Tomorrow's Transactions » People http://tomorrowstransactions.com Thought leadership from Consult Hyperion Fri, 18 Jul 2014 06:22:13 +0000 en-US hourly 1 http://wordpress.org/?v=3.9.1 What about a financial services passport? http://tomorrowstransactions.com/2014/07/what-about-a-financial-services-passport/ http://tomorrowstransactions.com/2014/07/what-about-a-financial-services-passport/#respond Wed, 09 Jul 2014 19:53:08 +0000 http://tomorrowstransactions.com/?p=4510 The problems around KYC for new financial services, especially for new entrants, might be mitigated by the introduction of a financier services passport based on modern technology and not stupid bits of paper. There was a great story on BBC Radio recently. It caught my attention because it demonstrated faults with our useless and outdated […]

The post What about a financial services passport? appeared first on Tomorrow's Transactions.

]]>
Dgwb blog white border

The problems around KYC for new financial services, especially for new entrants, might be mitigated by the introduction of a financier services passport based on modern technology and not stupid bits of paper.

There was a great story on BBC Radio recently. It caught my attention because it demonstrated faults with our useless and outdated cheque payments system and our useless and outdated identity infrastructure at the same time.

A listener posted a cheque for £36,000 to his bank. It was stolen and paid in by someone else to an account in approximately his name. £20,000 was withdrawn. Barclays, his bank, have agreed to refund him only the balance of £16,000. What are his rights? And will the new cheque imaging service be any safer and quicker?

[From BBC Radio 4 - Money Box, Wonga woes]

During the episode, the bank is quoted as saying that their cashiers are not experts in identification. Indeed, They are not. Which is why the business case for KYC and AML and ATF stuff is so confused. What is the point of asking people to present documents that cannot possibly be verified? How is the poor chap at the bank counter expected to know whether my Portugese fishing licence is still valid or not? Clearly the fraudster had to present some documents to open the account.

If you’re applying for a Barclays Bank Account or a Premier Current Account you’ll need to show us 2 valid and original documents from the list below -  one from the proof of ID list and the other to give proof of your current UK address. The same document cannot be used to verify both your identity and your address.

[From Identification for bank accounts]

Clearly, the documents presented were fraudulent. I’m not picking on Barclays, obviously. This is a general problem across jurisdictions and banks. While it is complicated and expensive and annoying for legitimate customers and business to comply with stupid KYC requirements, it is apparently trivial for the criminals to do so.

There is no point having an identity infrastructure where it is impossible to verify identity. On the other hand, an infrastructure that means identity is verified at every turn is invasive and open to abuse. We have a system that delivers neither, and costs a fortune.

KYC Exchange estimates that whereas a KYC request might take 30 – 50 days to turn around using standard industry measures, its own system can do the same work in five minutes. The time saved for a bank initiator is estimated at approximately 90%, while the receiving bank saves around 40-50%, according to von Hänisch.

[From Cost of KYC too high says Swiss start up » Banking Technology]

Maybe KYC Exchange could then issue a Financial Service Passport of some kind? There’s a thought. I’ve been with Barclays for 37 years: perhaps they could provide me with some sort of app on my smartphone that I could use to present KYC credentials when I want to take out insurance or get a mortgage or rent a house or anything. This is the sort of thing that I think we will be discussing at techUK next Monday, where Ian Jenkins of Deloitte and I will be chairing a discussion around the concept:

A ‘financial services passport’ refers to an aspirational digital identity, issued by UK financial services providers, and mutually recognised across the financial services industry. Such an interoperable digital identity could be utilised to correctly identify and authenticate end-users with appropriate security in a wide variety of circumstances and across a wide variety of channels.

[From Workshop: Towards a Financial Services Passport]

Look forward to seeing you there.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post What about a financial services passport? appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2014/07/what-about-a-financial-services-passport/feed/ 0
Payment system regulation as barrier to payment system innovation http://tomorrowstransactions.com/2014/06/payment-system-regulation-as-barrier-to-payment-system-innovation-2/ http://tomorrowstransactions.com/2014/06/payment-system-regulation-as-barrier-to-payment-system-innovation-2/#respond Mon, 16 Jun 2014 15:01:17 +0000 http://tomorrowstransactions.com/?p=4485 If we want more innovation, we need more competition, not more regulation. There was a good article back in the September “Financial World” magazine arguing that transparency is a key to regaining confidence in the banking system. I agree strongly, and I’m not the only one. More transparent record keeping would allow law enforcement to […]

The post Payment system regulation as barrier to payment system innovation appeared first on Tomorrow's Transactions.

]]>
Dgwb blog white border

If we want more innovation, we need more competition, not more regulation.

There was a good article back in the September “Financial World” magazine arguing that transparency is a key to regaining confidence in the banking system. I agree strongly, and I’m not the only one.

More transparent record keeping would allow law enforcement to trace the transfer of funds and identify those responsible for the illicit use or theft of virtual currency.

[From Virtual Currencies, Real Theft - Javelin Strategy & Research Blog]

Indeed it would, and some might argue that that transparency be extended to legacy infrastructure as well. (It’s not really the topic of this post but remember than transparency need not subvert privacy. You could have pseudonymous dark pools but force the release of linked identities given a warrant, for example.) If, however, transparency is taken to mean thorough KYC/AML/ATF procedures (henceforth known as CDD, or customer due diligence) that identify all participants to a transaction to all observers, then it will force criminals, terrorists and corrupt politicians to abandon electronic means of exchange and go back to cash. If that happens, then we are all worse off. Having some traceability is better than having none at all, as I’ve argued before. And it’s not as if having rigorous CDD solves the problem.

Worse still, the increased cost associated with a tougher stance on KYC does nothing to make the system any more secure, and may in fact drive up risk rather than reduce it.

[From Cost of KYC too high says Swiss start up » Banking Technology]

I suppose you could argue that what is driving the players at the moment is not risk but liability. So long as they can shift the liability onto someone else, no-one really cares who you are. The system is broken.

The two set up 68 accounts in 19 different cities using 24 aliases to handle the transfer of funds and sent the bulk of the money to individuals in Nigeria, who set up the operation. Money was also wired to addresses in the UK, Ecuador, India, the United Arab Emirates, and the US, none of which has been recovered.

[From Mother/daughter team jailed for million-dollar internet dating scam • The Register]

Hold on. 68 accounts using 24 aliases? What was the point of the billions of dollars spent on KYC, AML and ATF? And why am I going on about this anyway? Well, in her keynote at Payments Innovation 2014, Mary Starks (the acting MD for the UK’s new Payment System Regulator) said that on the whole regulators “don’t do innovation”. I was on the panel with her, so I made what I think was a reasonable point that the best regulatory approach to innovation is competition, and that a focus on reducing the barriers to entry to payments markets that do not involve systemic risk is probably sufficient. We don’t need to imagine what people might come up with, we just want to make it easy for them to do so.

When it came to the discussion that followed, I used CDD as an example of such a barrier. The costs and complexity of CDD can make it very difficult for new entrants, especially those dealing with low-value payments, the excluded and specialist niches to get off the ground. One of the reasons for this is that there is no infrastructure for them to plug in to, so everyone has to build everything from scratch.

Surely all of this dialogue about passports and utility bills, declarations and signatories and KYC and AML is pushing a demand for a new digital infrastructure to cure all of this mess.

[From Digital identities demand a digital infrastructure | Banking View]

Karen Wendel from Identrust talked about the infrastructural approach in her presentation as well, and this all links to the discussions about the idea of a financial service passport (or a “pay name”) at techUK last year. I really think that the idea of pseudonymous, strongly-authenticated CDD-inside identities is an idea whose time has come. I should be able to participate in a transaction as John Doe, provided that I can prove that someone (e.g., my bank) knows who John Doe actually is and that is is someone who has been approved after CDD. You don’t need to know who I am to do business with me, so long as you know that someone knows who I am.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Payment system regulation as barrier to payment system innovation appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2014/06/payment-system-regulation-as-barrier-to-payment-system-innovation-2/feed/ 0
Identity, so I hear, is the new money http://tomorrowstransactions.com/2014/06/identity-so-i-hear-is-the-new-money/ http://tomorrowstransactions.com/2014/06/identity-so-i-hear-is-the-new-money/#comments Thu, 12 Jun 2014 10:12:57 +0000 http://tomorrowstransactions.com/?p=4483 The CSFI roundtable on my book “identity is the new money” left me utterly depressed. Every single book sold was sold for cash. I will never recover from the embarrassment and public humiliation. Still, at least they sold some. The wonderful people at the Centre for the Study of Financial Innovation (CSFI) in London did […]

The post Identity, so I hear, is the new money appeared first on Tomorrow's Transactions.

]]>
Dgwb blog white border

The CSFI roundtable on my book “identity is the new money” left me utterly depressed. Every single book sold was sold for cash. I will never recover from the embarrassment and public humiliation. Still, at least they sold some.

The wonderful people at the Centre for the Study of Financial Innovation (CSFI) in London did me the great honour of holding one of their super lunchtime roundtable meetings around the publication of my new book, “Identity is the New Money“. I gave a short talk on a couple of themes on the topic, starting by exploring Jack Weatherford’s meme about the future of money being more like the money of the neolithic past than the money of today and finishing with the three suggestions for UK policy makers that I finished the book with — and trying to justify them to a financial services audience which, judging from some of the questions, I didn’t do too badly at.

  1. We need to begin by finding a way to make the construction and use of a new infrastructure for identity a national project of significance. We need to find something that can provide the “parasitic vitality” for a new identity paradigms. We already know that in the UK, as well as in the USA, Australia and many other countries, there is no appetite for any kind of national identity scheme. But there may be an alternative formulation that helps all stakeholders: individuals, business, governments, law enforcement and everyone else. A National Entitlement Scheme. Long before the late and unlamented national identity scheme in the UK, there was (back in 2002) the original proposal for an entitlement card. This should be revisited in the light of modern technology. We can use the modern privacy-enhancing infrastructure to decouple these entitlements from the underlying identities and resolve the paradox of more security and privacy.
  2. One very specific use of the new infrastructure should be to greatly reduce the cost and complexity of executing transactions in the UK by explicitly recognising that reputation will be the basis of trust and therefore transaction costs. The regulators should therefore set in motion plans for a Financial Services Passport. This would use the same infrastructure as the National Entitlement Scheme but with a sector-specific profile. The UK’s IT industry trade association, TechUK, has a working group looking at just this idea already and together with colleagues at Consult Hyperion we have put forward the same suggestion to the Federal Reserve in response to their November 2013 consultation on the evolution of the US Payments System. Since the financial services passport would be using the same infrastructure as the entitlesment scheme, one might expect the costs to be manageable and then cost savings to UK plc significant.
  3. Finally, I should like to make a rather technical and boring plea to the relevant authorities to make the UK’s National Payments Plan adopt an explicit target for reducing the total social cost of payments in the UK. This will inevitably mean coming up with tactics to reduce cash (and cheque) usage in the UK. This target will be made significantly easier to attain using the Financial Services Passport to lower the barriers to entry for new products and services, increasing competition in the sector (especially with respect to the financially-excluded groups who are too expensive to serve using existing infrastructure).

These are straightforward calls to action and I trust that you have been persuaded to support them!

CSFI Roundtable

I won’t report the excellent and wide-ranging roundtable discussion that followed (which was held under the Chatham House rule) except to note that David Rennie — from the Identity Assurance Programme (IDA) in the Government Digital Service (GDS) — was kind enough to join me at the roundtable and talk about the government’s current initiatives and how they support the idea of shifting toward entitlement as the basis for transactional interaction.

As is the tradition at such events, my publishers were kind enough to show up in person with a job lot of the heroic tome (plus some other titles in the Perspectives series) to knock out at the back.

Untitled

Despite accepting Bitcoin, Pingit, Paym and PayPal, I’m sorry to say that every single person who bought a copy paid cash. I will never recover from the shame.

Untitled

If we can’t persuade the nation’s financial elite to use mobile payments, who can we persuade?

P.S. Available at all good bookstores and some of the bad ones too. Kindle version now available as well. For our US readers, you can buy right now online with free shipping to the US at http://bit.ly/1pdzFN0.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Identity, so I hear, is the new money appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2014/06/identity-so-i-hear-is-the-new-money/feed/ 1
Identity might work better bottom up http://tomorrowstransactions.com/2014/06/identity-might-work-better-bottom-up/ http://tomorrowstransactions.com/2014/06/identity-might-work-better-bottom-up/#comments Mon, 09 Jun 2014 11:06:29 +0000 http://tomorrowstransactions.com/?p=4480 One way to help people obtain financial capital is by helping them to build up social capital. Forum friend Kosta Peric from the Bill and Melinda Gates Foundation (BMGF) Financial Services for the Poor programme recently picked out four technologies as being of particular interest right now. He pointed us to: bitcoin-inspired distributed systems, open […]

The post Identity might work better bottom up appeared first on Tomorrow's Transactions.

]]>
Dgwb blog white border

One way to help people obtain financial capital is by helping them to build up social capital.

Forum friend Kosta Peric from the Bill and Melinda Gates Foundation (BMGF) Financial Services for the Poor programme recently picked out four technologies as being of particular interest right now. He pointed us to:

  • bitcoin-inspired distributed systems,
  • open APIs (application programming interface) as a new way to consume business services on the internet,
  • crowd-sourced identity schemes, and
  • open source hardware and applications.

[From Four Technologies That Will Revolutionize Financial Services | copernicc]

I’m sure we’d all agree with his views on blockchain technologies and the “Amazonisation” of financial services organisation through APIs (I don’t know enough about open-sourced hardware to comment) but I think his point about crowd-sourced identity is especially interesting, as it points to a shift in the way that identities are created, managed and used. And, since I’m rather obsessed with identity right now (as our clients should be and, in some cases, are too) I thought I’d take the time to explain why I agree with him.

First, look at what the conventional, top-down notion of identity means. It means someone (the government, generally speaking) must find some way to assign an identity to everyone who needs one, record who those identities have been assigned to, and check that when the identities are presented they are genuine.

It is almost certain that the government is having difficulties establishing who is a genuine citizen purely on the basis of identification papers produced by the existing system. Some of the illegal immigrants caught in the current security swoop have Kenyan ID cards and passports but their details are not in the national database.

It has been claimed that immigration and provincial administration officials at all levels have enriched themselves by selling these sensitive documents while compromising national security.

[From KENYA: Kenyans to apply for digital identity cards, says Ruto]

There are problems with this top down approach. Apart from being expensive, it is also vulnerable. One a false identity has been entered into the system, it is no longer false (if you see what I mean). As a consequence, obtaining such an identity becomes an essential precursor to crime as well as legitimate use and therefore the identities are obtained by all sorts of people who are not supposed to have them and the system is subverted. Managing and protecting the database at the heart of this scheme is complicated and difficult. In a great many emerging markets, in particular, the national identity scheme is soon degraded: sometimes because of corruption, sometimes because of carelessness, sometimes because of errors in the concept and design. This is precisely what has happened with the Aadhar scheme in India.

What was supposed to be a unique identification number providing identification and access to a host of government benefits and services, ‘Aadhaar’ has almost unvaryingly been extended to anybody residing within Indian territories. Almost anyone, be it Indian or an illegal immigrant can get an Aadhaar Card made without any proof of identity. More importantly, they get a numbered identity.

[From Sting reveals Aadhaar documents forged for Nepal, Bangladesh citizens - IBNLive]

So how does the alternative, crowdsourced version of identity take us forward? Well, if national identity schemes don’t provide “real” security then why bother with them? Save the money. At a basic level crowdsourced identity means asking everyone who you are rather asking anyone (e.g., the government) who you are. Whereas we are used to the idea of identity as something that is granted to us by a third party, such as the government or a bank, and the idea of an identity based on reputation that grows up through our networks and long-term relationships seems rather different.

Compare the two kinds of identity and their functionality in practice. Crowdsourced identity may seem a poor substitute for national identity at first glance, but it seems to me that Kosta is onto something here for two specific reasons that I have touched on before. The first is that this kind of reputational identity is actually better than conventional national identity because it is much harder to forge or counterfeit. A good friend of mine told me a story about an industry event he attended recently where he ran into a chap late at night when he was going back to his hotel. The guy was in the hotel lobby and recognised my friend as he had been a speaker at the event. The man explained that he had been tricked by a woman in a bar into following her back to hotel room where he had been drugged and robbed. He had no money and was too embarrassed to call his wife and asked if my friend might loan him some money so that he could get home and would report his wallet lost on the train or something. My friend had never met the man before but asked him his name and who he worked for and then looked him up on LinkedIn. Having established that not only did the fellow have a full LinkedIn profile but was actually connected to my friend via several different people, my friend loaned him the money which was, of course, gratefully returned a couple of days later. Now imagine that the unfortunate chap had instead presented my friend with his Portuguese fishing licence: how would my friend evaluate that and assess the strangers plausibility from that official document?

The second reason is that these crowdsourced identities may well be far cheaper to establish and this is especially true, and especially valuable, in the developing world where official infrastructure may be unreliable at best and non-existent at worst. Here the particular combination of mobile phones and social networks is especially powerful, because mobile phones tend to deliver not only unique identity but transactional history to go with it and this can be linked through social networking in powerful ways. You might have listened to the podcast I recorded earlier this year with Shivani Siroya and and heard a very good example of this where the transactional histories from mobile payment accounts are slurped up by organisations who provide alternatives to conventional kind of credit reference agencies that we are used to in the developed world.

Shivani Siroya is currently the CEO and Founder of InVenture. InVenture facilitates financial access by providing simple mobile accounting and credit scoring tools for offline and unbanked individuals, the subject of this podcast.

[From Media - Consult Hyperion]

Taken together, I think these provide compelling support to Kosta’s intuition and it strikes a that, to use Jaron Lanier’s term in “Who owns the future?”, the “economic avatars” that arise at the intersection of the mobile phone and the social network may well prove to be more useful to a great majority of the world’s population than their “official” identities even if they have them and indispensable to them if they do not. And, by the way, if you regard the whole idea of giving people credit on the basis of social capital as ridiculous and fanciful, I guess you didn’t see this:

[Bogota] where Lenddo introduced a “social network” Visa card to 100,000 of its customers yesterday afternoon. By 4:00 p.m. today in New York, where the online lender for developing countries is based, more than 1,000 Colombians had applied for the card. Lenddo CEO and co-founder Jeff Stewart calls it the first time ever, anywhere, that approval for a credit card is based on applicants’ reputations on Facebook, Google, LinkedIn, and Twitter.

[From This Emerging Markets Credit Card Is Backed by Facebook Friends » Techonomy]

Identity is the new money, as they say. Well, as I say.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Identity might work better bottom up appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2014/06/identity-might-work-better-bottom-up/feed/ 3
Payment system regulation as barrier to payment system innovation http://tomorrowstransactions.com/2014/05/payment-system-regulation-as-barrier-to-payment-system-innovation/ http://tomorrowstransactions.com/2014/05/payment-system-regulation-as-barrier-to-payment-system-innovation/#comments Fri, 30 May 2014 18:43:54 +0000 http://tomorrowstransactions.com/?p=4457 The new payment systems regulator is tasked with increasing innovation. This means increasing competition, which means reducing barriers to entry. There was a good article back in the September “Financial World” magazine arguing that transparency is a key to regaining confidence in the banking system. I agree strongly, and I’m not the only one. More […]

The post Payment system regulation as barrier to payment system innovation appeared first on Tomorrow's Transactions.

]]>
Dgwb blog white border

The new payment systems regulator is tasked with increasing innovation. This means increasing competition, which means reducing barriers to entry.

There was a good article back in the September “Financial World” magazine arguing that transparency is a key to regaining confidence in the banking system. I agree strongly, and I’m not the only one.

More transparent record keeping would allow law enforcement to trace the transfer of funds and identify those responsible for the illicit use or theft of virtual currency.

[From Virtual Currencies, Real Theft - Javelin Strategy & Research Blog]

Indeed it would, and some might argue that that transparency be extended to legacy infrastructure as well. (It’s not really the topic of this post but remember than transparency need not subvert privacy. You could have pseudonymous dark pools but force the release of linked identities given a warrant, for example.) If, however, transparency is taken to mean thorough KYC/AML/ATF procedures (henceforth known as CDD, or customer due diligence) that identify all participants to a transaction to all observers, then it will force criminals, terrorists and corrupt politicians to abandon electronic means of exchange and go back to cash. If that happens, then we are all worse off. Having some traceability is better than having none at all, as I’ve argued before. And it’s not as if having rigorous CDD solves the problem.

Worse still, the increased cost associated with a tougher stance on KYC does nothing to make the system any more secure, and may in fact drive up risk rather than reduce it.

[From Cost of KYC too high says Swiss start up » Banking Technology]

I suppose you could argue that what is driving the players at the moment is not risk but liability. So long as they can shift the liability onto someone else, no-one really cares who you are. The system is broken.

The two set up 68 accounts in 19 different cities using 24 aliases to handle the transfer of funds and sent the bulk of the money to individuals in Nigeria, who set up the operation. Money was also wired to addresses in the UK, Ecuador, India, the United Arab Emirates, and the US, none of which has been recovered.

[From Mother/daughter team jailed for million-dollar internet dating scam • The Register]

Hold on. 68 accounts using 24 aliases? What was the point of the billions of dollars spent on KYC, AML and ATF? And why am I going on about this anyway? Well, in her keynote at Payments Innovation 2014, Mary Starks (the acting MD for the UK’s new Payment System Regulator) said that on the whole regulators “don’t do innovation”. I was on the panel with her, so I made what I think was a reasonable point that the best regulatory approach to innovation is competition, and that a focus on reducing the barriers to entry to payments markets that do not involve systemic risk is probably sufficient. We don’t need to imagine what people might come up with, we just want to make it easy for them to do so.

When it came to the discussion that followed, I used CDD as an example of such a barrier. The costs and complexity of CDD can make it very difficult for new entrants, especially those dealing with low-value payments, the excluded and specialist niches to get off the ground. One of the reasons for this is that there is no infrastructure for them to plug in to, so everyone has to build everything from scratch.

Surely all of this dialogue about passports and utility bills, declarations and signatories and KYC and AML is pushing a demand for a new digital infrastructure to cure all of this mess.

[From Digital identities demand a digital infrastructure | Banking View]

Karen Wendel from Identrust talked about the infrastructural approach in her presentation as well, and this all links to the discussions about the idea of a financial service passport (or a “pay name”) at techUK last year. I really think that the idea of pseudonymous, strongly-authenticated CDD identities is an idea whose time has come. I should be able to participate in a transaction as John Doe, provided that I can prove that someone (e.g., my bank) knows who John Doe actually is. You don’t need to know who I am to do business with me, so long as you know that _someone_ knows who I am.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Payment system regulation as barrier to payment system innovation appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2014/05/payment-system-regulation-as-barrier-to-payment-system-innovation/feed/ 2
Bots and pluggers http://tomorrowstransactions.com/2014/05/bots-and-pluggers/ http://tomorrowstransactions.com/2014/05/bots-and-pluggers/#respond Thu, 15 May 2014 01:49:57 +0000 http://tomorrowstransactions.com/?p=4435 What if my Twitter followers and Facebook “friends” aren’t real after all. It doesn’t bother me, but it might bother other people! What if social media end up as a vast network of bots talking to other bots? Had a conversation yesterday with someone about a new startup. I hope they won’t mind me mentioning that […]

The post Bots and pluggers appeared first on Tomorrow's Transactions.

]]>
Dgwb blog white border

What if my Twitter followers and Facebook “friends” aren’t real after all. It doesn’t bother me, but it might bother other people! What if social media end up as a vast network of bots talking to other bots?

Had a conversation yesterday with someone about a new startup. I hope they won’t mind me mentioning that one element of the conversation was about determining whether social media accounts were “real” or not. This reminded me what Sherry Turkle from MIT (who wrote the brilliant, seminal book on online identity, “Life on Screen“) said last year, when talking about the specific issue of twitter bots and fake social media accounts, that this is a really serious and really important problem because the inability to distinguish between real and fake accounts

will and should undermine trust

[From Twitter, Bots And Fake Accounts - Business Insider]

Indeed. I went to a marvellous panel session about this at SXSW, and I wrote at the time that there was a need to prove what you are (e.g., human) that is entirely distinct from the need to prove who you are:

An internet passport should be something different: whereas a mundane passport is valuable because it proves who you are, an internet passport should be valuable precisely because it doesn’t.

[From In cyberspace, no-one knows you’re a dogbot - Tomorrow's Transactions]

Given that the industrial-scale manufacturing of fake social media accounts is already widespread, you might wonder exactly who the fake accounts are for? I found this example in the WSJ quite interesting.

Rapper Tony Benson says hiring Mr. Vidmar to promote his account on Twitter is “the best decision I ever made.” Mr. Vidmar’s robots made the rapper, known as Philly Chase, a trending topic so often around Philadelphia that he attracted attention from local newspapers. Prominence on Twitter led to gigs, fans and ways to promote his videos, Mr. Benson says.

[From Inside a Twitter Robot Factory - WSJ.com]

In the early days of the pop business, as it was then called, record companies used to employ “pluggers”. In those days, the pop charts were compiled from the sales records of a small number of record shops. The identity of the shops was supposed to be secret, but the record companies of course knew which ones they were. So they would send their pluggers to buy copies of their own records to push their artists up the charts. Good for Tony Benson, who has found a way to replace pluggers with plugbots.

Much modern spam isn’t designed for consumption by humans at all; instead, it’s “robot-readable”, created by one non-human entity for the attention of another – specifically, the “spiders” that crawl the web compiling data for Google – in the hope of pushing a junk page higher up the list of search results.

[From Why Spam Works - Business Insider]

Is Twitter becoming a vast network of bots talking to other bots? What a fascinating idea to play with, and what a wonderful proto-case study for the future of business. I stand by my prediction of long ago. One day, IS_A_PERSON may be the most valuable online credential of all.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Bots and pluggers appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2014/05/bots-and-pluggers/feed/ 0
Crime correlates cash http://tomorrowstransactions.com/2014/04/crime-correlates-cash/ http://tomorrowstransactions.com/2014/04/crime-correlates-cash/#respond Fri, 04 Apr 2014 16:24:53 +0000 http://tomorrowstransactions.com/?p=4359 Now that banks are spending more on virtual security than physical security, robbers are going to have to change their strategies. I got into an interesting discussion about bank robbery at a recent lunch. We were talking about risk and risk analysis. It happens that Consult Hyperion has a very well-developed risk analysis methodology (it’s […]

The post Crime correlates cash appeared first on Tomorrow's Transactions.

]]>
Dgwb blog white border

Now that banks are spending more on virtual security than physical security, robbers are going to have to change their strategies.

I got into an interesting discussion about bank robbery at a recent lunch. We were talking about risk and risk analysis. It happens that Consult Hyperion has a very well-developed risk analysis methodology (it’s called “Structured Risk Analysis”, or SRA) that has been used rather successfully on a wide variety of transactional services around the globe to help clients to evolve security architectures and to direct countermeasure expenditures effectively. I was trying to make some points about why proper risk analysis like this is a more cost-effective way to proceed than (for example) panicking about newspaper stories on hacking, and that led to a train of thought around cost-benefit analysis for the robber, not the bank. Are robbers put off by thick doors and barred windows and such like? Are robbers deterred by visible, physical symbols of security?

The security of physical buildings is no longer as important for financial services.

[From CYBER SECURITY WITHIN FINANCIAL SYSTEMS NEEDS TO BE FRONT-OF-MIND | GlobalBankingAndFinance.com]

This is a fair point. So it set me thinking: if you are an amoral sociopath desperate for money, are you better off robbing a bank or working for it? As a responsible father, I want to help my teenage sons chart the best course for life. Right now, they are intent on going to University to study socially useful subjects in science and engineering, whereas I am trying to persuade them to become Somali pirates or Wolves of Wall Street. Having studied science and become a wage slave trapped in mortgage serfdom I understand that side of the equation, but am less certain of the other. So I started off by reading a paper called the “Decision-Making Practices of Armed Robbers” by Morrison and O’Donnell.

This paper is based on a study of commercial armed robbery in London, UK, involving the analysis of over 1,000 police reports and inter- views with 88 incarcerated armed robbers.

The paper, being about UK robberies, contains an interesting snippet: a great many of the armed robbers in the UK use imitation firearms even though they have ready access to real ones. I imagine that in the US the use of imitations is vastly less prevalent, since it’s presumably harder to buy an imitation gun than a real one there. But I digress.

almost all of these robbers evaluated the offence as having been financially worthwhile (aside from the fact that they were eventually caught and punished for their crime).

So robbing a bank seems like good idea, if you exclude the possibility (in fact, the likelihood) of being caught. I suppose this is standard “Wolf of Wall Street” thinking though isn’t it?

Neither does it seem practical to expect financial institutions and commercial properties to reduce counter cash much more than they already have.

I disagree, of course. This is exactly what we should expect them do, since as far as I am aware there is a direct and measurable relationship between the amount of cash (more on this later) and the amount of crime.

Even when the amount of money obtained was quite small (an element often touted in support of the irrationality of economic criminals), it must be recognised that even apparently small sums may be adequate for the offender’s immediate needs. Hence, gains may be subjectively much larger than they appear

So even thought the rewards of armed robbery seem to me, an educated middle-class professional, to be rather low, they are still sufficient to attract the robbers, because their needs are immediate and limited. They guy in the Nixon mask isn’t robbing a bank to pay his way through college or to obtain seed finance for a brilliant start up idea, he just needs to buy a car or some drugs or whatever. This article seems, then, to indicate that so long as there is some cash in the till, there will be robberies. This is not an observation confined to banking.

Our results indicate that the EBT program had a negative and significant effect on the overall crime rate as well as burglary, assault, and larceny.

[From Less Cash, Less Crime: Evidence from the Electronic Benefit Transfer Program]

What they are talking about here is the use of Electronic Benefit Transfer (EBT) programmes in the US, whereby benefit recipients are paid electronically and given cards that they can use in shops instead of being given cash. The authors found a 10% drop in crime correlated with the switch to EBT. It seems pretty overwhelming evidence, and even more so if you read the paper, which notes no impact on crimes that do not involve the acquisition of cash. If we can to stop armed robberies, that would surely be an excellent social benefit to the move to cashlessness and would help us to explain the nature of appropriate regulation to legislators.

But back to the specific point about the relationship between bank cash and robberies. What should we do about it, other than the obvious, necessary and socially-beneficial step of abolishing $50 and $100 bills (as well as £50 note and €100, €200 and the €500 “Bin Ladens” as well)? It looks as if the answer is, essentially, nothing.

But with most robbers taking a mere pittance and bank robberies being a relatively rare crime (there are more than 6,000 commercial banks in the United States and thousands more credit unions), it’s barely worth it for banks to invest in the screens, which cost a couple thousand per teller window to install… Overall, it’s probably not worth it to attempt a bank robbery, the researchers conclude. “The return on an average bank robber is, frankly, rubbish,” they write. “It’s so low that it is not worth the banks’ while to spend as little as [$7,000] per cashier position at every branch on rising screens to deter them.”

[From What You Should Know Before Robbing a Bank - US News and World Report]

The armed robbers, like everyone else, follow the money – literally – and so cash-in-transit (CIT) robberies are now the preferred option. We see the same in Europe where countries that have much higher usage of ATMs have much higher CIT robbery rates than countries that have lower ATM usage (see, for example, Sweden and Denmark).

More people seem to be taking that advice: In 2004, there were more than 7,500 bank robberies in America, 26 percent more than there were in 2010. According to the researchers, “robbing banks is no longer what you could call the crime of choice.” But they do have some other advice: “Security vans offer more attractive pickings.”

[From What You Should Know Before Robbing a Bank - US News and World Report]

Overall, then, we see another early indication of the emerging post-cash era: Spending on physical bank security is being reduced and spending on virtual bank security is being increased. We do, indeed, live in interesting times.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Crime correlates cash appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2014/04/crime-correlates-cash/feed/ 0
Digital money shouldn’t be anonymous http://tomorrowstransactions.com/2014/03/digital-money-shouldnt-be-anonymous/ http://tomorrowstransactions.com/2014/03/digital-money-shouldnt-be-anonymous/#comments Thu, 13 Mar 2014 14:38:39 +0000 http://tomorrowstransactions.com/?p=4296 Does electronic cash really need to emulate the anonymity of physical cash? I love Denmark. I feel that the ancient and historic bonds between England and Denmark are strong. Since I do not recognise the legitimacy of William the Bastard’s claim to the English throne in 1066, as far as I am concerned England remains […]

The post Digital money shouldn’t be anonymous appeared first on Tomorrow's Transactions.

]]>
Dgwb blog white border

Does electronic cash really need to emulate the anonymity of physical cash?

I love Denmark. I feel that the ancient and historic bonds between England and Denmark are strong. Since I do not recognise the legitimacy of William the Bastard’s claim to the English throne in 1066, as far as I am concerned England remains a Scandinavian country and part of the future Northern non-European Union. And my Danish connections do not end there. As a fully paid-up member of the English middle class I am (inexplicably) hooked on Borgen. I loved The Killing. And I love what the Danes are doing with cash, which is, by and large, getting rid of it. But not quickly enough.

At the Future of Money seminar in Copenhagen in November, I remember that one of the discussions was about anonymity. I can’t remember exactly what was said, but I do remember expressing the opinion that Bitcoin’s supposed anonymity was not as much of a selling point as the enthusiasts tell each other. Which is to ask, whether electronic cash really needs to emulate the anonymity of physical cash?

I thought about this today because in his entertaining interview for the new magazine from NETS “Digital Values”, Bjorn Ulvaeus (one of the Bs in ABBA, in case you didn’t recognise the name) calls for the Scandinavian countries to take the lead and become the first cashless countries. It’s well worth a read for many reasons, and I found myself nodding in agreement and smiling all the way through. But I disagreed with Bjorn about one thing he said when discussing the anonymity of cash as a means of exchange. He says that

We’re already a surveillance society and removing what’s left of the cash from society wouldn’t make any difference

Ah yes, but I will be able to mitigate the impact of the surveillance state by dressing in my Facebook-blue burkha whenever I leave home. How will I mitigate the recording of all transactions? It’s a point that needs addressing. The impact of removing the anonymity of cash is hardly a new speculation. In 1968, Paul Armer of the RAND Corporation testified in front of a U.S. Senate subcommittee about his concerns for privacy in the future.

It seems high time to me that some organization in the executive branch of the government be charged with concern over the problem of privacy — just as the Department of Defense is charged with providing for the common defense, and as HEW is charged with the problems of health and education.

[From The Privacy Dangers of a Cashless Society Were Clear Over 40 Years Ago]

I don’t think the government has any kind of strategic view of identity and therefore a strategic view of privacy, but there are people who do (e.g., me) and I think that the problem of cash is a specific and tangible place to apply and explore them. Bjorn’s sounds like a counsel of despair! I’m not prepared to give up so easily. If we get rid of cash, we should aim to replace it with something that provides not the anonymity of cash but the privacy that is necessary in a civilised society. Will blog.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Digital money shouldn’t be anonymous appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2014/03/digital-money-shouldnt-be-anonymous/feed/ 3
We can contribute to childhood e-safety http://tomorrowstransactions.com/2014/02/we-can-contribute-to-childhood-e-safety/ http://tomorrowstransactions.com/2014/02/we-can-contribute-to-childhood-e-safety/#respond Mon, 03 Feb 2014 16:22:41 +0000 http://tomorrowstransactions.com/?p=3859 We can use identity and authentication (ie “recognition”) technologies to improve Internet safety, if we use them correctly. It is good to wander out of the comfort zone from time to time and expose your ideas to more acid tests. Hence I went along to the seminar on “Childhood and the Internet – Safety, Education […]

The post We can contribute to childhood e-safety appeared first on Tomorrow's Transactions.

]]>
Dgwb blog white border

We can use identity and authentication (ie “recognition”) technologies to improve Internet safety, if we use them correctly.

It is good to wander out of the comfort zone from time to time and expose your ideas to more acid tests. Hence I went along to the seminar on “Childhood and the Internet – Safety, Education and Regulation” in London in January. I was there for three main reasons:

  1. I am interested in the evolution of identification and authentication in an online environment, and protecting children is one of the cases that brings the mass market practicalities into sharp relief.
  2. We have clients who are developing recognition services, and it seems to me that if these services can contribute to a safer environment for children then we may have something of a win-win for encouraging adoption.
  3. Protecting children is an emotional topic, and as responsible member of society it concerns me that emotional responses may not be society’s best responses. This is a difficult subject. If, as technologists, we make any comment about initiatives to protect children being pointless or even counterproductive we may be accused of being sympathetic to criminals and perverts hence we need to learn to engage effectively. I’m not interest in childhood e-safety theatre, but childhood e-safety.

The seminar was kicked-off by Simon Milner, the Policy Director (UK and Ireland) for Facebook. He started off by noting that Facebook has a “real” names policy. Given my fascination with the topic, I found his comments were quite interesting as they were made on the same day that the head of Facebook, Mark Zuckerberg, was interviewed in Business Week saying that the “real” names policy was being amended.

One thing about some of the new apps that will come as a shock to anyone familiar with Facebook: Users will be able to log in anonymously.

[From Facebook Turns 10: The Mark Zuckerberg Interview - Businessweek]

Simon went on to say that the “real” names policy, setting to one side whether it means anything or not, is a good thing (he didn’t really explain why and I didn’t get a chance to ask) and then talked about how children who are being bullied on Facebook can report the problem and so on. I know nothing about this topic, other than as a parent, so I can’t comment on how effective or otherwise these measures might be. To be honest, there were several talks that I’m not qualified to comment on so I won’t, other than to say I found some of the talks by the subject matter experts extremely thought-provoking and I’m glad I heard them.

The main discussion that I was interested in was led by Helen Goodman MP (the Shadow Minister for Culture, Media and Sport) and Claire Perry MP, who is the Prime Minister’s special advisor on preventing the sexualisation and commercialisation of childhood. The ex-McKinsey Ms. Perry attracted a certain amount of fame in web circles last year (just search on “#PornoPerry”) when she made some public statements that seemed to indicate that she didn’t completely understand how the internet worked, despite being behind the government’s “porn filter”. (I am not picking on her. I should explain for foreign readers that most MPs are lawyers, management consultants, property developers, PR flacks and such like and they don’t really understand how anything actually works, least of all the interweb tubes. Only one out of the 635 MPs in the British Parliament is scientist.)

Now, let me be completely honest and point out that I have previously criticised not only the “real” names movement in general but Ms. Goodman’s views on anonymity in particular. I think she is wrong to demand “real” names. However, as I said a couple of years ago,

I’m not for one moment suggesting that Ms. Goodman’s concerns are not wholly real and heart felt. I’m sure they are.

[From The battle of the internet security experts - Tomorrow's Transactions]

This does not make her right about what to do though. Forcing people to interact online using their mundane identity is a bad idea on so many levels.

But that was the same month that the Communist party struck its first major blow against Weibo, requiring users to register their real names with the service. From that point, those wishing to criticise the Party had to do so without the comforting blanket of anonymity and users started to rein themselves in.

[From China kills off discussion on Weibo after internet crackdown - Telegraph]

I’m not suggesting that Ms. Perry represents a government intent on creating a totalitarian corporatist state that reduces us wage-slaves to the level of serfs to be monitored at all times. I’m sure her good intentions are to block only those communications that challenge basic human decency and serve to undermine the foundations of our society, such as MTV, but the end of public online space seems a drastic step. What has been the result of the Chinese campaign to end anonymity? What is the practical impact of a real names policy?

Once an incalculably important public space for news and opinion – a fast-flowing river of information that censors struggled to contain – it has arguably now been reduced to a wasteland of celebrity endorsements, government propaganda and corporate jingles.

[From China kills off discussion on Weibo after internet crackdown - Telegraph]

None of us, I’m sure, would like to see pillars of our society such as the Daily Mail reduced to the level of “celebrity endorsements, government propaganda and corporate jingles”. Perhaps there is now less crime in China too, but I have yet to discover any statistics that would prove that. I don’t want this to happen to Twitter, Facebook and The Telegraph web site (where it is my right as Englishman to post abuse about the Chancellor of the Exchequer should I so choose). So here is a practical and positive suggestion. At the seminar Helen said the “The gap between real-world identity and online identity is at the root of [the problem of cyberbullying]“. So let’s close that gap. Not by requiring (and policing) “real” names, but by implementing pseudonymity correctly. I wrote an extended piece on this for Total Payments magazine recently.

Now imagine that I get a death threat from an authenticated account. I report the abuse. Twitter can (automatically) tell the police who authenticated the transaction (i.e., Barclays). The police can then obtain a warrant and ask Barclays who I am. Barclays will tell them my name and address and where I last used my debit card. If it was, say, Vodafone who had authenticated me rather than Barclays, then Vodafone could even tell the police where I am (or at least, where my phone is).

[From Dave Birch’s Guest Post: Anonymity – privilege or right? - Total Payments : Total Payments]

As I said, I don’t just want to talk about doing something about cyberbullying and the like, I actually want to do something about it. “Real” names are a soundbite, not a solution. What we need is a working identity infrastructure that allows for strongly-authenticated pseudonyms so that bullies can be blocked and revealed but public space can remain open for discussion and debate. Then you can default Facebook and Twitter and whatever to block unauthenticated pseudonyms without insisting the kid looking for help on coming out, the woman looking at double-glazing options or the dreary middle-aged businessman railing against suicidal economic policies from revealing their identities unless they want to

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post We can contribute to childhood e-safety appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2014/02/we-can-contribute-to-childhood-e-safety/feed/ 0
What will the new UK Payments Regulator change? http://tomorrowstransactions.com/2014/01/what-will-the-new-uk-payments-regulator-change/ http://tomorrowstransactions.com/2014/01/what-will-the-new-uk-payments-regulator-change/#comments Fri, 24 Jan 2014 17:47:01 +0000 http://tomorrowstransactions.com/?p=3095 You may think payments regulation is a rather dull subject, but it isn’t. Angus McFayden from Pinsent Masons spoke about the changes to the regulation of the UK payment sector at the Westminster e-Forum on “Digital Payments in the UK” [PDF] that I spoke at last November. As I remember him pointing out, with characteristic accuracy, […]

The post What will the new UK Payments Regulator change? appeared first on Tomorrow's Transactions.

]]>
Dgwb blog white border

You may think payments regulation is a rather dull subject, but it isn’t. Angus McFayden from Pinsent Masons spoke about the changes to the regulation of the UK payment sector at the Westminster e-Forum on “Digital Payments in the UK” [PDF] that I spoke at last November. As I remember him pointing out, with characteristic accuracy, these changes are not going to drive down costs (there is nothing in the UK National Payment “Plan” about this anyway), which I would have thought to have been a reasonable goal. So what are they going to do? Well, they are supposed to improve competition while simultaneously ensuring stability and so forth.

How? You may remember that HMT (Her Majesty’s Treasury, the UK’s Ministry of Finance, essentially) had a public consultation on the options for UK regulation a while back, and…

So given it was what the government said they wanted, want the respondents said they wanted and, most importantly, what I said that I wanted… the government has decided to choose an alternative path and it now says it will create a new payment regulator

[From You searched for response to consultation - Tomorrow's Transactions]

So we are going to have a new payments regulator, and this will improve competition and ensure stability. Angus explained that this regulator, expected to be operational in April 2015, will have a number of powers and that one of them will be to mandate access to payment systems. This means for schemes, rather than direct access to accounts, and is laudable. If more organisations have access, there will be more competition and therefore, hopefully, reduced costs. So far, so not particularly interesting.

However, under proposed reforms to PSD2 things might move a little further and, somewhere downstream, there may be changes following on from the European Commission’s consultation on third-party access to the bank account, known as “XS2A”. In this scenario, I would be able to grant a licensed third party (a Payments Institution or bank, essentially) access to my bank account so that they could get the balance, look at transactions and perhaps even trigger FPS payments. Now this is really interesting. The potential for new services here is obvious and by removing an intermediary layer there should be a reductions in costs. But, and this is a big but as far as I am concerned, without the right identity infrastructure, the right security and the right compliance regime, this could be another Chernobyl.

I imagine that this is the sort of thing that will be discussed in London in February at the forthcoming “Payments Intensive”, where you can listen to Consult Hyperion’s Anthony Pickup and Adrian Kamellard, the Chief Executive of the Payments Council, amongst others, talking about payments regulation in more detail.

Payments Intensive 2014: Future Development and Regulation, will bring together key figures from business, legal and regulatory backgrounds, to discuss the most pressing issues in the payments sector today.

[From Payments Intensive 2014: Future Development and Regulation | Cecile Park Conferences]

The magnificent group of gentlepersons and scholars at Cecile Park have very kindly given Tomorrow’s Transactions a complementary delegate place at this event to dispose of as we please, so we’re having one of our blog competitions. If you are going to be in London on 6th February and would like to attend the Payments Intensive, then all you have to do is be the first person to comment on this post with the name of the British record label that has just released a version of Bach’s Wurttemberg Sonatas performed by the Iranian-American harpsichordist, Mahan Esfahani, and you will be given entirely free a place at the event (worth an astonishing THREE HUNDRED AND FORTY FIVE of your English pounds).

As always, the judge’s decision is arbitrary and capricious.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post What will the new UK Payments Regulator change? appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2014/01/what-will-the-new-uk-payments-regulator-change/feed/ 3