To fly, to Serve

[Dave Birch] Isn’t it boring when people tell you that payments work fine and that it’s pointless for us technology persons to waste time on mobile payments? Things just don’t work fine at all. We’ve only taken baby steps towards the mobile future.

For example. I checked in for my last United flight using the app on my smartphone. Cool. It worked quite well once I’d found the confirmation code (or whatever they call it) in an old e-mail from our travel agent. The mobile check-in gives you a QR code that you can use to check in at the airport. But the machines at the United counters at JFK don’t read these codes, so you have to type in your confirmation again at the counter. Then the machine asks you if you want to check a bag. I did, and the machine then wanted $25 (*). You would think that, this being nearly 2014, and since the machine and my app both know which booking this is and since they are both connected via the interweb tubes, that my app would then pop up and ask me to confirm the $25 charge and then charge it against a card on file or take it from the company account that was used to book the ticket or whatever. But no. So I had to get out my wallet and swipe a card. Swipe! Not even chip and PIN! I could, of course, have used anyone’s card since there is no CVM at all, PIN or otherwise.

On the plane, the United purser announced the meal service. You have to pay for the meals in economy class so I just got a snack box. Anyway, admirably, they won’t take cash and you have to use a card. But my card was in my wallet, which was in my laptop back, which was in the overhead bin. Total hassle. Once again, I note that you can use anyone’s card since there is, again, no CVM.

Apparently, using anyone’s card must have been happening a lot on British Airways, because if you use your card in-flight on BA, even if it’s a BA Amex chip and PIN card and you have status on BA and you must have had a boarding card to be in the seat in the first place, they swipe the card rather than do a chip transaction and they make you get your passport out and they record the details. When, on a recent BA flight, I asked why they had adopted such a time-consuming and irritating payment process, the flight attendant told me that they had very high card fraud on certain routes. In a spirit of international harmony I will not repeat the specific routes that she mentioned, and the geography is not relevant to my point here, but again I wonder why I can’t buy stuff in-flight using my BA app. My app could record the purchases in-flight and then charge against a card on file or an account when I get off the plane. How much fraud could there be? It’s my phone and my app (you have to enter a password to run the BA app) and they can see which seat I’m in. Maybe BA could try another kind of innovation, though, and follow the example of the Indian airline that sends people round to your house to collect the cash…

The airline is still happy since the cost of the cash collection service is actually lower than the average Merchant Discount Fee currently incurred by the airline for accepting card payments

[From The Less-Cash Society | Snarketing 2.0]

I don’t feel that I’m asking for the moon to ask for a little integration between Amex and an airline. Why can’t my Amex app grant my BA app permission to charge in certain circumstance? Why can’t my BA app link to the BA in-flight system? Why doesn’t my BA app have a prepaid account connected to it (hello Serve) for offline in-flight payments? Why can’t everyone play together nicely in the payments and travel world! I can assure you it’s not a new idea! There was a time when new technology brought Amex payments and an airline together…

In January 1970, American Express issued 250 000 mag-stripe cards to its Chicago-area customers and installed self-service ticketing kiosks at the American Airlines counter at Chicago O’Hare International Airport. Cardholders could opt to get their tickets and boarding passes from the kiosk or from a human agent. They flocked to the kiosks. In fact, United Airlines customers walked to American Airlines—at the other end of the terminal a quarter mile away—to use the kiosks.

[From The Long Life and Imminent Death of the Mag-Stripe Card - IEEE Spectrum]

Wow. That was a couple of generations ago. As I said, we’re only just beginning. This was at the dawn of the magnetic stripe era and I hope for some similar innovation at the dawn of the mobile era. To me it seems a rather appealing vision to potter along to the airport with my phone and use it to check in, get on the plane and interact in-flight. Maybe contactless technology could help here.

The airline has 3 million EuroBonus members, and among these it issued the sticker to many of its most loyal frequent flyers, EuroBonus Gold members. It issued 20,000 stickers last fall in Sweden and another 35,000 in Denmark and Norway starting in March… A follow-up survey of these users by SAS found that 87% said they had applied the stickers to the back of their mobile phones, and 68% said they had used it at least six times since October.

[From Airline to Introduce NFC App Following Successful Sticker Launch | NFC Times – Near Field Communication and all contactless technology.]

Stickers are, as I may have mentioned, the future. But in another parallel universe, where NFC has a future, there are some people who are still working on that phone-based contactless future with gusto and developing scenarios where it might be a success.

A guide setting out the potential use cases for NFC in the air travel sector has been published by the International Air Transport Association (IATA) and The NFC Forum.

[From IATA and NFC Forum publish NFC air travel reference guide • NFC World]

Could there be progress in this area? It’s difficult. We looked at this for a client a couple of years ago and found real barriers. For one thing, all of the “component experiences” in a journey belong to different people. The airline doesn’t control the immigration desk, the immigration desk doesn’t control the airport, the airport doesn’t control the handsets and so on. Yes, phones could work as tickets and boarding cards, although I have to note that this trivial and obvious use of NFC has already been patented by Apple, whose phones do not have NFC.

The USPTO has granted Apple a patent for a service that lets travellers use their mobile phone to both buy an airline ticket and pass more smoothly and speedily through an airport on their day of travel.

[From Apple awarded patent for mobile airline ticketing and travel service • NFC World]

Never mind, I expect they have some clever Bluetooth LE plus fingerprint alternative waiting in the wings. I see, by the way, that both Amex and United have been announced as partners for the Samsung Wallet. As the good people at Samsung have very kindly asked me to come along and give a talk at their forthcoming developer event for Europe, I shall pass on my suggestions (and any further that you send me) to the relevant people in person.

(*) I simply do not understand airline policy on this. United were charging people $25 to check a bag. As a consequence, people get on to the plane looking like models for Buckaroo. Naturally, this means that a) getting on the plane takes forever and b) there’s no room in the overhead lockers. As a consequence, the staff have to make people check their bags at the gate. But get this: if your bag is checked at the gate, it’s free. I took a laptop bag and checked my suitcase and paid the money. Next time, I’m taking two huge carry-ons and I’m going to call one of them a purse.

These are personal opinions and should not be misunderstood as representing the opinions of�
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The internet of things needs some thinking through

[Dave Birch] There was a story in the British newspapers recently about an Italian criminal family (literally, a father and son) who were arrested for selling fake Romanée-Conti wine (a Burgundy that is one of the most expensive in the world at £14,000 a bottle). The police say that the fake labels applied to the bottles of plonk were “near perfect”. Aha. My eyes pricked up at this. A genuine problem, for which there may be a technological solution that some of our clients could benefit from supplying.

The NFC tags are located behind the label on the winery's Vintage 2010 range, with bottles selling at €2,000 to €2,500 each.

[From French winery picks NFC tags for authentication • NFC World]

Setting aside the interesting technical question of whether these tags are actually NFC or not, I have to report that this is not a new use case for contactless. I wrote up the use of RFID in the drinks business in Korea three years ago when we were looking at some identity-related business cases for one of our telecoms clients.

When the whiskey is bottled, the caps have an RFID tag added to them. This is coded with a URL and an identifier. When a customer, or a shopkeeper, or a policeman, or in fact anyone else wants to check whether the whiskey is real or not, they touch the cap with their phone and the URL launches a web site that knows the provenance of the identifier and can tell you when and where it was bottled as well as some other information. When the customer opens the bottle, the tag is broken and can no longer be read.

[From Digital Identity: There's whiskey in the jar-o]

I happened to find myself sitting next to Erik Harvey from iProof, one of the leading companies in this field, at the WIMA NFC event in San Francisco this week, and he made the very sound point to me that to work for all the stakeholders, systems such as these must involve the consumers. If consumers don’t tap on or scan the labels then there’s no data flowing around the system. We need consumers to be an active part of the anti-counterfeiting activity or it won’t work: they have to want to take part. I think, with the appropriate messaging, that they would. After all, who wants to be embarrassed serving a fake wine at dinner and, aside from that, who doesn’t want to learn more about a wine that they try and like? I’ve often seen people use their mobile phones to take the picture of the label on a bottle at a restaurant, presumably because they find the wine delicious and may want to order it again in the future.

This problem of epicurean counterfeiting is not confined the exclusive French vineyards. It’s a problem the world over, although it takes different forms in different cultures.

The bird's nests can be sealed in a box with an RFID tag that contains a microchip embedded with details about the harvest. A handheld scanner emits a radio frequency to unlock that information.

[From BBC News - RFID technology thwarts bird's nest counterfeiters]

Now, as have pointed out more than once in this context, the tag by itself isn't very useful (especially since absolutely no-one bothers implementing the security layer of NFC). The people who steal authentic labels from designer goods factories will steal authentic RFID tags as well. What is critical is the ability to determine provenance and this mean mutual authentication as well as a managed infrastructure.

Without an infrastructure that includes end-to-end digital signatures there's no way round this. The phone needs to know the chip is authentic. The database needs to know who is asking, and the consumer needs to know who is answering.

[From Digital Identity: There's whiskey in the jar-o]

The security of stuff in the internet of things (IoT) is a really, really interesting subject. It has implications that go way beyond protecting connoisseurs from embarrassment.

Rob Wainwright, director of the EU’s crime-fighting agency, said Europe’s black market in counterfeit foodstuffs, pharmaceuticals and machine parts doubled to a value of about €2bn in the early years of the recession.

[From Crime gangs look to clean up as Europe’s black market balloons - FT.com]

The odd couple of billion here or there doesn’t seem like a big deal to me, especially when the same article notes that VAT fraud is at least fifty times bigger, but taking counterfeit medicine or flying in a plane with a counterfeit part does seem like a big deal to me and I’d rather it didn’t happen. I hate  to say it, but perhaps some form of European co-operation might be needed…

One more thing. I don’t see that the security and privacy issues that come along with the IoT have been thought through at all. I tried to make this point a few years ago, using my pants as the target object, when I was looking at the use of RFID in high-value consumer goods. We need to develop an additional layer that delivers both enhanced security and enhanced privacy. It’s one thing for dinner guests to scan my wine bottle to see that it is a real Romanée-Conti and another for them to scan my Rolex to check that it is indeed a first-class far-eastern knock-off, but it’s quite another for them to be able scan my underpants and determine that they date from 1983. How do we turn tags on and off? How do we grant and revoke privileges? How do we allow or deny requests for product or provenance? These are difficult questions.

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Don’t panic. Whatever the papers say.

[Dave Birch] There’s a new press regulation environment in Britain. The government has just passed a new law to stop newspapers from saying bad things. I heard about it on the radio. I didn’t quite catch all of the story, but I think in essence newspapers have to have stories approved by Hugh Grant or someone similar before publication. About time too! The excesses of the British journalist need to be addressed and the full power of the law must be applied to irresponsible reporting that scandalises, misleads and obfuscates. Exhibit A:

The banking industry […] insists: “The technology is extremely robust, has been thoroughly tested and is working as expected. Payments can only take place where the card is placed within 5cm (2 inches) of the terminal”. This was apparently disproved in the University of Surrey’s research,

[From Engineers claim to prove risks of 'contactless' bank cards - Telegraph]

This is, like anything else you read in the papers concerning a subject you have even the vaguest understanding of, wrong. The journalist clearly didn’t read the paper or pay any attention to what was actually said by the researchers. They did not say, claim, imply, hint or suggest that you can do a payment from more than a couple of inches away. They did not “apparently” or indeed actually disprove any such thing. What they said was that you can eavesdrop on a transaction from more than the 8cm read/write range for NFC devices. This is one example of the fun reporting of a recently-published academic paper on NFC security that has kept our PR people busy for a day or two…

Contactless cards can be hacked with off-the shelf technology

[From Contactless cards can be hacked with off-the shelf technology - E & T Magazine]

Really E&T Magazine? Hacked? No such thing. This paper, published by researchers from the University of Surrey, showed that it is possible to eavesdrop on NFC communications from a couple of feet away under certain circumstances. They built a rig for doing this from easily-obtainable bits and pieces.

Inconspicuous equipment including a shopping trolley, a backpack and a small antenna were used to intercept synthesised payments card data.

[From BBC News - Contactless payment data can be picked up at a distance]

Putting to one side the issue of whether a shopping trolley might genuinely be considered “inconspicuous” or not, it’s a story where the media got the wrong end of the stick big time. I urge you to go and reader the paper for yourself:

Eavesdropping near-field contactless payments: a quantitative analysis

[From IET Digital Library: Eavesdropping near-field contactless payments: a quantitative analysis]

If you read to the end of this paper, you will see…

This work was funded by EPSRC and Consult Hyperion.

So what is the background to all of this? Well, several years ago Consult Hyperion was commissioned by UK Cards to run detailed experiments on contactless security and we were able to establish that it was possible to eavesdrop on contactless transactions under laboratory conditions. Naturally, since we are seen as being industry thought-leaders in the field of secure electronic transactions, it was important to us to understand all aspects of this issue so that we could give our clients accurate advice. We do a lot of risk analysis work for organisations developing new transactional systems and the integrity of our recommendations depends on an understanding of the details of the vulnerabilities: What is the cost to an attacker? What is their likelihood of detection?

We decided to explore the area further by funding PhD research at the University of Surrey to get some new perspectives on the subject and I have to say that it has been wonderful to witness the ingenuity that the researchers brought to the topic! If you read the paper, you will see that they were able to design kit that means you could in theory stand within a couple of feet of someone at a supermarket checkout and listen in on the communications between their contactless bank card and the supermarket terminal. This is because the cards and the terminals work using the EMV (“chip and PIN”) standard that does not encrypt the data between the card and the terminal. Now, this does not mean that the payment system is compromised! The data that you might be able to obtain in this way (the card number and the expiry date) is printed on the front of the card anyway – if you’re that close to someone you might as well just read it as scan it – and because of the way that the EMV works, you can’t use this data to create a clone card. Just as when we did the original risk analysis on contactless in 2007, the conclusion is that contactless bank cards are fit for purpose.

Summary: we thought that this kind of eavesdropping is not a practical attack on contactless bank cards and the research appears to have confirmed that. Boring, but the truth, and very reassuring to our clients in that space.

There is another point to be made, though, which actually is important. Remember that the research was not specifically about payments but about contactless transactions in general. It stands as a general and timely reminder to the designers of NFC-based systems to carry out proper risk analysis and not to rely on the short range of NFC communications to preserve privacy/confidentiality.

We’re very proud to have been able to support this research. Our clients depend on us exploring the frontiers of knowledge in these areas so that they can be utterly confident in our advice and we will continue to research the field to their benefit. Open discussion of threats, vulnerabilities and countermeasure is the way that the industry works to keep payments safe.

These are personal opinions and should not be misunderstood as representing the opinions of�
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.