Comments on: NFC aftershocks http://tomorrowstransactions.com/2013/03/nfc_aftershocks/ Thought leadership from Consult Hyperion Tue, 09 Sep 2014 00:19:19 +0000 hourly 1 http://wordpress.org/?v=4.0 By: Steve Wlson http://tomorrowstransactions.com/2013/03/nfc_aftershocks/#comment-194 Sun, 19 May 2013 11:06:06 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2013/03/nfc_aftershocks/#comment-194 I know it’s odious how MNOs gate access to the Secure Element, but that problem relates to their business model, which could change. We must make it change.

The idea of the Trusted Service Manager closely parallels the way GSM SIMs are managed. High grade hardware based security was standardised for the GSM network from the outset because it was seen that criminal attacks on the telephone system were inevitable. SIMs hold keys just as Dave describes EMV chips holding keys, and those keys and other codes can only get on to the SIMs over-the-air via stringent personalisation services. Now, the potential rewards from attacking the mobile payments system are vastly greater … and yet here we are, countenancing a security-convenience tradeoff because we’re annoyed by the telcos’ TSM behaviour. The idea of using software based key rollover techniques in a handset is especially worrying given the state of application security today. Time and time again, mobile banking and payments apps are shown to be extraordinarily shoddy, thanks largely to the unseemly rush to market. Security and quality are sacrificed for product cycle time and convenience. I would have little confidence in any application level key tricks.

If mobile really is the major platform of the future — and not just for payments but for digital identity too — then we must treat it seriously, and leverage the mission critical security infrastructure that is already in place. Secure Elements and TSMs are terrific infrastructure, fit for the very serious purpose of securing mobile transactions. At some level, it’s proper that SEs cannot be modified too easily; after all, the ease of access by application software to executive functions in the PC platform is what enables most cyber crime today. Telcos are rather too avaricious in their TSM policies and business models but I don’t think renting SIM space is inherently evil. In fact I think if banks thought to rent out space and cryptographic functions in their EMV chips then we could see more innovation in e-commerce, e-government and eID.

So let’s not abandon SEs and TSM, but instead work out more equitable ways of sharing the security infrastructure so vital to the long term success of the mobile platform.

]]>
By: Didier http://tomorrowstransactions.com/2013/03/nfc_aftershocks/#comment-193 Mon, 18 Mar 2013 05:23:08 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2013/03/nfc_aftershocks/#comment-193 Hi Dave,
Very interesting … in terms of marketing
I understand that they are planning to replace the SE for two purposes: one being the EMV card PAN, which becomes a one-time PAN fetched by the App after authentication, why not. The other one being the authentication, and here, as an expert, I’m quite worried, because serious (i.e. secure J) authentication requires either an SE or at least a reverse-engineering resistant technology (check http://bit.ly/Z9v3Fi), which does not seem to be the case here … Or did I miss something ?
Cheers, Didier

]]>
By: Mark Cross http://tomorrowstransactions.com/2013/03/nfc_aftershocks/#comment-192 Thu, 14 Mar 2013 09:05:12 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2013/03/nfc_aftershocks/#comment-192 Hi Dave, I understand that EMV via NFC is really cool, but as I understood it, PayPass allows a low threshold. But EMV is basically your chip and PIN situation we are used to in the UK.

My experience of US culture is that EMV via NFC in the retail environment would go down like a Led Zeppelin. Great for the customers getting out of the door quicker but zeroing the up-sell opportunity/time, or effectively removing it? It totally removes KYC in a small retail environment and leaves everything to Loyalty system profiling. What an awful dehumanising world?

Am I missing something here please? Cheers Mark

]]>
By: Alexander Peschkoff http://tomorrowstransactions.com/2013/03/nfc_aftershocks/#comment-191 Mon, 11 Mar 2013 06:04:01 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2013/03/nfc_aftershocks/#comment-191 I wonder why the schemes permit that? I.e. they are crying “Wolf!” to the whole idea of PIN entry on a mobile (for mobile-linked mPOS solution), even where TEE is involved. Yet they are allow some (unsecure!) mobile app to control a very sensitive task – grant payment permission. There is no consistency there, at all, IMO… Either mobile apps ARE secure for EMV-related processes, or they are not.

]]>
By: Steven Murdoch http://tomorrowstransactions.com/2013/03/nfc_aftershocks/#comment-190 Mon, 11 Mar 2013 03:00:32 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2013/03/nfc_aftershocks/#comment-190 Thanks for the additional information. What I’d be interested to know is how the app authenticates to the bank in order to download the information (a temporary key?) to generate the ARQC and TC. This aspect, along with PIN verification (if used) feel like the weak points of the system. Maybe it will be possible to reduce the risk to an acceptable level though.

]]>
By: Consult Hyperion http://tomorrowstransactions.com/2013/03/nfc_aftershocks/#comment-189 Sat, 09 Mar 2013 10:07:55 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2013/03/nfc_aftershocks/#comment-189 Yes it is an EMV transaction. WIll blog.

]]>
By: Alexander Peschkoff http://tomorrowstransactions.com/2013/03/nfc_aftershocks/#comment-188 Fri, 08 Mar 2013 05:56:41 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2013/03/nfc_aftershocks/#comment-188 What kind of payment is that, in case of Bankinter? I didn’t see the word “EMV” there.

The company (Seglan) that helped them to develop the solution claims it is “EMV compatible”. Is that like “almost pregnant”? How can someone do a contactless EMV “cardholder present” transaction without… EMV (i.e. chip, i.e. SE)?

Am I am missing something big here?..

]]>
By: Mark Cross http://tomorrowstransactions.com/2013/03/nfc_aftershocks/#comment-187 Thu, 07 Mar 2013 07:53:17 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2013/03/nfc_aftershocks/#comment-187 In practice if Paypass is ever rolled out. What’s to stop you requesting a new credit card, in your spouses name and then cut it up small and stick the module to you mobile with gaffer tape?

]]>
By: David True http://tomorrowstransactions.com/2013/03/nfc_aftershocks/#comment-186 Tue, 05 Mar 2013 03:59:24 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2013/03/nfc_aftershocks/#comment-186 Dave, I got into a back’n’forth with Cherian Abraham when I tweeted this blog post. See exchange at this link :http://www.linkedin.com/nhome/updates?topic=5714353362850283520

Can you comment?

[Dave Birch] Yes

]]>
By: David True http://tomorrowstransactions.com/2013/03/nfc_aftershocks/#comment-185 Mon, 04 Mar 2013 03:00:20 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2013/03/nfc_aftershocks/#comment-185 Having read this I revise my thinking about NFC adoption prospects, Now it is now longer a business model question, but a marketing question. Can awareness of Bankinter solutions spread quickly and widely before too many players decided to pursue non-NFC contactless solutions?

]]>