Tomorrow's Transactions » crime http://tomorrowstransactions.com Thought leadership from Consult Hyperion Fri, 18 Jul 2014 06:22:13 +0000 en-US hourly 1 http://wordpress.org/?v=3.9.1 Crime and contactless http://tomorrowstransactions.com/2014/06/crime-and-contactless/ http://tomorrowstransactions.com/2014/06/crime-and-contactless/#comments Fri, 06 Jun 2014 17:49:50 +0000 http://tomorrowstransactions.com/?p=4476 Just because there isn’t any contactless crime does not mean that we should ignore the fears of consumers (or, for that matter, the police). Time for some mass market education on cuddle cards, as I now call them. Although we don’t focus on it — by and large because it works and has become business […]

The post Crime and contactless appeared first on Tomorrow's Transactions.

]]>
Dgwb blog white border

Just because there isn’t any contactless crime does not mean that we should ignore the fears of consumers (or, for that matter, the police). Time for some mass market education on cuddle cards, as I now call them.

Although we don’t focus on it — by and large because it works and has become business as usual — I think that contactless payment technology is fun. I had an enjoyable couple of days trying out my usual panoply of cards, phones, watches and stickers when I was last in Canada and I have to report that the situation was all systems go (except for one of my UK MasterCards that was inexplicably declined) whereas in the US it remains mixed. Meanwhile, it’s going gangbusters down under, as I discovered on my last trip to Australia. I paid with cards everywhere, and almost everywhere I paid I paid with contactless. Like in this taxi, for example.

Untitled

Unfortunately, the Aussie rousers are less enthusiastic than I am about the amazing technology, the rapidly-evolving Australian retail payment environment, innovation at point of sale and quick and easy transactions for consumers. They claim, in fact, that there is wave, plague and apocalypse of crime that can be directly attributed to the new technology.

“We’re seeing many, many theft of motor cars, handbags and burglaries where people are looking for these cards, are getting hold of them and within hours of getting them, they’re going into stores and using them.

[From Tap-and-go credit cards contributing to increase in crime stats, Victoria Police says - ABC News (Australian Broadcasting Corporation)]

This is, if true, rather interesting. I say “if true”, of course, because I have been unable to uncover any statistics that back up the Victoria police claim. Nor, it seems, have any of their fellow law enforcement agencies.

Police around the country have differing views on the effect the cards are having on burglaries. The NSW Police said it had “not seen a spike in credit card related fraud since the advent of contactless payment technology”.

[From Banks stare down police over tap-and-go]

Still, this tidal wave of contactless crime must surely have shown up in the bank fraud statistics.

One of the major banks said on Thursday it had 30 per cent more ­contactless cards in the market compared with a year ago but card fraud was flat.

[From Banks stare down police over tap-and-go]

Oh well. Let’s just assume for sake of argument that there is a crime wave, plague and apocalypse but only in Victoria and only amongst issuers who do no collect or report card fraud statistics. That still sounds like a bank problem to me, since issuers will bear the losses. If a mugger demands my contactless card then I will give it to him. I couldn’t care less since it’s not my problem: the UK banks have an unequivocal guarantee to refunds unauthorised transitions. Nevertheless, the Melbourne heat seem most upset about contactless in general and especially miffed that they were not one of the stakeholders consulted in the banks’ roll-out.

he said police were not consulted before tap-and-go credit cards were introduced and that he regretted their introduction… “They are chewing up an enormous amount of police resources.

[From Tap-and-go credit cards contributing to increase in crime stats, Victoria Police says - ABC News (Australian Broadcasting Corporation)]

The crime wave, by the way, does not seem to have affected public confidence, since contactless use continues to soar. It is at very high levels in Australia already, with more than two-third of supermarket transactions already tap and go. Use amongst police chiefs, so far as the statistics presented in the article would indicate, seems particularly high.

Mr Lay did admit he used a tap-and-go card all the time.

[From Tap-and-go credit cards contributing to increase in crime stats, Victoria Police says - ABC News (Australian Broadcasting Corporation)]

Aha. I should point out, by the way, that the Victorian peelers objections to contactless go back some time. They’ve always been uncomfortable with contactless.

Police want to ban banks’ tap and go technology after vowing to take on big business over sloppy work practices. The force said it is sick of “mopping up” for “totally slack” initiatives that it states encourage crime.

[From Police want ban on tap and go technology, saying sloppy practices can promote crime | Herald Sun]

We have to address real issues, of course, but the fact is that public perception around contactless is not always rational. That Australian story was widely reported in the British press, fuelling public concerns (I have made a fascinating podcast with Karen Williams from Spectrum Insight on this topic). The British press have, it seems to me, always been rather keen on these scare stories. See this hilarious comment on a Daily Mail story about contactless.

It is well known that in America, thieves carry tablets and electronic readers in bags, walk around railway stations and shopping malls and scoop up all data automatically from these cards.

[From Customers charged twice for items because contactless cards were activated from their pockets | Mail Online]

Really? “Well-known”? If anyone can point to me a single reputable report of this ever happening, I would be grateful as I would like to link to it and continue the investigation. Far from being “well-known” I frankly doubt that it has ever happened at all. If you jammed an electronic reader up against my arse on the Tube, and kept it there undetected long enough to scan my card (I only have one in London wallet – haven’t you ever heard of card clash) then you would not get my name or the CVV for the card, so it’s not much of master crime. You can’t use the data to make a clone card and you can’t use it to buy online. Neverthess, as the analysis of contactless sentiment I discussed earlier in the week show, just because something doesn’t happen does not mean can ignore it. If consumer believe it, then we must deal with it.

I think we as an industry should probably be reacting to the “fear” area with some pretty clear messaging around how the technology works, how liabilities are distributed and the consumer protection that the combination provides.

[From Contactless sentiment - Tomorrow's Transactions]

The traditional way of educating the mass market in the UK about anything is to pester the BBC to include it as an EastEnders story line. I shall come back with some ideas soon, but since I haven’t watched EastEnders for at least a decade, it may take some research to get a viable narrative.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Crime and contactless appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2014/06/crime-and-contactless/feed/ 4
Card crime and nostalgia http://tomorrowstransactions.com/2013/12/card-crime-and-nostalgia/ http://tomorrowstransactions.com/2013/12/card-crime-and-nostalgia/#respond Mon, 23 Dec 2013 13:35:31 +0000 http://tomorrowstransactions.com/?p=2895 In America, card fraudsters are wrapping satellite dishes in tinfoil to stop terminals from going online and then using counterfeit and stolen cards to buy gas. Amazing! I had no idea that people still used satellites for this sort of thing. I was flabbergasted to read in the September ISO & Agent magazine that “Crooks […]

The post Card crime and nostalgia appeared first on Tomorrow's Transactions.

]]>
Dgwb blog white border

In America, card fraudsters are wrapping satellite dishes in tinfoil to stop terminals from going online and then using counterfeit and stolen cards to buy gas. Amazing! I had no idea that people still used satellites for this sort of thing.

I was flabbergasted to read in the September ISO & Agent magazine that “Crooks wrap parts of satellite dishes in cooking foil to stymie data transfer and then use bogus cards to ‘purchase’ gasoline” — Heun, D., “Foiling Tin-Foil Thieves” in “ISO & Agent”, p.99 (Sep. 2013). I had absolutely no idea that people still used satellite links for this kind of thing! The story triggered a wave of nostalgia for me because the first IT project I ever worked on for banks involved satellite connections. So gather round the yule log and listen to my tale…

Cast your mind back to 1982. The interweb tubes are a distant dream. Meanwhile, in Indonesia, a group of talented young men (for they were all men) are writing computer programs to run on the world’s first regional satellite system, the Palapa-B1 service (a Hughes HS376, for the technical, with 24 C-band transponders). One of these dashing you software engineers — for it was, indeed, me — was tasked with writing initially the (and here’s one for the teenagers) X.28 code and then the X.25 code to allow (amongst other things) bank terminals and other equipment to connect via the satellite network to allow communications between bank branches on far flung islands throughout the Indonesia archipelago and bank offices in Jakarta and elsewhere. You couldn’t buy communications software for the processors we were using. You had to write it from scratch. If you tell the young people of today that, they won’t believe you.

Indo83 3 

We were working at a telecoms supplier’s site in Bandung. I know it doesn’t look much from the outside.

A Japanese team were building the baseband modems and implementing the Aloha link protocol that had originally been invented for Alohanet. This gave me the primitives to work with to implement the CCITT protocols on top. X.28 was the protocol for character input/output (using to connect terminals across a network to mainframes) and X.25 was the packet-switching protocol for interconnecting computers. I still think of terminals at DTEs (Data Terminating Equipment) and I still think of networks as DCEs (Data Circuit Terminating Equipment). All of these quaint terms vanished from the pages of history about a week after TCP/IP was invented.

Indo83 

As you can see, inside we had access to many modern facilities.

Implementing X.28 meant that staff could log on to bank mainframes using terminals in the branches. Implementing X.25 meant that remote minicomputers could interconnect. Getting the code to work, and getting it to work quickly enough, and getting it to work in the limited memory available was a fantastic education.

Indo83 2 

Here I am making a few small adjustments to the communications processors boards.

It was here I learned all my UNIX tricks and C programming stunts. Those were the days when if you didn’t like the way that the team wrote code you could quickly knock up a parser to force them into line (which one of my colleagues did, using YACC), when you had to pretend to the system administrator that you didn’t have root access (which we all did) and when the disk packs held 5Mb so you had to be very careful with the space available (wipes tear from eye).

 Indo83 1

As you can see, the team really appreciated my mad programming skills and their contribution to the great success of the project.

A few years later, I worked on a similar system using VSAT terminals in K-band (too much information, ed.) for a US telecommunications provider, one of Consult Hyperion’s first US projects. In those still pre-internet days, if you wanted to get data from a branch office back to HQ reasonably quickly you had to pay for a leased data line from the phone company, which was very expensive. Putting a satellite terminal on your roof was a cheaper alternative and as the frequencies went up from C- to Ku-based, so the dish sizes came down. The cost of installing and maintaining a six foot dish compared very favourably with the costs of leased lines.

I remember that one of the users of the system was a chain of car dealerships who had come up with a tremendously clever business case. When a customer came in to buy a car, the dealership would use the new satellite network to instantly credit check them. If they had good credit, they would be offered dealer credit. If they had bad credit, they would be referred to the local bank. Nice one. 

In the late 1980s and very early 1990s, I enjoyed working on a wide variety of projects around satellite data communications. I worked on technical architectures, system designs and even on regulation in a team with the now-infamous Vicky Pryce (who was then chief economist at KPMG, and who I remember as a very impressive and really clever, but also really nice person). Hence my nostalgia for the days of link budgets, low-noise blocks and data broadcasting.

What’s kind of weird now is that the stuff we used to send via satellite (TV, data) now comes into my house by fibre optic cable (another technology that destroyed part of my life’s work, as life as a Physics undergraduate included months spent working on a dissertation about gas lenses for lasers) and the stuff that we used to send by cable (phone calls) now comes into my house via wireless.

Ah, the good old days.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Card crime and nostalgia appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2013/12/card-crime-and-nostalgia/feed/ 0
So many people miss the point about Bitcoin http://tomorrowstransactions.com/2013/12/so-many-people-miss-the-point-about-bitcoin/ http://tomorrowstransactions.com/2013/12/so-many-people-miss-the-point-about-bitcoin/#comments Thu, 19 Dec 2013 13:49:02 +0000 http://tomorrowstransactions.com/?p=2842 Some of what is reported about Bitcoin, even in reputable journals of record is, frankly, mad. The media is missing the most interesting aspect, which is the technology. Here’s a typical example of media comment on Bitcoin that makes little sense to me. The article was labelled “Mastercard Hates Bitcoins” which, I think, is at […]

The post So many people miss the point about Bitcoin appeared first on Tomorrow's Transactions.

]]>
Dgwb blog white border

Some of what is reported about Bitcoin, even in reputable journals of record is, frankly, mad. The media is missing the most interesting aspect, which is the technology.

Here’s a typical example of media comment on Bitcoin that makes little sense to me. The article was labelled “Mastercard Hates Bitcoins” which, I think, is at minimum an exaggeration.

The new boss in charge of giving out a MasterCard licenses has no intention of allowing the brand or any bank that does private label cards to use Bitcoins. In fact, he nearly bragged to me about killing the BitInstant deal with a U.S. bank for the first planned $BTC card this year.

[From Mastercard Hates Bitcoins]

The Bitinstant deal that is referred to here is something mentioned in a couple of presentations earlier in the year.

Exchange service BitInstant is reportedly planning to bridge the gap between the digital world of Bitcoin virtual currency and the real world of debit/credit card payments. An unconfirmed source from the company has revealed that BitInstant is in the final stages of creating a Bitcoin card that will also function as a standard international MasterCard.

[From BitInstant to Bridge Virtual, Real Currencies with Bitcoin Credit Card]

I have to say that it is not obvious why, or how, MasterCard could stop a bank from accepting Bitcoins if it wanted to. In fact I there is one MasterCard-issuing bank that already does, which is Fidor. The idea that is behind the old BitInstant deal that is being referred to here is that a bank might want to issue a US$ MasterCard that is connected to a Bitcoin Wallet. Conceptually this is no different to the way my Simpleaccount works. My Simple account is a prepaid Visa card connected to a share of a bank account somewhere. So my BTCard (or whatever it might be called) would be a prepaid US$ MasterCard connected to a share of a Bitcoin wallet somewhere. The only difference is that where my Simple card spend converts at par to debits on the bank account, my BTCard spend would convert at the prevailing exchange rate to debits on the Bitcoin wallet. And it would still obtain interchange on the transaction. The volatility might be a problem, in terms of working out which price to use and when to apply it, but it’s not a conceptual problem.

Bitcoin’s backers admit that there is some inherent risk to the electronic currency. After all, there is no FDIC for Bitcoin. It’s also volatile: In the last 30 days, the value of a Bitcoin in U.S. dollars has ranged between $7.58 and $15.40.

[From Get ready for BitInstant's Bitcoin debit card - Aug. 22, 2012]

I don’t understand why MasterCard would care about this. I mean, I know why they don’t care about it in practice (because the retail spend on Bitcoins is so tiny – most Bitcoins are hoarded) but I wonder if they care about it at a conceptual, policy and strategy level? I’m not saying that they shouldn’t care about it, by the way. They should. But not as the (n+1)th currency in the world. They might, for example, want to look at using something Bitcoin-like as a backbone for the new remittance business that they have just acquired from our friends at eServGlobal, HomeSend. I remember Consult Hyperion doing a study some years ago on using digital money as an international backbone for internal use for a large foreign exchange business that wanted to minimise cross-border bank transfers to settle between currencies and it looked pretty good. The newspapers look at Bitcoin for retail payments, especially for drugs and such like, but it may be far more disruptive on the wholesale side.

Gumroad’s Sahil Lavingia also chipped in with his two cents – suggesting Bitcoin’s biggest impact could be how it inspires others to build products… “A lot of the ideas that it contains are really interesting and will affect the way other people think about building stuff”.

[From Bitcoin’s Biggest Impact Could Be Changing How Others Build Products, Say Digital Money Firms | TechCrunch]

I agree with that wholeheartedly. As I said when first asked about Bitcoin a couple of years ago and consistently since a few times via various media channels (see for example, Wall Street Journal TVthis week), Bitcoin is more interesting to people like me for the technology than for the currency and I’m pretty sure that’s true for our clients as well even if they don’t realise it yet. Someone much smarter than me, Google’s Chief Economist Hal Varian, puts it like this:

I think something like this technology will take hold in the future but I am not particularly optimistic about bitcoin because it suffers from being the first in the area<

[From Not particularly optimistic on Bitcoin future: Google official - The Economic Times]

Hal and Sahil are surely correct to focus on the underlying technology. The family of technologies for distributed public ledgers that Bitcoin has founded are set to disrupt by realising the dreams of the early “digital bearer instrument” pioneers in a very different way by finding an alternative route to fixing the well-known problem of double-spending. This is exciting and interesting and important, and it’s much more of a story than some guy tossing his Bitcoins in the garbage by accident, which is the sort of thing media focus on.

The impact of Bitcoin will not be a digital gold standard. It might not even be payments. In his much-linked talk at Le Web, the well-known venture capitalist Fred Wilson said that “we have allowed Google and Facebook to become our de facto identity services” and he predicted that a “Bitcoin-like” identity protocol will arise in the future. Interesting. In other words, for Bitcoin as for everything else, identity is the new money.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post So many people miss the point about Bitcoin appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2013/12/so-many-people-miss-the-point-about-bitcoin/feed/ 1
It’s always, always the same http://tomorrowstransactions.com/2008/12/its-always-always-the-same/ http://tomorrowstransactions.com/2008/12/its-always-always-the-same/#respond Mon, 22 Dec 2008 19:13:47 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2008/12/its-always-always-the-same/ [Dave Birch] One of the reasons why a digital identity infrastructure ought to be more than just building a big database of everyone and then letting everyone have access to it is that the infrastructure will inevitably be abused by those on the inside, no matter how much effort goes into keeping out the bad […]

The post It’s always, always the same appeared first on Tomorrow's Transactions.

]]>
[Dave Birch] One of the reasons why a digital identity infrastructure ought to be more than just building a big database of everyone and then letting everyone have access to it is that the infrastructure will inevitably be abused by those on the inside, no matter how much effort goes into keeping out the bad guys on the outside.

Missouri Citibank employee Brandon Wyatt… accused of tapping Citibank's computers for customer information, then using it to set up checking accounts online with competing banks, including Bank of America, Washington Mutual and AmTrust. Wyatt allegedly wire transferred customer funds from Citibank to the new accounts, then cashed them out with additional transfers, checks, debit card purchases and ATM withdrawals. His take, according to federal prosecutors in St. Louis, was at least $380,000.

[From Fed Blotter: Citibank Worker Allegedly Plunders Customer Accounts | Threat Level from Wired.com]

It's hard to see how you can stop this from happening completely in an economic way, but what you can do is make sure that there is an audit trail so that someone how decides to have a go at this kind of fraud has a reasonable expectation of being caught. Although I have to say that armed bank robbers have a reasonable expectation of being caught (and a reasonable expectation of a long sentence if they are caught) but they still do it. Anyway, my point is that if you take people personal data and put it in a honeypot, there is only one outcome. A database is not an infrastructure.

As I am sure that we all understand, the problem of insiders obtaining personal data (stealing or, more accurately, copying identites) in financial systems is the least of anyone's worries because at the end of the day all that is stolen is money. There are far more important systems, where there are much greater ramifications to identity crime.

A hacker in Chile calling himself the 'Anonymous Coward' published confidential data belonging to six million people on the internet. Authorities are investigating the theft of the leaked data, which includes identity card numbers, addresses, telephone numbers, emails and academic records.

[From Emergent Chaos: 6/16ths of Chileans personal information leaked by hacker]

As I asked the Home Secretary at her update on the ID card, what is the "break the glass" plan when this happens? When people do this kind of thing for political purposes they don't care about the personal consquences. If a disgruntled civil servant decides to publish the entire contents of the national identity database on the web as a protest against government policy on something or other, they know they are going to get caught. But they don't care. Political conscience aside, sometimes, people do this kind of thing just because they are, well, people.

This brings up another problem that ties into this, or what is known as medical identity theft. While medical identity theft hardly ties into Britney Spears getting her information "peeked at," it has become a huge problem. The tie would be the ease in which naughty employees, with no business looking at it, were able to do so.

[From Fraud, Phishing and Financial Misdeeds: Naughty UCLA employees peek at Britney's medical information]

If you could look up the medical records of neighbours, employers, celebrities or "love rivals" on the web, then you would, not because you are evil but because you are human. We need to be realistic about human behaviour in the systems we build. If we don't want people to snacking on personal tidbits in a the data fridge, a sternly-worded magnet on the door isn't going to help: we shouldn't leaving them in there at all.

These opinions are my own (I think) and are presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post It’s always, always the same appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2008/12/its-always-always-the-same/feed/ 0