Tomorrow's Transactions » Uncategorized http://tomorrowstransactions.com Thought leadership from Consult Hyperion Fri, 18 Jul 2014 06:22:13 +0000 en-US hourly 1 http://wordpress.org/?v=3.9.1 A cryptocurrency for Scotland? http://tomorrowstransactions.com/2014/04/a-cryptocurrency-for-scotland/ http://tomorrowstransactions.com/2014/04/a-cryptocurrency-for-scotland/#comments Wed, 02 Apr 2014 09:14:35 +0000 http://tomorrowstransactions.com/?p=4348 I rarely recommend reading the reader comments at the Guardian Online (or indeed any other newspaper site) unless you need a fast cure for low blood pressure or get a kick out despising your fellow man. However last week I did actually learn something interesting from the comments to a Guardian article about Bitcoin. In […]

The post A cryptocurrency for Scotland? appeared first on Tomorrow's Transactions.

]]>
jane100100I rarely recommend reading the reader comments at the Guardian Online (or indeed any other newspaper site) unless you need a fast cure for low blood pressure or get a kick out despising your fellow man. However last week I did actually learn something interesting from the comments to a Guardian article about Bitcoin.

In common with countries such as Iceland, Scotland now has its own cryptocurrency – Scotcoin.

It’s not altogether clear from the Scotcoin website (http://scotcoin.org) exactly how Scotcoins are created but in contrast to Bitcoin they are pre-mined and will be distributed free to anyone in Scotland who wants some. At present they cannot be exchanged for other altcoins and they have no value in fiat currency (unless the free market decides otherwise, according to the website). Nor is it entirely clear whether the founder is actually based in Scotland but he was, he says, born there.  The purpose of Scotcoin, he says, is to provide a plan B currency for an independent Scotland.

Now, as someone who is not by nature a libertarian, at least where others are concerned, I’m a bit suspicious about cryptocurrencies. I don’t own any Bitcoin and feel slightly seasick at the idea of an asset whose value fluctuates more than the waves on a bad ferry crossing. Here at Consult Hyperion thought we generally believe that the technology behind Bitcoin, the blockchain, is a lot more interesting than the currency itself.

Nonetheless I felt moved, as a Scottish resident, to obtain some Scotcoins. Purely out of professional curiousity, you understand.

This involved downloading and installing the Scotcoin wallet. In other words downloading and installing an executable file from a non-https website I’d previously not heard of. As an IT security graduate this made me feel even sicker than the Bitcoin exchange rate but I did it nonetheless (to an old laptop) and I now own 1000 shiny Scotcoins.

Now what? It’s hard to say. Is it for real?

I feel obliged to report that not everyone is convinced about Scotcoin (see http://loggingoff.tygabitworks.com/) but then there’s a lot of negativity about Bitcoin too. I’m absolutely not endorsing that view, merely reporting it but the Scotcoin website certainly displays a creative attitude to punctuation and spelling, whether that means anything or not. On the other hand around 100 or so other Scots seem to have downloaded the wallet so presumably they think it’s fine*. And my virus checker (paid for AVG) hasn’t picked up anything feeding my online banking details offshore.

In any case there’s absolutely nothing wrong with the concept of a Scottish cryptocurrency, irrespective of whether Scotcoin is it or not and Alex Salmond would be well advised to consider it. If you’d like to know more, Dave Birch will be talking about the idea of a Scottish virtual currency to the Financial Services Club Scotland in Edinburgh on 29th April. 

*I’m enchanted to note that one of the first power users is called Dug. Dug of course is Scots for Doge.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post A cryptocurrency for Scotland? appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2014/04/a-cryptocurrency-for-scotland/feed/ 2
ACH infrastructure needs replacing, not patching http://tomorrowstransactions.com/2014/03/ach-infrastructure-needs-replacing-not-patching/ http://tomorrowstransactions.com/2014/03/ach-infrastructure-needs-replacing-not-patching/#respond Mon, 24 Mar 2014 16:41:08 +0000 http://tomorrowstransactions.com/?p=4326 The US should take a bold step forward and forget about patching up the old, creaking ACH infrastructure. Build something for the 21st century! Tim Sloane from Mercator wrote a super piece on how the US ACH infrastructure isn’t quite up to the job of providing the real-time funds transfer infrastructure needed for a 21st-century […]

The post ACH infrastructure needs replacing, not patching appeared first on Tomorrow's Transactions.

]]>
Dgwb blog white border

The US should take a bold step forward and forget about patching up the old, creaking ACH infrastructure. Build something for the 21st century!

Tim Sloane from Mercator wrote a super piece on how the US ACH infrastructure isn’t quite up to the job of providing the real-time funds transfer infrastructure needed for a 21st-century economy.

in the best possible scenario they are more or less correct; funds will appear in the consumer’s prepaid account on some random day in the future

[From Prepaid Program Managers Take the Blame for the Problems of the ACH - PaymentsJournal]

Here in the UK, the picture is different. The new ACH, the Faster Payments Service (FPS), is working splendidly well and is already spawning new payment products (e.g., Barclays PingIt, Zapp and Paym). It’s not perfect (it would be nice to have messaging with more and structured content, for example), but it’s pretty good. Surely it can’t be that complicated for the top 10 banks in the US just to build something similar — but better, with messaging and APIs — and then open it up on the same basis as FPS: free to retail customers.

Per my blog yesterday, ACH debit tokens can work, particularly if the consumer doesn’t have to enter them. Also in ACH, banks are in a position to influence acceptance.

[From Payment Tokenization | FinVentures]

Following the Federal Reserve’s consultation process, NACHA has indeed said that it will look at delivering a more modern infrastructure for the US, but I still think (as we said in our response to the Federal Reserve consultation) that tinkering with the disco-era systems in place isn’t the best solution for the US.

The expense of making technology improvements is widely seen as a key reason that some banks opposed the 2012 proposal to modernize the automated clearing house network.

[From Nacha Revives Faster Payments Plan|PaymentsSource]

Indeed. So why bother? Leaving the existing network alone and build a new Faster Payment Service (FPS) on cheaper modern technology, using 20022 XML, and go push-only. Let the old ACH, and its pull services, wither away.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post ACH infrastructure needs replacing, not patching appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2014/03/ach-infrastructure-needs-replacing-not-patching/feed/ 0
Google Wallet Review http://tomorrowstransactions.com/2014/03/google-wallet-review/ http://tomorrowstransactions.com/2014/03/google-wallet-review/#comments Thu, 20 Mar 2014 07:53:29 +0000 http://tomorrowstransactions.com/?p=4316 Google Wallet is back!  They have moved away from a focus on NFC to an e-wallet that will work with all mobile phones and have drastically reduced the friction with merchants, banks, mobile carriers and customers. Downloading the Google Wallet app to my iPhone was quick and easy.  After downloading the wallet, it asks you […]

The post Google Wallet Review appeared first on Tomorrow's Transactions.

]]>
OLYMPUS DIGITAL CAMERA

Google Wallet is back!  They have moved away from a focus on NFC to an e-wallet that will work with all mobile phones and have drastically reduced the friction with merchants, banks, mobile carriers and customers.

Downloading the Google Wallet app to my iPhone was quick and easy.  After downloading the wallet, it asks you to “sign in with your Google Account” or “create an account”.  The tag line is “One Google Account for everything Google”…you don’t see sign-in with Facebook here!

google1

After signing in, and giving my Zip Code (as you must live in the U.S.), and agreeing to the T&C and allowing messages to be pushed to me, I was instructed to create a Wallet PIN.

After confirming my PIN, it takes me to My Wallet home screen.   It screams out “P2P” wallet, as the Send Money banner is very prominent.   If I am a customer that has just downloaded this wallet for “in-store” purchases, you are going to be confused and think you can only send money to other people (since wallets and using them to shop in-store is extremely rare in the U.S. probably not an issue now).   If you have gone to the Google web site and read about the wallet, and Google Card, there is nothing within the wallet that leads you to the getting the card.

The Send & Receive money function requires Google to verify your identity.   Before I do the verification steps, I wanted to understand program Fees. Fees are as follows:

  • Free to send money directly from your bank account or using the balance in your Google Wallet
  • Fee of 2.9% per transaction (min. of $0.30) to send money using a credit or debit card (Free promo until March 19th)
  • Receiving money and transferring to your bank account is always free

An interesting note is when you go the Google Wallet web site, and click on Send Money it takes you automatically to add a credit card and not the verify your identity step.  Additionally, you have the option to order your Google Card and when you click to order, it takes you to verify your identity page.

The verification process is name, address, birthdate and last 4-digits of Social Security number.  As soon as the verification process is approved, the Send Money options immediately change to reflect an option to add a funding source, by linking a bank account and/or debit or credit card.  Additionally, the wallet home page is changed to reflect a Wallet Balance dollar amount and a new banner appears advertising that you can get the Google Wallet Card.   It seems the verification step is the critical step that activates the options of the card and bank account.  They don’t want to go too far down the path before they do the standard verification steps.

Now lets take a look at the Offers and Loyalty program feature.  Under the Loyalty program tab you have the option of adding your own program or selecting from a pre-populated list of 15 programs such as Walgreens to Marriott.  If you have a loyalty program card that is not listed, the wallet asks you to scan the barcode on the card using the built in scanner.  If no barcode exists, you can enter the account number manually.  For the list of programs, you can enter your account number, or if not an existing member, join the program.

It’s a very easy and straight forward process to setup your cards. When using the barcode, it automatically recognizes the program name (i.e., CVS extra care) and adds the card to the wallet along with the barcode and account number.  You have the option to pick card color as an option.  When using a pre-existing program such as Marriott Rewards, you enter your Marriott number, it verifies the account and brings back your number of points and program level such as Gold.  When you click on the Marriott card, it takes you to another page that provides a banner page for Marriott, messages, view your hotel bill, and other links to Marriott and related promotions such as their co-branded credit card.  The additional page with links, messages and promotions are only available to those companies that are pre-listed within the loyalty program.

The Offers tab is a little confusing. When you see the Offers and Loyalty programs banner on the home page and you click “View offers and loyalty programs”, it doesn’t do anything – just takes you to an info screen that tells you to use the menu button to view your saved items.  When you go to Offers, there is a My Offers and Explore tab.  The Explore tab has three offers (based on my zip) under local offers and you can save the offer, which then appears in My Offers. From the comments and reviews I see online, people are confused and not seeing the Explore tab as many people are asking how to get offers added to the wallet.   I do find it very interesting that Google has not integrated their Google Offers app into the Google Wallet.  When you add offers to My Offers within the Google Offers app, they automatically appear in the My Offers in my Google Wallet.  These two apps should be integrated.  Also, Google says that merchants will start to place Google Offers on their web sites and other locations.

Offers Note:  In my area there were very few offers available, and no offers that appealed to me.  Google does say that they will continue to tailor offers in the Explore section based on my Google Offers usage (the separate app) and my Google account activity and changes in my location.  Also, allowing the Wallet owner to mark offers as “used” doesn’t provide merchants with much protection from multiple use of the offer.  It would be interesting if Google could create a unique “barcode” or “offer” code that tracks not only that the offer came from Google, but also specifically track the user – maybe  new product coming from Google?

google2

Now let’s review the Google Wallet Balance and adding your bank account to fund the wallet.  Since this is a free option, I will be adding my bank account and not a credit or debit card wherein I will incur a 2.9% fee.  They do inform you that bank transactions usually take 3 days but can take up to 10 days.

Entering the bank account information was very easy.  They clearly identified the information required and where/how to find the information.  The next step was the account verification step.  You can verify immediately by entering your bank account Member/User ID and Password, which links your bank account, or the Challenge Deposit, which takes 2 to 3 days to verify.  As I did not want to link my account and I was curious about the Challenge Deposit method, I selected Challenge Deposit.

In the Challenge Deposit process, Google will make a deposit of an amount up to a $1 to your bank account.  You check your bank account, look for the deposit amount, and they enter the amount in the wallet to complete the account verification step.  This took two days in my case.

Adding funds by credit card (Visa/MasterCard) is an option, but you cannot use your American Express to add funds.  You can use your American Express to send money, but not to add funds to your wallet.

google3

 I ordered the Google Card, which arrived in approximately 3 weeks, and I was surprised to see the card was a MasterCard Prepaid card.  The MasterCard logo and hologram is on the back of the card.   Card activation was achieved via the Wallet.  Next step was to add funds to my Wallet, and I go online to my bank account and look for the Google Challenge Deposit I outlined above.  I find a $0.80 cents deposit transaction and go to my Wallet to enter the deposit amount.  Google Wallet verifies the amount is correct and I am now able to add funds to my Wallet.  I elect to add $20, and the transaction adds the $20 immediately.  Even though I was expecting to wait 2 to 3 days for the funds to appear, it occurs immediately.  Google communicates that adding funds from your banking account could take up to 5 days, but they note that only a small percentage take more than 2 days.

Add Funds Note:  The process is very easy and straightforward.  It does seem that Google must be doing some fraud/security steps during the add funds process.  In my case they added the funds immediately, no waiting, which means they were willing to take the risk that I had the $20 in my bank account, since it takes at least 1 day via ACH to receive funds. If Google is willing to take the risk, could they create a “near real time” ACH type of payment?  Something that the Federal Reserve is studying, and banks say will take years to implement, if ever, as they say they do not understand the business case to support it.

  google4

First use of the Google Card was at Home Depot on one of my 3 trips per project visits!   The clerk had never seen a Google Card and didn’t think it would work.  I swiped the card and it asked from my PIN number and transaction was approved.  Before I left the store I received a mobile message with my transaction information and my current Wallet Balance.  It worked just as easily as my bank’s debit card and actually was a much better experience in that my bank does not automatically send me via app message/text message my transaction information and my current bank account balance!

 google5

 Google Card Note:  The Google Card works just as easily as my bank debit card at the POS and it has the ability to add greater functionality in the future such as automatically utilizing Offers and Loyalty programs at the point-of-sale.  The one big negative with the Google Card, is that it will decline any transaction that is “greater” than my current Wallet Balance.  They do not automatically pull funds from my bank account or registered credit/debit card, they decline the transaction.  They do not offer the feature to “top off” my Wallet Balance automatically by allowing me to set floor limits, wherein my Wallet Balance reaches a specified balance, they add funds automatically (like my Starbucks wallet).  Google’s approach is to have me control my authorization of funds to transfer to my Wallet balance.

Now let me respond specifically to my list of questions and ratings from the original blog article. The rating is from a general public perspective, on each of the category questions listed here, on a scale of 1, 2 or 3.

•          1 (Confusing, Needs Work)

•          2 (Okay, Average)

•          3 (Easy, Better Than Most)

The rating is based on the individual wallet, and not compared against other wallets, since I have not worked with all of the wallets as of today. I will do an overall rating at the end of my e-wallet journey.

1 How is the wallet marketed/advertised to the general public?  What media channels?  How do I know the wallet exists? What is the message to me?

The advertising seems to be limited to online, and someone has to be looking to add the wallet.  You can see it listed as an option on your Google account.  I have not noticed this advertised in any other media channels, so you have to be looking for this wallet.  The message to consumers is that the wallet is for shopping, saving and paying.  Doing ecommerce faster/quicker seems to be the main message. Rating: 2

2 Why do I need this mobile wallet?  (Isn’t this the first question that needs to be answered in a manner that is simple and straightforward for the general public?) What issue does it address?  How is my life better by using the wallet?

This is a key question to be answered by all the wallets.  As I think about this from a general consumer (from the perspective of my wife – Lisa).  Why would I want to download this wallet?  What can I do that I can’t already do with my credit/debit cards in my physical wallet?  Lisa said that if she could save all her Loyalty cards to the wallet, this would be convenient and she wouldn’t have to carry all the cards in her purse.  From my point-of-view, they have not answered this question for me – more on this later. Rating: 1

3 Is it a payment-only wallet?  Does it have loyalty/rewards?  Other benefits?

This is intended to be an all-in-one wallet, with P2P, POS, and loyalty and offers all in one wallet.  It does not have its own loyalty/rewards program, but provides access to other programs.  It comes with a MasterCard card, which does provide in-store functionality.  Rating: 3

4 How do I get the wallet?  Download from iTunes app store?  Scan a QR code? Go to a web site?

You download from the app store. Rating: 2

5 Now that I have downloaded the app to my mobile phone, how difficult is it for me to register/set up?  Are there a few simple steps or do you need to be a nuclear engineer to figure it out?  Does it ask from my bank account information?  My debit/credit card number?

Set up as described above was very easy and straightforward.  Rating: 3

6 Where can I use the mobile wallet?  How many stores (real brick-and-mortar stores) not online stores – use it at Point-of-sale (POS) locations.  Transit?

The mobile Wallet cannot be used at any in-store locations. The Wallet can be used for online/internet shopping where the Google Wallet icon is available at checkout.  The Wallet can be use anywhere MasterCard is accepted via the Google Wallet Card, which is a MasterCard Prepaid account.  The Wallet Card does provide the user with the ability to use the Wallet wherever MasterCard is accepted.  On the other hand, it only accesses the balance in your Wallet and does not automatically “top-off” balances. A transaction will be declined if your current Wallet Balance is not great enough to cover it.   Rating: 1

7 What is the POS set up –stand alone tablet? Integrated cash register?  Typical card reader POS?  Contact-less/NFC?

Wallet can only be used via the Google Wallet Card, which is a MasterCard debit card.  Merchants do not have to do anything special to accept the payment. Rating: 3 (From a merchant perspective)

8 Is the POS experience easy?  Hard?  Confusing?  Does it actually work?

Easy…same steps as using a standard Visa/MC debit card.  It works.  So on one hand the e-wallet really “does not work” at the POS, since it is using a standard Visa/MC debit card and it is restricted by current Wallet Balance to cover the transaction. Rating: 1 (From a customer perspective)

9 What information do I get sent to me after the sale?  Do I get my receipt emailed to me?  A text message?  Is the transaction listed on my wallet?  Did I earn points?

I received a mobile message immediately after the transaction with details of my transaction.  Rating: 3

10 Are there fees? Do I need to reload my wallet (manually or automatically)? Is the transaction a prepaid card?  Or my debit/credit card?  Does it use the Automated Clearing House (ACH) network?

No fees if linking your Wallet to your bank account.  I need to manually reload my wallet; there is no automatically topping off if balance falls below a specified threshold.  You can link to your credit/debit card, and fees apply as I outlined above. Rating: 2

Overall I like the Google Wallet.  It is easy to set up and use as a P2P application and having the Google Card allows it to be used everywhere MasterCard is accepted.  But will I use it?  Not as a payment tool.  I am not someone that sees the value in P2P and I can easily use any one of my exiting credit/debit cards in my “physical” wallet.  Will I use it to store my loyalty/reward cards?  Maybe.  I already have used CardStar for a number of years for that purpose, so do I take the time to set up the Google version?  Not sure.  How about the Offers?  Again, in my area there are no enticing offers and the Google Offers app is not integrated with the Google Wallet – two separate apps.  The bottom line, Google Wallet has not answered for me (maybe for other people they have) the basic question of “Why do I need/want to download this app to my mobile phone?”

Next up will be Starbucks.

 

 

 

 

 

 

 

 

 

 

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Google Wallet Review appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2014/03/google-wallet-review/feed/ 4
Wallets, wallets everywhere! Which ones have an edge today? http://tomorrowstransactions.com/2014/03/wallets-wallets-everywhere-ones-edge-today/ http://tomorrowstransactions.com/2014/03/wallets-wallets-everywhere-ones-edge-today/#comments Tue, 04 Mar 2014 14:54:53 +0000 http://tomorrowstransactions.com/?p=3947 As someone that is exposed to the payments industry, attends conferences, reads the industry publications and generally interested in all things payment related, even I am surprised at the number of mobile wallets that are available.  Everyone wants me to download his or her e-wallet to my mobile phone – from Starbucks, to Square Wallet […]

The post Wallets, wallets everywhere! Which ones have an edge today? appeared first on Tomorrow's Transactions.

]]>
OLYMPUS DIGITAL CAMERAAs someone that is exposed to the payments industry, attends conferences, reads the industry publications and generally interested in all things payment related, even I am surprised at the number of mobile wallets that are available.  Everyone wants me to download his or her e-wallet to my mobile phone – from Starbucks, to Square Wallet to Isis and the list goes on.  So I have decided to take a journey over the next few weeks and experience a variety of mobile wallets that are available in the US marketplace.  And here is the real challenge – I carry an iPhone! 

As “us” industry experts know, the iPhone does not have any Near Field Communication (NFC) capabilities and hence I will be limited by the wallets I can actually use (the general public doesn’t know NFC from ABC and do not care).  But, in the US, the iPhone is still the most widely used US mobile phone[1] and if you are going to be successful in the US, then you need to build your wallet to work with iPhones.

With so many competing wallets, it has become too confusing and too burdensome for the consumer to select any wallet.   Merchants, like Chipotle, have their own wallet, MasterCard and Visa have their wallets, banks have their wallets, card issuers that their wallets and there are a number of general purpose wallets…everyone has a wallet!  Based on my research, there must be over 100 competing wallets available today and new ones are being added every day.

Before I start my journal, I want to outline some questions that I believe need to be answered by each wallet I test.   And the questions are really from the perspective of the general public (not us payment people).  Here are mine, and I would like to hear from others on questions that you would like to address.  Here are my questions in a chronological order:

  1. How is the wallet marketed/advertised to the general public?  What media channels?  How do I know the wallet exists? What is the message to me?
  2. Why do I need this mobile wallet?  (Isn’t this the first question that needs to be answered in a manner that is simple and straightforward for the general public?) What issue does it address?  How is my life better by using the wallet?
  3. Is it a payment-only wallet?  Does it have loyalty/rewards?  Other benefits?
  4. How do I get the wallet?  Download from iTunes app store?  Scan a QR code? Go to a web site?
  5. Now that I have downloaded the app to my mobile phone, how difficult is it for me to register/set up?  Are there a few simple steps or do you need to be a nuclear engineer to figure it out?  Does it ask from my bank account information?  My debit/credit card number?
  6. Where can I use the mobile wallet?  How many stores (real brick-and-mortar stores) not online stores – use it at Point-of-sale (POS) locations.  Transit?
  7. What is the POS set up –stand alone tablet? Integrated cash register?  Typical card reader POS?  Contact-less/NFC?
  8. Is the POS experience easy?  Hard?  Confusing?  Does it actually work?
  9. What information do I get sent to me after the sale?  Do I get my receipt emailed to me?  A text message?  Is the transaction listed on my wallet?  Did I earn points?
  10. Are there fees? Do I need to reload my wallet (manually or automatically)? Is the transaction a prepaid card?  Or my debit/credit card?  Does it use the Automated Clearing House (ACH) network?

These are just some of the questions I intend to answer, and I am sure as I go thru my journal, I will add more questions. In addition to answering the questions, I will rate each of the wallets from a general public perspective, on each of the category questions listed here, on a scale of 1, 2 or 3.

  • 1 (Confusing, Needs Work)
  • 2 (Okay, Average)
  • 3 (Easy, Better Than Most)

wallets

 How many wallet apps are too many?

The following wallets will be reviewed in the coming weeks:

  1. Square Wallet
  2. Google Wallet
  3. bPay
  4. CardStar
  5. LevelUp
  6. LifeLock (formally Lemon)
  7. Belly
  8. Venmo
  9. PayPal
  10. MocaPay
  11. Starbucks, and many more

If you have a wallet that you would like me to add to my list, please let me know.

First up will be the Google Wallet!  Check back to see how Google fared.

 


[1] The newest report from Kantar Worldpanel ComTech shows the iPhone with a 43.4 percent share of the United States market for the three months ending in July. That represents a 7.8 percentage point increase over the same period from a year ago. The United States, according to Kantar’s numbers, remains Apple’s strongest market, though the iPhone saw identical growth in Great Britain, where it jumped 7.8 points year-over-year to take a 31.1 percent share.

 

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Wallets, wallets everywhere! Which ones have an edge today? appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2014/03/wallets-wallets-everywhere-ones-edge-today/feed/ 3
Threats, risk and attacker motivation: a real life example http://tomorrowstransactions.com/2013/12/threats-risk-attacker-motivation-real-life-example/ http://tomorrowstransactions.com/2013/12/threats-risk-attacker-motivation-real-life-example/#respond Fri, 27 Dec 2013 09:23:16 +0000 http://tomorrowstransactions.com/?p=2888 Travelling home from a meeting at the Payments Council on Monday afternoon, I was enjoying the peace and quiet of the train gradually emptying as it drew further out of town. At Sunningdale, a station normally notable only for the most prosperous passengers, a group of excitable teenagers joined the train obviously looking for trouble. […]

The post Threats, risk and attacker motivation: a real life example appeared first on Tomorrow's Transactions.

]]>
Margaret FordTravelling home from a meeting at the Payments Council on Monday afternoon, I was enjoying the peace and quiet of the train gradually emptying as it drew further out of town. At Sunningdale, a station normally notable only for the most prosperous passengers, a group of excitable teenagers joined the train obviously looking for trouble. Brandishing camera phones, they seemed more of an irritant than a threat.

Avidly reading advice on strategies to avoid arrest by over-zealous US police officers, quoted in an article from the latest edition of Cryptogram, I felt comfortably detached from my surroundings. The luxury of a half-empty train on the Reading line is a rare treat.

The author of the article advised that unlawful activity is best indulged in from the comfort of your own home. If you must commit crimes in public, avoid drawing attention to yourself. In particular, even if you become aware of an officer while performing an illegal act, it is better to continue rather than raise suspicion through a sudden change in behaviour.

At this point I became aware that I had unwittingly become the focus of the gang, who had moved on from threatening to punch random strangers to wielding newspapers and cigarette lighters while daring each other to take my phone. Suddenly alert to the situation, I put my phone away, muttered ‘excuse me’ and wandered gently up the carriage. They left the train at the next station.

I’d made the mistake of forgetting that my brand new phone which I regarded as a standard device for accessing content and keeping in touch, could also be seen as a status symbol with significant market value. On reflection, it gave me a tangible example of one of the key risk concepts being investigated by the TREsPASS project: attacker motivation. This had moved from the general to the specific, as an opportunity was spotted and the incident unfolded. It was clearly unpremeditated and yet in many ways predictable.

As my brother commented the next morning, teenage gangs in our area just aren’t what they were in our youth, when they would steam the length of trains in groups of twenty or more. He also gave me a great tip for protecting my phone in future, which in his experience deters all potential muggers.  Waterproof, costing only a few pence, with the option of additional cotton wool for extra authenticity: an attractive little black plastic bag with yellow drawstring, as commonly carried by dog walkers.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Threats, risk and attacker motivation: a real life example appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2013/12/threats-risk-attacker-motivation-real-life-example/feed/ 0
If it’s not malware it should be http://tomorrowstransactions.com/2013/08/if-its-not-malware-it-should-be/ http://tomorrowstransactions.com/2013/08/if-its-not-malware-it-should-be/#respond Thu, 15 Aug 2013 14:22:35 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2013/08/if-its-not-malware-it-should-be/ Trying to google medical information on my phone about a pain in the backside turns out to be another pain in the backside.

The post If it’s not malware it should be appeared first on Tomorrow's Transactions.

]]>
[Jane Adams] I’ve got a sore back. Or to be more precise I’ve got a sore tail bone. I don’t know whether it’s from being thrown in a fight or from the amount of time I spend on trains commuting between home (Edinburgh) and work (Guildford) but sitting down has been painful recently. Last night I felt moved to Google the problem on my phone to see what could be done.

Google did its job with a multiplicity of results. But I couldn’t access any of them because my MNO blocked them all as adult content. I didn’t use *rse or b*m as search terms but anything below the waist appears to be out for this MNO.

What I was presented with was a tiny, barely legible (even on my Samsung S3), barely branded screen asking me to input my credit card details to prove that I was old enough to read about what is probably age-related spine degeneration.

On an Android phone? You must be kidding.

And why is this necessary? I have an account with my phone provider (one of the big 4). I’ve had a business account with my phone provider for something like 10 years. Until recently, when I got my proper job with Consult Hyperion, I was VAT registered and the MNO had that information in its system. If, as the phone owner, I’m old enough for a VAT registration, I’m old enough to read about bottoms. And if I’m not the venerable phone owner and I’ve nicked their phone, I’ve probably nicked their credit card too.

There’s a lot of talk about big data at the moment. Proper use of data could considerably improve the prospects for mobile wallets. However if this is indicative of what mobile operators are doing with data, I’m not optimistic.

Frankly, I rather hope that the screen was malware generated rather than genuine.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post If it’s not malware it should be appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2013/08/if-its-not-malware-it-should-be/feed/ 0
Mobile money in the UK http://tomorrowstransactions.com/2013/06/mobile-money-in-the-uk/ http://tomorrowstransactions.com/2013/06/mobile-money-in-the-uk/#respond Wed, 12 Jun 2013 09:18:17 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2013/06/mobile-money-in-the-uk/ Despite mobile money’s success in developing markets, it’s well suited to use closer to home.

The post Mobile money in the UK appeared first on Tomorrow's Transactions.

]]>
[Paul Makin] When you use the term ‘mobile money’, your audience generally assumes you are referring to the phenomenon of mobile phone-based money transfer schemes in emerging markets, in particular its poster child, M-PESA in Kenya.  And there’s good reason for this; most press about mobile money focuses on emerging markets and if you visit the GSMA’s Mobile Money Tracker (http://www.mobileworldlive.com/mobile-money-tracker), it lists a large number (182 at the last count) of mobile money deployments around the world, all of which are in the emerging markets of Latin America, Africa, and South and Southeast Asia.

This may be because the data is supplied by the GSMA’s Mobile Money for the Unbanked (MMU) team and focuses on the community that the MMU team engages with, so perpetuating the view that mobile money is exclusively an emerging market phenomenon – a view that I disagree with, if not in actuality, certainly in potential.

Consider what constitutes a mobile money scheme:

·         Customers’ access to their account, for carrying out transactions or for managing their account, is primarily through the medium of the mobile phone;

·         Cash can be deposited and withdrawn via the intermediary of human ‘agents’ in local shops;

·         Cash can (sometimes) be withdrawn at ATMs;

·         Transactions are fast, and tariffs are low;

·         Registration is simpler and faster than for a local bank account.

In addition, it is fair to say that mobile money schemes are generally aimed at the unbanked market – that is, people who are unable to access traditional banking services, however basic – but I would argue that that is a characteristic of the available, under-served market, rather than any law of nature.

The dramatic growth of mobile money services in the emerging markets is a consequence of the huge size of the unbanked market in those countries, coupled with the launch of services that provide them for the first time with readily accessible basic financial services.

But there are mobile money services elsewhere, and they certainly occur in the so-called emerged markets. In the UK, for example, we have seen a number of such services being launched in recent years. A prime example is O2 Money, launched in Q2 2012. This has all of the characteristics of a mobile money scheme, as described earlier, but with one important extension to ensure its applicability to the British way of living – it has a companion card, a plastic card which allows O2 Money to be spent in shops, and which can also used for ATM withdrawals.

It must be said, though, that none of the schemes in the emerged markets have broken through in quite the same way that M-PESA has in Kenya. This is principally due to the differences in the markets. As an example, in the UK (as in other “developed” countries), people with a bank account can access the services offered by mobile money using cards on line or in person and most have access to mobile banking.

So people with UK bank accounts are unlikely to be regular users of a mobile money scheme, and therefore a strategy needs to be developed to recruit customers that offers something beyond the basic financial services. I am of the firm belief that such a strategy can be developed, and that a successful strategy would embrace elements aimed at three different groups: the mainstream banked; the not yet banked (teenagers); and the unbanked (the poorer sections of society).

The mainstream banked will be the most difficult to attract, and the key here will be differentiators from the mainstream banks’ offerings.  As mentioned above, mobile money offers little advantage to them.

The not yet banked are a slightly easier proposition –almost all of them have a relationship with a mobile phone operator, and are very familiar with buying things with their mobile phone. A proposition is required to meet their needs, by incorporating elements such as entertainment tickets (discounts are the key) and products linked to stadiums and venues (such as closed loop payments), and the option of a companion plastic card is essential.  But ultimately, whether or not this supports an attractive business case is another matter.

But the UK unbanked are a proposition with great potential.  There are around 1.25 million unbanked households in the UK[1], equating to around 4.5 million unbanked individuals. There is a real need here, and the unbanked could form a valuable element of a broader model for a mobile money operator. And you can bet that, in modern Britain, the vast majority of these people have a mobile phone.

To those who would say that the unbanked have no money, and cannot therefore be of interest, I would point out that, in common with poor people the world over, they pay significantly more for financial and other services than any other segment: fuel, cheque cashing, and short term loans are all examples of the amount such people are forced to pay for services that the mainstream gets either for free or at very low cost.

At the core of any unbanked proposition must be the facilitation of social payments. The majority of social payments in the UK (including pensions) are delivered directly to bank accounts, and in a cost-efficient manner that is at least competitive with any mobile money offering. However, the 4.5 million unbanked recipients receive their payments by alternative means, and at significant expense to the UK Government. Giving these recipients a mobile money account, and facilitating these social payments, should be at the core of any strategy.

Access to cash is also an issue. In many of the poorer areas of the UK bank branches have been closed, and the only ATMs that remain are private ones in small shops that typically charge around £2 for a withdrawal. By adopting the agent approach of emerging markets, access to cash from the mobile money account would be greatly facilitated, and drive additional revenue into the local community.

By definition, unbanked people do not have access to the conventional banking system, and there is an opportunity for a mobile money operator to facilitate that access and so enhance their own proposition. Basic functionality, such as direct debits, should be offered in order to address, for example, fuel poverty (if you cannot pay for fuel – gas and electricity – by direct debit in the UK, you will be paying a lot more for the fuel you use). Another aspect of being unbanked is the lack of access to loans at reasonable cost (hence the controversial rise of the so-called ‘payday loan’) – there is an opportunity for a mobile money operator to create a portfolio of relevant of financial services for their customers here, in which partnerships could be formed with local organisations, such as credit unions, in order to promote savings and loans.  I am sure there are lessons that can be learned from the experiences of microfinance institutions (MFIs) in the emerging markets.

In summary, I do not believe that mobile money is exclusively a phenomenon of the emerging markets. There are significant populations in developed markets that closely match the characteristics of mobile money customers in the emerging markets, and there is a clear opportunity for the right mobile money propositions.



[1]Defined as households without access to a bank account – savings accounts are excluded.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Mobile money in the UK appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2013/06/mobile-money-in-the-uk/feed/ 0
Finovate Europe http://tomorrowstransactions.com/2011/02/finovate-europe/ http://tomorrowstransactions.com/2011/02/finovate-europe/#respond Thu, 03 Feb 2011 22:24:48 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2011/02/finovate-europe/ [Dave Birch] The first Finovate in London was a big success.

 

The post Finovate Europe appeared first on Tomorrow's Transactions.

]]>

I really enjoyed the first Finovate Europe in London. We had an excellent couple of days, because we had BarCampBankLondon the day before (I’ll write something about it later), and lots of folk came in for that too.

Although it was in London, three of the UK’s four biggest banks had just one person at the event. Three of the others didn’t send anyone at all. Barclaycard and Santander sent six each. Hmmm. Perhaps the others are just being careful with taxpayers’ money. I wish the head of eBusiness from my bank had been there.

[From Some Observations From Finovate Europe | Forrester Blogs]

To be completely honest, I was looking at most of the presentations in horribly mercenary terms: asking only which of our clients might be able to exploit this? As a consequence, I wasn’t really grabbed by what one of my fellow delegates called the “wheelspinning” around personal financial management (looking at pie charts of your overdraft and that sort of thing). Our space is the secure electronic transaction space, so I enjoyed the presentations from our friends at SecureKey and VoiceCommerce. It’s that kind of thing that is hot, I think. I’m going to find out more about Miicard as well.

I liked the StockTwits presentation, which probably combined innovation in technology and innovation in business model in the most interesting way, targeting a specific niche in an engaging way. There’s a lesson for me here: if I used Twitter for something more than moaning about South West Trains, I could have been a contender. Boku were great and so were Ixaris: I understand what they are trying to do in payments and I’m sure that both of them will succeed. None of my picks made it in to the delegate’s top three in the final vote, but I’m happy to stand alone.

All things considered it was a super day, an excellent opportunity to connect with clients and colleagues, and an energising look around the space. Jim and all of the chaps should be very happy with it.

The presentation that I probably thought about the most after the event, though, was the one from Fidor Bank. They have integrated a variety of alternative currencies into their online banking platform. These are presumably attractive to German consumers fleeing the euro, with folks memories of hyperinflation pushing them toward non-fiat stores of value.

The partnership will enable Fidor’s customers to buy gold, silver, platinum and palladium without completing any GoldMoney application forms. Orders will be processed daily through the FidorPay Account at the bank and then placed with GoldMoney through an ‘Omnibus-Holding’ in the name of Fidor.

[From Finextra: Germany's Fidor Bank to offer retail access to precious metals via GoldMoney]

If you want to find out more about GoldMoney, forum friend James Turk, their CEO, will be at this year’s Digital Money Forum. Although only precious metals are live at the moment, Fidor are planning to integrate virtual currencies the future. I didn’t get a chance to talk to them to find out what the mechanism for this is: as far as I know there’s no API for accessing your Everquest platinum (or, literally, a payments wizard) so it would have to be done using screen scraping with usernames and passwords, just as it is for other services with no security (eg, banking).

I’m naturally fascinated to see how customers respond to this. If you can shift from euros to gold to World of Warcraft gold in a simple and friction free way, then we might see some interesting markets emerging.

These are personal opinions and should not be misunderstood as representing the opinions of
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Finovate Europe appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2011/02/finovate-europe/feed/ 0
Making credentials practical http://tomorrowstransactions.com/2011/02/making-credentials-practical/ http://tomorrowstransactions.com/2011/02/making-credentials-practical/#respond Tue, 01 Feb 2011 11:10:39 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2011/02/making-credentials-practical/ [Dave Birch] We’re a long way from having an infrastructure that can help with educational and resume credentials, although we can see how one might work, I think.

 

The post Making credentials practical appeared first on Tomorrow's Transactions.

]]>

When I’m talking about identity, I sometimes joke that our ill-thought out perspectives on the topic have led to the bizarre situation that in the UK it is much easier to get a job with a bank than an account. In The Daily Telegraph for 29th January 2011, I read under the headline “False CV Fooled Bank” that:

A fraudster used a false CV [claiming degrees from Oxford and Harvard] to gain a £165,000 per annum job at a City investment bank.

I assumed that everybody made up stuff on their resumes, but it turns out that it’s against the law, so the culprit, Mr. Peter Gwinnell, was prosecuted and given a suspended sentence (I assume he’ll skip over this on his next CV). We keep being told that employers use Facebook profiles nowdays (I hope they use mine: it says that I am the most intelligent person alive today and that Nelson Mandela queued for my autograph) so perhaps CVs will soon be a thing of the past. Just out of curiosity I googled Mr. Gwinnell and found that as well as his empty LinkedIn profile, the bald fact of his departure is there on the web.

PETER GWINNELL Appointment terminated as director on 15 Feb 2010 (Document)

[From AHLI UNITED BANK (UK) PLC of W1H 6LR in LONDON UNITED KINGDOM]

To be honest, if an employer wanted proof of my A-Level in Mathematics or O-Level in British Constitution or the Degree I scraped through with in 1980, I’d be hard pressed to provide it. I don’t have the faintest idea where the relevant certificates are. I suppose I could ring the University and ask them to send me a letter, but how would the employer know I hadn’t forged the letter. And how would Southampton University know that it is me calling? Or, for that matter, how would they know that I hadn’t forged the O-Level in British Constitution certificate?

When I started my first job after university, I don’t remember being asked to provide any such proof. Come to that, I don’t remember being asked to prove who I was either. In those days, all you needed was a national insurance number. But if employers are going want proof, like the actual certificates, then there will be a bit of a premium on the certificates. Once the certificates are worth something, they will be stolen. This is what happens in China.

Local officials said the files were lost when state workers moved them from the first to the second floor of a government building. But the graduates say they believe officials stole the files and sold them to underachievers seeking new identities and better job prospects — a claim bolstered by a string of similar cases across China.

[From Files Vanished, Young Chinese Lose the Future - NYTimes.com]

How are we going to deal with this digitally? It shouldn’t be that complicated for Harvard to create a digital certificate to attest to the fact that the owner of a particular identity did, in fact, graduate. If there were some sort of device or token, perhaps some form of card, that contained my educational identity (ie, key pair) then Harvard could simply sign the public key with their private key and the whole problem is fixed (glossing over, of course, where this device or token might come from, and so on).

Something does have to be done though. The current system is simply a joke. It’s quite funny when someone cons a bank into giving them a senior position despite knowing nothing about banking (imagine!) but one of the areas that really bothers me, and probably should bother you too, is the ease with which medical credentials are forged.

A conman from Lancashire who posed as a vet and nearly killed a pony by botching its castration has been jailed for two years. Russell Oakes also masqueraded as a doctor, carried out an intimate examination and charged for false diagnoses, Liverpool Crown Court heard. The 43-year-old, of Hesketh Bank, admitted 41 charges of fraud, forgery and perverting the course of justice.

[From BBC News - Bogus Lancashire vet jailed after botched castration]

How did he do this? Was he a master forger, capable of producing an authentic-looking medical school diploma using specially-aged paper, his engraving skills and authentic ink procured from the correct German manufacturer? No, of course not: this is a post-modern crime.

He bought a fake university certificate off the internet, the court heard.

[From BBC News - Bogus Lancashire vet jailed after botched castration]

Now imagine an alternative infrastructure. I am asked to prove that I have a degree from Southampton University. I log on to the university using my OpenID id.dave.com and answer some questions, provide some data, to satisfy the university that I am, indeed, the relevant dave. My OpenID profile includes a public key, so the university creates a public key certificates, signing that key and some standard data that they provide. I can now give this certificate to anyone, and they can check it by verifying the signature using the published Southampton University public key, resolving the certificate chain in the usual way.

the BBC suffered another embarrassment today after a man interviewed on Radio 4′s World at One who claimed to be a Liberal Democrat MP was revealed to be an imposter.

[From Radio 4 follows Jeremy Hunt gaffe by interviewing fake MP | Media | guardian.co.uk]

How would the proposed infrastructure help here? The system has to be so easy to use that a harassed BBC researcher can use it. Come to that it has to be so easy that military installations, the police and other can use it too.

During the period of January to June 2010, undercover investigators utilized fraudulent badges and credentials of the DoD’s military criminal investigative organizations to penetrate the security at: 6 military installations; 2 federal courthouses; and 3 state buildings in the New York and New Jersey area

[From Schneier on Security: The Security Threat of Forged Law-Enforcement Credentials]

Step forward the mobile phone. Every single one of the people who were “verifying” IDs in these stories has a mobile phone, so there’s no need to look any further. The military policeman’s mobile phone should be able to check your ID. And your mobile phone should be able to check his ID. And if you’re both using mobile phones, both IDs can be checked simultaneously. We already know that symmetry is an important property of an identity infrastructure: the bank needs to be able to check it’s me, but I need to be able check it’s the bank. And the mobile phone can do both. So next time Peter shows up for an interview, the interviewer can simply tap Peter’s NFC phone against their NFC phone and see a full list of his credentials.

(Law enforcement has special additional issue though: sometimes, the policeman doesn’t want to reveal that he’s a policeman, but that’s a topic for another day.)

These are personal opinions and should not be misunderstood as representing the opinions of
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Making credentials practical appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2011/02/making-credentials-practical/feed/ 0
Apple and NFC, a strawman http://tomorrowstransactions.com/2011/01/apple-and-nfc-a-strawman/ http://tomorrowstransactions.com/2011/01/apple-and-nfc-a-strawman/#comments Sun, 30 Jan 2011 17:28:04 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2011/01/apple-and-nfc-a-strawman/ [Dave Birch] Are Apple really planning to use iTunes for retail payments? Possibly, but not because they want a payments business.

 

The post Apple and NFC, a strawman appeared first on Tomorrow's Transactions.

]]>

WIth Apple’s domination of media mindshare almost total, the fact that you can already buy other handsets with NFC in them (eg, the Google Nexus S and the Nokia C7, although both are currently software-limited) and that the first Blackberry handsets are imminent has been overlooked. All press comment (I know, because I contributed to some of it) has been about the iPhone. One of the questions that I was asked, repeatedly, was about iTunes morphing into a new payment scheme.

“They have 160 million users with digital wallets in iTunes accounts. They don’t have to do anything other than to NFC-enable their phones,” Litan said.

[From Analysts: Apple could disrupt mobile payment industry | BappProducts | iOS Central | Macworld]

They do have numbers on their side, that’s true. But as we all know, payments is a two-sided market, so there has to be a reason for the merchants to get on board too.

For merchants, an Apple payment system could prove attractive. Many merchants are raring for alternative payment systems, to avoid having to pay the hefty fees that credit card companies charge for every transaction.

[From Analysts: Apple could disrupt mobile payment industry | BappProducts | iOS Central | Macworld]

Yes, but how will Apple avoid them? Everything I buy on iTunes goes to my MasterCard. Sure, Apple aggregates the payments, but the banks don’t provide this service for free, even for Steve Jobs. In order to avoid having to pay credit card fees, Apple would have to do what PayPal does and start persuading people to sign up with their bank account details, which would in turn mean building the kind of anti-fraud platform that PayPal have been building for a decade. And why would they do that? It seems like a lot of non-core investment to commit to.

This investment is needed because the biggest problem will be security. So long as my iTunes password only allows you to buy music tracks for my iPod or games for my iPad or note-taking applications for my Macintosh, to risk is manageable. But if my iTunes password allows you to walk out of a store with a pair of shoes or a telly, then my iTunes password will become valuable. Microseconds after extending iTunes payments to retail stores, Apple would be dealing with millions of customers calling up because their passwords had been phished, copied, guessed.

Japanese police have arrested two people suspected of stealing virtual goods from players of online game Lineage II. The pair tricked victims via a booby-trapped program that claimed to help people play the game. Instead of boosting a character’s abilities the program stole account names and passwords.

[From BBC News - Lineage II pair arrested for stealing virtual goods]

I’m sure Apple are perfectly well aware of this kind of crime and know that were iTunes to become a general payment paltform, then it would become widespread. This is hardly wild projection, since the phishing of iTunes accounts is already widespread.

It least one group of scammers has found a way to charge thousands of dollars to iTunes accounts through PayPal. One targeted customer told us, “My account was charged over $4700. I called security at PayPal and was told a large number of iTunes store accounts were compromised.”

[From Fraudsters Drain PayPal Accounts Through iTunes]

I’m sure Apple already has lots of people working on this problem but ultimately it’s very difficult to stop people from giving away their passwords and I’m sure the phishers will soon learn to send out the right kind of e-mail messages.

Roughly 50,000 Apple iTunes accounts stolen by hackers are said to be for sale on China’s largest auction site.

[From 50,000 Stolen iTunes Accounts On China Auction Site -- Apple iTunes -- InformationWeek]

The underlying problem is, of course, that passwords are not security and no-one should be allowed to use the phrase “password security” in any serious context. So long as the cost of phishing, guessing or actually breaking passwords is fantastically less than the value of the account that they give access to, there is no solution.

Thomas Roth of Cologne, Germany told Reuters he used custom software running on Amazon’s Elastic Compute Cloud service to break into a WPA-PSK protected network in about 20 minutes. With refinements to his program, he said he could shave the time to about six minutes. With EC2 computers available for 28 cents per minute, the cost of the crack came to just $1.68.

[From Researcher cracks Wi-Fi passwords with Amazon cloud • The Register]

Ah, you might say, but suppose Apple implements a Secure Element (SE) for NFC and that SE uses standard PKI applications on industry-standard Global Platform in an industry-standard JavaCard. Then a thief would have to steal the iPhone as well as the password, and this indeed true. Apple could implement an identity-based payment mechanism and persuade merchants to install the contactless terminals, implement the new scheme and pay Apple instead of paying the banks (whose fees have just been capped by the Durbin amendment.

Again, why bother. You may as well do a deal with a bank to put a contactless EMV application in the SE. But suppose you are not going to care about anything at retail POS — except in your own stores — but instead want to improve security and convenience for customers in general? Imagine this scenario a year from now: I log in to iTunes and it gives me the option of switching to two-factor authentication. (Apple wouldn’t call it that, they have better marketing people – suppose they call it Apple Passport or something like that, maybe iMe or whatever.) I accept. From then on, when I log in to iTunes on my iPhone, I don’t noticed anything different, but under the hood iTunes is sending a digitally-signed challenge to a digital signature application in the SE. It’s decoded using Apple’s public key, and signed using my public key (which, of course, Apple know) and sent back. Sorted. Now with this strong authentication, Apple can have higher-priced items for sale via iTunes. When I log in on my PC, a message pops up on my iPhone and I have to enter my passcode. Under the hood, the same process. Now you have to steal my passcode and my iPhone.

A little later, I’ll be given the option of making my OSX login “iMe only” and so on.

If anyone can bring PKI to the masses, Apple can. Soon, other companies will negotiate with Apple to join “iMe Connect” and because it is more secure than a password, they will pay to use it. There are payments applications for this (it means that mobile payments can be lifted beyond ringtones and music tracks, and at a lower margin than operators) but I don’t see them as being central to the business proposition, because people will be using their iPhone to log in to everything (internet banking, shopping, government) and then, because of the NFC interface, they will begin to use it to “log in” in Apple retail stores and then, soon, enough, other places. Meanwhile, credit cards and Bling, Amex and PIN debit will all be loaded into the SE anyway, so customers will find themselves using their iPhones to get on BART and pay in CVS. This will save the issuers money, because they don’t need to issue the plastic, so they can offer a good deal. Andrew Johnson was surely right to point this out in American Banker.

In the end, banks have a lot to gain by being willing to give pricing concessions to Apple in exchange for getting their payment card information directly located in Apple’s mobile wallet service. Doing so could give those banks a first-mover advantage.

[From In Apple Mobile Pay Plans, a Possible Opening for Banks - American Banker Article]

Apple doing the identification and micropayments, leaving larger payments to the finance sector who will in turn pay Apple. Now we can see the real play, and a first-rate strategy for the next phase of online evolution: own identity and authentication. ITunes as a payment scheme to rival cards, PayPal, iDeal? No. iTunes as a payment scheme to get people used to logging into things with their iPhones? Plausible. iTunes as something that delivers a variety of customer communication and management option of real value to merchants (a cross between Barclaycard Freedom, Bling and Taggo)? Yes. Why? Because knowing who someone is is so much more valuable than a small slice of their payments, a fact that informed industry observers have pointed to since the Apple/NFC rumourmongering began.

the real revenue streams to Apple will not be from “interchange” but from advertising as iAD provides the “Yang” to the NFC’s “Ying”. Creating a new payment ecosystem means having incented partners. The timing on Apple’s iAD and NFC developments are not accidental, my belief is that they are part of a very solid mCommerce expansion strategy.

[From Apple’s NEW NFC Patent « New Ventures in Financial Services]

Look, I don’t know what Apple’s strategy is any more than you do, but from the perspective of helping clients to formulate their own broad strategies for NFC, payments, value-added payment services and identity, this is a reasonable strawman, which is why we’ve been using it.

These are personal opinions and should not be misunderstood as representing the opinions of
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Apple and NFC, a strawman appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2011/01/apple-and-nfc-a-strawman/feed/ 1