Tomorrow's Transactions » Retail http://tomorrowstransactions.com Thought leadership from Consult Hyperion Fri, 18 Jul 2014 06:22:13 +0000 en-US hourly 1 http://wordpress.org/?v=3.9.1 Targetting decoupled debit http://tomorrowstransactions.com/2014/06/targetting-decoupled-debit/ http://tomorrowstransactions.com/2014/06/targetting-decoupled-debit/#respond Fri, 20 Jun 2014 17:52:54 +0000 http://tomorrowstransactions.com/?p=4488 All other things being equal, it seems to me that the merchants will want to move to payment solutions that go direct to the customer’s payment account. This mean incumbents have to innovate and deliver genuine value-added services to stay in the loop. There was a discussion about decoupled debit at a meeting I was […]

The post Targetting decoupled debit appeared first on Tomorrow's Transactions.

]]>
Dgwb blog white border

All other things being equal, it seems to me that the merchants will want to move to payment solutions that go direct to the customer’s payment account. This mean incumbents have to innovate and deliver genuine value-added services to stay in the loop.

There was a discussion about decoupled debit at a meeting I was in last week. The context is not germane to this post, but I referred someone to a super piece about Target’s decoupled debit payment scheme that I’d seen in American Banker. It makes the central point that decoupled debit isn’t only about the cost to the retailer but about the overall purchasing experience, including offers and rewards. If it was only about costs, the decoupled debit proposition would be under some pressure.

Store-branded debit cards were supposed to die after price caps on swipe fees took effect in 2011, since one of its major advantages was that it allowed retailers to avoid paying the hefty interchange fees that banks were charging. Those fees have fallen sharply over the last two years. Yet Minneapolis-based Target is showing that under the right circumstances, store-branded debit cards can still work for retailers.

[From Target Card Tests Future of Store-Branded Debit - American Banker Article]

Target are not the only people who think that this is true, although in an odd way they might be a key reason for stimulating the sector, and not because of their (considerable) success in persuading customers to use the Target Red product but because of their rather famous Target data breach. Remember, when the Target data began sloshing through the interweb tubes, a clear media message was that scheme cardholders were vulnerable, but Target’s own cardholders were not.

National Payment Card Association’s merchant-branded decoupled debit cards may be part of an industry-wide solution to preventing the next Target breach.

[From 2014 - Will The Target Breach Kill Branded Debit Cards? | PYMNTS.com]

I was not joking about the success of the product, by the way. It has been incredibly successful. It’s something like 20% of the volume already in the early-adopting stores and set for further growth.

Consumers who have a Target debit card increase their spending by an average of 52%, according to a presentation the company made last year. In the second quarter of this year, sales on the debit cards surpassed sales on Target’s credit cards for the first time, according to the company..

[From Target Card Tests Future of Store-Branded Debit - American Banker Article]

Now, I suspect that this success has not gone unnoticed in a number of boardrooms, both in financial institutions and retailers.

some experts believe that store-branded debit cards will be part of the strategy employed by the Merchant Customer Exchange, or MCX, the fledgling consortium of retail chains that is looking to challenge the traditional electronic payments system.

[From Target Card Tests Future of Store-Branded Debit - American Banker Article]

The mention of MCX is interesting. Obviously there are all sorts of different models that MCX could adopt for its nascent payment scheme, but many observers focus on the direct-to-bank debit solution as the most likely nudge the mass market.

The MCX white knight, many think, is store-branded debit products, also known as decoupled debit.

[From Commentary - MCX and the Giant Payments Networks: A Payments Fairy Tale | PYMNTS.com]

I saw Dodd Roberts (from MCX) give an update on the scheme down in Melbourne recently, and he identified five drivers for MCX from the retail community.

  • Customer experience.
  • Consistency of solution.
  • Security.
  • Data.
  • Flexibility.

He also talked specifically about payments as critical success factor, and about how to address (as they see it) the “payments imbalance” and the “efficiencies for issuers and merchants”, saying that  MCX are going to deliver a mobile commerce app that will deliver a better shopping experience on a secure platform that safeguards “stakeholders’ interests” and implements a “balanced, competitive payments ecosystem”.

We continue to believe the funding sources for MCX’s wallet are a combination of private-label credit, decoupled debit, and stored value (i.e., gift cards), rather than traditional (credit card) accounts… Merchants seem hopeful that the ACH system will move closer to real-time authorization, but acknowledged that scenario is likely a good 3-4 years away.

[From Retailers' Mobile Wallet Seen Delayed To 2015; Apple Boost? - Investors.com]

Now, the payment incumbents, such as Visa and MasterCard, are not stupid people — in fact they are very clever people — and they can read the newspapers just as well as me. There will be a new cost floor emerging as the merchants use mobile phones, apps and customer experience to drive consumers to choose ACH over alternatives (“Pay with your Tesco and get double points” is an easy proposition for them and the transaction is indistinguishable from a normal debit transaction tot he average consumer). Therefore, the advantages of using scheme credit and debit will have to come from value-added services that deliver something to consumers and merchants alike, otherwise they will be nudged out of the loop.

Unless… Here’s a thought experiment. What if the schemes decided to disrupt themselves? What if the schemes developed their own decoupled debit proposition that used “hard” tokenisation and the internet instead of plastic cards, chips and proprietary networks? I mean, I know Christensen is somewhat unfashionable this week, but he has point doesn’t he? They could call it super debit or turbo debit or something. Couldn’t they?

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Targetting decoupled debit appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2014/06/targetting-decoupled-debit/feed/ 0
Payments are boring (not to me, obviously) http://tomorrowstransactions.com/2014/05/payments-are-boring-not-me-obviously/ http://tomorrowstransactions.com/2014/05/payments-are-boring-not-me-obviously/#respond Thu, 22 May 2014 09:04:29 +0000 http://tomorrowstransactions.com/?p=4444 The horrible truth is that payments are boring, so they are going to go away. At Payments Innovation 2014, Forum friend Roy Vella just said that I am the only person in the world who wakes up looking forward to making a payment. Well, I guess I have to admit it. Not everyone in the […]

The post Payments are boring (not to me, obviously) appeared first on Tomorrow's Transactions.

]]>
Dgwb blog white border

The horrible truth is that payments are boring, so they are going to go away.

At Payments Innovation 2014, Forum friend Roy Vella just said that I am the only person in the world who wakes up looking forward to making a payment. Well, I guess I have to admit it. Not everyone in the world thinks that payments are fun. In fact, to a first approximation and rounding to one significant figure, no-one does. That’s why a mobile, digital, electronic or any other sort of wallet that is only about payments gets no traction.

I saw Jed speaking on this topic earlier in year (and I made a podcast with him too) and he said, when asked about QR codes and NFC and Bluetooth in a question-and-answer session following a terrific presentation, that it doesn’t really matter how the phone is associated with the retailer through the point-of-sale (or, as we would put it, the consumer is “recognised”) the experience is the same, what’s important is that it’s a great experience. The person who can optimise for a great experience in any particular retailer is the retailer themselves.

Earlier this week I wrote about how electronic receipts might be part of that great experience but there are, of course, all sorts of other elements to that experience. This makes me really interested to look at what retailers are doing with their wallets, since there may be opportunities for some of our clients to provide services to help them deliver something above and beyond.

We are developing a digital wallet, focusing on marketing and loyalty aspects, but payment may not enter the wallet. We have a payment system in place already and we don’t want to disrupt it if it doesn’t add any value

[From Tesco: NFC payments are too complex and offer too few benefits • NFC World]

A wallet that has no payments in it isn’t terribly useful. So, as must be obvious, it is important to develop payment systems and interfaces that fit into wallets. This is a paradigm shift: instead of designing a payment system for the consumer, we have to design one for an app. That means the selling points aren’t nice adverts and pictures on cards but APIs and reliability and scalability and developer programmes and test harnesses and all that other stuff.

[Tesco is] reported to be trialling a wallet that sits inside its current app. This will enable users to add any payment card and then scan items as they journey round the store – and pay at the end. The new feature will sit alongside other features of the app, like Click & Collect, in-store maps and Clubcard coupons.

[From Tesco to add digital wallet to its smartphone app | Mobile Money Revolution]

Once again we see how payments can contribute to a great experience by, essentially, going away.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Payments are boring (not to me, obviously) appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2014/05/payments-are-boring-not-me-obviously/feed/ 0
Receipts are a way to make wallets better http://tomorrowstransactions.com/2014/05/receipts-are-a-way-to-make-wallets-better/ http://tomorrowstransactions.com/2014/05/receipts-are-a-way-to-make-wallets-better/#comments Mon, 19 May 2014 06:31:45 +0000 http://tomorrowstransactions.com/?p=4439 One of the things that a digital wallet can do better than a leather one is manage receipts. We all understand that if we are going to replace the leather wallet with a digital one, it’s got to do a lot more than payments. Korea’s second largest mobile operator, KT, know this and so when […]

The post Receipts are a way to make wallets better appeared first on Tomorrow's Transactions.

]]>
Dgwb blog white border

One of the things that a digital wallet can do better than a leather one is manage receipts.

We all understand that if we are going to replace the leather wallet with a digital one, it’s got to do a lot more than payments. Korea’s second largest mobile operator, KT, know this and so when they launched a new m-payment system “MoCa” they were part of the package. They also kicked off the “The MoCa Alliance”, which has already brought on board over 60 companies including the country’s leading banking institutions, coffee shop chains, and department stores.

[Interview : Shim Kyu-young, Seoul Resident] “I didn’t like that my wallet was thick due to cards, receipts, and coupons. Now my wallet is thin and it’s nice that I can comfortably use my smartphone.”

[From Arirang News]

This may have lost something in translation, but you get the point. Making payments electronic only gets us part of the way to the digital wallet. We need to make everything else electronic as well and the rather obvious place to start is the receipt, something of a weak link. A typical modern payment experience, for me, involves tapping a card or a phone on a reader for a transaction that takes a couple of hundred milliseconds and then standing around waiting for a printer to chunter out a paper receipt that I don’t actually want anyway. There must be a better way, and Walmart is trying one.

The retailer will identify the consumer by asking her to type in her mobile phone number on the debit card reader at checkout. If she chooses the e-receipt option and opts in, the e-receipt will be delivered by free text message after the transaction is complete.

[From E-mail Marketing - Wal-Mart will turn the electronic receipt into a sales tool - Internet Retailer]

This seems a little clunky, a little interim, to me but there are other implementations of electronic receipts emerging. Square’s new “Feedback” product will extend electronic receipt capabilities to smaller merchants and go further to allow consumers to give instant input after paying for something using Square but inviting feedback on the delivery of an electronic receipt, and will give those kinds of small businesses a way interact more intimately with customers.

“What if we saw it as a communication channel,” he asked. “What if we saw it as a publishing medium, what if we saw it as a connection, and a reminder, and a potential for more of those experiences?”

[From Jack Dorsey Is Planning to Reinvent the Humble Receipt | TIME.com]

So, yes, e-receipts are inevitable. But I wonder about the managed kind of e-receipt. If I was a retailer, I’d want to convert to e-receipts in my own wallet, not in someone else’s. If I were Waitrose, I’d want my app to do this, of course, because if they allow third-parties to manage the receipts for me, then that means those third-parties will get access to the level 3 POS data (the detailed line item data) and I’m sure they won’t want that to happen. This what some of the players are working on.

The idea is to know far more than Clubcard can about consumers because – with all the necessary consents – this is a system that can span the high street and online retail, effortlessly connecting the dots.

[From Receipts: the digital future - Telegraph]

The future narrative for the retail app with payments and receipts will, surely, be that I amble into Waitrose, my Waitrose app opens automatically because of BLE and displays my shopping list and notes, I get a coffee (I love the free latte in Waitrose, even if it does attract the wrong sort of person) and wander around self-scanning my groceries. When I’ve finished, I tap out using NFC and the Waitrose app (which has used the Partnership Services API to pull down an HCE token for my John Lewis MasterCard) pays via the standard contactless terminal and checks me out, at which point the till knows that as I’m using the Waitrose app I don’t want a stupid paper receipt and just sends the receipt back via NFC (or over the air using the interweb tubes) into the Waitrose app. Using the app and the “small data” tools provided by Waitrose I can then search, print, export or do whatever else I want to with my receipts – I’m not smart enough to imaging what else I actually might want to do with the receipts but I’m sure innovative persons will find some amazing things to do with them.

One final point about receipts. They need to be secure. You might think that they don’t need the same degree of security as payments, but I think you’re wrong. It’s time to bring digital signatures to bear on them to ensure that when you pull up an old receipt and present it for whatever purpose (returns, warranties, who knows what) the system can depend on its integrity.

To begin to comprehend China’s vast underground economy, one need only visit this city’s major transportation depots and watch as peddlers openly hawk fake receipts.

A scalper mumbles, “Fapiao, fapiao,” or receipts, at the Shanghai Railway Station. The trade in receipts is more or less open.

“Receipts! Receipts!” calls out a woman in her 30s to passers-by as her two children play near the city’s south train station. “We sell all types of receipts.”

Buyers use them to evade taxes and defraud employers. And in a country rife with corruption, they are the grease for schemes to bribe officials and business partners.

[From Coin of Realm in China Graft - Phony Receipts - NYTimes.com]

I was surprised on my first visit to Russia to see this same kind of business conducted openly in the subway system. When I went on to the Moscow subway for the first time, genuinely marvelling at the Stalinist splendour, I was given a couple of cards by a hawker as I passed by. I couldn’t read them, so I asked one of our Russian hosts what they were, and he said that one was an advertisement for bogus receipts for travel and the other was an advertisement for bogus medical certificates. No-one seemed at all fazed by this.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Receipts are a way to make wallets better appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2014/05/receipts-are-a-way-to-make-wallets-better/feed/ 2
Business owners and cash http://tomorrowstransactions.com/2014/05/business-owners-and-cash/ http://tomorrowstransactions.com/2014/05/business-owners-and-cash/#respond Wed, 07 May 2014 14:40:05 +0000 http://tomorrowstransactions.com/?p=4426 Legal businesses want electronic payments. No two ways about it. Well, the gauntlet was well and truly thrown down on Twitter. There was a Twitter exchange (I don’t really want to label these enjoyable interludes “discussions”, but I can’t think of a better word) on the back on Jim Marous’ post on the use of […]

The post Business owners and cash appeared first on Tomorrow's Transactions.

]]>
Dgwb blog white border

Legal businesses want electronic payments. No two ways about it.

Well, the gauntlet was well and truly thrown down on Twitter. There was a Twitter exchange (I don’t really want to label these enjoyable interludes “discussions”, but I can’t think of a better word) on the back on Jim Marous’ post on the use of cash in the USA, triggered by the Federal Reserve study on same. I wrote a guest post for Jim to build on his comments about this study, but in the course of the Twitter exchange I happened to see this from an interested member of the general public.

I can do better than that “ben_katz” — is Jonathan at work today :) — I can point to several business owners who say that they would prefer electronic payments to cash. (Yes, I’ll admit, these are the honest ones, but I don’t think it should be core social policy to reduce transaction costs for criminals.) Last week, the Jeremy Vine show on BBC Radio 2 had an interesting phone-in segment on cash. They had a taxi driver complaining about cash and lauding contactless and mobile solutions, a sandwich shop owner talking about the problems of managing cash float (and change) and someone complaining about parking machines. They were all challenging the assumption that the inertia around cash means an insurmountable barrier to change. It does not. The honest retailers also want it to vanish in favour of more efficient electronic alternatives.

I’m a retail manager. Please, please, please, for the love of god, let cash die already. It’s expensive to store, sort, count, and transport. It goes missing. It falls apart. It sticks together. It slows down the checkout process.

[From Paper Or Plastic: How Americans Buy Stuff, In 1 Graph : Planet Money : NPR]

This plea by itself would merit comment here, but what particularly fascinated me was the manager’s subsequent comment about power and fallback, which we have discussed here before. In that particular shop, I imagine that the POS terminals are handheld devices with rechargeable batteries.

And losing power and/or communications does NOT stop us from accepting cards. It will, however, prevent our CASH registers from operating in a secure and audit able fashion.

[From Paper Or Plastic: How Americans Buy Stuff, In 1 Graph : Planet Money : NPR]

And if the POS terminals run out of juice after a few hours, then the store manager could just use a Square or an iZettle and get on with things. Note, however, the manager’s emphasis on the final point: auditable. Getting rid of notes and coins and replacing them with electronic payments has implications for retailers beyond the cost savings of cash handling and paying taxes in a fair market is one of them that we all accept.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Business owners and cash appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2014/05/business-owners-and-cash/feed/ 0
NFC isn’t a business model http://tomorrowstransactions.com/2014/04/nfc-isnt-a-business-model/ http://tomorrowstransactions.com/2014/04/nfc-isnt-a-business-model/#comments Wed, 23 Apr 2014 13:28:58 +0000 http://tomorrowstransactions.com/?p=4407 NFC is an interface, it’s not a business model. So when commentators said NFC was finished, they meant the telco-centric NFC business model was dead. The rocky road to the mass market use of Near-Field Communication (NFC) technology has plenty of twists and turns. In the US, where it has an entirely different context at […]

The post NFC isn’t a business model appeared first on Tomorrow's Transactions.

]]>
Dgwb blog white border

NFC is an interface, it’s not a business model. So when commentators said NFC was finished, they meant the telco-centric NFC business model was dead.

The rocky road to the mass market use of Near-Field Communication (NFC) technology has plenty of twists and turns. In the US, where it has an entirely different context at retail point-of-sale (POS) because no-signature stripe payments are so quick and convenient (contactless payments are no quicker, but when the US moves to PIN at POS then they will be) it has been a source of tension between stakeholders.

Adding to the turf battle now building over mobile payments, a few national retailers who are MCX members have begun turning off the ability of recently-upgraded payment terminals to recognize NFC payments or read smart credit and debit cards embedded with a chip

[From Isis CTO accuses retailers of turning off NFC and smartcard payment tech - Computerworld]

I don’t doubt this is part of the ongoing battle between merchants and banks in the US but if you think about it, it’s the business models and not the technologies that are competing. MCX could perfectly well use NFC (in fact, it would surely be quicker and more convenient if it did) and banks could perfectly well use QR codes. What’s happened here is that the products have become bound up with the interfaces, and that’s why strategies have become confused.

MCX plans to sidestep any requirement that customers load up a Visa or MasterCard card to a smartphone, and will instead require them to make purchases with phones and barcodes directly from their bank accounts — a significant departure

[From Isis CTO accuses retailers of turning off NFC and smartcard payment tech - Computerworld]

Look at how Target Red (the decoupled debit proposition) has taken off — as I understand it, Target Red is something like a fifth of the volume in early adopting stores and the analyst Gill Luria said (at BAI Payments Connect) that if this performance scales across MCX members it will take something like three or four percent of scheme volume in the USA — and was energised because it wasn’t subject to the same problems that credit and debit cards suffered in the Target breach. Now, taking an NFC handset and downloading a Target app that includes a Red card that runs over the NFC interface sounds (I’m sure) much more appealing to Target than simply adding NFC at POS for scheme payments. When you look at things from this point of view (seeing HCE, tokenisation, contactless POS, APIs and so on as components of a revolution at POS), NFC looks far from dead.

McKee expects Google’s HCE innovation to lead to an NFC renaissance in 2014,

[From Isis CTO accuses retailers of turning off NFC and smartcard payment tech - Computerworld]

I’m sure this is true – in fact, it’s what we at Consult Hyperion told our clients some time ago – and it has been reinforced in the last couple of days because of remarks from David Marcus, the head of PayPal.

“I’m moving from being a massive skeptic of NFC, to being cautiously optimistic on NFC HCE take-up in very specific shopping use cases,”

[From PayPal takes another look at NFC • NFC World]

I’m sure David would agree that what he was (rightly) sceptical about in the past was that NFC business model built around mobile network operator (MNO) infrastructure, not a quick and simple means to transfer data over a short range!

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post NFC isn’t a business model appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2014/04/nfc-isnt-a-business-model/feed/ 2
Paying in the pub of the future http://tomorrowstransactions.com/2014/01/paying-in-the-pub-of-the-future/ http://tomorrowstransactions.com/2014/01/paying-in-the-pub-of-the-future/#comments Wed, 22 Jan 2014 22:41:49 +0000 http://tomorrowstransactions.com/?p=2956 We went off to Britain’s first robopub to have a pie and a pint and to watch the Blues demolish West Ham. Oh, and to see next-generation hospitality retailing in action. By happy coincidence, the evening that we decided to go and try out Britain’s first robopub – The Thirsty Bear in Southwark – solely […]

The post Paying in the pub of the future appeared first on Tomorrow's Transactions.

]]>
Dgwb blog white border

We went off to Britain’s first robopub to have a pie and a pint and to watch the Blues demolish West Ham. Oh, and to see next-generation hospitality retailing in action.

By happy coincidence, the evening that we decided to go and try out Britain’s first robopub – The Thirsty Bear in Southwark – solely in the pursuit of retail payments knowledge, and incurred certain entertainment expenses wholly and necessarily in connection with our principal business, was the evening that Manchester City were playing their League Cup semi-final second leg against West Ham. Perfect. We had a lovely pint or two, an excellent helping of haddock and chips with New Labour guacamole (or mushy peas, as the dish is known in the far North) and excellent company and conversation for the night. And as if we couldn’t have made the event even more English had we tried, the footie was live on the big screen in the upstairs lounge.

photo 2

The first thing that you will notice about The Thirsty Bear is that the tables have one iPad and two beer taps (one bitter, one lager) on them. The two are interconnected in an Internet of Grog, as will be revealed shortly. In the centre of the table is small credit-card sized recess. Here’s how it all works…

http://farm8.staticflickr.com/7380/12092652854_22ac3016e8_n.jpg

When you go in, you give them a payment card and they give you a contactless card, called a “Tab”. I assume they auth the card at that point but forgot to ask. You find a table and sit down and put your Tab in the recess in the centre of the table. At this point the table is activated and you can either pull your own pint from the on-table taps (the iPd displays as flow meter so you can see how much you are pouring) or you can use the iPad on a rotating mount in the centre of the table to order food, drinks and sundries. The iPad showed you customer ratings for the ales on offer and we could have punched up a couple of pints of wallop but we preferred the time-honoured method of asking me in host to recommend beverages. He suggested real ale for the men and white wine or a fruit-based cocktail for the ladies, so we went with the darker of Windsor & Eton Canberras on offer. I can personally attest to its quality.

http://farm3.staticflickr.com/2878/12092284515_2062e8d13e_n.jpg

If you go to another table, you can buy the drinks there by putting your Tab down. Similarly, if its someone else’s round at the table, you pick up your Tab and they put down theirs. Whatever is ordered/pumped at the table is added to the Tab. Simple. The table tablet has other functionality, aside from Facebook and Twitter access. A couple of twitter correspondents asked if there was a pub quiz or similar and there wasn’t, although I mentioned this to the software guys and they agreed this might be a good idea. It did have a jukebox app connected to the pub sound system but, oddly, it didn’t have any Hawkwind on it.

http://farm8.staticflickr.com/7366/12092656564_6947fd7813_n.jpg

We then chose some food from the attractive and well-presented screens. A great system, especially because the menus are updated in real time so as they sell-out of various dishes the menu reflects this. I can see that, if properly handled, the use of differential pricing might be a very interesting development.

http://farm6.staticflickr.com/5504/12092581333_9a4c52e421_n.jpg

A great pub with great beer, great food and great technology. When we were chatting about it afterwards, a couple of people did wonder why they bothered with the Tab card, since everyone in the pub had a smartphone (so an HCE pub app would have done the trick) and most of them would have had a contactless card as well, so why not just use those? I expect they’re right and in time the tablets and the card will probably vanish. But for the time being, this is a pretty convenient way to order and pay.

http://farm6.staticflickr.com/5481/12092927906_ff1083e474_n.jpg

I had the opportunity to chat to the manager of the pub and he told me that 55% of sales come through the tablets and 45% over the bar. He was very enthusiastic about the infrastructure. These are tough times for pubs in the UK but here they have year-on-year growth in sales. The manager attributed this to uplift at the tables (especially amongst groups after work or watching the football) and more room at the bar (since the bar is not as crowded there is more walk-in trade). I liked it a lot. We’ll be back.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Paying in the pub of the future appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2014/01/paying-in-the-pub-of-the-future/feed/ 3
NFC and BLE are friends http://tomorrowstransactions.com/2014/01/nfc-and-ble-are-friends/ http://tomorrowstransactions.com/2014/01/nfc-and-ble-are-friends/#comments Fri, 17 Jan 2014 10:54:51 +0000 http://tomorrowstransactions.com/?p=2942 As the recent Apple patent application shows, NFC and BLE are not rivals, but a potentially powerful combination of interfaces that might transform retail payments. [Correction: as numerous correspondents pointed out, this story concerns an Apple patent filing, not an award, and I have changed the wording accordingly.] What an interesting combination of events. I […]

The post NFC and BLE are friends appeared first on Tomorrow's Transactions.

]]>
Dgwb blog white border

As the recent Apple patent application shows, NFC and BLE are not rivals, but a potentially powerful combination of interfaces that might transform retail payments.

[Correction: as numerous correspondents pointed out, this story concerns an Apple patent filing, not an award, and I have changed the wording accordingly.]

What an interesting combination of events. I happened to be at a meeting with a large UK organisation yesterday — I won’t mention the name so I hope they won’t mind! — and one of the subjects under discussion was the combination of proximity and vicinity interfaces to deliver the best possible shopping experience to a customer. In other words, how to combine BLE and beacons with NFC and other interfaces in the best way. After the meeting, I was ambling down the road reading Twitter and I saw that Apple have filed a patent for just such a combination and thrown in tokenisation for good measure.

The patent language notes that the invention covers a commercial transaction method in which a purchasing device, such as an iPhone, finds and establishes a secure connection to a point of sale system via a first wireless interface. Following link up, the device identifies a second, different wireless interface to connect to a backend server for transaction completion.

[From Apple details secure 'touchless' e-wallet strategy in patent filing]

So, basically, I walk into Tesco and tap something with my NFC phone, at which point my Tesco app opens up and establishes a BLE connection. BLE is used to send coupons and offers to the app and when you tell the app to check out, the app sends a token that Tesco can hand to their acquirer. At no point do Tesco ever see card data.

(It is baffling to me that companies are allowed to patent this sort of thing, by the way, but there you go. If this sort of combination of proximity and vicinity interfaces, a smartphone and a secure element was obvious to me, it must have been obvious to a great many people.)

Nothing particularly interesting in that, you might think, and you’d be right. However, it’s stll worth noting. What this patent filing does do, I think, is support the tactical approach that we have been recommending to our clients. Last year, I wrote that I thought that some observers were wrong to frame the discussion about retail interfaces as NFC vs BLE. While it is certainly true that Apple’s decision not to put NFC in the iPhone changed the trajectory of mobile payments, as I said at the time:

An HCE/NFC/BLE world seems rather attractive from a consumer experience perspective.

[From You searched for hce - Tomorrow's Transactions]

This is a very flexible landscape with a wide variety of options for retailers to choose from. Retailers that want to use their existing contactless terminal estate can complete the transaction via the NFC interface by adding HCE to their app (the Tim Horton approach – the picture below shows the Tim Horton HCE being used by an @chyppings consultant in Toronto this very week!), other retailers might decide to complete without using terminal estate at all. Some retailers might decide to use beacons to deliver offers and guide shoppers, other retailers might decide to send offers over the air. Also, remember that Apple don’t have to use NFC for the proximity trigger. Customers could scan a barcode, enter a password, whatever.

timhorton screenshot

Personally, I feel that it might make sense to use proximity and vicinity the other way round, if you see what I mean. Use BLE (or other geolocation or even manual location selection) vicinity to trigger the retailer app and then use NFC (or manual checkout or barcode scan) to execute the transaction. The reason I think this is that I think the positive action of tapping is more direct instruction to transact, but given what little I know about UI, I’m open to suggestions and interested what others think.

The bottom line is that the “triple-A play” of authentication, apps and APIs is looking like a pretty good approach for the next generation of retail payments.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post NFC and BLE are friends appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2014/01/nfc-and-ble-are-friends/feed/ 1
Don’t Bogart that Square, my friend, pass it over to me http://tomorrowstransactions.com/2014/01/dont-bogart-that-square-my-friend-pass-it-over-to-me/ http://tomorrowstransactions.com/2014/01/dont-bogart-that-square-my-friend-pass-it-over-to-me/#respond Fri, 10 Jan 2014 16:06:40 +0000 http://tomorrowstransactions.com/?p=2921 I’ve had another business idea. I want to open up a new market sector. My slogan will be “Buy your Camberwell Carrot with Doobie Debit”. It’s not often that we get to discuss recreational drug use on this blog, since we don’t generally pay any attention to news stories that do not involve electronic transactions. […]

The post Don’t Bogart that Square, my friend, pass it over to me appeared first on Tomorrow's Transactions.

]]>
Dgwb blog white border

I’ve had another business idea. I want to open up a new market sector. My slogan will be “Buy your Camberwell Carrot with Doobie Debit”.

It’s not often that we get to discuss recreational drug use on this blog, since we don’t generally pay any attention to news stories that do not involve electronic transactions. That’s why, for example, there is no story here concerning self-confessed dope smoker Nigella Lawson and her ex-husband’s socially irresponsible habit of using cash. However, recent events in the US mean that we can no longer avoid the topic.

Now that several states have legalized medical, and in some cases recreational, use of marijuana, card networks have to decide if they will process these transactions on their network.

[From Card Networks Take Positions on Marijuana Purchases - PaymentsJournal]

As Mercator point out, this puts the networks and acquirers in an interesting position. After all, while it is not legal everywhere, it is a huge cash-based business that is ripe for conversion to electronic payments.

The broad acceptance of credit and debit cards could eventually be a big boost for the card industry, which is eager to convert everyday cash purchases into plastic. Colorado marijuana shop owners estimated that they rang up $1 million in sales on New Year’s Day, the first day recreational pot became legal.

[From Card Conundrum Develops in Colorado Over Marijuana Sales - WSJ.com]

Reading this led me to wonder whether cards or other electronic payments are used to facilitate marijuana sales elsewhere? It’s very hard to find any actual figures for this. In the UK, for example, it’s illegal to sell marijuana. So while I don’t doubt for a moment that enterprising unregulated pharmaceutical executives are already using mPOS and P2P and FPS to facilitate transactions, there are no statistical analyses that I can refer to. Then it struck me: Amsterdam. That’s the only place I can think of where people can buy marijuana. Given that The Netherlands is a heavily debit-centric market that is making an effort to reduce cash usage, surely the famous coffee shops might provide a case study. But alas not, and for a reason that hadn’t occurred to me when I first wrote on this topic.

These coffee shops are being pressured to start accepting cards so that more of their operations are on the books. This is, of course, a good idea… But the coffee shops, tolerated under the Dutch system, have a supply chain chain that is not. The wholesalers, so to speak, have expressed a marked reluctance to be paid by SEPA credit transfer.

[From The Dutch retailers and the war on cash - Tomorrow's Transactions]

Why does any of this matter? Well, it seems to me that the use of electronic payments is a badge of respectability. People who run legitimate business want to accept electronic payments: it marks them as being socially responsible, taxpaying businesses mindful of their role as guardian of the complex rights and responsibilities that create the conditions for commerce to take place in ways that benefit all of us. Conversely, if I see a sign on a restaurant door that says “cash only”, I naturally assume that the owners are tax evaders or a front for organised crime.

In ten years time, one panel moderator predicted, “cash won’t be something that nice people do.” Instead, he thought, “the C word” will be tied to drugs and other illicit dealings.

[From A Dispatch from the Future (of Money and Technology Summit) — Cultural Anthropology]

This echoes one of my all-time favourite quotes from one of my all-time favourite books from one of my all-time favourite authors. In the brilliant “Count Zero” by the brilliant William Gibson, we read:

He had his cash money, but you couldn’t pay for food with that. It wasn’t actually illegal to have the stuff,it was just that nobody ever did anything legitimate with it.

I can see the problem in the US because of the difference between state and federal law but I can think of at least one solution: why doesn’t an issuer in Colorado come up with a “Colorado Card” that can only be used within the state? Then the acquirers and processors could handle the transactions and everyone is happy. I’ve said before that I would be perfectly happy for Barclays to mark my debit card as UK only and block all CNP usage. Since almost all physical retail transactions are local (I don’t know what the figures are for the US exactly, but I’d imagine that 98% of offline debit card use is local) this should be workable. If the issuers don’t do this, then a State-only decoupled debit or ACH front end is on the way! I’m going to nip out and register “Doobie Debit” as a trademark.

As Karen Webster says, though, “there’s always Bitcoin”. Could legal marijuana sales be an opportunity for Bitcoin to gain some mainstream transactional action? It would be lovely to think so, but I’m afraid I doubt it. The comments of the marijuana sellers quoted in the articles above, and others than I’ve read, make it clear that the preferred option of both buyers and sellers are, as in all other retail environments as far as I know, debit cards. Hence if anything I would expect to see a measurable growth in Square, GoPayment, PayPal Here and friends rather than a spurt in Bitcoin transactions. Maybe some people might think it is cool to buy illegal drugs using Bitcoin (although, frankly, almost all illegal drugs are purchased with cash) but once the excitement of the black market is removed, buyers and sellers of reefer will judge the payment mechanism the same way as buyer and sellers of shoes: convenience, costs and consumer protection.

What’s the direction of travel then? When it comes to weed, maryjane, grass, hash, bhang and ganja, I’m certain that payments will follow the trajectory of the sector as whole (although possibly with a greater focus on two-sided conditional anonymity as a transaction model) and the payment will soon vanish into the app.

The U.S. medical marijuana industry now has its own mobile app. Medical Cannabis Payment Solutions, which describes its mission as providing end-to-end management across multiple systems for medical marijuana operations, announced the launch this week.

[From Medical marijuana payment company launches mobile app | MobilePaymentsToday.com]

I looked it up. The app handles push notifications, in-app messaging, social media integration, e-commerce, third-party integration and multimedia but not, as far as I could see, payments. It’s only a matter of time. Surely some enterprising venture capitalist is even now funding the bastard son of Uber and GrubHub with in-app payments, ratings and one-click Ben and Jerry’s. And if the gear doesn’t show up in 30 minutes, it’s free.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Don’t Bogart that Square, my friend, pass it over to me appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2014/01/dont-bogart-that-square-my-friend-pass-it-over-to-me/feed/ 0
Target breach may have consequences beyond EMV http://tomorrowstransactions.com/2014/01/target-breach-may-have-consequences-beyond-emv/ http://tomorrowstransactions.com/2014/01/target-breach-may-have-consequences-beyond-emv/#respond Fri, 03 Jan 2014 15:02:29 +0000 http://tomorrowstransactions.com/?p=2905 The Target breach will encourage the US to adopt EMV, but it’s not a magic bullet. However, the breach may have wider implications for the future of retail transactions than EMV adoption. The fun end-of-year card fraud story was, of course, the infamous Target breach, an epic-scale hack that obtained millions of card details. Nov. […]

The post Target breach may have consequences beyond EMV appeared first on Tomorrow's Transactions.

]]>
Dgwb blog white border

The Target breach will encourage the US to adopt EMV, but it’s not a magic bullet. However, the breach may have wider implications for the future of retail transactions than EMV adoption.

The fun end-of-year card fraud story was, of course, the infamous Target breach, an epic-scale hack that obtained millions of card details.

Nov. 27-Dec. 15: A data hack at U.S. Target stores exposes as many as 40 million credit- and debit-card customers to potential fraud.

[From Target’s Data-Breach Timeline - Corporate Intelligence - WSJ]

The scale of the hack is unusual, but it also noteworthy because of the mechanism employed. If media reports are accurate, then it appear that the retailer’s systems were thoroughly penetrated.

The thieves breached the point-of-sale system (POS) and stole customer magstripe data, including names, credit or debit card numbers, expiration dates and everything else needed to make counterfeit cards.

[From Target Admits Massive Credit Card Breach; 40 Million Affected | Threat Level | Wired.com]

Everything else needed to make counterfeit magnetic stripe cards, to be more specific. But we’ll come back to this later on. One notable feature of the breach was that the POS system was compromised so thoroughly that all of the data that the POS handles, including the PINs, were stolen. In the case of the PINs, however, this is unlikely to help the thieves terribly much.

While we previously shared that encrypted data was obtained, this morning through additional forensics work we were able to confirm that strongly encrypted PIN data was removed. We remain confident that PIN numbers are safe and secure. The PIN information was fully encrypted at the keypad, remained encrypted within our system, and remained encrypted when it was removed from our systems.

[From Target Data Security Media Update #4 | Target Corporate]

In an odd way, I found the reports of what had happened to the card details after they had been stolen as fascinating as the attack itself, because these reports tell us a lot about the shape and nature of the underground market for card details. Brian Krebs has a series of wonderful stories about the breach over at his “Krebs on Security” blog, which I urge you to read, and which has astonishingly interesting observations on that market. Why, for example, is there a discrepancy in the cost of domestic and international cards? 

Hundreds of thousands of cards issued by non-U.S. banks that were used at Target across the United States during the retailer’s 19-day data breach. It’s not clear how quickly the non-U.S. cards are selling, but they seem to be fetching a much higher price than those issued by U.S. banks.

[From Krebs on Security]

I guess it might be that international cards have chips on them but that fraud systems have been told to allow stripe transactions but only in the US. Personally, I would prefer my issuers to disallow stipe (and online) transactions for all of my cards unless I specifically tell them others. My Barclays debit card, to give an obvious example, has a stripe on it and is embossed 1950s style. I would prefer it to have neither. But back to the story. Issuing banks have responded in different ways. Some have placed limits on compromised card activity, some have invited customers to ask for new cards if they are worried and so and so forth.

Many banks are taking more of a wait-and-see approach, asking customers to monitor their accounts, and using the banks’ fraud analytics software to monitor transactions for signs of foul play, but not rushing to close accounts and reissue cards.

[From Target Breach Raises Questions About Security, Account Limits and EMV - American Banker Article]

Sales at Target stores are supposedly down slightly but I don’t know enough about the figures to know whether this is due to the breach or not. What our clients are more interested in, I’m sure, is looking at what will be the longer term impact of the Target breach. Gartner analyst Avivah Litan, who I always pay attention to, puts it simply:

it’s time for the U.S. card industry to move to chip/smart cards and stop expecting retailers to patch an insecure payment card system.

[From What can we learn from the Target Breach]

I’m sure everyone agrees that this is the way forward. When Avivah says “smart cards” she means payment cards that use the EMV (“Europay-MasterCard-Visa”) standard  that it used almost everywhere else in the entire world. So let’s look at how exactly EMV might have helped. In an EMV scheme, it doesn’t matter if you capture all of the card details that are sent unencrypted from the card to the terminal. That is because you cannot use these details to create either a counterfeit magnetic stripe card (because the ICVV given up by the card chip is not the same as the CVV on the magnetic stripe) or a clone chip card (because you do not have access to the security keys inside the chip – these are used to create the digital signatures passed in the transaction). What’s more, you shouldn’t be able to use those details in a CNP transaction either, because they do not include the CVV2 on the back of the card. However, some retailers — and it is up to them because it is at their own risk — do accept cards for online payments without checking the CVV2 (or even, in some cases, the AVS). If you were able to capture the unencrypted PIN (PIN encryption is not mandatory in EMV) it sill wouldn’t help you unless you could steal the physical card as well.

So what does this all mean?

Well, the Target hack has given us the opportunity to look again at how EMV might help and, just as importantly, how it might not help. Since it looks as if the US Senate might be discussing the subject in the future, I thought it might be friendly and helpful for CHYP USA to provide some background for US lawmakers…

Three US senators have proposed to the Senate Banking Committee that they hold hearings on the issue of customer data security following the Target data breach. They specifically seek to address the adoption of EMV in the hearings.

[From US Senators seeking to publicise the EMV debate in US following Target breach | The Bankwatch]

The most important point is that EMV isn’t a magic bullet to fix card fraud and it would be a mistake to try and formulate an industry business case based on that alone. However, if you look at the costs across all of the stakeholders, it seems to me that on balance it still makes sense that the US to proceed with its EMV migration even though everything that has been said about alternative payment technologies is simultaneously true.

Yes, EMV was designed for the offline world of 1994 even though mobile phones and the Internet already existed.

Yes, it is entirely possible to start designing a second-generation “son of EMV” that comes off the drawing board in a world of ubiquitous, pervasive interconnection and industry-wide initiatives in identity and authentication.

Yes, I don’t doubt for a moment that it is possible to make such a son-of-EMV even more secure than EMV is today and, what’s more, make it work in online environments.

Having said all that, we are where we are. Most non-cash payments at retail point of sale are card, and will stay card across the next post replacement cycle. Since all of the bits and pieces that banks need to buy, retailers need to buy, processors need to buy etc are all readily available, along with the expertise needed to make them work cost-effectively, it’s the easiest choice. US cards will them work fine overseas, overseas cards will then work fine in the US and without the pantomime of signing for transactions.

Signed and Sealed

If we want to look at how EMV will change the fraud situation in the US, then the obvious place to look is in France. France has had chip cards longer than any other country and it resembles the US in an important way: it has inefficient payment system that still uses checks. So now that we have had many years to observe the dynamics around the transition to smart cards in retail purchases, what have we learned? Well, here are the basic facts (“French card fraud continues upward trend .

  • Card present fraud at retail point-of-sale is about two basis points (2bp).
  • Card not present fraud on the Internet is about 299bp (ie, two orders of magnitude worse).
  • Mail-order/telephone order fraud is about 338bp.

Here in the UK the criminals have responded to the adoption of EMV in two ways: by inventing ever-more elaborate scams to get hold of cards and PINs and by stepping up their efforts on the internet. Right now, they are doing rather well, as fraud is up again this year. This is why I stress that EMV is not a magic bullet and it will not eliminate fraud.

So what we see in the UK and France is exactly what we would expect to see given what we know about EMV. It leads to a major reduction in card-present (CP) fraud, partly because you cannot counterfeit the chips used in the smart cards and partly because of the off-line PIN verification. It does nothing to help with card-not-present (CNP) fraud and it does nothing to help with mail-order/telephone order (MOTO) fraud. It could, but it doesn’t.

Most banks in Europe decided not to use EMV is the basis for their 3-D Secure (3DS) authentication, so although there are ways to use EMV cards to combat both both CNP and MOTO fraud, they are not used. I can give you a UK example. My bank is Barclays and they sent me a little calculator like device called a “PIN sentry” several years ago. This implements a standard for using offline PIN to provide one-off numbers for authentication (using the MasterCard CAP and Visa DPA protocols). In fact, since both of my sons bank at Barclays as well we have more than one of these devices lying around the house. When I want to log into online banking, I take my debit card and pick up any one of the PIN sentries, insert the card and punch in my PIN. The device displays a one-off number and I type this in to the Barclays web site to log in. It’s easy and I like it.

PIN Sentry

But if I were to use my debit card to buy something online (which is hypothetical, since I would never do this) then I have to remember a 3DS password. It would be much easier to use the PIN Sentry again. The PIN Sentry is a simple and cheap device because all of the cryptography is inside the EMV chip. I did suggest doing this inside a standardised identity framework a few years ago (we called this “4D Secure”, but it never took off!). So, for various reasons, EMV cards were not used to attack online fraud and now, given the trajectory of mobile transactions, will never be. I say this because it seems obvious that the mobile phone will become the authentication device for transactions across all channels. In the future will be using my mobile to pay in Waitrose and at John Lewis’ web site, and as a consumer i won’t know or care that the protocols used a mundane and virtual POS are different.

One more point.

I see that there has been a traditional American response to the breach.

Just days after acknowledging a massive hack of customer credit card data, Target is facing at least two dozen lawsuits. And more could be on the way.

[From Lawsuits piling up on Target over hack - Dec. 23, 2013]

I suspect that there may well be another consequence of the Target breach, once the costs reach a few billion or so. Since class action lawyers are more effective agents of change than consultants or, indeed, the US Senators are, this might be the tipping point for a major change in the use of new retail transaction technologies in the US. Yes, it will provide a kick to implement EMV and transfer liability back to the card issuers, but it may also provide a kick to reduce the dependence on “traditional” card products entirely. Note that the Target hack included the theft of Target’s own Red decoupled debit card details. These are of no use to the criminals because they can only be used in Target. They are, to use the jargon, “tokens”. They point the way forward: the major international payments schemes are involved in a huge effort to move to tokenisation for mobile and online transactions. But the payment schemes will not be the only organisations to have noticed this dynamic as the consequences of the breach unfold. Indeed, observers are already (correctly, in my opinion) noting that retailers will be exploring other possibilities too.

Retailers have a unique opportunity to lower payment liability by shifting consumers to card and mobile ach decoupled debit.

[From The Target Breach: what it means to card and mobile ACH payment: | The Competitor's Code]

I wonder if this may be the long-term legacy of the breach? If the issuers don’t get their act together and accelerate EMV deployment, then the retailers will be tempted to move away from the traditional card schemes altogether and use their own tokens, either via their decoupled debit cards or via their own apps (using HCE/BLE so that standard terminal estate can be used) to both reduce that payment liability and reduce costs.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Target breach may have consequences beyond EMV appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2014/01/target-breach-may-have-consequences-beyond-emv/feed/ 0
The “hot five” retail transaction technologies for our clients in 2014 http://tomorrowstransactions.com/2014/01/the-hot-five-retail-transaction-technologies-for-our-clients-in-2014/ http://tomorrowstransactions.com/2014/01/the-hot-five-retail-transaction-technologies-for-our-clients-in-2014/#comments Thu, 02 Jan 2014 16:03:54 +0000 http://tomorrowstransactions.com/?p=2902 It’s traditional in blogs of this kind to have a go at a “top N” set of predictions for the coming year, so I’ll give it a bash and have a go at what I think will be the “hot five” secure electronic transaction technologies that will have our clients updating their roadmaps in 2014. […]

The post The “hot five” retail transaction technologies for our clients in 2014 appeared first on Tomorrow's Transactions.

]]>
Dgwb blog white border

It’s traditional in blogs of this kind to have a go at a “top N” set of predictions for the coming year, so I’ll give it a bash and have a go at what I think will be the “hot five” secure electronic transaction technologies that will have our clients updating their roadmaps in 2014.

First, some background as to why I started thinking about this topic and ended up with my shortlist of five. A couple of weeks back, as Richard Watson mentioned on his excellent “What’s Next” blog, we had a bit of a catch up, talking about the major trends in and around the technologies, businesses and social memes that we are interested in.

Or it could it be the rather relaxed lunch I had with Dave Birch talking about Bitcoin, identity and steak.

[From Just stuff | What's Next: Top Trends]

We did have a relaxed lunch, it’s true. Richard is a futurist, and the author of The Future Files, which he kindly came and talked about at our Forum a couple of years ago and in a rather spooky coincidence he emailed me about something while I actually had a copy of his book on my desk! I had been looking up something for a book I am writing. But back to lunch.

Untitled

I’m going to be helping Richard update the financial services route on his roadmap (which is what he’s looking at in the restaurant in the picture) and we were discussing the long term significance of Bitcoin and the Bitcoin family of technologies. Richard set me thinking about ways to provide useful input to his roadmap. In our internal roadmap, the one we use to support clients in developing their product and service roadmaps, we divide technology evolution into “now” (1-2 years), “soon” (3-5 years) and “later” (5+ years). One way of using this roadmap is to see business as a way of connecting the technology push and the social pull to deliver sustainable value. With this framing, I looked at the technologies that are reaching the mass market now and that gave me a short list. Then I went and asked around a few of our guys. Since they are, by and large, out working for clients (who are some of the biggest and most important players in the retail transactions space) and since, by and large, they are working on projects around exploring the latest technologies, they are a pretty good barometer.

So, by combining projects that we are working on now with the likely business impact of the technologies, taking away the projects that are confidential (!) and focusing on technologies likely to be of interest to blog readers, I got my “hot five” technologies for 2014! I’m genuinely interested in your feedback on my picks, which are…

Proximity and vicinity interfaces. The arrival of Host Card Emulation (HCE) and Bluetooth Low Energy (BLE) will open up mobile transactions, taking them away from (expensive) secure, controlled infrastructure and out into the open. While security and risk analysis skills will be crucial to delivering operational systems, I think that the overall mobile security environment means that there will be a revolution in app-centric retail. I can well imagine using NFC to “tap in” to Waitrose before being guided around by BLE and then a “tap out” to close and pay. See if you can spot the BLE beacon in this photograph of our CTO hard at work down at CHYP End…

Untitled

Tokenisation. This made the front pages later in the year when the major payment schemes made it a priority and I suppose it was given an end-of-year boost because of the Target breach. I’ll blog about it soon, but one of the key points in the coverage to date is that Target’s own tokenised product was safe from the hackers whereas the untokenised general-purpose card numbers were not. This reinforced the schemes’ determination to make a serious dent in online fraud by moving away from cardholder PANs as the key to payments.

Visa, MasterCard and American Express have announced a proposed framework for a new global standard to enhance the security of digital payments and simplify the purchasing experience when shopping on a mobile phone, tablet, personal computer or other smart device.

[From MasterCard, Visa and American Express Propose New Global Standard to Make Online and Mobile Shopping Simpler and Safer]

This has been reported as being a technology initiative that undermines NFC, whereas I tend to think that it dovetails with it.

My two cents is that this finally puts the stake in the heart of NFC by those who started the whole thing in the first place.

[From 2013 - Networks, The Cloud And Many Open Questions | PYMNTS.com®]

As I said at the time, I’m not sure I agree with Karen about this because there is a positive synergy between tokenisation and proximity interfaces that is mutually beneficial. Tokens don’t need the same kind of security that card details do so they can thrive in the HCE/BLE-driven app.

Recognition. We’ve been using the world “recognition” to mean the combination of good enough identification and good enough authentication to make commerce possible. The mobile phone has an obvious and important role to play here, to the point where downstream tokenisation will shift to recognition (in other words, it will be the customer’s identity that is used to make a payment). I continue to think that making privacy part of the consumer proposition here will be a good strategy. It also seems to me that the tools for creating recognition infrastructure at reasonable cost are becoming standardised (FIDO, OpenIDConnect, OIX, that sort of thing) so organisations will want to use them on a large scale. HCE/BLE give us the convenient interfaces, tokenisation protects privacy and customers benefit from a personalised experience.

2014 will be the year in which you walk into a store and it “knows you” and customizes your visit.

[From Predictions for 2014: Computing Technologies In The Age Of The Customer | Forrester Research]

Small Data. With all the talk about Big Data, I think there is an opportunity for “small data” to make a difference. Giving customers their own data and the tools to manage it seems to me to be a way to balance individual and organisational wants. The relevance of this to payments and identity plays is that the “wallet” of whatever form becomes a place to store and manage this small data — consumer receipts and warranties, spending history, loyalty and so on — as well as the tools that consumers can use to manage that data to their benefit. I saw a nice comment about this in response to Robert X. Cringley’s call for 2014 predictions:

2014 could benefit from a renewed focus on delivering value by sorting out the small data first.

[From I, Cringely Call for 2014 predictions! - I, Cringely]

APIs. The glue that holds all of this together. There is no doubt about the crucial role of APIs in the future business architecture, but what will change in 2014 is that APIs have become a management issue, not a technology issue. I’m fascinated by the nature of API-based competition, but for our clients (who tend to be at the larger end of the scale) the fact that they can start to compete on the basis of APIs is problematic because they have no experience of competing in that way. It’s been a while since the Credit Agricole app store (the CAStore) became the first post-modern (!)bank app and the floodgates haven’t opened yet, but when Consult Hyperion studied financial services APIs for one of our international clients earlier in the year one of the clear conclusions of the work was that APIs will increasing shape the products and services that are delivered through them.

The CAStore uses an open API, or application programming interface, in which technology is shared freely with outside developers so that it can be integrated into new programs, without compromising compatibility.

[From Open API for Bank Apps: Can Credit Agricole s Model Work Here? - American Banker Magazine Article]

When we are helping clients to put together their technology roadmaps we try to find ways for business to link the push of new technology with the pull of social change to identify new products and services in the secure electronic transactions world. I think these five technologies form the basis for a consistent narrative for retail transactions in response to real customer requirements for convenience, security and value. I can’t wait for the next version of my Waitrose app!

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post The “hot five” retail transaction technologies for our clients in 2014 appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2014/01/the-hot-five-retail-transaction-technologies-for-our-clients-in-2014/feed/ 3