Cash means a lot of baggage

[Dave Birch] With my feet up and a cup of tea, I was relaxing reading David R. Warwick’s “The Case Against Cash” in the July edition of “The Futurist” magazine. He notes that of the $829 billion in US currency “in circulation”, two-thirds is outside the US. According to the Boston Fed, the average US consumer has only $79 about their person, with another $157 at home or in the office. Say $200 each for 200 million consumers, that comes to only $40 billion. Even if you calculate it at $300 each for 300m consumers, that’s still only $90 billion, which would imply that about two-thirds of the cash in the US in unaccounted for, a figure that tallies well with more detailed calculations made for some European countries. That means that if the US is as law-abiding as, say,� Norway, then there’s about $200 billion of cash in the US that is� only used for tax evasion, crime, money laundering and so on.

Mr. Warwick says that the biggest single benefit of the abolition of cash in the US will be the elimination of cash robberies, which costs the country about $140 billion per annum. This may be so, but personally, I think that the greatest benefit will be what he puts second on the list: financial inclusion. People trapped in a cash economy are not only discriminated against (because they pay the highest transactions costs) but they are cannot get on the financial services ladder. They have to take payday loans instead of bank loans, use cheque-cashing services and so on. Helping these people on to that ladder is a very positive outcome for the electronic payments industry (assuming that it can deliver the low-cost products that are needed to do this).

Naturally I sympathise with Mr. Warwick, but I don’t hold out much short term hope for the US getting rid of cash, although I can see that there are some interesting ways to make progress. A correspondent wrote, kindly, in response to a recent post I made about the role of e-payments in reducing cash evasion.

In addition to strict regulations that require POS technology to retain sales records (and criminal liability if they are found to be tampered), the Brazilian state of Sao Paulo created a program called “Nota Fiscal Paulista” which works by consumer demand. It encourages consumers to ask for their receipts, which pressures the business into declaring their sales taxes to the state tax collector. At year’s end the consumer gets a share of their taxes paid returned to them, as well as an entry in a larger lottery. I’ve had family members win sizeable pots simply for opting in to this receipt at check out.

Many merchants really dislike this scheme, presumably because it works, but they are obliged to offer it because of consumer pressure. There’s another similar scheme in Korea, whereby merchants who take more than some threshold (75%?) volume of their transactions electronically rather than in cash get a tax break. The government has presumably calculated that reducing tax evasion from cash sales more than makes up for the revenue reduction from the tax break. Perhaps in these straightened times the US tax authorities might begin to make similar calculations.

However, while the US may not be able to get rid of cash domestically—more’s the pity—it could at least start trying to get rid of cash in some other theatres. Perhaps a good place to start might be somewhere where, unlike America, there is a viable mobile phone-based alternative to cash: Afghanistan, where the M-PAISA scheme is up and running.

Electronic payments, if implemented properly, can bring transparency as well as efficiency. And transparency can have some unexpected consequences. Look what happened when the M-PESA service was launched in Afghanistan (as M-PAISA) and used to introduce efficiency into the process of salary payments for civil servants…

[From� Digital Money: Cash does have some unique properties]

Another factor pointing to Afghanistan as the nexus for such an experiment is that the campaign against cash there may be able to co-opt a pretty powerful ally: the US military.

For the past few years the military has been striving to replace its cash transactions with electronic fund transfers and debit card payments in the hopes of achieving a “cashless battlefield,” in the words of Peter Kunkel, a former assistant secretary of the Army.

[From� Turn In Your Bin Ladens - NYTimes.com]

Right now, the battlefield is only cashless because all of the cash is being spirited away as soon as it arrives and (I’m sure) to no good purpose—as I heard our (former) man in Kabul� Sherard Cowper-Coles pointing out on the� BBC’s Start the Week programme recently—and there doesn’t seem to be any way to keep it in place.

Last month, a well-dressed Afghan man en route to Dubai was found carrying three briefcases stuffed with $3 million in U.S. currency and $2 million in Saudi currency, according to an American official who was present when the notes were counted. A few days later, the same man was back at the Kabul airport, en route to Dubai again, with about $5 million in U.S. and Saudi bank notes.

[From� Officials puzzle over millions of dollars leaving Afghanistan by plane for Dubai]

I love the title of the article, don’t you? It doesn’t seem that much of a “puzzle” to me.

Cash declaration forms filed at Kabul International Airport and reviewed by The Washington Post show that Afghan passengers took more than $180 million to Dubai during a two-month period starting in July. If that rate held for the entire year, the amount of cash that left Afghanistan in 2009 would have far exceeded the country’s annual tax and other domestic revenue of about $875 million.

[From� Officials puzzle over millions of dollars leaving Afghanistan by plane for Dubai]

There really ought to be more upset about the havoc that these billions of US dollars cause but not merely facilitating but actively encouraging corruption on such an enormous scale, yet even at the very highest levels there’s no sense (that I can find) of outrage. In fact, everyone (except taxpayers, presumably) seems quite happy with the seigniorage-powered status quo.

Karzai said cash transactions are quite normal and then-President George W. Bush was aware of the Iranian donations. The United States supposedly gives him bags of cash as well.

[From� BlogPost - Karzai’s bags of cash a conundrum for the U.S.]

Interestingly, when he says “bags of cash” he isn’t speaking metaphorically: they actually do give him bags of cash, as do the Iranians apparently. I don’t think any of them are going to get behind my campaign to reduce the use of cash to the great benefit of society as a whole.

Suspicions of corruption in the Afghan government, with one cable alleging that vice president Zia Massoud was carrying $52m in cash when he was stopped during a visit to the United Arab Emirates.

[From� US embassy cables leak sparks global diplomatic crisis | World news | The Guardian]

Not mobile phone top-up vouchers or open-loop prepaid cards or high-street vouchers, but FIFTY TWO MILLION GREENBACKS. That made me wonder about his baggage allowance. How much would $52m in weigh? Could you fit it in cabin luggage or would you have to check it? After all 520,000 $100 bills take up a fair bit of space. I seem to remember from a previous discussion, that a cereal box can hold $500,000 so we’re talking about 100 cereal boxes at least.

In reality, restricting ourselves to $100 bills, the maximum is only $450,000 (the New Jersey ne’erdowells didn’t pack optimally!).

[From� Digital Money: Has cash jumped the shark?]

I don’t think you could fit 100 cereal boxes in the two checked bags that you’re allowed on British Airways, but I suppose vice presidents are allowed a couple more. But back to the point, which is…

Why does the world need 1 billion $100 bills? Indeed, why does the U.S. continue to print C-notes at all?

[From� Hundred-dollar bills are for criminals and sociopaths. Why do we still print them? - By Timothy Noah - Slate Magazine]

Look, I’m not making any sort of political point about Afghanistan, I’m arguing this general point. The US should cease printing $50 and $100 bills immediately. They have no function in supporting commerce.

And it’s not just that carrying around cash is inconvenient and time consuming. These days, one of its main functions is to finance the black economy: drug deals, counterfeiting, under-the-table employment and other nefarious activities. Because cash is anonymous, people can easily opt out of the taxable economy – leaving the rest of us to pick up the tab for their use of public services. Remove cash entirely, and you make it far more difficult to avoid tax, not to mention discouraging criminal activity.

[From� I’m dreaming of a cashless Christmas - Telegraph]

I written before about a current example of large amounts of cash making a problem (that no-one would claim is caused by cash) significantly worse.

Ransoms are paid in cash, partly because Somalia has no functioning banking system, and partly to hamper American anti-money-laundering investigators

[From� Piracy: No stopping them | The Economist]

I have to say that this piracy is looking more and more like a viable career option to me. It is very well remunerated and there appears to be much less chance of going to jail than in, say, investment banking or management consultancy.

Of the 650 Somali pirates caught since late 2008, 460 have already been released, according to Lloyd’s Market Association

[From� Prime Numbers: The Pirate Den - By Bridget Coggins | Foreign Policy]

The English have a proud history of piracy, so I think I’d fit right in. Avast ye landlubbers!

These are personal opinions and should not be misunderstood as representing the opinions of
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Cash means a lot of baggage

With my feet up and a cup of tea, I was relaxing reading David R. Warwick’s “The Case Against Cash” in the July edition of “The Futurist” magazine. He notes that of the $829 billion in US currency “in circulation”, two-thirds is outside the US. According to the Boston Fed, the average US consumer has only $79 about their person, with another $157 at home or in the office. Say $200 each for 200 million consumers, that comes to only $40 billion. Even if you calculate it at $300 each for 300m consumers, that’s still only $90 billion, which would imply that about two-thirds of the cash in the US in unaccounted for, a figure that tallies well with more detailed calculations made for some European countries. That means that if the US is as law-abiding as, say, Norway, then there’s about $200 billion of cash in the US that is only used for tax evasion, crime, money laundering and so on.

Mr. Warwick says that the biggest single benefit of the abolition of cash in the US will be the elimination of cash robberies, which costs the country about $140 billion per annum. This may be so, but personally, I think that the greatest benefit will be what he puts second on the list: financial inclusion. People trapped in a cash economy are not only discriminated against (because they pay the highest transactions costs) but they are cannot get on the financial services ladder. They have to take payday loans instead of bank loans, use cheque-cashing services and so on. Helping these people on to that ladder is a very positive outcome for the electronic payments industry (assuming that it can deliver the low-cost products that are needed to do this).

Naturally I sympathise with Mr. Warwick, but I don’t hold out much short term hope for the US getting rid of cash, although I can see that there are some interesting ways to make progress. A correspondent wrote, kindly, in response to a recent post I made about the role of e-payments in reducing cash evasion.

In addition to strict regulations that require POS technology to retain sales records (and criminal liability if they are found to be tampered), the Brazilian state of Sao Paulo created a program called “Nota Fiscal Paulista” which works by consumer demand. It encourages consumers to ask for their receipts, which pressures the business into declaring their sales taxes to the state tax collector. At year’s end the consumer gets a share of their taxes paid returned to them, as well as an entry in a larger lottery. I’ve had family members win sizeable pots simply for opting in to this receipt at check out.

Many merchants really dislike this scheme, presumably because it works, but they are obliged to offer it because of consumer pressure. There’s another similar scheme in Korea, whereby merchants who take more than some threshold (75%?) volume of their transactions electronically rather than in cash get a tax break. The government has presumably calculated that reducing tax evasion from cash sales more than makes up for the revenue reduction from the tax break. Perhaps in these straightened times the US tax authorities might begin to make similar calculations.

However, while the US may not be able to get rid of cash domestically — more’s the pity — it could at least start trying to get rid of cash in some other theatres. Perhaps a good place to start might be somewhere where, unlike America, there is a viable mobile phone-based alternative to cash: Afghanistan, where the M-PAISA scheme is up and running.

Electronic payments, if implemented properly, can bring transparency as well as efficiency. And transparency can have some unexpected consequences. Look what happened when the M-PESA service was launched in Afghanistan (as M-PAISA) and used to introduce efficiency into the process of salary payments for civil servants…

[From Digital Money: Cash does have some unique properties]

Another factor pointing to Afghanistan as the nexus for such an experiment is that the campaign against cash there may be able to co-opt a pretty powerful ally: the US military.

For the past few years the military has been striving to replace its cash transactions with electronic fund transfers and debit card payments in the hopes of achieving a “cashless battlefield,” in the words of Peter Kunkel, a former assistant secretary of the Army.

[From Turn In Your Bin Ladens - NYTimes.com]

Right now, the battlefield is only cashless because all of the cash is being spirited away as soon as it arrives and (I’m sure) to no good purpose — as I heard our (former) man in Kabul Sherard Cowper-Coles pointing out on the BBC’s Start the Week programme recently — and there doesn’t seem to be any way to keep it in place.

Last month, a well-dressed Afghan man en route to Dubai was found carrying three briefcases stuffed with $3 million in U.S. currency and $2 million in Saudi currency, according to an American official who was present when the notes were counted. A few days later, the same man was back at the Kabul airport, en route to Dubai again, with about $5 million in U.S. and Saudi bank notes.

[From Officials puzzle over millions of dollars leaving Afghanistan by plane for Dubai]

I love the title of the article, don’t you? It doesn’t seem that much of a “puzzle” to me.

Cash declaration forms filed at Kabul International Airport and reviewed by The Washington Post show that Afghan passengers took more than $180 million to Dubai during a two-month period starting in July. If that rate held for the entire year, the amount of cash that left Afghanistan in 2009 would have far exceeded the country’s annual tax and other domestic revenue of about $875 million.

[From Officials puzzle over millions of dollars leaving Afghanistan by plane for Dubai]

There really ought to be more upset about the havoc that these billions of US dollars cause but not merely facilitating but actively encouraging corruption on such an enormous scale, yet even at the very highest levels there’s no sense (that I can find) of outrage. In fact, everyone (except taxpayers, presumably) seems quite happy with the seigniorage-powered status quo.

Karzai said cash transactions are quite normal and then-President George W. Bush was aware of the Iranian donations. The United States supposedly gives him bags of cash as well.

[From BlogPost - Karzai's bags of cash a conundrum for the U.S.]

Interestingly, when he says “bags of cash” he isn’t speaking metaphorically: they actually do give him bags of cash, as do the Iranians apparently. I don’t think any of them are going to get behind my campaign to reduce the use of cash to the great benefit of society as a whole.

Suspicions of corruption in the Afghan government, with one cable alleging that vice president Zia Massoud was carrying $52m in cash when he was stopped during a visit to the United Arab Emirates.

[From US embassy cables leak sparks global diplomatic crisis | World news | The Guardian]

Not mobile phone top-up vouchers or open-loop prepaid cards or high-street vouchers, but FIFTY TWO MILLION GREENBACKS. That made me wonder about his baggage allowance. How much would $52m in weigh? Could you fit it in cabin luggage or would you have to check it? After all 520,000 $100 bills take up a fair bit of space. I seem to remember from a previous discussion, that a cereal box can hold $500,000 so we’re talking about 100 cereal boxes at least.

In reality, restricting ourselves to $100 bills, the maximum is only $450,000 (the New Jersey ne’erdowells didn’t pack optimally!).

[From Digital Money: Has cash jumped the shark?]

I don’t think you could fit 100 cereal boxes in the two checked bags that you’re allowed on British Airways, but I suppose vice presidents are allowed a couple more. But back to the point, which is…

Why does the world need 1 billion $100 bills? Indeed, why does the U.S. continue to print C-notes at all?

[From Hundred-dollar bills are for criminals and sociopaths. Why do we still print them? - By Timothy Noah - Slate Magazine]

Look, I’m not making any sort of political point about Afghanistan, I’m arguing this general point. The US should cease printing $50 and $100 bills immediately. They have no function in supporting commerce.

And it’s not just that carrying around cash is inconvenient and time consuming. These days, one of its main functions is to finance the black economy: drug deals, counterfeiting, under-the-table employment and other nefarious activities. Because cash is anonymous, people can easily opt out of the taxable economy – leaving the rest of us to pick up the tab for their use of public services. Remove cash entirely, and you make it far more difficult to avoid tax, not to mention discouraging criminal activity.

[From I'm dreaming of a cashless Christmas - Telegraph]

I written before about a current example of large amounts of cash making a problem (that no-one would claim is caused by cash) significantly worse.

Ransoms are paid in cash, partly because Somalia has no functioning banking system, and partly to hamper American anti-money-laundering investigators

[From Piracy: No stopping them | The Economist]

I have to say that this piracy is looking more and more like a viable career option to me. It is very well remunerated and there appears to be much less chance of going to jail than in, say, investment banking or management consultancy.

Of the 650 Somali pirates caught since late 2008, 460 have already been released, according to Lloyd’s Market Association

[From Prime Numbers: The Pirate Den - By Bridget Coggins | Foreign Policy]

The English have a proud history of piracy, so I think I’d fit right in. Avast ye landlubbers!

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Anywhere, yes, but anyone, no

[Dave Birch] I’ve been reading Emily Nagel’s book “Anywhere”. She’s the CEO of Yankee Group and the book is about global connectivity revolutionising business. I hope she won’t be offended if I say that it’s an “airport book”, but it’s an accurate description, at least for me, because I read it on the plane. There’s something that bothers me about it, though. It has lots of stories and examples and narrative about ways in which business is transformed as it goes online, but it doesn’t have “identity” or “authentication” in the index and says nothing about the identity problems that will need to be solved in order to realise the full potential of connectivity. As I’ve often observed before, using my favourite Kevin Kelly classification, connection isn’t the problem: it’s the disconnection technologies that will shape the medium-term roadmap for transforming new technology into business models: once everything is connected to everything else, the business model shifts to the creation and management of subgroups within that single, giant internet of everything.

Here, things aren’t going so well. By coincidence, the Saturday newspaper that I picked up after putting down Emily’s book had a technology advice column, and there was a letter from a typical consumer in it. I paraphrase:

I have a long list of passwords for home banking, shopping, social networks, magazines and so on. I’ve put them all in a Word document. How can I encrypt it?

This is, in a nutshell, the state of the mass market today. We all have masses of passwords, we’ve been complaining about it since 1994, and nothing much seems to happen, largely (I think) because the costs of our time don’t factor into business models. And yet… we don’t seem to be evolving any better business models and we don’t seem any closer to better identity infrastructure. Should we give up? No! I say we should remember William Samuel Henson.

It is sad that the name of� William Samuel Henson is largely unknown today. A man of great vision, he petitioned Parliament for permission to set up an airline—with a business model largely based on post—flying to Egypt, India and China. Parliament turned his proposal down on the grounds that it was 1843 and no-one had invented airplanes yet. Henson knew this, obviously, but could see which way technology was evolving and correctly reasoned that just because he didn’t know how to get an airplane off the ground (he had been involved in numerous experiments around powered flight), that didn’t mean that no-one else would. And when they did, there would be a new business to build on aviation technology. So he started thinking about the businesses that would make sense and, since the post had just been invented in the UK, he looked at how that might work in the future.

This is a parable of our identity space now. We can’t get the technology to work, but we know that someone will, so we’re trying to think of business models (I should be clear in our case: we’re trying to think of business models for our clients) that will make sense when the technology works. But we’re thinking about web browsing and e-mail because these have just been invented and they’re our equivalent of the post service. Maybe we should challenge ourselves harder to look at wider possibilities, start from the perspective of social networking, virtual worlds and Twitter rather than Alice sending her credit card details to Bob.

Facebook is better understood, not as a country, but as a refugee camp for people who feel today’s lack of identity-forging social experience.

[From� Facebook: the heart in a heartless world | spiked]

I think many organisations should be focusing on the next phase of evolution of online business, and phase that will be fundamentally shaped by the emerging identity infrastructure. But we must be careful not to take what has just been invented (in this case, say, Facebook) and project it into the future as the key to new business models. We have to think more broadly to develop strategic roadmaps for business that can react to the general trends to exploit the technology downstream. An example? Well, it doesn’t matter which social network we’ll be using in five years time, we’ll still need to authenticate ourselves in a more effective way that a Word file full of passwords. It isn’t only me that thinks this.

The president wants consumers to use strong authentication, something more than user name and password, which will most likely add another security factor, say officials familiar with the project.

For example, user name and password is one-factor security, something you know. But additional factors can be added. A token or digital certificate can be a second factor, something you have, resulting in stronger two-factor authentication. If you add a fingerprint or other biometric, something you are, it’s increased to three-factor security.

[From� NFCNews | Potential technologies that consumers may use for online ID]

There follows an interesting, but confused, list of options. I’d like to suggest a more straightforward taxonomy, based on a digital identity infrastructure (which doesn’t exist, of course). The article, to my mind, confuses the distinct bindings between the virtual identities that exist in the Net and the real identities that are connected to. This is why it is useful to introduce the notion of digital identity in the middle. So then we get the two categories of things that might be used to solve the

  • Linking virtual identities to digital identities. The article suggests that digital certificates and PKI might be a good way to do this and I agree. Think of a digital identity as a private-public key pair … tamper-resistance… smart cards, tokens, smart phones.
  • Linking digital identities to real-world entities. The article suggests that passwords will be supplanted by biometrics.

Each of these will be a separate business that operates according to difference scale factors (scale in the first case, scope in the second). I don’t know how to make them work, but someone will.

These are personal opinions and should not be misunderstood as representing the opinions of
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Anywhere, anyone

I’ve been reading Emily Nagel’s book “Anywhere“. She’s the CEO of Yankee Group and the book is about global connectivity revolutionising business. I hope she won’t be offended if I say that it’s an “airport book”, but it’s an accurate description, at least for me, because I read it on the plane. There’s something that bothers me about it, though. It has lots of stories and examples and narrative about ways in which business is transformed as it goes online, but it doesn’t have “identity” or “authentication” in the index and says nothing about the identity problems that will need to be solved in order to realise the full potential of connectivity. As I’ve often observed before, using my favourite Kevin Kelly classification, connection isn’t the problem: it’s the disconnection technologies that will shape the medium-term roadmap for transforming new technology into business models: once everything is connected to everything else, the business model shifts to the creation and management of subgroups within that single, giant internet of everything.

Here, things aren’t going so well. By coincidence, the Saturday newspaper that I picked up after putting down Emily’s book had a technology advice column, and there was a letter from a typical consumer in it. I paraphrase:

I have a long list of passwords for home banking, shopping, social networks, magazines and so on. I’ve put them all in a Word document. How can I encrypt it?

This is, in a nutshell, the state of the mass market today. We all have masses of passwords, we’ve been complaining about it since 1994, and nothing much seems to happen, largely (I think) because the costs of our time don’t factor into business models. And yet… we don’t seem to be evolving any better business models and we don’t seem any closer to better identity infrastructure. Should we give up? No! I say we should remember William Samuel Henson.

It is sad that the name of William Samuel Henson is largely unknown today. A man of great vision, he petitioned Parliament for permission to set up an airline — with a business model largely based on post — flying to Egypt, India and China. Parliament turned his proposal down on the grounds that it was 1843 and no-one had invented airplanes yet. Henson knew this, obviously, but could see which way technology was evolving and correctly reasoned that just because he didn’t know how to get an airplane off the ground (he had been involved in numerous experiments around powered flight), that didn’t mean that no-one else would. And when they did, there would be a new business to build on aviation technology. So he started thinking about the businesses that would make sense and, since the post had just been invented in the UK, he looked at how that might work in the future.

This is a parable of our identity space now. We can’t get the technology to work, but we know that someone will, so we’re trying to think of business models (I should be clear in our case: we’re trying to think of business models for our clients) that will make sense when the technology works. But we’re thinking about web browsing and e-mail because these have just been invented and they’re our equivalent of the post service. Maybe we should challenge ourselves harder to look at wider possibilities, start from the perspective of social networking, virtual worlds and Twitter rather than Alice sending her credit card details to Bob.

Facebook is better understood, not as a country, but as a refugee camp for people who feel today’s lack of identity-forging social experience.

[From Facebook: the heart in a heartless world | spiked]

I think many organisations should be focusing on the next phase of evolution of online business, and phase that will be fundamentally shaped by the emerging identity infrastructure. But we must be careful not to take what has just been invented (in this case, say, Facebook) and project it into the future as the key to new business models. We have to think more broadly to develop strategic roadmaps for business that can react to the general trends to exploit the technology downstream. An example? Well, it doesn’t matter which social network we’ll be using in five years time, we’ll still need to authenticate ourselves in a more effective way that a Word file full of passwords. It isn’t only me that thinks this.

The president wants consumers to use strong authentication, something more than user name and password, which will most likely add another security factor, say officials familiar with the project.

For example, user name and password is one-factor security, something you know. But additional factors can be added. A token or digital certificate can be a second factor, something you have, resulting in stronger two-factor authentication. If you add a fingerprint or other biometric, something you are, it’s increased to three-factor security.

[From NFCNews | Potential technologies that consumers may use for online ID]

There follows an interesting, but confused, list of options. I’d like to suggest a more straightforward taxonomy, based on a digital identity infrastructure (which doesn’t exist, of course). The article, to my mind, confuses the distinct bindings between the virtual identities that exist in the Net and the real identities that are connected to. This is why it is useful to introduce the notion of digital identity in the middle. So then we get the two categories of things that might be used to solve the

  • Linking virtual identities to digital identities. The article suggests that digital certificates and PKI might be a good way to do this and I agree. Think of a digital identity as a private-public key pair … tamper-resistance… smart cards, tokens, smart phones.
  • Linking digital identities to real-world entities. The article suggests that passwords will be supplanted by biometrics.

Each of these will be a separate business that operates according to difference scale factors (scale in the first case, scope in the second). I don’t know how to make them work, but someone will.

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Reflecting on NSTIC

[Dave Birch] I’ve been reading through the final version of the US government’s� National Strategy on Trusted Identities in Cyberspace (NSTIC). This is roughly what journalists think about:

What’s envisioned by the White House is an end to passwords, a system in which a consumer will have a piece of software on a smartsphone or some kind of card or token, which they can swipe on their computers to log on to a website.

[From� White House Proposes A Universal Credential For Web : The Two-Way : NPR]

And this is roughly what the public think about it

Why don’t they just put a chip in all of us and get it over with? What part of being a free people do these socialists not understand?

[From� White House Proposes A Universal Credential For Web : The Two-Way : NPR]

And this is roughly what I think about it: I think that NSTIC isn’t bad at all. As I’ve noted before I’m pretty warm to it. The “identity ecosystem” it envisages is infinitely better than the current ecosystem and it embodies many of the principles that I regard a crucial to the online future. It explicitly says that “the identity ecosystem will use privacy-enhancing technology and policies to inhibit the ability of service providers (presumably including government bodies) to link an individual’s transactions and says that by default only the minimum necessary information will be shared in transactions. They have a set of what they term the Fair Information Practice Principles (FIPPs) that share, shall we say, a common heritage with Forum friend Kim Cameron’s laws (for the record, the FIPPs cover transparency, individual participation, purpose specification, data minimisation, use limitation, data quality and integrity, security and accountability and audit).

It also, somewhat strangely, I think, says the this proposed ecosystem “will preserve online anonymity”, including “anonymous browsing”. I think this is strange because there is no online anonymity. If the government, or the police, or an organisation really want to track someone, they can. There are numerous examples which show this to be the case. There may be some practical limitations as to what they can do with this information, but that’s a slightly different matter: if I hunt through the inter web tubes to determine that that the person posting “Dave Birch fancies goats” on our blog comes from a particular house in Minsk, there’s not much I can do about it. But that doesn’t make them anonymous, it makes the economically anonymous, and that’s not the same thing, especially to people who don’t care about economics (eg, the security services). It’s not clear to me whether we as a society actually want an internet that allows anonymity or not, but we certainly don’t have one now.

The strategy says that the identity ecosystem must develop in parallel with ongoing “national efforts” to improve platform, network and software security, and I guess that no-one would argue against them, but if we were ever to begin to design an EUSTIC (ie, an EU Strategy for Trusted Identities in Cyberspace) I think I would like it to render platform, network and software security less important. That is, I want my identity to work properly in an untrusted cyberspace, one where ne’erdowells have put viruses on my phone and ever PC is part of a sinister botnet (in other words, the real world).

I rather liked the “envision” boxes that are used to illustrate some of the principles with specific examples to help politicians and journalists to understand what this all means. I have to say that it didn’t help in all cases…

The “power utility” example serves as a good focus for discussion. It expects secure authentication between the utility and the domestic meter, trusted hardware modules to ensure that the software configuration on the meter is correct and to ensure that commands and software upgrades do indeed come from the utility. All well and good (and I should declare an interest a disclose that Consult Hyperion has provided paid professional services in this area in the last year). There’s an incredible amount of work to be done, though, to translate these relatively modest requirements into a national-scale, multi-supplier roll-out.

Naturally I will claim the credit for the chat room “envision it”! I’ve used this for many years to illustrate a number of the key concepts in one simple example. But again, we have to acknowledge there’s a big step from the strategy to any realistic tactics. Right now, I can’t pay my kids school online (last Thursday saw yet another chaotic morning trying to find a cheque book to pay for a school outing) so the chance of them providing a zero-knowledge proof digital credential that the kids can use to access (say) BBC chatrooms is absolutely nil to any horizon I can envisage. In the UK, we’re going to have to start somewhere else, and I really think that that place should be with the mobile operators.

What is the government’s role in this then? The strategy expect policy and technology interoperability, and there’s an obvious role for government—given its purchasing power—to drive interoperability. The government must, however, at some point make some firm choices about its own systems, and this will mean choosing a specific set of standards and fixing a standards profile. They are creating a US National Project Office (NPO) within the Department of Commerce to co-ordinate the public and private sectors along the Implementation Roadmap that is being developed, so let’s wish them all the best and look forward to some early results from these efforts.

As an aside, I gave one of the keynote talks at the Smart Card Alliance conference in Chicago a few weeks ago, and I suggested, as a bit of an afterthought, after having sat through some interesting talks about the nascent NSTIC, that a properly implemented infrastructure could provide a viable alternative to the existing mass market payment schemes. But it occurs to me that it might also provide an avenue for EMV in the USA, because the DDA EMV cards that would be issued (were the USA to decide to go ahead and migrate to EMV) could easily be first-class implementations of identity credentials (since DDA cards have the onboard cryptography needed for encryption and digital signatures). What’s more, when the EMV cards migrate their way into phones, the PKI applications could follow them on the Secure Element (SE) and deliver an implementation of NSTIC that could succeed in the mass market with the mobile phone as a kind of “personal identity commander”.

These are personal opinions and should not be misunderstood as representing the opinions of
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

NSTICy questions

I’ve been reading through the final version of the US government’s National Strategy on Trusted Identities in Cyberspace (NSTIC). This is roughly what journalists think about:

What’s envisioned by the White House is an end to passwords, a system in which a consumer will have a piece of software on a smartsphone or some kind of card or token, which they can swipe on their computers to log on to a website.

[From White House Proposes A Universal Credential For Web : The Two-Way : NPR]

And this is roughly what the public think about it

Why don’t they just put a chip in all of us and get it over with? What part of being a free people do these socialists not understand?

[From White House Proposes A Universal Credential For Web : The Two-Way : NPR]

And this is roughly what I think about it: I think that NSTIC isn’t bad at all. As I’ve noted before I’m pretty warm to it. The “identity ecosystem” it envisages is infinitely better than the current ecosystem and it embodies many of the principles that I regard a crucial to the online future. It explicitly says that “the identity ecosystem will use privacy-enhancing technology and policies to inhibit the ability of service providers (presumably including government bodies) to link an individual’s transactions and says that by default only the minimum necessary information will be shared in transactions. They have a set of what they term the Fair Information Practice Principles (FIPPs) that share, shall we say, a common heritage with Forum friend Kim Cameron’s laws (for the record, the FIPPs cover transparency, individual participation, purpose specification, data minimisation, use limitation, data quality and integrity, security and accountability and audit).

It also, somewhat strangely, I think, says the this proposed ecosystem “will preserve online anonymity”, including “anonymous browsing”. I think this is strange because there is no online anonymity. If the government, or the police, or an organisation really want to track someone, they can. There are numerous examples which show this to be the case. There may be some practical limitations as to what they can do with this information, but that’s a slightly different matter: if I hunt through the inter web tubes to determine that that the person posting “Dave Birch fancies goats” on our blog comes from a particular house in Minsk, there’s not much I can do about it. But that doesn’t make them anonymous, it makes the economically anonymous, and that’s not the same thing, especially to people who don’t care about economics (eg, the security services). It’s not clear to me whether we as a society actually want an internet that allows anonymity or not, but we certainly don’t have one now.

The strategy says that the identity ecosystem must develop in parallel with ongoing “national efforts” to improve platform, network and software security, and I guess that no-one would argue against them, but if we were ever to begin to design an EUSTIC (ie, an EU Strategy for Trusted Identities in Cyberspace) I think I would like it to render platform, network and software security less important. That is, I want my identity to work properly in an untrusted cyberspace, one where ne’erdowells have put viruses on my phone and ever PC is part of a sinister botnet (in other words, the real world).

I rather liked the “envision” boxes that are used to illustrate some of the principles with specific examples to help politicians and journalists to understand what this all means. I have to say that it didn’t help in all cases…

The “power utility” example serves as a good focus for discussion. It expects secure authentication between the utility and the domestic meter, trusted hardware modules to ensure that the software configuration on the meter is correct and to ensure that commands and software upgrades do indeed come from the utility. All well and good (and I should declare an interest a disclose that Consult Hyperion has provided paid professional services in this area in the last year). There’s an incredible amount of work to be done, though, to translate these relatively modest requirements into a national-scale, multi-supplier roll-out.

Naturally I will claim the credit for the chat room “envision it”! I’ve used this for many years to illustrate a number of the key concepts in one simple example. But again, we have to acknowledge there’s a big step from the strategy to any realistic tactics. Right now, I can’t pay my kids school online (last Thursday saw yet another chaotic morning trying to find a cheque book to pay for a school outing) so the chance of them providing a zero-knowledge proof digital credential that the kids can use to access (say) BBC chatrooms is absolutely nil to any horizon I can envisage. In the UK, we’re going to have to start somewhere else, and I really think that that place should be with the mobile operators.

What is the government’s role in this then? The strategy expect policy and technology interoperability, and there’s an obvious role for government — given its purchasing power — to drive interoperability. The government must, however, at some point make some firm choices about its own systems, and this will mean choosing a specific set of standards and fixing a standards profile. They are creating a US National Project Office (NPO) within the Department of Commerce to co-ordinate the public and private sectors along the Implementation Roadmap that is being developed, so let’s wish them all the best and look forward to some early results from these efforts.

As an aside, I gave one of the keynote talks at the Smart Card Alliance conference in Chicago a few weeks ago, and I suggested, as a bit of an afterthought, after having sat through some interesting talks about the nascent NSTIC, that a properly implemented infrastructure could provide a viable alternative to the existing mass market payment schemes. But it occurs to me that it might also provide an avenue for EMV in the USA, because the DDA EMV cards that would be issued (were the USA to decide to go ahead and migrate to EMV) could easily be first-class implementations of identity credentials (since DDA cards have the onboard cryptography needed for encryption and digital signatures). What’s more, when the EMV cards migrate their way into phones, the PKI applications could follow them on the Secure Element (SE) and deliver an implementation of NSTIC that could succeed in the mass market with the mobile phone as a kind of “personal identity commander”.

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The mobile payment horizon

[Dave Birch] What is the leading edge in mobile payments? And where is that leading edge? I’m always scanning for new ideas to bring back to our clients and I’m always looking out for ways to exploit new technology in the transaction space.

Doug Busk, mobile brand strategy and global connections at The Coca-Cola Co.,was one of the participants in the “What’s on the Horizon with Mobile Payments: How All the Pieces Come Together” session. He pointed to a vending machine that uses mobile SMS to enable payment

[From� Coca-Cola SMS-enabled vending machine changing future of mobile payments « Near Field Communications / Smart mCommerce]

You’ve got to at least raise an eyebrow at a talk about the mobile payment horizon that uses SMS payment for Coca Cola as an example of the brave new world just around the corner since, to the best of my knowledge, the very first mobile payment ever made (in Helsinki, in 1997) used SMS payment for Coca Cola! But not a million miles away from this birthplace of a new economy,

Meanwhile, Denmark’s banks are also working together on a different sort of mobile payments system, using text messaging. BankSMS is slated to launch later this year, enabling users to initiate purchases of things like train tickets by sending a text message with a product code.

[From� Finextra: Danish telcos team on NFC payments; banks put faith in SMS]

Maybe I’ve totally missed the curve on this one, what with getting distracted by these new-fangled proximity interfaces. But further afield, an astonished correspondent writes (28th June 2011) to say

I am in Jakarta right now and am seeing an NFC terminal for payment at a coffee shop

What’s going on? The developed world is going back to the future with the SMS while emerging markets are getting in touch with NFC?

These are personal opinions and should not be misunderstood as representing the opinions of
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Near and far

What is the leading edge in mobile payments? And where is that leading edge? I’m always scanning for new ideas to bring back to our clients and I’m always looking out for ways to exploit new technology in the transaction space.

Doug Busk, mobile brand strategy and global connections at The Coca-Cola Co.,was one of the participants in the “What’s on the Horizon with Mobile Payments: How All the Pieces Come Together” session. He pointed to a vending machine that uses mobile SMS to enable payment

[From Coca-Cola SMS-enabled vending machine changing future of mobile payments « Near Field Communications / Smart mCommerce]

You’ve got to at least raise an eyebrow at a talk about the mobile payment horizon that uses SMS payment for Coca Cola as an example of the brave new world just around the corner since, to the best of my knowledge, the very first mobile payment ever made (in Helsinki, in 1997) used SMS payment for Coca Cola! But not a million miles away from this birthplace of a new economy,

Meanwhile, Denmark’s banks are also working together on a different sort of mobile payments system, using text messaging. BankSMS is slated to launch later this year, enabling users to initiate purchases of things like train tickets by sending a text message with a product code.

[From Finextra: Danish telcos team on NFC payments; banks put faith in SMS]

Maybe I’ve totally missed the curve on this one, what with getting distracted by these new-fangled proximity interfaces. But further afield, an astonished correspondent writes (28th June 2011) to say

I am in Jakarta right now and am seeing an NFC terminal for payment at a coffee shop

What’s going on? The developed world is going back to the future with the SMS while emerging markets are getting in touch with NFC?

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Events are conducive to contactless

[Dave Birch] Off to the� Barclaycard Wireless Festival for the day. I don’t really understand why its still called that. In the old days, when it was sponsored by O2, then calling it the wireless festival sort of made sense. But now it’s sponsored by Barclaycard, they should probably call it the Contactless Festival instead. Anyhow it featured a great many very popular bands, as evidenced by the enormous crowd trying to get in.

IMG_0406

I know it looks chaotic but in the end it only took about 25 minutes to get in. Contactless was much in evidence. Barclaycard had kitted all of the bars out with contactless terminals and were kind enough to give me one of the promotional lanyards containing a contactless card (a Visa gift card preloaded with £20) to go and try out. Which, naturally, I did. And, I have to say, it worked perfectly. As testimony, allow me to present the first beer I bought with it!

Dave at Wireless 2011

Being me, I couldn’t leave it at that though, and I started to try out some other contactless paraphernalia about my person. An obvious experiment was to try my Barclaycard phone, and that worked too, but oddly it went online, which rather slowed the transaction down. I don’t understand why it did this, so I’ll ask the chaps when I’m next in the office.

More interestingly, I asked a couple of the bar staff what they thought about contactless and they had both positive and negative observations that I promised myself to report in a spirit of openness and balance…

Positive. It’s quick, and you don’t have to hand the terminal to the customer for them to enter a PIN. And they thought my phone was really cool. They also said that some customers had been paying with their own contactless cards and not just the promotional lanyards.

Negative. There were two big issues that came up in both conversations with bar staff. One was the spending limit, which the bar staff said was too low at £12 (the limit was actually £15, but the all of the drinks cost £4, so you could buy three drinks at £12 but not the advertised four beers in a drinks carrier, because that costs £16). Surely it would have made sense to have subbed the bars so that four beers plus carrier was a £15 special.

Enough of these scientific experiments (most of which I drank), and off to see some of the popular beat combos on show. Here’s 47 second taster so that you can get the idea if you’ve never been to one of these events before.

I was reflecting on the security issue later on, because it really seemed a block. I took the time to explain to one of the women at the bar that there was no risk to her as a customer, because the UK banks’ were unequivocal about unauthorised use: if someone uses your card without your permission, they will refund the transaction. Yet she was unconvinced and was clearly uncomfortable about the idea of “no CVM” purchase. This has been true since the earliest days. As I highlighted four years ago:

Among those that are not yet ready to use contactless, security appear to be the dominant consideration. Which means, of course, that whatever we might think about actual security situation we must get better at communicating it.

[From� Digital Money: Contactless update]

As I don’t know anything about customer communications and public information, I genuinely don’t know how to cross this chasm, but I wonder if it’s yet more evidence that we should be moving more quickly to contactless phones. The simple PIN code that I need to open up the mobile wallet on my Barclaycard MasterCard phone (the Samsung Tocco that I wrote about before) might well provide the reassurance that people want, even though it doesn’t really make much difference to the overall risk (phones are inherently safer than cards because people notice when they go missing anyway).

Overall, the weekend’s experiences did leave me with three firm conclusions:

1. Both the public and the merchants liked contactless. In this kind of environment – crowded, quick service – the technology performs very well. These were similar to the results seen elsewhere: the punters like contactless payments.

Festival-goers quizzed on the experience, said they were quicker (96%) and easier to use (98%) than credit or debit cards, while a resounding 100% said they’d want to use the PayPass prepaid wristbands again to pay at other festivals, concerts and sporting events.

[From� Finextra: Contactless wristbands join wellies and camping gear as festival essentials]

2. We should accelerate the development of contactless phones, because they help with the security issue.

3.� The Horrors are a good band, but not my cup of tea.

These are personal opinions and should not be misunderstood as representing the opinions of
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Wireless Sunday

Off to the Barclaycard Wireless Festival for the day. I don’t really understand why its still called that. In the old days, when it was sponsored by O2, then calling it the wireless festival sort of made sense. But now it’s sponsored by Barclaycard, they should probably call it the Contactless Festival instead. Anyhow it featured a great many very popular bands, as evidenced by the enormous crowd trying to get in.

IMG_0406

I know it looks chaotic but in the end it only took about 25 minutes to get in. Contactless was much in evidence. Barclaycard had kitted all of the bars out with contactless terminals and were kind enough to give me one of the promotional lanyards containing a contactless card (a Visa gift card preloaded with £20) to go and try out. Which, naturally, I did. And, I have to say, it worked perfectly. As testimony, allow me to present the first beer I bought with it!

Dave at Wireless 2011

Being me, I couldn’t leave it at that though, and I started to try out some other contactless paraphernalia about my person. An obvious experiment was to try my Barclaycard phone, and that worked too, but oddly it went online, which rather slowed the transaction down. I don’t understand why it did this, so I’ll ask the chaps when I’m next in the office.

More interestingly, I asked a couple of the bar staff what they thought about contactless and they had both positive and negative observations that I promised myself to report in a spirit of openness and balance…

Positive. It’s quick, and you don’t have to hand the terminal to the customer for them to enter a PIN. And they thought my phone was really cool. They also said that some customers had been paying with their own contactless cards and not just the promotional lanyards.

Negative. There were two big issues that came up in both conversations with bar staff. One was the spending limit, which the bar staff said was too low at £12 (the limit was actually £15, but the all of the drinks cost £4, so you could buy three drinks at £12 but not the advertised four beers in a drinks carrier, because that costs £16). Surely it would have made sense to have subbed the bars so that four beers plus carrier was a £15 special.

Enough of these scientific experiments (most of which I drank), and off to see some of the popular beat combos on show. Here’s 47 second taster so that you can get the idea if you’ve never been to one of these events before.

I was reflecting on the security issue later on, because it really seemed a block. I took the time to explain to one of the women at the bar that there was no risk to her as a customer, because the UK banks’ were unequivocal about unauthorised use: if someone uses your card without your permission, they will refund the transaction. Yet she was unconvinced and was clearly uncomfortable about the idea of “no CVM” purchase. This has been true since the earliest days. As I highlighted four years ago:

Among those that are not yet ready to use contactless, security appear to be the dominant consideration. Which means, of course, that whatever we might think about actual security situation we must get better at communicating it.

[From Digital Money: Contactless update]

As I don’t know anything about customer communications and public information, I genuinely don’t know how to cross this chasm, but I wonder if it’s yet more evidence that we should be moving more quickly to contactless phones. The simple PIN code that I need to open up the mobile wallet on my Barclaycard MasterCard phone (the Samsung Tocco that I wrote about before) might well provide the reassurance that people want, even though it doesn’t really make much difference to the overall risk (phones are inherently safer than cards because people notice when they go missing anyway).

Overall, the weekend’s experiences did leave me with three firm conclusions:

1. Both the public and the merchants liked contactless. In this kind of environment – crowded, quick service – the technology performs very well. These were similar to the results seen elsewhere: the punters like contactless payments.

Festival-goers quizzed on the experience, said they were quicker (96%) and easier to use (98%) than credit or debit cards, while a resounding 100% said they’d want to use the PayPass prepaid wristbands again to pay at other festivals, concerts and sporting events.

[From Finextra: Contactless wristbands join wellies and camping gear as festival essentials]

2. We should accelerate the development of contactless phones, because they help with the security issue.

3. The Horrors are a good band, but not my cup of tea.

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.