NFC in the real world

Nick Holland from Yankee Group made a good point in their recent webinar on “NFC Not Just for Cards“. I’m probably only saying it’s a good point because it’s a point that I make too, but nevertheless the addition of an NFC interface to a mobile does change the relationship between the real and virtual worlds.

Put the two things together, in the form of near-field communication (NFC) handsets, and you have something special… Over the coming decade, the mobile phone will shift from being a network end-point to being a pivot between local and global environments, an indispensable and personal security token that bridges physical and virtual commerce.

[From Digital Money: Ten more years of technology]

Nick talked about this “hyperlinking” to the physical world and made the sensible point that while dull persons such as myself are obsessed with payments, the use of NFC will be far wider. This is perfectly correct, and I happened to see an excellent illustration of this general point in NFC World this very morn.

Some 35,000 households in Haiti are receiving ‘clean water’ buckets — which consist of a chlorine solution and an RFID-tagged five-gallon bucket to treat and store water — from the charity Deep Springs International (DSI). On each bucket is an RFID tag which is read during regular visits by community-based health workers who carry NFC-equipped Nokia 6212 phones. Just holding the phone up to the bucket reads the tag and records the visit, then they measure the amount of chlorine in the water and key it in to the handset

[From NFC phones help provide clean water to Haiti earthquake victims • NFC World]

In fact we have consistently advised clients that payments will be a niche. Anyway, Nick is correct, and on the Digital Identity Blog I’ve repeatedly made the point that the use of NFC to support digital identity applications will, in the long run, be far more important than digital money applications. A big step forward in assembling this infrastructure went almost unnoticed last year when the NFC specifications were extended to include the digital signing of data.

The Signature RTD candidate technical specification helps users verify the authenticity and integrity of data within NDEF messages by specifying the format to be used when signing single or multiple NDEF records. It defines the required and optional signature RTD fields, and also provides a list of suitable signature algorithms and certificate types that can be used to create the signature

[From NFC Forum : NFC Forum Announces Specifications to Support Peer-to-Peer Device Communication and Verify Data Authenticity ]

This is important, because if you want to go round touching real world things and have them connect to virtual world things, you need to be sure that they are what you think they are and they are part of the right infrastructure. When I tap on the poster in the restaurant window, I want to be sure that it is a legitimate hyperlink that will take me to a menu and not to a porn site. With this infrastructure in place, all sorts of new businesses become possible (and desirable). It means that someone if going to have organise how exactly the key, certificates and signatures are going to work and interoperate and that someone probably won’t be the mobile operators but a new entrant.

These “pivot” functions, that link the local and remote environment will, I firmly predict, lead to some incredible new applications. Fortunately, some of them will involve payments, which will be really good news for some of our clients.

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The fraud trajectory

There’s no doubt that chip and PIN is one of the key planks in the industry strategy to reduce card fraud to manageable levels (which is not the same as eliminating card fraud, note). One of the reasons why it is so secure is that is uses offline PIN verification, where the chip on the card checks that the PIN input at POS is the correct one. And since the PIN is known only to the cardholder, and they never divulge it, this provides validation that… no, wait…

Despite the strict recommendations from card providers about keeping your PIN confidential, research by shopping website VoucherCodes.co.uk has revealed that over half (59pc) of Brits are flouting the rules by sharing their bank card PIN codes and are putting their personal finances in jeopardy.

[From More than half of card users share their PIN - Telegraph]

Uh oh. But come on – anyone out there in the real world will know that it’s impossible to get through life without giving your spouse your PIN. What happens when (to pick a hypothetical example) she can’t remember what the hell she’s done with her handbag and needs to get to Homebase to buy some paint? Or (to pick a hypothetical example) a husband may have stupidly left his wallet in his desk at work but needs to get cash out at an ATM on the way to a football game. Come on – we’ve all done it (except me, I should point out to the terms and conditions chaps at Barclaycard).

The poll of 3,000 people revealed that Brits are most likely to entrust their partners with this security information, but a surprising one in twenty (5pc) adults feel that it is safe to divulge this information to their children.

[From More than half of card users share their PIN - Telegraph]

What? Not in my house they don’t. We have a Visa prepaid card for “house” use, so if the kids need to get some shopping, stuff for school or other supplies, they use that one, and I top it up online when necessary. It’s a simple way to manage money, so I’m surprised more people don’t do this: and it has the added benefit that it doesn’t have a name on it, so if it gets lost or stolen it can’t be used to start identity fraud.

Incidentally: 3 per cent of the people surveyed said that they wrote their PIN on a piece of paper and kept it in their wallet, which may account for at least some of the incidence of the ATM and POS chip and PIN fraud more plausibly than complex attacks on the unencrypted messages between the card and terminal.

There are plenty of other initiatives aimed at improving the overall level of card security. 3D-Secure has taken a long time to get traction but is now widely used in e-commerce. PCI-DSS is costing a fortune, but may reduce the industrial-scale counterfeiting of the magnetic stripe cards still widely used for retail payments in less-developed parts of the world.

In raids conducted Feb. 1, agents seized $300,000 in cash, three firearms and ammunition as well as equipment to make fake credit cards from the gang… The credit card details and stolen identity information was purchased from “online data traffickers via Web-based portals, and the purchasers would store the stolen credit card information in shared e-mail accounts, allowing several defendants to begin creating counterfeit credit cards,” prosecutors said.

[From US indicts 27 in Apple product credit-card fraud ring | MP3 Players | Macworld]

Anything that stops card details like these from falling into criminal hands so easily must be worth the money, right? Actually, on the costs of PCI-DSS, there may be some relief in sight for European retailers.

Visa last week announced a new programme which means European merchants will no longer need to prove they adhere to PCI DSS regulations on an annual basis, as long as 75 percent or more of their transactions originate from EMV-enabled chip and pin terminals. The programme will be introduced on 31 March, 2011

[From Visa PCI DSS exemptions send out mixed messages to merchants | Business Computing World]

So come on, it’s not all bad. In fact the bottom line is that the fraud figures have been improving, and I expect them to improve further still over the next couple of years as we begin the integration of cards and mobiles. This is because even simple integration (eg, texting unusual transactions) delivers good returns and the impending integration of payments with handsets means that issuers will be able to go even further with 24/7 access to the “card”. I won’t rehearse the basic arguments, but I think there are many reasons for thinking that the mobile is a means to manage card fraud down, and line of thinking that we have presented frequently over the years.

So, are mobile payments safe or not? It’s not a “yes” or “no” question, as we hope this discussion has shown. Let’s ask another question instead: Can we make the risks of mobile transactions manageable? The answer to that is “yes”. In fact, in the particular case of mobile proximity payments, we happen to believe that there is more security overall in using a mobile than in using a card payment

[From TM Forum - Article: Mobile Payments - Safer than Cards?]

For one thing, as noted, we can use the mobile to provide information and as communication channel to report on and detect suspicious activity. Potentially more interesting, though, there are techniques that take advantage of the characteristics of the mobile channel, primarily location There are some practical problems to be overcome though.

ValidSoft [has] direct access to mobile networks, tables, and services around the globe and can provide mobile based location services without requiring that users opt in. Many financial institutions are interested in using these services for fraud detection but are concerned about the privacy implications and don’t want their customers thinking they are following them around.

[From Visa Europe sets trend with mobile location-based fraud detection]

Actually, I might well want my issuer to follow me around, but I might also want it to stop other people from following me around. Anyway, I’ll be talking about this kind of thing — including lessons from our practical experience advising leading payments organisations around the world and some of the things we are learning from the Ph.D in mobile handset security that Consult Hyperion is funding at the University of Surrey — at the excellent UK Card Fraud Conference on 29th/30th March 2011 in London.

The magnificent people at DT Conferences have given me a delegate pass for the event — worth an amazing ONE THOUSAND TWO HUNDRED POUNDS plus VAT — to give away on this blog as a competition prize! So if you are going to be in London on those dates and you’d like to come along to meet some of the leading thinkers in the UK’s fight against card fraud (and me) then all you have to do is be the first person to comment on this post with the name of the doomed precursor to 3D-Secure, the PKI-based online card payment security system developed in the 1990s: full name, please, not just the TLA!

In the traditional fashion, this competition is open to all except for employees of Consult Hyperion and members of my immediate family, is void where prohibited and has been gritted for your safety. The prize must be claimed within three months. Oh, and no-one can win more than one of the Digital Money Blog prizes per calendar year.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Mobile payments are good for mobile banking

Mobile payments and mobile banking are not the same thing at all and, as I have long maintained, there is no reason to think that mobile payments should be provided by banks, nor that mobile operators want to get in to banking. This is why I maintain the much of the comment around these topics is misleading. For example:

Geo-strategic and political consultant at Nova-Comm Strategy Group, Brett Goldman, says: “With M-Pesa… Essentially, what you are doing is eliminating the need for a bank,”

[From Near field comms: How are mobile payments changing traditional banking? - 2/22/2011 - Computer Weekly]

Well, up to a point. They are not eliminating the need for a bank, they are eliminating the need for banks to run payment services. And this is not bad for banks, or customers, because M-PESA don’t need to eliminate banks in order to improve the banking infrastructure as it demonstrates with the example of the M-KESHO service, launched with Equity Bank, that allows M-PESA customers to transfer money to and from savings accounts.

With the M-Kesho Account, customers will be able to get pre-qualified personal accident insurance, access to short-term loan facilities ranging from KES 100, and interest on the mobile account from as little as KES 1. The application is built with the ability to score a customer’s credit rating using a six-month history of his M-Pesa balances.

[From Safaricom, Equity Bank launch M-Pesa bank account - Telecompaper]

How interesting is that? The transaction history built up inside M-PESA provides a straightforward mechanism for financial inclusion, simply not available in a cash economy, and an apparently entirely viable alternative to credit history. The service has been tremendously successful.

He noted that some 21 percent of M-PESA users in Kenya now use the service simply to store money and earn interest. The savings service – branded as M-KESHO and in partnership with Kenya’s Equity Bank – has effectively set-up 750,000 new bank accounts in Kenya since launching in May with deposits totalling KES900 million (US$10.7 million).

[From Vodafone, Telenor To Expand Their Financial Services | Telecom Recorder]

Scatchamagowza! They’re on their way to creating a million new bank accounts. Far from taking customers away from banks, M-PESA is bringing customers to them! As far as I can see, this is pretty conclusive proof that banks are wrong to lobby regulators to insist that mobile payments can only be provided by banks and that regulators are wrong to listen to them. (In Europe, fortunately, this is not true because of the Payment Services Directive: O2 have applied for a payments licence in the UK, for example). So, an efficient and effective mobile payments platform adds value to mobile financial services by making those financial services more accessible at lower cost. And while stimulating this, operators can make money too.

Aite says mobile payments will account for $214 billion in gross dollar volume by 2015, up from only $16 billion in 2010

[From The Smartphone Payments Train’s Leaving the Station - Bank Technology News]

That means lots of transaction fees. It’s interesting to note how M-PESA’s transaction fee income has held up.

As the use of M-Pesa spread, Kenyans started using it for smaller and smaller transactions. The average amount sent through M-Pesa declined from the equivalent of about $50 in March 2007 to less than $30 by March 2009.

[From Fascinating Stat and Lesson for the US About Mobile Payments in Africa]

So Kenyans are sending smaller amounts and are paying transaction fees that amount to larger fraction of the transaction (around 7%) because they still find it more convenient to do this than to use any of the alternatives. Once again, we see the mobility premium in action and a new value network that enables mobile operators to provide profitable payment services (because of that mobility premium) while simultaneously enabling bank, insurance companies and others to provide profitable financial services using mobile payments as a conduit.
More important than the mobile payments business itself will be the businesses that it enables. Just like M-KESHO, there will be new financial services businesses that only make sense on the mobile payments platform. In the UK, initiatives such as O2 Mobile Money and Orange Cash should provide some useful early indications as to how the market might evolve: if third-party financial services offer new products using these payments (eg, SME payments, media subscriptions, that kind of thing), then I think that will show that the pie will get bigger instead of getting sliced.

P.S. By way of an experiment in the service of readers, I have instructed no.1 son to go mystery shopping for an Orange Cash card and will report here in a couple of weeks.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

And they vote, too

Last year, I read a Deutsche Bank Research note about mobile payments that was given to me in a meeting with one of our clients (E-Banking Snapshot 34, August 2010). It highlighted a Forrester Research finding that 74% of European consumers and 64% of US consumers are not interested purchasing goods or services via their mobile phones and said that this means there are substantial barriers to adoption of mobile payments. Well, there are certainly substantial barriers to the adoption of mobile payments, but in my experiences consumers are not one of them. Quite the reverse: in every project that I have been involved in, consumers have loved buying things using their mobile phones. The discrepancy comes, I think, because when you ask consumers about something in new in a field they don’t care about (let’s face it, consumers don’t really spend that much time thinking about payments) they will react conservatively. Say to the average British consumer “would you like to use your mobile phone to pay for cups of coffee” and they can’t envisage what you are talking about, especially if they don’t live in London and use Oyster all the time or use 2D barcodes for travel tickets or whatever.

In a survey of 2,500 members of Springboard UK, the market research experts, on behalf of Vision Critical, half of respondents (51%) reported being fairly or very uncomfortable at the prospect of mobile payments.

[From British 'uncomfortable' about making mobile payments - Marketing news - Marketing magazine]

When consumers are given a mobile payment system that works and is convenient, adoption is rapid. Incidentally, in that survey only a fifth of consumers said they were interested in a prepaid wallet. I’ve heard this over and over again: one of the arguments against substituting cash (which most consumers don’t see as a pre-paid product) with some form of “purse” product is that people don’t want to pay up front for good or services that they might use in the future. Fair point. Oh, wait…

Starbucks Corp. customers loaded a record $700 million on to the Seattle coffee chain’s prepaid card accounts during its most recent quarter, up 39% from a year earli

[From Starbucks Prepaid Loads Jump 39% - American Banker Article]

Turns out that if you know stuff about marketing, consumer behaviour, distribution, management, convenience, payment choices, advertising, incentives and, above all, retailing then customers are only to happy to go with mobile prepaid. That’s how come Starbucks went from a mobile payments experiment…

The ultimate goal of the program is to get customers to trade in their physical Starbucks Cards for the digital variety — it’s a time saving exchange for the customer and a cost saving exchange for the company. Already, one in five of all in-store transactions are paid for via Starbucks Card (mobile or physical), and more than $1 billion will have been loaded on to cards by year’s end.

[From Starbucks in New York Now Accepting Mobile Payments | The Total Footballer]

…to a national roll-out in a quarter. Our good friend Brett King gave the Starbuck’s national mobile payment scheme a try and said that

this is far superior to a current interaction using cash or a card for a number of reasons. This gives us a glimpse of what the cashless society will be like; it isn’t risky, it isn’t subject to fraud or theft, it is safe, secure and fast.

[From Brett King: Starbucks Mobile Payments -- The Future Is Coming Fast (VIDEO)]

We all know that mobile will be the focus for the evolution of retail payments, and I think the message is getting out. Eric Schmidt’s talk at Barcelona — saying that NFC will be profitable — attracted a great deal of attention, mainly from people who didn’t listen to what he said when still CEO of Google.

Google wants the next generation of Android phones to replace credit cards, Eric E. Schmidt, Google’s chief executive, said Monday at the Web 2.0 Summit in San Francisco. The newest version of Android, Google’s mobile phone operating system, code-named Gingerbread, will come out in a few weeks, he said. It will include NFC…

[From Schmidt: Android Phones Will Be Credit Cards - NYTimes.com]

There’s still a long way to go in the mass market though, and it’s fair enough to comment on it. Consumers, journalists, commentators don’t yet understand how this new infrastructure is going to work. But I think that’s about to change. Britain’s biggest retailer is Tesco, so they are a benchmark for the acceptance of new technology, and they are going to go contactless this year.

Tony Saunders is the director of marketing for VeriFone in Europe, the Middle East and Africa… Saunders told us that within six months, Tesco will be rolling out near-field communications capabilities to its 35 – 38,000 checkouts across Britain

[From The future of the high street: near-field communication (Wired UK)]

This might be connected with a story that I touched on before in another context, illustrating the point about the ability of retailers to exploit the new contactless technologies in interesting ways.

Tesco will relaunch its Clubcard scheme as an online rewards programme as it gears up to reach customers in the digital age. Developing a ‘secure, multichannel’ smart card, the UK retailer will move the scheme to digital channels in an effort to simplify its rewards programme and cut down on direct-mail costs.

[From Tesco will relaunch Clubcard scheme in 2011 : WCJB]

Incidentally, I didn’t quite understand the rest of the Wired story, so I dropped an e-mail full of NFC articles to the reporter who had said that

The only obstacle could be similar, but proprietary, technologies set up by banks — which are known as “contactless” payment options. Barclays’ contactless cards are a good example, as are Visa’s PayWave cards, which are being trialled in Europe using an iPhone dongle.

[From The future of the high street: near-field communication (Wired UK)]

I shouldn’t make fun. The technology might be old to us, but it’s new to the mass market. And I should not that it isn’t just UK journalists who get a bit confused.

For example, special payment stickers are available already that allow merchants to NFC-enable their point of sale terminals by simply affixing a sticker to the terminal, Litan said. Such stickers go for as little as $18

[From Analysts: Apple could disrupt mobile payment industry | BappProducts | iOS Central | Macworld]

Wait, what? I think the journalist got the wrong end of the stick on this one! Let’s be clear. The contactless payment schemes are NFC and the cards, phones, stickers, watches, hat, badges or anything else will all work with the NFC POS terminals. The key point here is that the retailers are rolling out NFC at POS not just because they want to accept NFC contactless cards, which many of them don’t really care about, but because of NFC contactless phones, which promise an entirely new mobile shopping experience. The retailers want mobile wallets as soon as they are practical, because the value-adding opportunities around coupons, loyalty, location-based marketing and all sorts of other things besides payments are so great.

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Mobile challenges to the financial sector

What’s big in payments right now? I don’t think we have to guess. Our good friends at PaymentsNews have already pointed out that

Two payment-related themes are emerging from NRF conference being held this week in New York: POS encryption/tokenization and mobile payments acceptance.

[From Payments News from National Retail Federation BIG Show 2011]

One of these themes is all about reducing costs (the costs of PCI-DSS compliance are very high, but I don’t want to talk about them in this post), the other about creating new opportunities. It’s hard to argue with this prioritisation: mobile has to be the no.1 strategic issue. But new opportunities for who? The mobile operators? The international payment schemes? The banks? Chetan Sharma’s survey says that it will be the schemes. I’m not so sure, because it would mean that current value networks will be substantially unchanged through the transition, which doesn’t seem right to me.

Can the current payments landscape of banks issuing cards being accepted at merchants being acquired by other banks translate into the mobile environment? We (the industry) used to think that banks and mobile operators would eventually get around to being pals and would sort things out to set the new value network in motion. Will they? Who knows: but the barbarians are at the gate. Eric Schmidt, the Google CEO, writing in the Harvard Business Review, set out Google’s strategic priorities for the coming year:

Second, we must attend to the development of mobile money.

[From Preparing for the Big Mobile Revolution - HBR Agenda 2011 - Harvard Business Review]

Wow. Mobile money is Google’s second-highest priority. In fact, as Eric notes, Google top three strategic priorities are all about mobile. They are going to be a big part of the mobile marketspace from now on.

In last year’s survey, Google/Android narrowly missed out to be the biggest story of the year but this year, the verdict was clear that Google will continue to dominate the headlines with Android devices and new updates and apps.

[From Always On Real-Time Access » 2011 Mobile Predictions Survey Results]

There’s a particular interest there for those of us who have long thought that NFC is going to be a gamechanger because customers find the convenience of contactless so attractive: it energises all sorts of applications, not only payments (actually, payments are rather dull – probably not the application that drives people into the stores to get NFC handsets).

Google is building a mobile wallet nicknamed “Cream,” which it plans to integrate with Android NFC phones that consumers could tap to pay in stores

[From Google Building an NFC Mobile Wallet; U.S. Banks Are Interested | NFC Times – Near Field Communication and all contactless technology.]

You can see where this is going. Banks will be offered a choice of loading their payment applications to the operator-controlled UICC or to the embedded secure element in Android phone, iPhones (rumoured to have NFC soon) and Blackberries (the first Blackberry devices with NFC are about to launch). Not only will these not be controlled by the bank, they won’t be controlled by the operator either. If the infrastructure for accepting NFC payments is simply more mobile phones, even mobile phones with knobs on, there’s no barrier to new types of payments sitting in those secure elements.

Anyway, back to the competitive landscape. If you were being negative about mobile operators, you might conclude that they’ve blown it: a couple of years ago they had the chance to get NFC moving on their terms, but they wouldn’t order the handsets. Now they’re going to have to work hard to get back into the value network. And a particular issue will be the basis of competition: what are they going to offer on their NFC platforms? I’ve mentioned before that I think identity is an area where innovation might generate something new for them, so perhaps the operators are developing new propositions around digital identity (the mobile passport or whatever), or couponing and loyalty, or sports, or event ticketing and management.

And so it is that accountants, banks and mobile phone companies see themselves as engaged in intense competition while customers think they are all the same. Competition as businesses perceive it is not at all the same as competition as consumers perceive it.

[From John Kay - Radical innovation rarely comes from within]

John is typically thought provoking, and surely correct. In the specific case of mobile, though, there’s another aspect: the operators ability to innovate, even if they wanted to, is being constrained.

The Verizon iPhone is exactly the same as the AT&T iPhone, just on a different network — and not even on Verizon’s fastest, latest network, which could have showcased Verizon’s strengths.

[From Why Verizon’s iPhone spells the end of the golden age for carriers | VentureBeat]

There’s a difficult line to tread when blogging: after all, we provide consultancy services to the industry and I have to try to balance the display of corporate expertise and depth of understanding with sensitivity to clients plans. I hope I won’t get in to trouble for saying that I think it is a real problem for some of our clients that their strategy people think about competition in conventional terms: operators, banks, schemes. These aren’t the people who will put them out of business — or, more likely, reduce them to pipes (for bits, money, data), which could still be a good business if they are operationally efficient — if they do nothing to respond to the challenge coming from the outsiders. Its going to be a fun year in mobile.

If you’re interested in learning more about this kind of thing, Consult Hyperion’s Head of Mobile Money, Paul Makin, will be presenting on the challenges that mobile presents to the financial services sector at Mobile Financial Services in London on March 15th-16th 2011. Do come along and join in the discussion.

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Resolution no.1: stop making predictions

Osama Bedier, VP of Platform, Mobile and New Ventures at PayPal, joins the tradition of making predictions for the coming year. I’m always loath to do this, for two reasons:

  1. because it’s a dangerous game as a consultant. Consult Hyperion are working on plenty of client projects that are confidential and relate to new products and services that will be announced during the year and I don’t want to mess up and accidentally “leak” any of these;

  2. because it’s really difficult and wrong predictions come back to haunt you.

In Osama’s case, however, I think at least four of his five key trends are spot on and the fifth is probably right. Let’s join in the New Year fun and have a look at what he said.

Mobile, mobile, mobile. Wallet in the cloud. The digital wallet. Call it what you want, but mobile devices are poised to become a primary form of payment for millions of people around the world… Consider that PayPal saw a 310 percent increase in mobile payment volume on Black Friday 2010 compared to the previous year, and a 292 percent increase in mobile payment volume on Cyber Monday 2010 compared to Cyber Monday 2009. Without a doubt, mobile payments are here to stay and will see significant innovation in the coming year.

[From Five payment trends to watch in 2011 | VentureBeat]

This is impossible to contradict and anyone who doesn’t think that mobile is central to the evolution of the entire payments market this coming year is absolutely 100% wrong. I’ve consistently said — for a decade — that mobile payments will be more important than web payments and I absolutely stand by this. I think I might go further and say that the biggest mobile payments story of the year will be the arrival of Android phones with NFC interfaces, and these will transform the payments landscape.

T-commerce. TV will go from a passive (viewing-only) experience to a highly interactive activity as more and more apps are developed specifically for the platform.

[From Five payment trends to watch in 2011 | VentureBeat]

One of the very first reports that I ever wrote about payments and the new media said the companies should focus on t-commerce as well as m-commerce because in the medium term these would become the key channels. I was wrong about the TV side of things: it has take much longer to develop than I thought, probably because the sector remains focused on “traditional” business models around subscription and advertising. Surely it’s going to change this year.

Appification’. IDC issued a new report that says, among other things, over the past three years the mobile apps space has seen an “appification” of “broad categories of interactions and functions in both the physical and the digital worlds.” And this only stands to continue — in fact, the same IDC report projects mobile app revenue to grow from $4.9 billion in 2010 to $35 billion by 2014.

[From Five payment trends to watch in 2011 | VentureBeat]

In the smartphone world, payment apps are going to be big, but I think we all recognise that they are one part of a new value-adding ecosystem that involves vouchers, coupons, loyalty and so on as well as the basic payment itself. This is why I suspect that simply porting exiting payment mechanisms (eg, credit cards) to the mobile platform will not be sufficient to obtain competitive advantage.

A Cashless Society. Now let’s not go crazy here, I’m not suggesting that by this time next year we’ll be living in a cashless society. Far from it. That said, 2011 will undoubtedly see several significant steps that will take us closer to such a world.

[From Five payment trends to watch in 2011 | VentureBeat]

I think he’s right about this, even though plenty of other people are sceptical. In many places, these first steps have already been taken and I think the pressure to reduce the amount of cash in circulation over the coming year will come not from the electronic payments industry but from governments, law enforcement agencies, trade unions and others who want to make a start on reducing crime and tax evasion. The trigger, however, is mobile. It is the arrival of mobile payments that makes cashlessness a realistic possibility and means that the industry can respond to these pressures.

Social shopping is clearly poised for significant growth… Among the key drivers of this trend are micropayments and digital goods. Along the same lines of merging physical world experiences with digital activity, the ability to make quick, small purchases for online content represents a huge opportunity for both content producers and providers.

[From Five payment trends to watch in 2011 | VentureBeat]

This is the one I’m not sure about, and that’s because while we tend to focus on what’s happening at Facebook and the like, I think we’re still in the very early stages of social media and I don’t think we really understand how the sector is going to develop. The role of mobile, NFC and other connectivity technologies in the evolution of social media is still changing and the disconnection technologies are still awaiting standardisation and mass deployment. So while I agree that social shopping will continue to grow, I’m not sure whether it will change the payments space or simply use the products coming from the payments space (or, to put it another way, will Facebook credits break out into new markets?). Perhaps there’s another possibility for this fifth spot. Over at the Financial Services Club, someone whose opinions I always takes seriously highlights something else:

Major investments in creating agile infrastructures and platforms to respond to regulatory requirements.

[From The Financial Services Club's Blog: Six key technology developments for banks in 2011]

I’m sure Chris is right. The changing regulatory environment is bound to be a big influence on the technology spend for the coming year. New platforms that help to make compliance, in particular, easier to manage will be very attractive to financial institutions. You only have to look at what’s been happening in the cards world to see this.

He noted that PCI compliance has been a significant burden, costing an average of $20,000 for merchants that average only $32,000 in pretax profits; they will gravitate to solutions that reduce PCI scope (tokenization, point-to-point encryption, etc.).

[From Tidbits and Sound Bites from the 2010 Chicago Fed Payments Conference — Payments Views from Glenbrook Partners]

Scatchamagowza! Compared to the cost of renting the terminal, merchant fees and other costs associated with accepting cards payments, this is huge. Shaving a tiny amount off of fees won’t tip a business model anything like as much as making a significant cut to compliance costs, so this must be a priority area for investment and new services that can help will find a ready market.

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

In your Facebook

Facebook itself has been playing with this kind of thing – personal location – for a while. We’re all familiar with the various “check in” services, but the internet of things is something much more.

All attendees of the f8 developer conference are receiving special RFID tags that enable them to check-in to various locations throughout the conference venue. The service lets you tag yourself in photos, become a fan of various Facebook Pages, and share activity to your Facebook profile. While it’s still a concept service, it’s interesting to see some of the things that Facebook developers are currently testing

[From Facebook Tests Location Through RFID AT f8]

Is this just the same as messing about with FourSquare or Facebook Places? I think not. Bernhard Warner, editor of Social Media Influencer puts it very nicely.

Location-based services take either a lot of time — you have to manually check in everywhere you go — or take a lot of liberties — you open up your personal information to businesses.

If RFID checks you in and out automatically, then the web will certainly “take a lot of liberties” (although this may well be what people want). But this is just about the location of people. What will happen when the location of things becomes part of the natural order?

I happened to be chairing a panel at IIR’s M2M Business Exchange event in London recently, and I have to say that I was surprised by the range of organisations that came along. I’d assumed that it would be mainly hardware guys and telcos, but the sessions that they had on smart metering, remote healthcare, retail and so forth were actually discussing some quite diverse applications. Naturally, I was on the lookout for things that might make a business for our customers, so I was focused on the applications that demand more security, such as payments.

ETSI, the telecoms standards body, has been working on what they call SES, which stands for “Service Enablement Services” to form a standard layer between the internet of things and the value-added services to sit above them. Joachim Koss, the TC M2M Vice Chairman said that the standard would include security “tools”, which obviously I would like to see as including fully-functional digital money and digital identity elements because this connects to my somewhat simplistic definition: smart pipe = dumb pipe + digital identity + digital money.

I think this is the right approach, provided that the SES layer contains rich enough services to provide for a proper spectrum of identity types (that is, it does not require the full disclosure of “real identity” or allow uncontrolled anonymity). Another advantage that I can see is that if mobile operators were to get their act together, they might be able to use the SES in combination with a secure token (in the UICC) to make a business from it: for example, I might want to choose an option on my phone which means that my location is visible to anyone on LinkedIn provided they work for Consult Hyperion, and then temporarily extend this to a client for a month in connection with a project, but allow my wife to see it via Facebook at all times, that sort of thing. It would be another example of a value-added service that could, when built in to the infrastructure of other more sophisticated value-added services, generate much more income than raw data.

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

iPown

To understand why the fuss, and why this is of relevance to the digital money world, you need to understand a couple of technical architectures relating to mobile phones and the role of the Secure Element (SE). The SE doesn’t exist in phones yet, but it’s important because if we want to implement anything important (such as payments) inside a phone, we need somewhere to store cryptographic keys, and that somewhere needs to be tamper-resistant to a great degree. Thus we need a handset to have an SE. Ah! You might say: but handsets already have a tamper-resistant thingumy inside them, why not use that?

That’s a good point. In the modern way of things, the tamper-resistant chip thingumy the handset is more properly called the UICC:

The UICC (Universal Integrated Circuit Card) is the smart card used in mobile terminals in GSM and UMTS networks. The UICC ensures the integrity and security of all kinds of personal data, and it typically holds a few hundred kilobytes. With the advent of more services, the storage space will need to be larger.

[From UICC - Wikipedia, the free encyclopedia]

Historically, we’ve tended to associate the UICC (in the form of a removable smart card) with one application only, and that application is the Subscriber Identification Module (SIM) that allows the phone to connect to a mobile network and refer to the combination as “the SIM”. But…

A UICC may contain several applications, making it possible for the same smart card to give access to both GSM and UMTS networks, and also provide storage of a phone book and other applications

[From UICC - Wikipedia, the free encyclopedia]

It can also contain more than one of each. Thus, you could have multiple “soft SIMS” inside one UICC (that special case where the UICC contains only one application, and that is a SIM, we will refer to henceforth as the “hard SIM”). Now let’s consider what happens when Apple add an NFC interface to their devices and therefore need an SE.

The filing also points to the inclusion of near-field communication (NFC) technology in upcoming iPhones — and, for that matter, in Macs and media devices such as the Apple TV.

[From Apple patent seeks to reinvent retail • The Register]

Where can the SE that makes the NFC interface useful go? Either we can plug in an SE (eg, a DeviceFidelity microSD) or we can add an SE to the UICC (the e GSM Association, GSMA, preferred option) or we can build an SE into the device by adding it to the motherboard. The GSMA want to put the applications that control the NFC interfaces to be on the UICC, which kind of makes sense because if you take your UICC out of one phone and put it in another, then you’d want your SE applications (eg, your MasterCard, Oyster etc) to go with it. But not everyone thinks that the SIM is the key to this picture.

Suppose that instead of adding an SE, Apple add a UICC and put the SE in that? What this means in practice is that the UICC will be inside the iPhone or iPad or Mac, on the motherboard. But the SE need not be the only contents of the UICC. Why not put soft SIMs in there as well and do away with fiddly microSIMs? If I walk into the Apple Store in London and buy a 3G iPad, say, then the UICC could come with a default SIM application. Let’s say this is O2. When I take the iPad to France, instead of paying outrageous 3G roaming charges (and therefore leaving my iPad at home), my iPad will download a French operator’s SIM application and start using that. I won’t choose the operator — in fact I won’t even know this is going on, because Apple will simply negotiate with mobile operators to provide commodity service.

In other words, perhaps we move to a world in which the operators’ SIM connectivity function becomes just software running on someone else’s physical card.

[From Dean Bubley's Disruptive Wireless: Apple, embedded SIMs, NFC and mobile payments - some speculation]

Dean is spot on. And you can see plenty of positives in this architecture. If you’re not a mobile operator, that is. If you’re a mobile operator, this is another step towards being nothing more than a pipe. As a customer, I think I’d be quite happy with the mobile operators as a pipe, selected purely on a cost/QoS basis (and competing with each other on that basis). After all, they haven’t (in Europe) got very far with “smart pipe” services such as, just to name two examples, digital money and digital identity. So the Apple UICC containing soft SIMs and an SE may not be such a bad architectural option for consumers. But…

The operators are privately saying they could refuse to subsidise the iPhone if Apple inserts an embedded subscriber identity module, or Sim card.

[From FT.com / Telecoms - Apple warned over built-in Sim cards]

There are other people in this value chain too, such as smart card manufacturer Gemalto who were rumoured to be making the Apple UICC.

Gemalto explained to us why such a deal, which involved a significant amount of devolution from the mobile phone operators to the mobile phone manufacturers, is unlikely to happen without the tacit approval of network carriers themselves.

Gemalto has been a strategic partner for mobile phone operators for more than a decade now (the company is the biggest SIM manufacturer in the world) and gets the majority of its revenue (more than 60 per cent of last year’s 1.654 billion Euros).

[From Gemalto : No Apple iPhone 5 Deal On The Table Yet | ITProPortal.com]

Quite. But let’s just go back over another main point: in order to provide payments, or other useful services, via NFC it is not necessary to have the co-operation of the carriers.

Visa’s approach “shows that basically there’s nothing that the carriers can do that the [payment] networks can’t do without them,” McPherson said.

[From Mobile Payments Set for Surge, But Who ll Set the Pace? - American Banker Article]

The mobile operators have no acceptance at retail POS so they have to work with payment scheme partners to reach scale, but other payments players don’t need the operators. They can put stickers on the back of phones, plug microSD into handsets or use the NFC interfaces that will be built in by Google, Apple and RIM. Since customers will come to expect these services, they will eventually get built in to all handsets. Unless the operators can launch highly functional NFC platforms quickly (which they probably should have started doing a couple of years ago) then they will be out of the loop.

Issuing hard SIMs is expensive, so if the operator’s connection with the customer is downgraded, there is no point in doing it and the operators would save money by providing soft SIMs to any UICC that they can bill to. So I think the situation is this: in the future, many devices will a UICC built-in. This UICC will function as an SE for NFC interfaces. The UICC will store a number of soft SIMs, not only for mobile phone communications but for future 4G and 5G communications. The UICC will also hold standard digital money and digital identity applications. And instead of Vodafone and Telefonica controlling the matrix, Apple and Google will.

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Oil and water

[Dave Birch] In the early days of mobile payments, the relationships between banks and operators were a little strained. I can remember the first time we ever won work advising an operator/bank joint venture (which was a surprisingly long time ago — in the 1990s) and how disappointing it was when they couldn’t work together. Yet many commentators still expect things to improve.

Crucially, what this also shows is that it is possible for banks and mobile operators to compete and cooperate at the same time – a phenomenon in academic circles called “coopetition”.

[From Who Says Elephants Can’t Dance? Structuring Win-Win Partnerships Between Banks and MNOs | Mobile Money Exchange]

Compete and co-operate on what? Operators can’t compete in banking businesses because these are heavily regulated. Banks can’t set up mobile networks without a licence. Surely it would it be more of a win-win for each of them to get on with what they are best at (ie, savings and loans for banks, being a pipe for operators) and have a third-party run the payment service under a separate license?

Here’s a case study to think about. I saw a presentation from Thomas Capka of A1 Bank in Austria, explaining why the operator A1 decided to start its own bank. He said (I’m a paraphrasing) that A1 decided to go and get its own banking license and do everything themselves and be “more flexible than the Austrian banks” (some of whom, incidentally, seemed very flexible about who they lent money to!) because they’d got fed up after years of negotiating co-operation with retail banks. But one of the questions that he was asked was about the way that European regulation has changed. So, if A1 were going to launch services today, would they start a bank, as they did a decade ago, or would they use PSD and EMD to obtain a Payment Institution (PI) license and an Electronic Money Institution (ELMI) license? Thomas said that almost all of what they do could now be achieved without banking license, the exceptions relating to the provision of credit on card products (which, quite rightly, remains a banking business).

So there’s no need for MNOs to co-operate with banks to provide payment services and no particular reason why banks would want to do a deal with MNOs. In fact, right now banks are doing everything they can to go around MNOs, with stickers, SD cards, handset SE, SIM overlay and whatever else.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Expected and unexpected

It’s uncontroversial to note that mobile money in the developing world is having more of an impact than mobile money in the developed world.

While the UK may have an extremely effective online banking model, the Afghan necessity-is-the-mother-of-invention mobile banking model is certainly more interesting than the UK where banks have finally woken up to the fact that the occasional commercial and putting more five-pound notes in cash machines is not innovative enough for a supposedly technically developed country.

[From Afghanistan shows the UK how mobile banking should be done - Telegraph]

So if you’re going to start a cash-replacement technology it makes sense to start it in a place where the use of cash is disastrous as opposed to a place where it’s merely inconvenient and expensive. But is it just all about cost? I don’t think so, because mobile deliver additional functionality as well: it means new applications as well as lower-cost transactions. This is recognised at the highest levels.

One of the interesting things about new technology is because so many countries in Africa have come late to the development, they’ve actually leap-frogged and the applications that they’ve developed for mobile telephony, for one, are far more advanced than many of the things you’ll see in this country… We are interested in how we can, as the U.S. Government, tap into those mobile networks to provide information that people can use very directly on their phones, in their communities, whether it’s tele-medicine, tele-banking, all of that.

[From Diplomacy Briefing Series - Conference on Sub-Saharan Africa - Poten & Partners]

This is you would expect. In the development world, there is little retail financial services infrastructure so there is a great pull to use new technology to provide that infrastructure. This had led to innovation, and some of that innovation may drive new products in the developed world. But the extent to which the innovation in mobile money is developing has some interesting implications for society, and one of them is that this new infrastructure based on mobile provides a means to deliver social inclusion. Why? Ignacio Mas and Dan Ratcliffe from the Gates Foundation are concise and explicit.

Cash is the main barrier to financial inclusion.

[From Mobile Payments go Viral: M-PESA in Kenya - pymnts.com]

Cash isn’t just quaint, it’s a drag on development. Professor Njuguna Ndung’u, the gorvenor of the Central Bank of Kenya, speaking at a time when M-PESA volumes had already surpassed Ks 1 billion per day, pointed out that micro-banking, insurance services and mutual funds need low cost delivery channels and the mobile phone is the way to provide them. Quoted in SPEED magazine (Spring 2010), he said that

The Kenyan authorities are creating an enabling legal and regulatory environment comprising: The National Payment System Bill that will strengthen the oversight mandate of the central bank; The Proceeds of Crime and Anti-Money Laundering Bill; and an amendment to the Banking Act to enable banks to use non-bank agents to extend their reach (and these non-bank agents will use mobile technology to reach customers even if the banks do not).

In a relatively short time, M-PESA has become a standard and widely accepted mechanism for exchange and in some circumstances it is already preferred to cash.

I have personally witnessed this at 11:00pm at night when a colleague made a payment recently to a taxi-driver in Nairobi when such a message was received, and the taxi-driver’s response was that we did not have to wait 10 mins that we could go, M-Pesa was good for the payment. This is trust.

[From Details | LinkedIn]

I wonder if this was the same taxi driver mentioned in a post over at the GSMA.

A conversation I recently had with a taxi driver in Kenya illustrates why talk of the death of banks is unfounded. He explained that M-PESA is one of a portfolio of financial tools that he uses to manage his money, and that his bank is an indispensible part of that portfolio. In fact, I’ve come to believe that mobile money services can increase, rather than dampen, demand for traditional banking services

[From Mobile Money and the Demand for Banking | Mobile Money Exchange]

I’m sure that this is true, although it may not necessarily mean that traditional banking services should be delivered through traditional bank channels.

Equity Bank Ltd., Kenya’s largest provider of small loans, plans to more than double the number of accountholders this year after forming a partnership with Safaricom Ltd., East Africa’s biggest mobile-network operator… Safaricom and Equity Bank announced on May 18 an initiative where Kenyans will be able to open bank accounts through Safaricom’s mobile money-transfer service known as MPESA.

[From Equity Bank of Kenya Aims to More Than Double Accounts in 2010, CEO Says - Bloomberg]

This service has, at the time of writing, already led to something like 750,000 new accounts being opened, so it’s absolutely clear that mobile money provided by non-banks not only does not compete with banking services it can actually turbocharge them. But back to the streets of Nairobi

Last week as I was coming from the office @ about 5.30am (I work late sometime). I noted a group of not so sober men lined up in a M-Pesa retailer, the men had spent the whole night drinking and were making cash withdraws to clear the debt to the pub. The M-Pesa integration allow them to withdrawal from their Bank account. To me saved money should not be this liquid.

[From Details | LinkedIn]

This is a fabulous quote, on so many levels, and I will inevitably use it to make some convoluted “joke” about liquidty in the future. Nevertheless, it is worth using it to flag up the point that even for digital money fanboy such as yours truly, not all of the consequences of spending at the speed of light are positive. But there are other, wider consequences of M-PESA’s great success in Kenya.

I’d say that there is at least as much of a lack of innovation in mobile money because MNOs are simply trying to copy M-PESA.

[From Are banks the bad guys in the mobile money innovation debate?]

This is a perspective that I’ve heard expressed more and more in mobile money circles throughout the year. It has a negative effect, I think, because there were special circumstances and factors around M-PESA.

In any case, from a global perspective, the runaway success of M-PESA is likely to remain the exception, rather than the rule, for mobile money deployments. In most markets, one provider won’t be able to get a big enough head-start to generate the powerful network effects enjoyed by Safaricom and the net result will be several modestly-successful mobile money services in each country.

[From Don't be Seduced by the Magic of M-Pesa | Mobile Money Exchange]

I’m sure it’s true that M-Pesa will remain the exception. It cannot be replicated in South Africa, because apart from anything else it would be illegal: the rules there require bank involvement so M-PESA there is a different kind of beast. But remember how Visa started as BankAmericard? In some countries this will be the more likely path surely: one provider will launch, get some traction and then competitors will join and compete no longer on the network but on products and services built on the network. Another impact will come in the retail value chain as M-PESA continues to grow at point-of-sale (I’m told on good authority that there are some bars in Nairobi that will only accept M-PESA). It has signed up Kenya’s second biggest supermarket chain already. What will happen?

Conrad Sheehan, founder and CEO of mPayy, tells Econsultancy: “If you’re going to introduce a mobile carrier into that value chain without raising the price, something’s gotta give. You have to lower the price to the merchant.”

[From In mobile payments, credit card companies might be a third wheel | Econsultancy]

That simply isn’t true, since the mobile carrier might have some alternative source of revenue. In a recent podcast in the Tomorrow’s Transactions series, Michael Joseph (CEO of Safaricom when they launched the highly successful M-PESA service) points out that he was interested in profitability through customer acquisition and reduced churn. As with the example of NTT DoCoMo in Japan, there is a suspicion that the carriers could give the payment system away for free if it generated enough other revenue for them and that they’ll keep this up their sleeve for when there’s is competition. So is M-PESA generating other revenue? Well…

according to Safaricom’s annual financial statements released just a few days ago accounted for 9 percent of company revenues in the last fiscal year, for a total contribution of USD 94.4 mil (Ksh 7.56 bil). M-PESA revenues grew 158% over last year’s figure of USD 36.6 bil (Ksh 2.93 bil).

[From Proof mobile money can make money? M-PESA earns serious shillings for Safaricom]

M-PESA accounts for almost half of all Safaricom’s data revenues.

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.