Who’s square? Jesse is

Some people don’t really understand the big picture around innovation, and how it takes inventions and turns them into sustainable new value-adding processes. Here’s one example.

Last Friday, Congressman Jesse Jackson Jr. (D-IL) took to the floor of the House of Representatives to decry the iPad as a job killer, as people are using the device to read books rather than buy them from bookstores.

[From Lesson to Congress: iPad Doesn’t Kill Jobs, Government Does - Gary Shapiro - The Comeback: Innovation Economy - Forbes]

But wait a minute: surely books were destroying jobs in the scribe industry. Jesse’s job creation scheme ought to be banning books, not praising them. Anyway, many popular books are written by non-Americans — why should American’s hard earned dollars flow to J. K. Rowling’s UK bank account? Hold on though — scribes were destroying jobs in the storytelling industry. Jesse needs to attack the problem at source: we need to stop people from reading and writing. Unless we’re going to do that, we should instead welcome and encourage innovation because we need an economy that adds more value. I’m not smart enough to know what that means for individual companies, although I am lucky enough to have a job that means I can experience many different organisations approaches and learn from them.

In 1994, the dominant global provider of mobile handsets was Motorola: its shares were trading at an all-time high and it was seen as an outstanding innovator and even described by a senior consultant at A. T. Kearney as “the best-managed company in the world”

[From Why Nokia's Collapse Should Scare Apple - Patrick Barwise and Seán Meehan - The Conversation - Harvard Business Review]

That’s the thing about technology-based innovation: it doesn’t follow the smooth distribution of best practice that is the realm of management consultants. It didn’t matter if you were the best urine trampler in the land, when a German chemist synthesised urea you were on the scrapheap. It doesn’t matter how good your printing company is when e-book sales exceed printed book sales.

Motorola missed most of these market trends, was slow to invest in digital (it was a classic victim of the innovator’s dilemma),

[From Why Nokia's Collapse Should Scare Apple - Patrick Barwise and Seán Meehan - The Conversation - Harvard Business Review]

This “innovator’s dilemma” analysis, which says that it’s just too hard for companies to invest in their own disruptors, suggests that it may be difficult for the incumbents in the payments world to innovate in the right direction. The case study that everyone is focused on right now is mobile.

Bill Gajda, Visa’s head of mobile innovation, is confident that Visa and the other card networks, in conjunction with banks, will be at the center of mobile payments in the future.

[From Leading Mobile Payments | Visa’s Blog – Visa Viewpoints]

I understand where Bill is coming from, but have to admit that I can see other scenarios as well, where Visa interconnects non-bank, sector-specific, mobile-centric payment accounts rather than only bank accounts. It must be said though that Visa have made a number of substantial investments in the mobile payments space and have been actively developing products and services. Not all observers think that this strategy is optimal.

Visa for you to execute in this space, spin out Bill Gajda and team to build a new network. You certainly have the capital and intellectual horsepower to do it.. Don’t think of mobile as a service on VisaN

[From FinVentures]

In the medium term, the existing players (by which I mean banks, the international schemes and processors) will find it more and more difficult to compete with IP-based alternatives because their cost base is just too high. Therefore, it might make sense for a company like Visa to start building one of these, but use their experience to build a better one. Alternatively, they could look for someone else who is building one, and then invest in it. This is what they have done recently with Square (Visa invested an unspecified amount in Square in April 2011). Square is much in the news at the moment, but what is actually interesting about it? As I wrote before, it is not the stripe reader, it’s the niche…

So where is Square seeing the most traction? Without a doubt, small businesses, independent workers and merchants comprise most of Square’s rapidly growing user base.

[From Square Now Processing Millions Of Dollars In Mobile Transactions Every Week | TechGoo]

In a way, this real-world PSP is a small but interesting niche play in a large acquiring market, and as we’ve advised our clients for many years that the mobile-phone-as-POS meme will be more revolutionary than the mobile-phone-as-card meme, it’s an existence proof of new opportunity.

While merchants have to qualify for the app, Square’s qualification rules are more relaxed than those of standard credit card processors.

[From Square Now Processing Millions Of Dollars In Mobile Transactions Every Week | TechGoo]

Never in a million years would I consider signing up as a merchant with my bank. Yet I went into an Apple Store in the US last time I was there and bought a Square (actually, we bought eight of them to play with). It took a couple of minutes to sign up on the web and I accepted my first payment (in Stuart Fiske’s iPad) a minute later!

IMG_0312

Pretty cool, although naturally I was outraged when I got off the plane in the UK and discovered that my lovely Square only works in the US. Anyway, Square were making me think about innovation again yesterday. They just announced their wallet product, Card Case. Once you’ve paid with your card at a retailer once, Square’s server stores the card details, so from then on the merchant has only to identify you. They can even do this without you having a card or phone, because they can look up your picture (although I have good reasons for thinking that this won’t scale).

The obvious idea is to make payments “frictionless” — easier and faster for the user and merchant. (Assuming that the app is fast enough that it is actually more convenient to pay this way than just to have your card swiped. Wireless data networks aren’t always reliable, etc.)

[From Jack Dorsey's Square Starts Its Bid To Kill The Credit Card]

Indeed, they’re not. But imagine what this will look like with NFC in place: you have an iPhone, the merchant has an iPad, you place your iPhone on the iPad, they beep, done. And it’s a card present transaction. Now, we all know that Square Card Case isn’t the only wallet game in town, because anyone with any sense is already developing a wallet proposition since that’s what the merchants want. Right now we are helping clients in the financial sector and the telecommunications sector with ideas in this space. Visa, being smart, are of course already in the game.

Fourteen US and Canadian banks have signed up for the launch later this year of a multi-platform digital wallet that can be used for e-commerce, m-commerce and mobile contactless transactions and includes mobile payment, NFC and coupon capabilities.

[From Visa unveils mobile wallet plans • NFC World]

But now continue the Square-related thought experiment. Suppose that Square are successful at signing up lots of people, so that people don’t want an AT&T wallet or a Citi wallet or a Visa wallet? If all of the transactions are now between the secure element in a mobile phone, via Card Case, to the secure element in another phone, via the Square app, then aren’t Square at some point going to get rid of intermediaries and just move the money from one bank account to another, in a retailer-centric decoupled debit proposition (which won’t be called debit, because of Durbin) that is proactively marketed by the retailers? That really would be disruptive.

just as the iTunes store completely upended the sale and distribution of digital media, Square just might upend the entire real-world payments industry–whether it meant to or not.

[From How Jack Dorsey's Square Is Accidentally Disrupting The Entire Payments Industry | Fast Company]

So, in response to the e-mails I’ve had over the last couple of days, let me say that the Square trajectory confirms the strategic advice that we gave our clients some years ago (which is great!) and that is it not a “rival” to NFC but an exploiter of it. Square might be a niche in the payments business, but it shows a really interesting innovation path that sees payment cards going the way of books, and probably without Jesse Jackson Jr. to plead their case. That doesn’t mean that Square will succeed, but if they don’t, them someone else following that same path will.

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

An idea for the Independent Commission on Banking

The Independent Commission on Banking recently published an interim report on their Consultation on Reform Options. This interim report raises the subject of bank account number portability. Section 5.17, to be specific, says that:

Beyond improvements to the existing system, full account number portability would enable customers to change banking service providers without changing their bank account number. This would remove the need to transfer direct debits and standing orders, which remains the main area where problems may arise. In the past, portability has been rejected as overly costly, but if no other solutions appear effective and practicable, it should be reconsidered to see if this remains the case given improvements in IT and the payments system infrastructure.

It seems reasonable for the Commission to wonder why customers cannot port their account number from one bank to another the way that they can port their mobile phone number from one network to another. That seems a plausible request for 2011, but phone numbers and account numbers aren’t quite the same thing. A phone number is an indirect reference to your phone (well, your SIM card actually) whereas the account number is the “target”. Thus, we shouldn’t really compare the account number to the phone number, but think of it more as the SIM. Each SIM card has a unique identifier, just as each bank account has an international bank account number (IBAN). When you turn on your phone, essentially, your SIM tells your mobile operator which phone it is in and then “registers” with a network. I am writing this in Singapore, where I just turned on my iPhone, so now my O2 SIM card is registered with Singtel. When you call my number, O2 will route the call to Singtel, who will then route it to my phone. But how does the call get to O2 in the first place?

In most developed nations there is what is called an “All Call Query” or ACQ system: there is a big database of mobile phone numbers that tells the operators which mobile network each number is routed by. In order to make call connections as fast as possible, each operator has their own copy of this database that is regularly updated. Note that for reasons that are too complicated (and boring) to go into there, in the UK there is a different scheme, known as indirect routing, whereby when you dial my phone number 07973 XXXXXX it is routed to Orange (because that’s where all 07973 numbers originated from) and then Orange looks XXXXXX number up in its own database to see where to route the call to (in this case to O2). This is why calls to ported numbers in the UK take longer to connect than they do in other countries.

It’s entirely possible to envisage a similar system working for banks, whereby we separate the equivalent of the mobile phone number — let’s call it the Current Account Number (CAN) — from the underlying bank account and have an industy database that maps CANs to IBANs. This database would be the equivalent of the ACQ database. (I rather like the branding too: if the banks decided to operate this cross-border, they could label it the international current account number, or iCan.) So the bank sends your salary via FPS to the iCan, and the database tells FPS which actual IBAN to route it to. No matter which bank accounts you use or change to throughout your employment, the employer always sends the salary to the iCan and thus reduces their own costs.

There is an analogy to this is in the way that some of the new contactless payment cards work. In the US, American Express credit cards give up what is called an “alias PAN”. The PAN, or primary account number, is the 16-digit number on your credit card. When you use your Amex card via contactless, the 16-digit number it gives up is not the actual plan but an alias PAN. Only Amex know which actual PAN this alias PAN refers to. The advantage of doing this is that if criminals get hold of the alias PAN, they can’t use it to make a counterfeit magnetic stripe card, because the alias PANs are only valid for the contactless cards (which they can’t counterfeit, because the contactless cards have computer chips in them).

In the UK, we route by sort codes. Any account number beginning 20- is known to be Barclays, so a payment switch will send the payment through to Barclays. We might decide, say, that sort codes beginning with 00 are iCans. When you get your first bank account, the bank sets up the IBAN and iCan. For your salary, direct debits, standing orders and so forth, you give the iCan. BACS and FPS will be told about iCans, so when a payment to an IBAN beginning “UK00-” enters one of those systems, they go to a shared database and look up the IBAN to route the payment to.

The advantages of this are that banks would not have to do anything with their existing systems, because the iCans will always be translated into IBANs by the time they reach their systems.

The disadvantages are that the public might not understand what is going on and, since they don’t change bank accounts that often, they might not bother to find their iCan and tell their employers, utility companies and others. It doesn’t deliver enough value to them, so we need to find some way of bundling the iCan to find more ways to use it to the benefit of stakeholders. One idea might be to create some kind of Financial Services Identifier, or FSI, which is an index not only to the iCan but to other data as well. If this meant an increase in consumer convenience, then it would spread by itself and take the iCan with it.

To see how it might work, consider my household. I rather belatedly decided to remortgage in order to abandon my outrageous fixed rate and obtain a base rate plus variable rate mortgage just in time for interest rates to rise again (I know nothing about personal finance). I went along to Barclays, my bank of 33 years, to apply and they sent me a multi-page form to complete. I was unable to uncover a single question on this form that they didn’t already know the answer to. Yet I had to fill it out and they had to type it in. What a waste of time and money.

Similarly, when I applied for the most middle-class of all financial instruments, the John Lewis MasterCard with cashback in the form of Waitrose vouchers, I went off to their web site and filled some stuff out and it said something like “congratulations, you’re accepted”. My happiness was short lived, as it soon became apparent that they weren’t going to send me a card at all, but a form to fill out and sign. Whatever. When it turned up I signed it, my wife signed it and I sent it back, then went away on business.

My wife phoned me after a few days wondering where her new card was. When I got back, I discovered that my card had arrived but hers had not. So I gallantly gave her mine (one of the great advantages of PIN cards over signature or biometric cards), and started going through the rest of the backlog of mail. Eventually I came across a letter to me explaining that John Lewis could not send my wife her card without further proof of identity because of know-your-customer and anti-money laundering regulations. My wife has only lived in the UK since 1986 and has only had a Barclays account for 20 years, so you can see why they might be suspicious. She follows a pattern well-known to FATF investigators of international organised crime: live at the same address for the last 15 years, use your Barclaycard to buy food at the same Waitrose every week and work for Surrey County Council, presumably a known hot-bed for narco-terrorism.

In order to prove her identity, and therefore get her card, she had to (in hommage to the founding of the John Lewis partnership in 1929) post them her council tax bill and last month’s bank statement, a handy identity theft kit all in one. Coincidentally, she also had to post off her driving licence because of a speed camera ticket, and it never came back. Foreign readers might be puzzled at this Victorian process, but it’s because British driving licences have a paper supplement on which (I’m not making this up) the police write your speeding points. Such is the state of our identity infrastructure in 2011.

All of this is ridiculous in this day and age. Once someone is “known” to the British, or perhaps even European, financial services industry then there should be no need to go through all of this nonsense every single time they come into contact with the industry again.

In the world of payments, a related discussion has sprung up. This is the discussion about Legal Entity Identifiers (LEIs) that have been going on recently. Many interbank payment messages have account identifiers only and the some law enforcement agencies want to stop this and have banks validate the names as well (it will help to track funds to and from suspects I guess).

A global standardized Legal Entity Identifier (LEI) will help enable organizations to more effectively measure and manage counterparty exposure, while providing substantial operational efficiencies and customer service improvements to the industry … The LEI Solution is a capability that will help global regulators and supervisors better measure and monitor systemic risk.

[From Legal Entity Identifiers: An Emerging Risk Management System]

I’m sure I’d heard somewhere before, possibly at the International Payment Summit, that the plan was to use the SWIFT business identifier codes (BICs), but apparently that’s no longer the case. Fabian Vandenreydt, the new Head of Securities and Treasury Markets at SWFIT, recently said that the International Standardization Organization’s Technical Committee 68 (ISO TC68) has concluded that developing a new code would help avoid ambiguities that might be involved if existing codes are used. The BIC is made up of eight to 11 alphanumeric characters with four letters for the bank, two letters for the country, two digits for the location, and three digits for the specific branch but ISO TC68 want we we nerds call an MBUN (a “meaningless but unique number”).

I don’t think this is way forward for people, though. LEIs are unique corporate identifiers: a corporate identity has one, and only one, LEI. Fortunately, or unfortunately, depending on your view, there is no unique identifier for British persons (and nor is there likely to be under the present administration), nor Europeans, nor citzens of the world. And I don’t think we would want the financial services industry to develop its own sort-of-identity card scheme. We just want a simple, portable, pointer to a person that can be used to index into their KYC’d persona.

The easiest way to do this would be to assign a unique financial services identifier (FSI) to a person or other legal entity the first time that they go through a KYC process. I might have the FSI “citizendave!barclays.co.uk”, for example. One someone has one of these FSIs, then there would be no need to drag them through “know your customer” (KYC) again. This would greatly reduce industry costs and make the process of obtaining a new financial service — a new bank account, a new credit card, a new insurance policy, a new accountant — much simpler. Imagine the simplicity of applying for in-store credit for that new sofa by just giving them your FSI and watching the application form magically populate by itself on screen.

It doesn’t matter if a person has multiple FSIs, because each FSI will have been obtained as the result of a KYC process. If the FSI Directory ends up with two “Dave Birch” entries, so what? It’s not an ID card scheme, it’s a “save money for the financial services sector and make life easier for consumers” scheme. And it wouldn’t matter either if both of my FSIs point to different iCans: I might, for example, have a personal persona and a small business persona — lets say citizendave!barclays.co.uk and citizendave!rbs.co.uk and that point to my personal and my small business accounts — and I want to use them for different purposes.

Picture this. You are fed up with the appalling service you get from your bank, so you walk into a branch of New Bank. You ask to open an account, and are directed to the ATM in the lobby and asked to request a balance from your existing current account. You put in the card and enter the PIN. While the ATM is carrying out the balance enquiry, the FSI (obtained from your card) is sent to the Directory and within a couple of seconds both your account balance (from your bank) and your picture (from the FSI Directory) are on the screen. The New Bank agent presses a button and a pre-filled application form is printed out for you to sign and, once you have, the existing system for transferring accounts is triggered.

There might be another useful spin-off from the FSI as well. Suppose you could designate a default account against the FSI: generally speaking, your iCan, but it could also be a prepaid account somewhere, or your PayPal account or whatever. Then someone could send you money by giving your FSI: no need to type in names, sort codes, account numbers. Anyone could pay anyone by entering the FSI into the ATM, or their internet banking screen, or (most likely) their mobile. You might get used to storing FSIs in address books. There’s nothing secret about them, and because every use of an FSI would require two-factor authentication, no-one can do anything with your FSI just by knowing it (except send you money).

For this to work, then, there needs to be some way for a customer to prove that they are, indeed, the person referenced by the FSI. There’s no need to invent anything new for this: banks could use CAP/DPA, some third-party service (which in a rational world would be provided by mobile operators) or their own app to do the authorisation. We have everything we need to deliver the results that the Commission wants: step 1 create the iCan, step 2 create the FSI, step 3 operate a more efficient, more effective and more convenient banking system.

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Day zero

Today is rather an interesting day in our tiny corner of the digital money universe. Today, the first NFC mobile phone with a contactless EMV application on the SIM goes on sale in the UK. It’s the Samsung Tocco Quick Tap, a version of the best-selling Samsung Tacco Lite with NFC, a product developed by Orange and Barclaycard.

Before I go any further let me make an explicit declaration of interest. Consult Hyperion has provided paid professional services to companies mentioned in this post in connection with the development of the products and services discussed in this post. As you may well remember…

…the public launch of a product that Consult Hyperion has been working on for some time for Barclays: Mobile operator Orange UK and credit card company Barclaycard have announced a long-term strategic partnership to develop m-payments technology including mobile wallet handsets.

[From Digital Money: Some real mobile, nfc and payment stuff in the UK]

Back to the story. Today, (well, yesterday, actually) I used one of these phones to buy a cup of coffee in Eat. And it worked. Perfectly. You might not think that’s amazing, but I do, because I know how much work has gone in to implementing a standard contactless EMV application in a standard mobile handset with a standard SIM for use in a standard terminal on a standard network. And it’s for use by normal people, not geeks like me.

The phone has a J2ME “Orange Wallet” that is connected via JSR177 to a Barclaycard MasterCard pre-paid EMV card application on the SIM. The application uses SWP to access the NFC interface. You can either connect this prepaid card to one of your existing Barclaycards or an Orange Credit Card that you apply for on the spot. There’s no “untethered” version that you could not link to an existing card but simply top-up online or in store. It works as you would imagine: for payments under £15 you just tap and go. The wallet contains the basic services you would expect: you can look at transactions, top up the card (I have my phone linked to my Barclaycard OnePulse with the built-in Oyster card) in a simple one-button plus PIN action

MMP_6301 logoNO EAT_pay_scr

Though I say so myself (as a big fan of stickers!!) the integration is nice. The phone implements the usual NFC tag reading, so you can tap things and have URLs or phone numbers pushed on to the phone (the phone comes with a bunch of tags for you to try it out on) and I’m sure that people will find fun things to do with these. I suppose like a lot of people I’d rather have my Orange Wallet running on my iPhone, but this is a great first step and, most importantly, it actually works, it’s not just some Powerpoint at a conference. It will be spreading to smartphones soon and the knowledge and experience gained by Orange and Barclaycard ought to stand them in good stead.

Last week Google confirmed that Android 2.3 will support Near Field Communication, as will Nokia and RIM smartphones, starting next year. And judging from Apple’s recent hiring of an NFC expert , and patent filings for a probably-NFC-powered iTravel app, the iPhone 5 will boast NFC too.

[From I Have Seen The Future, And It Looks A Lot Like Bump (Without The Bump)]

When I took the phone home last night and showed it to a statistically-invalid sample group of four teenagers, I was quite surprised as to how much they liked it. They were familiar with the handset and they like prepaid instruments and all wanted to try it out.

According to the recently released results of a survey from MasterCard; it looks like the public, especially the younger generation, are willing to embrace NFC if it ever becomes the standard method of payment in the future… From their findings, 63% of the US population aged 18-34 would be at ease with using mobile phones to make payments, while in the 35 or older age group, only 37% are comfortable with the idea.

[From MasterCard says NFC will be embraced by the younger generation in the US | Ubergizmo]

All in all I had rather an exciting day of contactless activity, because I popped into Tesco Express to buy a cold drink and noticed that they had installed contactless terminals. But more importantly, they’ve installed them properly. What I mean by this is that when you buy something, the checkout operators scans it and then contactless terminal lights up automatically. You tap and go. Or you tap and wait for a receipt to print out, and go. I was so shocked to see contactless payments implemented so well that I made a video:

Put these two things together: contactless rails and the mobile carriage and you finally have a genuinely new and attractive customer experience. No-one is mad enough to believe that people are so wild about payments that they will buy these phones just because of the on-board Barclays MasterCard (the mass market needs a portfolio of interactive services), but it’s a super first step. Today was a good day and naturally I’d like to share the excitement. I happen to have on my desk a spare pay-as-you-go Samsung Tocco Quick Tap, so if you’d like to dip your toe into the ocean of future payments, all you have to is be the first person to respond to this post telling me what the acronym SWP — used above — stands for. (Hint: it’s not the Socialist Workers Party).

In the traditional fashion, this competition is open to all except for employees of Consult Hyperion and members of my immediate family, is void where prohibited and has a new and improved formula. The prize must be claimed within three months. Oh, and no-one can win more than one of the Digital Money Blog prizes per calendar year.

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

News from the bunker

The government is battening down the hatches and repelling all boarders, even if they have e-tickets. And not before time!

Foreign intelligence agencies are carrying out sustained cyberattacks on the UK Treasury, targeting it with malicious emails and programs designed to steal information, the Chancellor, George Osborne, has revealed. He said that government systems are the target of up to 20,000 malicious emails every month

[From Osborne: Treasury under sustained cyberattack | Technology | guardian.co.uk]

And that’s not counting the ones from taxpayers, I imagine. Setting aside how ludicrous and meaningless this figure is, there is nonetheless a serious point. If Son-of-Stuxnet crashes the Treasury, that might well be a net benefit to the economy, but if it crashes the electricity distribution network, even I won’t be laughing. We need effective cyberdefences. So what should the authorities do to bolster these defences? I would have thought that have some kind of working identity infrastructure might be a first step, and in that respect things haven’t been going to well in the UK.

The Home Office slipped out the final report of the Independent Scheme Advisory Panel (ISAP) this week, more than a year after it was written. The ostensibly independent report, which reveals how the ID system had been compromised by poor design and management, was submitted to the Home Office in December 2009.

[From Henry Porter - Home Office suppressed embarrassing ID cards report]

The report says that there were no specifications for usage or verification (which we knew – this was one of my constant complaints at the time) and, revealingly, that (in section 3.3) that “it is likely that European travel” will emerge as the key consumer benefit. This, I think, is an interesting comment. As I have pointed, what the Identity & Passport Service (IPS) delivered was, well, a passport. It had no other functionality and, given the heritage, was never going to have. Hence my idea of renaming it “Passport Plus” and selling it to frequent travellers (eg, me) as a convenience, and idea that really should have been taken more seriously by the coalition administration.

As an aside, the report also says (in section 5.5) that the “significant” number of change requests after the contracts had been awarded would likely increase risk, cost and timescale. Again, while this is a predictable comment, it is a reflection on the outdated consultation, specification and procurement processes used. Instead of a flagship government project heralding a new economy, we ended up with the usual fare: incomplete specifications, huge management consultant bills, massive and inflexible supply contracts.

The report repeated the same warnings ISAP had given the Home Office every year since the system blueprint was published in December 2006 by Liam Byrne and Joan Ryan, then Home Office Ministers, and James Hall, then head of the Identity and Passport Service (IPS).

[From Home Office suppressed embarrassing ID cards report - 1/7/2011 - Computer Weekly]

How did it all go do wrong? Liam Byrne was supposed something about IT as he used to work for Accenture, as did the James Hall (Joan Ryan was a sociology teacher who later became famous for claiming more than £170k/annum in expenses). All in all, it was a pretty disastrous period for those of us who think that identity infrastructure is crucial to the future of UK plc, let alone the UK government. This is not to say that, despite all of the evidence (including today’s fascinating FT piece on the UK government’s equally disastrous NHS infrastructure project), that the UK is uniquely hopeless at developing identity infrastructure for the 21st century.

Thai citizens who applied for their first national identity card or who applied to have their ID card renewed, have been issued with a yellow slip instead of the new microchip-embedded “smart” cards. The reason behind the problem is that the Interior Ministry refused to accept the new “smart” cards which were supplied by the Ministry of Information and Communications Technology, claiming that they did not meet the prescribed specifications stipulated in the ministerial regulation.

[From Bangkok Post : The silly saga of 'smart' cards]

Now, this may seem funny, but I ought to point out in the interests of international balance that there are, right now, in 2011, many people walking around branches of the British government with printed pictures of smart cards hanging around their necks. Yes, that’s right: pictures of smart cards, rather than actual smart cards. I’m afraid our cyberdefences are more a cyber home guard at the moment.

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

I see your 14443 and raise you 18092

A couple of people asked yesterday about the comments from Google concerning “card emulation” in Android phones. The twitterverse had noticed these remarks from Nick Pelly, the Android lead for NFC, concerning the lack of API support for NFC card emulation.

The problem is that the hardware out there today, you know, if you buy an NFC controller, it typically is only going to be able to emulate one of those RF-level technologies. So as an application developer, you don’t know which — when it’s getting deployed to a phone, which one is on the phone. So I guess until we see the industry standardize around maybe one RF-level technology or until we see NFC controllers able to support multiple of those

[From Google raises concerns over the viability of NFC card emulation mode for mobile payments • NFC World]

At first I just thought… wow, that’s smart. If Android phones won’t allow ISO 14443 card emulation (which is part of the NFC standard) then that means that Visa and MasterCard won’t be able to use them for payments, thus locking them out of the POS terminals that Google is developing for retailers. As I thought about it, however, and actually read what Nick had said, I realised that I couldn’t understand his comments, since phones are perfectly capable of dispatching to different applications depending on which card they read, so I thought I’d go and ask a couple of the world’s leading experts on implementing secure NFC applications in mobile phones. Fortunately Stuart Fiske and Neil Livingston both work for Consult Hyperion, so it was easy to find them. They told me…

We know that NXP and Inside Secure NFC controller devices support A, B, B’ and Mifare, all on the same chipset. GP provides mechanisms to manage protocol conflicts, etc., when multiple applets relying on incompatible protocols are trying to be active on the interface at the same time.

I thought this must be true, since I had in my office a Nokia handset with NFC that supports both contactless EMV transactions and contactless Oyster (ie, MiFare) transactions and it worked perfectly. I read a little further, and once again became confused. Due to my lack of experience, I was unable to determine what this means:

Typically, the hardware is set up to do card emulation through the secure element. Right now, we don’t have any APIs to talk to the secure element. And we think that we probably won’t be getting APIs to do that anytime in the near future in the SDK.

There are a bunch of different reasons. Again, the secure element is a very limited resource. It can’t hold a large amount of data in there. And if we open it up to any third-party application, there’s going to be a huge resource contention over the secure element.

Additionally, to talk to the secure elements, even from applications on the phone, you need to authenticate yourself properly.

And if you improperly authenticate yourself a certain number of times, there are secure elements out there that will physically destroy themselves and can never be recovered. So that’s something that we really think would be a bad experience for users

[From Google raises concerns over the viability of NFC card emulation mode for mobile payments • NFC World]

I have absolutely no idea what he’s talking about. I have never heard of a handset secure element (SE) that will physically destroy itself if authentication fails. I’ve checked the SmartMX data sheet this morning and I can’t see any such logic.

Screen shot 2011-05-12 at 11.03.45.png

If I put the wrong PIN into an EMV application in the secure element three times, it will lock and then require an over-the-air PIN unlock from the application issuer, but that’s a good thing. It’s certainly true that there’s a problem with secure applications controlling the screen and keyboard during authentication, but that’s because the Nexus doesn’t have any form of trusted execution mode and this is a well-known and well-understood (at least it’s well-known and well-understood by Consult Hyperion) constraint that feeds into the kind of risk analysis that we do for organisations who are thinking about developing transactional applications. The authentication itself is done within the SE, naturally, but you may have a virus that’s capturing the PIN, for example.

Meanwhile, I was thinking about the SE more. If I buy a Nexus S, how would an application provider request a Security Domain (SD) from Google? How would it be provisioned? Is Google building a Trusted Service Manager (TSM) to sell such a service? I haven’t got a clue. The guys told me (these are edited highlights, by the way)…

In J2ME, it’s typically the SE issuer (ie, Google, in this instance) that decides who can access the SE from apps in the phone, and sets up the access conditions on the SE to manage this (the ACF file). Essentially, what we need the Android stack to do is deliver what J2ME (and it’s JSRs) have been doing for several years now. That is, include APIs that provide the app with a mechanism to access an applet in the SE, and for Android to interact with the SE to manage access condition verification. You can’t block the SE if you can’t access it!…

…These comments from Google make it sound like Google won’t be doing anything with card emulation any time soon. If that’s the case, then what’s with all these stories about Google trialling contactless card payments in SF with MasterCard and Citibank, uing Verifone and Ingenico POS terminals? These POS terminals implement 14443 to read contactless cards, and I doubt that Google are going to develop custom terminals that implement P2P ISO 18000 instead. But who knows – it would be cool if they did…

…Perhaps the Android stack doesn’t need to implement card emulation mode if the underlying hardware implements it, i.e. if the NFC controller and SE together support 14443 and card emulation mode, then they can talk to the reader via the antenna independent of the Android stack. The stack needs to provide an access API to allow phone apps to access applets over the contact interface (if there is one, e.g. SIM), or the wired interface for embedded, or via the SD interface….

…So perhaps there is no need for a card emulation stack in Android after all? But we still need ot be able to switch the PN544 into card emulation mode and an SE access API supporting a decent access control mechanism…

That’s the actual problem, then. Developers can get to the SE interface but they can’t do anything with it (eg, load a payment card into it).

As of the 2.3.3 release of Gingerbread the Secure Element functionality has been enabled (but the API Hidden). You can confirm that there is a Secure Element (SmartMX) in the Nexus S just by looking at the debug log using adb logcat and switching on NFC via settings… That said I’m assuming that the keys etc are controlled by Google so actually doing anything with the embedded SE will be difficult/impossible at the moment.

[From Secure Element - SmartMX - seek-for-android | Google Groups]

What has happened is that Google used an NXP NFC stack when building the Android operating system image for the Nexus S, but switched off the card emulation using compiler switches. (There’s nothing to stop you, by the way, from recompiling the stack with those switches set to allow card emulation.) My interim conclusion is, then, that I have no idea what is going on. I don’t understand what Google mean and I don’t see how they can stop anyone from accessing secure elements. Sure, they can stop you for doing anything with the embedded SE (theirs) by not giving out any keys, but if there’s a UICC SE (from the operator) you can access that and if there’s an external SE (eg, a DeviceFidelity SD card) you can access that. If there’s no Google Android API elements for any of these, someone else can simply add their own.

After all, Google ordered the Nexus S with embedded secure chips, the PN65 from NXP Semiconductors, which can store applications. The NFC controllers in the phones also support applications for card emulation on SIM cards.

[From Card Emulation Expected Soon Despite Doubts from Google Engineers | NFC Times – Near Field Communication and all contactless technology.]

Indeed. So why the fuss? What does it matter whether Google want to provide card emulation APIs or not? The things is that Google’s opinions about NFC have taken on more and more significance recently as it has become clear that whatever mobile operators and banks may think about NFC, Google thinks that it is important and will drive it into the marketplace.

Google has obviously made a decision that NFC is an opening into something more interesting and lucrative than transforming a phone into a payment card– advertising and marketing opportunities at the point of sale – the physical point of sale. And, it has done a deal with VeriFone that takes the economic sting away from the merchants who need to buy into their vision to make it work – and who have by and large turned their noses up at NFC up to this point. Layer on top of that their Google Checkout asset and their newly launched One-Pass wallet application and you have the makings of an interesting new payments player.

[From Google Takes on NFC, Will They Crack the Code? at The Catalyst Code]

Karen is, as usual, spot on with this analysis. But I’m not so sure about this…

What’s amazing is that Google was the first to connect all of these dots

[From Google Takes on NFC, Will They Crack the Code? at The Catalyst Code]

This doesn’t seem amazing to me, because I’ve been involved in numerous attempts to develop mobile proximity payments for banks and operators. A month before the Google announcement, I wrote on Quora that “I’m sure [loyalty and rewards] will be Google’s strategy too. Payments are not an interesting enough application to persuade people to go out an get an NFC phone.” Years ago, I made a presentation (I think at NFC World but I can’t find it!) in which I said that no consumers will go into retail outlets and buy an NFC phone because of payments. They will buy the NFC phone so that they can read tags, swap Facebook profiles or (now, it seems) play proximity Angry Birds. But once they have that handset, then we need to make it easy and attractive for them to use it for payments.

Incidentally, Dean Bubley, who is in my opinion one of the very best analysts out there, called these non-payment applications “valueless” in a twitter exchange. He’s referring to things like “0-click” checkins and similar.

Starting tomorrow, just tap your NFC-enabled phone (most newer Android devices have it) against the poster, it’ll check you in with foursquare

[From Experimenting with NFC check-ins for Google I/O | Foursquare Blog]

I’m convinced that valueless is the wrong word. If Google (or Apple) or whoever track where you are via mobile location and then send you special offers, it’s creepy. But if you reach out tap when you enter the shop, or restaurant, or hotel, or office, that’s what advertising folk label “a call to action” that gives them permission to send you things, to steer you, to deliver added value. That’s what retailers will pay for — they’ll get the payments part for free — and that’s why the ecosystem will deliver real value.

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

25% increase in authentication

I had an annoying problem with my PayPal account that ended up with me being posted a password, all quite tedious and strangely manual. As I observed at the time, it seemed odd that in 2011 we hadn’t got anything figured out when it comes to authentication. Why couldn’t I use my Barclays 2FA PINSentry to prove who I was to PayPal? In fact, why couldn’t I use it for 2FA in general, since moving from passwords to 2FA involving tamper-resistant hardware would be a simple way to improve security across a range of services. We don’t use 2FA, and we should.

But that might be changing [recently] Google launched two-factor authentication for Google Accounts—the credentials you use to log in to all Google services, including Gmail.

[From Two-factor authentication: Gmail's new system offers more security than just a password. - By Farhad Manjoo - Slate Magazine]

This is a good step. I use gmail, and I’d actually prefer to use it with 2FA than without, provided that the 2FA is based on something I already have, such as my phone, because I don’t want to carry another dongle. Unfortunately, my mobile operator doesn’t provide any sort of identity management or authentication services, so I can’t use my phone. I do already have a tamper-resistant chip that I have with me most of the time, and that’s in my bank card. Why not use that in some way?

Alternatively, you could slide your credit card through your phone’s card reader—or simply wave your credit card so that it can be recognized by the “near-field communication” chip in your phone.
Are these things too far out?

[From Two-factor authentication: Gmail's new system offers more security than just a password. - By Farhad Manjoo - Slate Magazine]

I’d say not really, especially since I’ve seen SecureKey‘s system for doing just this work perfectly with Google, using a USB key NFC reader and the customer’s contactless bank card to provide the second factor. Today I read about someone pitching iris recognition via USB device as a potential third factor as well. But are three factors enough?

I saw a discussion over at the Identity Management Specialists Group on LinkedIn that set me wondering about authentication factors. Traditionally, us experts have referred to three authentication factors: something you know, something you have and something you are (or, as Ben Laurie once told me, something you’ve forgotten, something you’ve lost and something you were). The LinkedIn discussion was about whether location might be a fourth authentication factor, because it is independent of the other three and can be determined in isolation.

So does this make sense? Is location an alternative third factor, another kind of “something you are” or is it genuinely something new that adds an additional degree of authentication power. The conclusion in the group discussion was (I think!) that location isn’t an authentication factor because where you are doesn’t change who you are, but that it is an authorisation factor because you may wish to assign different capabilities to an identity depending on where the physical person is (ie, are they in the office or at home?). I’m not so sure about this: it seems to me that corroborating your location obtained from your mobile phone with, say, a password, does indeed strengthen authentication. There are plenty of options, so a workable strong authentication scheme must be getting closer. right?

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Innovation is technology-enabled

Around the world, when faced with new products in the payments space, banks naturally crank up their innovation departments and produce super new products and services to wow customers back. I’m joking, of course. What they actually do in many countries is to going whining to the regulator and force competitors to use the banks’ legacy infrastructure. This is what just happened in India, which really ought to be a huge and dynamic market for e-, m- and new payments of many kinds.

Consequently, from 1 March, the eBay unit says merchants in India cannot receive payments from abroad of over $500 per transaction. In addition, merchants will no longer be able to use any balance in their PayPal accounts to buy goods or services. Instead all payments must be transferred into Indian bank accounts first.

[From Finextra: RBI forces PayPal to restrict payments to Indian merchants]

Now, I’m not saying that banks are the only people who react to innovation in this way: that is, by trying to stop it. This goes on all the time.

For the last fifty years, hard disks have been increasingly super-charged gramophone records: at their heart, there is still a real disk rotating very fast on a real spindle. That’s not the only way to store data, as the memory stick revolution shows, but until now, solid state drives (which have no moving parts) have been too small and expensive to replace traditional hard disks as the main storage device for a computer. Now that’s changing, with real advantages for users as a result… Seagate’s response is to threaten to sue all the new entrants for patent infringement, while insisting that their existing market is not threatened.

[From Public Strategy: Innovator's irony]

At the dawn of the industrial revolution, the steam engine delivered the fundamental business school case study in this topic, something that I wrote about when I was invited to speak at the European Patent Forum back in 2009.

In his keynote address, the Czech Prime Minister Mirek Topolanek said that we had to find a balance in the intellectual property system, that it was right to let Stevenson patent his steam engine but not the screwdriver he used to build it (he didn’t explain why..).

[From Patent error | 15Mb: yet another blog from Dave Birch]

In fact, as I discussed in this post, history teaches the opposite lesson because the patent system held back the evolution of the steam engine for a generation! But back to our business. What kind of innovation is relevant to the payments industry? This is not clear to me. On the one hand, it seems reasonable to say that…

What would be refreshing is if the focus of innovation could be pegged to the value that it delivers to the entire ecosystem, not just the engineers who get a kick out of building cool new toys.

[From Payment Gadgets at The Catalyst Code]

But is this true? When Apple put together the iPod, it didn’t benefit the “entire ecosystem”. The disruptive innovations in fact devastate parts of the ecosystem, like forest fires that allow new shoots to grow. I hate to harp on about the M-PESA example, but I think it illustrates this point well. The banks complained about M-PESA and tried to stop it but fortunately failed. Now that M-PESA has 13m customers and 20,000 agents, the banks are able to deliver new services to new customers using the platform. Were they devastated by the forest fire? No: it gave them space for new shoots as well.

Where do we look for the next new shoots then? Not in banks, generally speaking, but elsewhere in the ecosystem. The payment innovations to come will be technology-enabled, which is why it’s important for businesses throughout that ecosystem to understand the new technologies relevant to payments and, just as importantly, understand the business model ramifications of seemingly dreary technology architecture decisions being made by nerds right now. While they will be technology-enabled, though, it’s the sustainable new business model that is the key. A good example of this is Square.

..if Square can provide just enough added-value with their app to get traction in the small business sector (they are already processing a million dollars a day), then when new payment technologies come along (eg, NFC phones that can accept payments from contactless cards) the merchants will just expect Square to handle them for them. We have long been advising clients that the key disruptive role of mobile phones in the payments world is the ability to take payments, not to make them.

[From Digital Money: Hip to be Square]

And we still do, in fact. I think Square is an interesting innovation case study. It does not compete with existing acquirers, but opens up the market so that more people can accept card payments.

So where is Square seeing the most traction? Without a doubt, small businesses, independent workers and merchants comprise most of Square’s rapidly growing user base. The technology only requires its tiny credit card scanner that fits into your audio jack and Square’s app. The device and the software are free, but Square takes a small percentage of each transaction (2.75% plus 15 cents for swiped transactions).

[From Square Now Processing Millions Of Dollars In Mobile Transactions Every Week | TechGoo]

In a way, this is a real-world PSP and an fascinating niche play in a large volume-driven acquiring market, one that can be seen to adumbrate mobile disruption and our projection that the mobile-phone-as-POS meme will be more revolutionary than the mobile-phone-as-card meme. But there’s something else to it as well. Conventional acquirers use conventional methods to assess applications.

Square’s qualification rules are more relaxed than those of standard credit card processors, There are no initiation fees, monthly minimums, and when merchants apply for a reader, Square doesn’t just focus on a credit check, but also takes into account the influence a company holds on Yelp, Twitter or Facebook.

[From Square Now Processing Millions Of Dollars In Mobile Transactions Every Week | TechGoo]

That, it seems to me, is more of a window into the coming economy based on the reputation interweb (or web 3.1, as I propose to call it, to avoid clashing with web 3.0). Can you imagine Barclays Business or Streamline giving you a merchant acquiring account according to the number of twitter followers you have rather than your trading history or bank references?

By the way, I can’t remember if I’ve blogged this before but one of my favourite stories about accepting merchants for acquiring accounts goes back more than a decade to the hazy days before the LastMinute flotation. I was doing some work over at what was then NatWest Capital Markets, who had invested millions in Lastminute, when they went beserk because NatWest Streamline wouldn’t give LastMinute a credit card acquiring account because it didn’t have two years’ trading history!

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Mexican standoff

At last year’s conference on The Macroeconomics of Mobile Money held at Columbia University in April 2010, Carol van Cleef (a partner at Paton Boggs LLP in Washington) gave a presentation on the “Opportunities and Dangers of E-Payments”, in which she noted that the Mumbai terrorists used mobile phones and “showed themselves to be part of the mobile phone generation” (as, I imagine, they showed themselves to be part of the mass transit generation and the automatic weapons generation). She notes that the attackers were using their own phones (so the IMEIs could be tracked, making the life of law enforcement easier) and that they had purchased more than 37 SIMs in different names using false identification (so the compulsory SIM registration was shown to be pointless — although some of the SIM card sellers were arrested). She also says that the most critical tool for drug traffickers in Canada is the prepaid phone (I’m sure she’s wrong: I’ll bet it’s either cash or cars).

I remember thinking when I read this at the time that this continued law enforcement focus on the prepaid phone and the prepaid card, both of which are critical tools for financial inclusion, would end up with restrictions on both that would make no difference to criminals but would make life much harder for the financially excluded, because of the strong link between identity and money.

Why do I think that? Well it is just not clear to me that demanding strong proof of identity for prepaid products will help. In Mexico there is a national registry for prepaid phones and all purchasers are recorded and fingerprinted, the operators keep calls logs, texts and voice mail for a year (in a database only accessible with a court order — or by criminals, I’d wager). All prepaid phones not in the registry were supposed to be turned off this month, although a quick round of googling and searching couldn’t tell me whether this is actually happening or not. As I wrote a couple of weeks ago, in the context of the Mexican government’s reward scheme for people who call in reports of money laundering:

Good luck to anyone who decides to report in person, or by telephone. SIM registration is mandatory in Mexico, which means that the money launderers will find you before the police do

[From Reputation does not depend on “real” identity]

If we focus on phones, for a moment, is it reasonable to assume that demanding identity in the purchase of phones (prepaid or otherwise) will do anything to reduce crime (or will it simply shift the crime to acquiring identities and actually raise the criminal premium on those identities?).

Eight men and one woman have been arrested on suspicion of conspiracy to defraud… calling expensive premium-rate numbers owned by the fraudsters that charge up to £10 a minute… O2 had a total of £1.2m stolen through premium phone lines throughout July, with police claiming that a West African gang bought the phones from high street stores using false identities.

[From British police arrest iPhone scam gang | News | TechRadar UK]

Like many similar scams, this isn’t a mobile fraud or a payment fraud or any other kind of fraud: it’s basic identity fraud, yet again. To some extent, therefore, one has to be a tiny bit unsympathetic to O2. Clearly, if they make everyone jump through hoops to get an iPhone then they won’t sell very many of them. On the other hand, allowing people to take out contracts without really proving who they are or (and this is the commercial arrangement that is lacking) providing an identity that is underwritten by someone who will take liability for it being wrong, means accepting risk. Remember, it’s not the mobile operators, handset manufacturers or criminals who pay for the police raids, the court system, the prison time: it’s us, the taxpayer. So the distribution of risks is not aligned with the distribution of liabilities, as is so often the case in the world of identity fraud. This isn’t a UK-only problem. It is very clear that in countries without secure national identity registers (ie, almost all countries), requiring mobile operators to determine the identity of subscribers (contract or prepaid) will solve nothing. This does not, by the way, mean that it is impossible to catch criminals. Far from it.

Deputy District Attorney Mena Guirguis said that after Manunga and her former boyfriend stopped dating in 2008, she took out a pre-paid cell phone in his sister-in-law’s name, and started sending the threatening text messages to her regular cell phone… Her scheme was uncovered when the victims went to the phone store, talked with the salesman and learned that Manunga had bought the pre-paid phone under the sister-in-law’s name, Guirguis said.

They reported that information to a Costa Mesa police detective, but by then a third arrest warrant had been issued for the sister-in-law. During a follow-up investigation, the detective discovered that most of the threatening text messages were sent when the pre-paid cell phone was in close proximity to Manjunga’s home or work.

[From Woman jailed for making threats – to herself | sister, law, manunga - News - The Orange County Register]

What this story shows is that actual police work is helped by the perps using mobile phones, even if you don’t know the identity of the person using the phone, because phones mean tracking and tracing and location. We read today that iPhones keep a complete record of everywhere they’ve been…

Apple iPhone users’ movements are being tracked and stored without their knowledge in a file that could easily be accessed by a snooping employer or jealous spouse, security researchers have found.

[From Apple iPhone tracks users' location in hidden file - Telegraph]

Surely it would be better to have criminals running around with iPhones, sending money to each other using mobile networks and generally becoming data points in the internet of things than to set rigorous, quite pointless identity barriers to keep them hidden.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Licensed operators

France has been in the forefront of the NFC revolution, with an early commitment to cross-industry co-operation, considerable work on standards and models and an aggressive timetable for getting phones into the market. Remember this?

A dozen French cities plan to launch wide-scale contactless payment and information service on mobile phones with the backing of the ministry of industry, reports Les Echos. The city projects approved under the initiative will receive state assistance for consultancy and engineering, but no other subsidies are planned at this stage.

[From Aid from French Ministry of Industry for mobile contactless cities. « Contactless & NFC City League]

You will undoubtedly recall that a few months later, the French mobile operators decided to get together with a processor and form a mobile payments proposition to launch a serious assault on the banks’ retail payment franchise.

Orange, SFR, Bouygues Telecom et Atos Origin créent une société commune pour proposer une plate-forme unique de paiement en ligne, sécurisée par le mobile.

[From Union sacrée des opérateurs mobiles dans le paiement sur Internet - OPERATEUR DE TELECOMMUNICATIONS SERVICES INFORMATIQUES ATOS ORIGIN FRANCE TELECOM SFR BOUYGUES TELECOM]

Well they’ve made their first assault on the enemy positions and have been granted a PI licence. Why would they bother, you might wonder, when polls show that the majority of consumers don’t want to use mobile payments?

The 59% of consumers who were against the idea, meanwhile, gave their reasons as: Security (79%)

[From Most French consumers not in favour of mobile payments • NFC World]

The answer is, of course, that consumers don’t know what they are talking about and it’s a waste of time asking them about anything new. Whatever they might say a priori, in all of the pilots and trials that we have been involved in, they really, really, liked mobile proximity.

But there are some real issues, and we need to address them.

Dead phone batteries. Wrong merchant terminals. Terminals turned off. Terminals unrepaired. No terminals at all.

These and other, less obvious glitches suggest contactless technology may not be the mobile payments panacea for tattered magnetic stripes and other problems with plastic cards.

[From Mobile Payments Inheriting the Problems of Contactless - American Banker Article]

Well, yes and no. (I am a consultant, after all). Let’s have a look at these

Dead phone batteries. NFC is interoperable with the existing contactless payments and ticketing systems. As you may have noticed, your Oyster card doesn’t have a battery in it: that’s because it is powered through the electromagnetic field of the terminal you touch it to, and the same is true for the NFC interfaces in phones: if the phone has no battery you may not be able to access your m-wallet to check your transactions, redeem coupons and so on, but you will be able to to use it pay in a shop and ride the subway.

Wrong merchant terminals. I don’t think this will an issue. Right now there are some problems with some cards not being accepted in some terminals, but this is the result of standards problems three or four years ago. The contactless EMV standard should interoperate seamlessly. Some of the terminals are certainly “wrong” from the point of view of consumer experience, but that’s a different thing.

Terminals turned off. Fair enough, I do see this from time-to-time. But it’s a teething problem. There is a problem with terminals being turned off after the merchant has rung up the purchase and then having press some more buttons to turn it on, but that’s an implementation issue.

Terminals unrepaired. I don’t think this is a long term problem. Contactless terminals (since they have no slot or contacts) are considerable more reliable in practice than contact or stripe terminals. Experience from other sectors suggests to me tha tthe cost of maintaining an estate of contactless terminals is less than half the cost of maintaining an estate of conventional terminals.

No terminals at all. This, I think, is the real problem. When I was last in the US, I saw contactless terminals in places where they didn’t really have much impact, like in CVS. But in the places where contactless would have really helped and speeded things up — BART machines, airport carts, Coke machines and so on — nothing.

The point is, that those are real issues that do need dealing with, whereas what the public says are their concerns, such as about the security are, in my opinion, not real issues and it should be handled through marketing communications. Oh, wait…

85% of users said they considered the protocols for operating with the NFC system to be sufficiently secure.

[From Sitges trial results: Consumers pay more often and spend more with NFC phones than with cards • NFC World]

This must be a translation from Spanish, because I’m not sure that “protocols for operating with the NFC system” translates properly in English, but it’s good news all the same. I’m not saying that everything is perfect in the NFC world. Even in France, where progress has been slow despite the commitment of major banks and operators. It’s still a new technology.

The problems are one of the main reasons bank Crédit Mutuel-CIC has held back on launching its m-payment service, according to Patrice Hertzog, payment systems manager for Crédit Mutuel-CIC. He said it has been difficult for the bank’s trusted service manager, Gemalto, to set up and manage the bank’s PayPass application on SIM cards produced by other vendors, such as Oberthur Technologies.

The problems have occurred despite much standards work by the French Association Française du Sans Contact Mobile, or AFSCM, and prior trials involving multiple French banks, mobile operators and vendors.

[From ‘Open’ Battles Break Out Among NFC Vendors Over Android | NFC Times – Near Field Communication and all contactless technology.]

To be honest, this suggests that vendors are not building TSMs from scratch based on the new standards but are putting wrappers around their existing card personalisation systems. That sort of thing is, to me, more of a real issue than incorrectly worrying about what the public think, but whatever. Things are moving. Even in the US, the new technology is getting a foothold and there will soon be TSMs there too.

The joint venture formed by U.S. mobile carriers to launch NFC-based mobile payment… has selected France-based Gemalto to download and manage payment and other secure applications on NFC phones to be used in pilots expected to be held in three to four cities during the second half of 2011

[From U.S. Carrier Joint Venture Chooses a Trusted Service Manager | NFC Times – Near Field Communication and all contactless technology.]

There’s plenty of activity in the US as elsewhere, and since I’ve been looking at the US for clients recently I was interested to read about the work done by the Federal Reserve Banks of Atlanta and Boston. This work suggests that the success factors for the US will rest on the evolution of an open eco system for NFC.

The mobile infrastructure would likely be based on Near Field Communications (NFC) contactless technology resident in a smart phone and merchant terminals.

Ubiquitous platforms for mobile should leverage existing rails, including the ACH network for non-card payments, and support new payment types that meet emerging needs.
Some form of dynamic data authentication would be at the heart of a layered mobile payments security and fraud mitigation program.

Standards would be designed, adopted, and complied with through an industry certification program to ensure both domestic and global interoperability, including a standard to ensure that devices used to facilitate mobile payments do not create any electronic interference problems.

A better understanding of a regulatory oversight model should be developed in concert with bank and non-bank regulators early in the effort to clarify compliance responsibilities.

Trusted Service Managers should oversee the provision of interoperable and shared security elements used in the mobile phone.

[From Mobile Payments in the United States Mapping Out the Road Ahead - Boston Fed]

On that final point, things are already moving.

The joint venture formed by U.S. mobile carriers to launch NFC-based mobile payment… has selected France-based Gemalto to download and manage payment and other secure applications on NFC phones to be used in pilots expected to be held in three to four cities during the second half of 2011

[From U.S. Carrier Joint Venture Chooses a Trusted Service Manager | NFC Times – Near Field Communication and all contactless technology.]

So there’s plenty of activity in the US as elsewhere and plenty of organisations are looking at how the move to mobile proximity may impact their businesses.

A white paper that outlines the survey findings, including how the most forward-thinking financial institutions are building a business case for mobile payments, is available at www.fiserv.com/mobilestrategy.

[From Forward-Looking Financial Institutions Focused on Mobile Payments Business Case, Says Fiserv Survey - pymnts.com]

I couldn’t help but think, as I read this, that the very act of building a business case for something like this is fundamentally backward-looking, trying to shoehorn something that is the basis of a new value network into the existing business models. The report says that the factors that the FIs evaluated across these business lines included customer retention and profitability, cost reduction, revenue generation and retention, increased customer engagement and competitive parity. When I looked at the revenue generation part of it, though, it only referred to revenue generation in terms of debit card transactions and keeping the connection to the DDA. This isn’t how forward-looking organisations are thinking about revenue generation from mobile payments, they are thinking about delivering entirely new products and services that are simply not possible in conventional (ie, card) environments, generating revenue from things that banks don’t do.

Google is to run tests of mobile payments at stores in New York and San Francisco in the summer, according to anonymous sources cited by Bloomberg. The search engine giant will pay for installation of thousands of NFC cash-register systems from VeriFone Systems at merchant locations, one source told the wire.

[From Finextra: Google to run commercial trials of NFC at the POS - Bloomberg]

Well, well. So while financial institutions are agonising over the business case, Google is giving out the terminals for free. It’s not hard to see why: they don’t care about the miniscule margins on the payment transaction and arguing about how to slide and dice the merchant fee, they care about building new business around knowing who is buying what and where. So leadership in the NFC space is may well shift away from the payment incumbents. Perhaps the answer to the age-old question about whether banks or operators would control the mobile payments space is… neither.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

“We already have a perfectly fine way to make non-cash payments”

On “Slate” there was an article entitled “Paying With Your Phone Is Awesome, Because … Because” with a sub-headline

We already have a perfectly fine way to make non-cash payments.

[From Paying by phone is insecure and unnecessary. - By Farhad Manjoo - Slate Magazine]

Really? That didn’t seem to be the case in my household this morning when my wife was hunting for the chequebook because she needed to pay for a school trip and settle a dentist bill. I wanted to pay my son’s school £20 on Thursday morning because he was going on a school trip, and I turned the house upside down looking for the chequebook, which I couldn’t find. I couldn’t pay them with a debit card, or cash (I didn’t have £20), or credit card, or bank transfer or any of the other “perfectly fine” ways to make the payment. Which boring tale illustrates the real point, that is, not that…

We already have a perfectly fine way to make non-cash payments.

[From Paying by phone is insecure and unnecessary. - By Farhad Manjoo - Slate Magazine]

…but that we don’t have a perfectly fine way to take non-cash payments. Mobile payments will be a disruptive force because the devices will serve both roles. Richard Johnson of Monitise made this point very well at the Intellect Payments Workstream meeting that I chaired last week. But it isn’t only the cheque that is set for extinction because of mobile. Anthony Jenkins, the chief executive of Barclaycard (Britain’s biggest card issuer), said that

“In 50 or maybe even 10 years’ time, we will still be using cash but I don’t think we’ll have plastic. It is comparable to the move from CDs to MP3 music files,” he said. “If I had said 10 years ago that you couldn’t pay with a cheque at the supermarket, you wouldn’t have believed me. That is now the reality, and we see plastic cards going the same way.”

[From End of the road for flexible friend as Barclaycard goes 'contactless' - Telegraph]

Now this seems a little far-fetched on first reading. But perhaps, once mobile payments cross the cusp into the mainstream (at, I would guess, around a 25% penetration in the consumer market), the move away from plastic could take place in a generation, much as the move into plastic did from the introduction of the magnetic stripe in the early 1970s.

Coins, paper money and plastic cards are going to be the next casualties. Don’t believe me? Then visit Korea. The only people who own a plastic credit card there are the ones who travel abroad; everyone else uses their mobile phone.

[From Peter Cochrane's Blog: Near-field tech edges closer | CIO Insights | silicon.com]

The combination of mobile and contactless seems to accelerate the transition: individually they are great, but together they are something special. Mobile payments by themselves have been around forever and have made little impact in the physical world (except for special niches like car parking). I still can’t use my mobile to buy a bottle of cold water from a machine in the Tube.

The first case of a mobile phone being able to be used to handle a payment was in 1998 as an experiment in Espoo Finland just outside of Helsinki, where two Coca Cola vending machines were installed with a mechanism to accept payment by SMS text messaging

[From Communities Dominate Brands: End of Cash? First blog in a series examining the pending doom of minted coins and printed banknotes]

Adding contactless transforms the proposition from fiddling about sending text messages to a quick tap. As far as I can tell, from the pilots that we have been involved in, customers are not a barrier. They like it. So why doesn’t my phone have NFC in it right now, and why doesn’t the drinks vending machine on the Tube have a reader?

Why is it taking so long? As with Faster Payments, the problem lies with the marketing teams in the major banks.

[From The innovative world of UK payments]

I disagree. I’m no fan of marketing departments, but the problem with mobile payments is different. Banks have never had to deal with payments in this way before: they can control ATMs and POS terminals, EMV cards and FPS. But they don’t control mobile, and in particular they don’t control the Secure Element (SE), the tamper-resistant hardware that transforms mobile phones from being content devices to transaction devices. There are different ways of dealing with this, but I think it is fair to reflect that the specific tension between banks and mobile operators remains problematic. In some countries they are joining forces, in others they are forging bilateral agreements, in others they are going their own.

while credit card companies might need the carriers to get into mobile payments, they might soon learn that the carriers don’t need them.

[From In mobile payments, credit card companies might be a third wheel | Econsultancy]

Indeed they don’t, but that has no relevance to the Isis initiative that is the subject of that post because

Verizon, T-Mobile and AT&T are entering into an agreement to let customers pay for products with their smartphones… they are not working with Visa, MasterCard, or American Express on this venture. They’re not working alone either, instead partnering with Discover and Barclays on this venture.

[From In mobile payments, credit card companies might be a third wheel | Econsultancy]

Hhmmm. So in this particular case, the carriers are partnering with a credit card company and a bank. So do they have somewhere to go? Well, let’s return to the point. We don’t have a perfectly fine way of taking non-cash payments, but soon we will because of mobile phones. And there are some dynamic go-ahead organisations that have already recognised this.

the local Girl Scout group there has teamed up with Intuit to accept credit cards using the company’s GoPayment app (and accompanying card reader) for iOS and Android

[From Teh Gay Geek: GIRL SCOUTS IN OHIO TAKING MOBILE PAYMENTS FOR COOKIES]

Back in the 1980s, there were people who said that mobile phones would never sell because there were payphones everywhere (eg, McKinsey). The POS terminal of 2011 is the payphone of 1981.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.