the payment vehicle. That works out to about 10 percent of all mobile subscribers, according to comScore.

[From� 10% of Japanese Use Mobile Payments | Mobile Marketing and Technology]

As far as I can tell, this means that the use of mobile proximity for payments (although not for loyalty, coupons and so on) has fallen over the last year. I wondered why it was not growing quicker, let alone growing at all. Michael showed a video that might explain why: in order to pay using mobile proximity, the user had to press several buttons and wait for software to load. It didn’t seem terribly convenient and, I have to say, it seemed a much worse user experience than the European and US mobile proximity payment systems that we are working on at the moment. This explained to me why the use of cards continued to dominate, but… there has also been a decrease in the number of people using the e-money cards as well. Why is this?

Well, if you delve around in the relevant sources of statistics (at least, the ones in English that I subscribe to RSS feeds for) you find an interesting and plausible explanation which I think has significant implications for the development of e-money services in Europe and in the US, especially given the pressure on debit interchange.

My IC card cash gets used on public transport and convenience stores only. All the other shops that accept it also accept the credit card portion, and most of them also award 3% points instead of just 1%, so it’s an easy choice. Furthermore, they more often than not don’t even ask for a PIN when using credit, so the extra effort required is minimal.

[From� Japanese electronic cash card users continue to decrease | 世論 What Japan Thinks]

Contactless credit cards that give 3% rewards appearing to be winning out over other e-payment mechanisms, particularly contactless prepaid cards, whether they are in a phone or not. It seems as if the march of e-money continues, but the mix is changing (probably, in my opinion, temporarily), and cash is the main victim. We can deduce this because the fall in the use of mobile proximity and card e-money does not seem to have been matched by an increase in the use of small denomination banknotes or coins. In fact the coins in circulation fell again last year.

22921.20110226142012

Michael noted that the the use of NFC in phones for non-payment purposes—coupons, loyalty etc—was actually far more prevalent, and I think this probably is one of the key lessons to learn. Customers aren’t going to buy NFC phones because they can make payments with them: they will buy NFC phones to do more interesting things than payments but we (ie, the payments industry) must be in position to take advantage of the platform.

NTT Docomo has begun the world’s first mass market deployment of mobile phones with NFC tag reading capabilities. Sixteen of the operator’s new range of mobile phones and a number of existing handsets will be able to perform both Osaifu-Keitai mobile contactless payments functions and NFC tag reading from next week.

[From� NTT Docomo adds NFC tag reading to wide range of mobile phones | Alan Cheslow’s Consumer Electronics Industry News]

Who knows what kind of services will be successful in Europe or the US. Coupons, like McDonalds club in Japan? Something else? That is the fun area for exploration for our clients right now: what’s going to go in the mobile wallet alongside the payment applications and how will it change for national and regional markets.

These are personal opinions and should not be misunderstood as representing the opinions of
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.