“Location-based” login protection

[Dave Petch] It’s not often the case that eBay users find cause to congratulate
the internet giant, in fact quite the opposite is usually the case. 
Whether it’s seller
rebellion against fee hikes
, anger at
seller policy changes
, lawsuits against
the selling of counterfeit goods
or password
vulnerabilities in the developer program
, eBay are never far away from
controversy of some kind.

So I was therefore pleasantly surprised to discover that eBay (in the UK at least) have implemented location-based login checks,
something which would surely assist in the ongoing fight against phishing
attacks were it implemented more widely at other online merchants /
communities. It was also another great but simple example of the utility of the
mobile phone as an authentication channel.

I discovered this through the somewhat suspect process of
using my friend’s eBay login details to help him sort out an item listing issue
that he had.  He’s one of those illiterate computer users who doesn’t know
one end of the web from the other
, so he didn’t hesitate in telling me his
login and password over the phone.

My friend lives 20 miles away from me.  When I tried to
log in using his valid credentials, eBay took me to a page stating it had been
noticed I was logging in from a “location” that was not my usual one.  I
presume this was detected using my IP address, although whether it was able to
trace me to a spot in Guildford or just to the location of my ISP is not clear
(a whois of my IP address at
home tells me that I live in Hull, East Yorkshire, which is at least 230 miles
from my house but unsurprisingly not very far from my ISP).  However, for
the security mechanism in question, this was more than enough information for eBay to detect the disparity from my friend’s usual network access data.

I was then asked if I wished to be authenticated using
either a phone call (instant) or an email (short delay).  I selected
authentication by phone call (it uses the existing registered number and does
not allow you to enter a different one), my friend’s mobile rang almost
instantly, after which an electronic voice announced, “Hello, this is eBay, are
you expecting this call? If so, press #”.   My friend pressed # and
an access code was read out to him.  He reported the code to me, I entered
it at the website and in I went.

The specifics of the situation were obviously beyond that
for which the protection mechanism was strictly designed, but the process
worked very smoothly and was close to real time, it presented the user with
alternative options for added convenience and, above all, it was simple. 
Sure, it slowed me down for a minute, but my initial thought was that such a
simple mechanism would surely assist in the fight against the use of phished
credentials.  If you cannot stop the consumer from continuing to fall for
what is fast becoming one of the oldest tricks in the book, then stopping the
use of those captured credentials using simple location checking seems to be a
worthwhile next step, at least until such time that the highly
flawed
method of user authentication that we call “passwords” is replaced
by something
better
.

There
was a flaw in the process, however.  Having completed my login to the
website using my friend’s credentials, I then asked him to log in at the same
time so that he could see the effect of the changes I was making to his item
listing.  eBay allowed him straight in, although it should have been clear
at this point that it was not possible for him to be in two different locations
at the same time, at least not without considerable mind power.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

A Question of Form

[Dave Petch] I was searching for articles on customer feedback on NFC-enabled Mobile Phone trials recently when I discovered what I thought was a very interesting comment from John Suchanec, the Senior Vice President of Payment Technology for Bank of America, regarding the bank’s own NFC trial that they carried out in late 2006 as part of a larger 5,000-employee pilot held at one of its corporate campuses:

The bank gave employees a choice of the contactless form factors they could use and employees chose key fobs to phones by a six-to-one ratio, Suchanec said. The application available for download to the phones was PayPass from MasterCard.

“Active fob users averaged three times more transactions than phone users,” he said. “One of the problems they had with the phone, you can’t do more than one thing at a time; you can’t talk and pay.”

[From: Contactless Technology in US Card ]

The article explains that one of the key issues reported during the trial was the complexity of getting the payment application to work in the NFC-enabled mobile phones (the Nokia 3220 model), including the slow download speed of the application, missed SMS messages and lost connections during the download process.

It piqued my interest because it would appear that many players in the emerging mobile payments industry have been and still are stating precisely the opposite i.e. that the mobile phone is the preferred form factor. Here are some examples.

When Consult Hyperion were working with MasterCard on the first U.S. field trial of mobile phones with contactless capabilities back in 2004, Motorola announced that:

“…recent MasterCard consumer research showed that consumers who found contactless payments to be extremely appealing, selected mobile phones, based on convenience and uniqueness, as a form factor of choice to be enhanced with PayPass."

[From: Motorola to Launch Trial of Handsets with MasterCard® PayPass Technology ]

In February 2007, the GSMA were saying this:

Several customer trials have confirmed that the mobile phone is the preferred form factor for contactless services. The demand for this new range of contactless services is applicable across all user and market segments. Furthermore, customers want to keep the same ease of use, “look & feel”, security and confidence as experienced with existing mobile services.

 

[From: Mobile NFC Services ]

 

In April 2007, the Retail Council of Canada published an article in the Canadian Retailer magazine which quoted Pat Daley from Deloitte:

“[A mobile phone] is the preferred form factor next to cards,” she says.

 

[From: 3,2,1...Contact(Less)! ]

 

Our own Dave Birch has consistently said that the mobile phone will be the ubiquitous payment / ticketing / loyalty / couponing mobile platform of choice when the numerous NFC trials have finally given way to a full-blown NFC ecosystem in the year 20-err…something. Many of his blog entries at http://www.digitalmoneyforum.com/blog/ are evidence of this.

So the question is whether Bank of America’s experience is similar to that of many other companies running NFC trials or an anomaly. The article states that the Nokia 3220 mobile was considered by the pilot employees to be unattractive and low on features, but it isn’t made clear whether the majority of the employees made their choice of fob over mobile before or after making this discovery. The key question would seem to be: Was their decision to choose a fob because of the mobile phone or despite it?

The pilot employees often chose a fob over a mobile because (as quoted above), “you can’t talk and pay”, and the reported result of this decision was that three times as many transactions were made on average on the fobs than the mobiles. But since paying takes a couple of hundred milliseconds is it really a big deal?

Is it really the case that, in everyday usage, the general public will want to be chatting to friends while they pay for their shopping? Will they consider this to be a key feature of their mobile device once it is equipped with all kinds of value added services? Perhaps in the field of transit or event ticketing there is a case to be made for “talking to your mate while walking through the gate”?

I think the key point here is that this limited pilot provided a single contactless payment application to the end user, not the fully-populated m-wallet that is highly likely to be the end result of this developing ecosystem. There is already much evidence that providing just mobile payment services alone is not likely to be the killer application for NFC.

Bank of America are very enthusiastic about mobile as a whole.  The Bank has recently reported great success with the rollout of its Mobile Banking service, hitting the 500,000 user mark at the end of last year (more than all the other US banks combined), so at least something is going well for them in the mobile finance space.

[From: Bank of America hits half a million Mobile banking customers ]


[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.