Is 2018 the year of the #IDIoT?

Greyscale backing image

My daughter has a blue rabbit in her bedroom that talks to her.  The blue rabbit says whatever I ask it to say and my daughter loves to listen.  She can talk back to the rabbit, and I can pick up her messages wherever I am in the world through an app and send a reply, all through the medium of a fluffy blue bunny.

My daughter is growing up in a generation that expects their things to be connected, and of course, the Internet of Things (IoT) has been on our radar here at Consult Hyperion for some time, with many of our clients looking to us to advise them on their strategy and R&D in this area.

It’s one thing successfully connecting something to the internet, it’s quite another to ensure that connection can only be used for the purposes for which it is intended.  My daughter’s cloud pet was secured with a username and password, so you can imagine the long sigh, as I read the email stating:

“We recently discovered that unauthorized third parties illegally gained access to our CloudPets server. Our investigation concludes that no voice recordings or profile pictures were stolen. The stolen user account information may have included names, email addresses, and encrypted passwords.”

Cuddly toy manufacturers are not security experts.  Neither are fridge manufacturers, baby monitor manufacturers or security camera vendors.

Consult Hyperion has recognised the need for stronger identity security for the IoT for a while.  Indeed, In 2015, our own Dave Birch emphasised the point that a more robust approach to identity was required for the Internet of Things by coining the tongue-in-cheek hashtag #IDIoT.

Three years on, we’re finally starting to see governments and industry bodies step-up to fill the IDIoT void.  Earlier on in the year the UK Government announced their Secure by Design report, proposing a common code of practice for IoT Security.  This week, the GSMA announced the launch of their IoT Security Guidelines, supported by their IoT Security Assessment Scheme.  So finally, frameworks are starting to emerge that could enable the delivery of IoT services across the economy with consistent security. Real industry frameworks mean real product opportunities, so we’re looking forward to helping our clients move forward, taking the IoT strategies and prototypes we have helped develop, and turning them into commercial offerings.

Of course, securing IoT isn’t just about identity and information security, it is also about payments. IoT takes on a new dimension when your things can buy stuff for you.  And of course, when money is involved, fraud becomes that much more lucrative, and so the security bar is raised yet again.  For us here at Consult Hyperion, IoT is starting to get really interesting.

Financial Services messaging standard at the heart of new payment infrastructure in UK

Greyscale backing image

This June, the Bank of England launched a six-week consultation on the adoption of ISO 20022 as the single message standard for payments in the UK. In conjunction with the New Payments System Operator (NPSO) and the Payment System Regulator (PSR); the Bank of England has published ‘ISO 20022 consultation paper: a global standard to modernise UK payments’. In this document the commitment to the standard is clear:
 

‘The Bank and NPSO as payment system operators, and the PSR, as economic regulator of payment systems, are (therefore) committed to pursuing an effective UK-wide adoption of ISO 20022, and will use all the tools at their disposal to ensure that this is achieved.’

 
ISO 20022 is a multipart standard produced by ISO Technical Committee 68 (Financial Services). Way back in September 2005 ISO approved the first ISO 20022 compliant messages: a set of four Customer-to-Bank Payment Initiation messages. In the 12 years that followed the compliant messages have grown to number more than 400.
 
One of the first widespread implementations of ISO 20022 was in the introduction of Payment messages for the Single Euro Payments Area (SEPA) Direct Debit/Credit Transfer scheme. SEPA DD/CT used the ISO 20022 payment messages and created a framework document (Rule Book), detailing the way that these messages were to be used within SEPA. SEPA DD and CT have been mandated for Euro area countries since 2014 and Euro denominated payments in non-Euro countries since 2016. The take-up of ISO 20022 word-wide is now growing. In real-time payments, ISO 20022 has launched in the US and Australia. Indeed, such is the take-up of ISO 20022 Payment Messages for real-time-payments that there is now a group set up under the ISO 20022 umbrella with the objective of documenting a harmonised and consistent view of ISO 20022 business processes, message components, elements and data content for Real Time Payments.
 
In late 2016, Payments Canada announced that ISO 20022 would be rolled out across all its systems as part of the mission to modernise the Canadian payments system. In the U.S. the wire systems – FedWIRE and CHIPS will adopt ISO 20022 beginning in 2020. The number of countries implementing ISO 20022, particularly in payments is growing at a fair rate.
 
As mentioned at the start of this blog, the standard will be adopted in the UK across CHAPS, Faster Payments and BACS, the three main interbank payments systems, which together process over 8 billion payments per year, with a total value of over £90 trillion.
 
Moving away from their legacy message formats will give all UK Payment schemes opportunities to enhance their messages with additional data that can be carried in ISO 20022 messages. This will give users better insight into the message content, for example by including invoice data. It will also give fraud engines more data to work on and enhance the ability to detect financial crime. The Bank also proposes that the CCM should use of the Legal Entity Identifier (LEI) within a dedicated field. This will enable clear and unique identification of legal entities participating in financial transactions. It is proposed that this becomes the universal identifier in the UK economy and will be applied to all business extending its use among medium and small business.
 
Additionally, if uniform structures and data formats are utilised across all payment platforms there is the potential to channel payments between schemes to boost resilience of the payments system as a whole.
 
The implementation of the ISO 20022 CCM will be using XML as its ‘syntax’, the language that is used to convey the message content. However, with much innovation being based on the use of APIs, ISO 20022 is not resting on its laurels. In November 2017 23 countries including China, Singapore and the UK decided to focus effort and pool resources to develop the first ISO standard for APIs in financial services’ and ISO 20022 .
 
Things move slowly in the world of international payments standards but now the rate of ISO 20022 deployments is accelerating, and it has a firm place at the heart of the UK Payments Infrastructure. Rest assured Consult Hyperion will be there to help guide you through the interesting times to come.

What is the Impact of Digital Identity on a National Economy?

Greyscale backing image

According to research just published by the Digital ID & Authentication Council of Canada (DIACC) with Consult Hyperion’s support, the potential value of trusted digital identity to the Canadian economy is at least 1% of Canada’s GDP, or CAD $15 billion.
 
Those of us who have recently been asked to provide copies of our passport and gas bill when opening a new bank account or taking out a new mobile phone contract, understand the lengths that organizations go through to incorporate old world identity processes into their new digital services. DIACC’s research paper highlights how the savings delivered by a robust digital identity ecosystem arises through reducing friction and increasing trust for governments, businesses and citizens alike.
 
One of the DIACC’s objectives is to drive the development of a digital identification and authentication trust framework to enable Canada’s full and secure participation in the global digital economy. When published, this framework will provide a common lexicon and guidelines for all the stakeholders within the digital identity community in Canada. It will allow each party to understand the roles and responsibilities of all parties in the ecosystem, while also allowing buyers of those systems to understand where a vendor’s solution competes with or complements, another.
 
In a market as dynamic and collaborative as Canada this is important.
 
Once a robust digital identity ecosystem is enabled and new solutions are introduced to the market by service providers, how will that impact the economy? DIACC’s research indicates, it will drive the adoption and use of digital services as it will make it easier for consumers to sign up for and access online services, provide the ability to obtain informed consent, and streamline the processes across a variety of industries such as government, healthcare, financial services, and eCommerce.
 
The research Consult Hyperion undertook with DIACC has shown the direct correlation between robust digital identity and economic benefit. Delivering a nation-wide solution will require both creativity and stamina. Lead applications must prove the benefits of digital identity. Service providers need to identify and root out inefficiencies in existing services. New digital business models will need digital identity to create fully digital user journeys. Everyone needs to work together to accelerate adoption and drive critical mass.
 
There will also be cost of doing nothing – marginalised parts of society continue to struggle to access important services, small businesses will face continued bureaucracy in an increasing digital world and criminals will continue to exploit the systemic gaps that exist in many digital services today.
 
Working with the Canadian community to explore the benefits of digital identity in numerous places across the economy has been fascinating. As payments and identity technology people, we know that tools and technology already exist to deliver wide scale digital identity.
 
The collaboration already evident in Canada is striking and something Consult Hyperion, are excited to be part of. Chat with us further at the IdentityNorth event taking place June 19-20, in Toronto.
 
http://www.identitynorth.ca/

Money 2020 Europe

Greyscale backing image


 
Money 2020 Europe in Amsterdam was bigger than last year’s event in Copenhagen but kept the same mixture of efficiency and serendipity that we love it for. Seven different tracks, sponsors suites all around, a full programme all day and every day but with a central atrium where everyone could meet, plenty of food areas where you could sit and chat, a huge but not overwhelming exhibition area, panels ranging from the serious and intellectual to the more frivolous but still educational and keynote speakers that you actually wanted to see. It was great, and the CHYP team set up camp there on the Sunday afternoon so as not to waste a moment of it. On Sunday evening we hosted a client reception with our friends from CCGroup and had an enjoyable start.
 

 
Yes, the event had all of those things. But it was also fun. In the lead up to the event I didn’t really pay attention to the circus theme that they were creating for it. Yet it worked. Big time. The Money 2020 team had created such an interesting atmosphere! As soon as you walked in in the morning you felt good about being there and the circus shtick was actually quite charming.
 

 
I’m not afraid to admit it, even to my Finance Director. We had fun! We met clients and prospective clients but we also met friends old and new. We spent long days in and out of meetings then we went to a street party until all hours. We had client events in nightclubs and parks. I’m already looking forward to going again next year and there really aren’t that many events you can say that about. The “street party” where they blocked off a whole street downtown and gave it over to Money2020 revellers was just amazing.
 

 
There was plenty of serious business getting done there as well. Here I am taking part in the Gemalto discussion about digital identity in the Amstelpark, for example.And this sort of thing was going on all the time – there was no shortage of stimulation as the bankers, fintechs, techs and others moved from the event to event.
 

 
The event itself had some terrific tracks that included presentations and panel discussions with many of Europe’s key players in the fintech space. I won’t go through all of the here but I will pick out out a couple of sessions that got talked about. Charlotte Hogg, the CEO of Visa Europe, had the unenviable job of giving a keynote on the Monday after the Friday before but handled herself perfectly. It wasn’t her fault that the authorisation network had fallen over but she took responsibility and delivered an appropriate apology. In fact, she inspired me to do the same later in the day when I had the even more unenviable task of telling the delegates gathered at the main stage that noted Hollywood personality would not be turning up in person to talk about identity fraud, biometrics and strong authentication but had instead sent a video.
 

 
When we were talking about the key themes from the event afterwards, I said that I thought that there were quite a few and that there were no standout dominant memes stalking the arena floor. Looking back on it, however, I think that there were three things that stood out to our team as distinct opportunities because they are areas where organisational strategies are still being formed and the interaction between technology, business and regulation is taking us in interesting directions.
 

 
The first of these was, obviously, identity. Our identity deep dive session on Wednesday morning was standing-room only. For a session on the morning of the final day to be this full means only one thing: that it’s a key topic for delegate take-aways. I hope our delegates were not disappointed. I had a great panel (Emma Lindley from Visa, Katryna Dow from Meeco, Jacoba Sieders from ABN Amro and Roger Haenni from Datum) and practical case studies from ForgeRock to finish the session. I gave quite a detailed presentation talking the delegates through Consult Hyperion’s well-established “three domain identity” model (3DID), using to explore issues around population-scale identity, mass-market identity services and the potential for the blockchain to disrupt: you can see it here:
 
Digital Identity, Not Digitised Identity from David Birch
 
Identity permeated throughout other discussions and debates as well. I think they may have to add a whole Identity 2020 day next time!
 
Everyone understood just how pressing the need for mass market solutions to deliver identification, authentication and authorisation services to support transactions and there were plenty of talks about biometrics, blockchains and bots implementing digital identity for our new online world.
 

 
The second key theme was open banking and the regulatory shaping of the financial services sector. My Consult Hyperion colleague Tim Richards ran the workshop on Open Banking on the final day, helping organisations to think through their competitive strategies in the face of the PSD2-inspired asymmetric warfare between banks and competitors. (Asymmetric because retailers and others will have access to the banks’ customer data but the banks have no reciprocal right.)
 

 
The relationship between PSD2, GDPR and bank strategies in the face of competition from internet giants and the Asian players is complex and fascinating and I heard many different scenarios from different perspectives over coffee and drinks. A commonly heard view was that the number of banks in Europe will shrink significantly over the next 5-10 years as will the number of payment card transactions. I came away certain that the long-term impact of open banking is far greater than many people think, a point I made when I was interviewed for “Studio V”, the Verifone video channel [Youtube, 5m50s].
 

 
The final, and I think in the long run most important, key theme was artificial intelligence. AI, and in particular machine learning (which is good for the incumbents because they have the massive quantities of data needed to fuel it). As several speakers noted at different points in the event, AI is coming and it’s coming pretty quickly. At the same time, it’s hard to imagine what the impact will be because bots selling financial services to bots while being regulated by bots takes us into a new world. While there was plenty of talk about jobs going, there was a surprising amount of optimism around as well. I suspect that many of the delegates are fundamentally optimistic people anyway, but hearing the legend (an overused term, but wholly appropriate in this case) Steve Wozniak talk positively about building ethics into machines would certainly have helped them look away from Terminator-style dystopias.
 

 
On which topic, I had the good fortune to chair the AI “bulls and bears” session, where experts Clara Durodie from Cognitive Finance, Terry Cordeiro from Lloyds Banking, Emma Stromfelt from Swedbank and Prof. Markos Zachariadis from Warwick Business School set out competing visions for AI in financial services and then we had the audience vote for the winner (which was Emma, as it happened).
 

 
For a final fun session on Wednesday afternoon, I took part in the “Room 101” debate (based on the British TV show of the same name). I decided to have a go at persuading the audience to join me in consigning “The Blockchain” to Room 101 on the grounds that it was nothing more than an expensive and inefficient database, something that I was indeed able to do!
 

 
I really don’t know how they do it. In few short years money 2020 has become a destination event for a great many people working across the world of financial services technology. Each year it raises expectations and then meets them and this year in Amsterdam continued this admirable tradition. Cheers!
 

Open (but asymmetric) warfare

Greyscale backing image

You’ve probably noticed that something big is going on in the UK. It’s called “open banking” and although it hasn’t made much difference to the man at the Clapham ATM just yet, it will. In computer terms, it’s rather as if the banks are being obliged to install sockets in customer accounts that anyone can plug in to access those account (with the customers’ permission, of course). So, you can tell your bank to let (eg) Amazon access your bank account and there’s nothing they can do about it. In a recent speech Karina McTeague, director of retail banking supervision at the Financial Conduct Authority (FCA), said that while banks must be “aware of their legal obligations in respect of data protection and consumer protection”, they should allow their customers to make use of [third-party services] in relation to those payment accounts without penalty, including allowing their customers to share their credentials”

So, basically, it’s on. Third parties can have access to bank customer data and there’s nothing that banks do about it. Who will benefit from this? We have long advised our clients that the competition to incumbent financial services providers will not be fintechs. I wrote last year that the major beneficiaries of the regulators pressure to open up the banks will be the internet giantswho already have the customer relationships. Of course, when I say it, no listens. But when the woman at the top of Europe’s biggest retail bank weighs in, I suspect one or two people may sit up and pay attention.

Ana Botín, executive chairman of Santander, told the Financial Times that the EU’s Second Payments Services Directive “needs to be reviewed for the digital age. The theory is good but it needs to be fair — at the moment it’s not symmetrical.”

From Santander chair calls EU rules on payments unfair.

Her point is that by creating the asymmetry described above, regulators may well have created the conditions to replace an uncompetitive oligarchy (as they it) of banks with an uncontrollable oligarchy of internet giants. This is not, as my colleague Tim Richards wrote last month, a theoretical issue. He used the example of UK insurer Admiral, which created a scheme to allow people with limited credit histories access to insurance products using social media data. The idea was that if people were willing to grant Admiral access to this data they could perform a form of social identification and verification with an element of personality checking to identify people with traits conducive to good driving. It’s didn’t last. Facebook blocked Admiral from getting access to the data:

Is this, as Ms. Botin asks, really fair?

If it isn’t, what should be done about it?

Earlier this year, I had the honour of chairing Scott Galloway at the KnowID conference in Washington. Scott is the author of “The Four”, a book about the power of internet giants (specifically Google, Apple, Facebook and Amazon). In his speech, and his book, he sets out a convincing case for intervention. Just as the government had to step in with anti-trust acts of the early 20th century in recognition of the fascist nature of monopoly capitalism, so Scott argues that they will have to step in a century on and, again, not to subvert capitalism but to save it. His argument centres on the breaking up of the internet giants, but I wonder if the issue of APIs might provide an alternative and eminently practical way forward?

Two and The Four

With Scott Galloway at KnowID

Ana suggested that organisations holding the accounts of more than (for example) 50,000 people ought to be subject to some regulation to give API access to the consumer data and it seems to me that this might kill two birds with one stone: it would make it easier for competitors to the internet giants to emerge and might lead to a creative rebalancing of the relationship between the financial sector and the internet sector.

This gives us the obvious regulatory response to the need to create a level playing field: let us put in place a set of reciprocal rights and responsibilities. Forum friend Simon Lelieveldt, who I always listen to on these matters, also suggests this as the way forward. He says that if the European Commission wants a “balanced” market with effective competition then it should “redress the design errors in the PSD-2 and allow banks to ask fees and allow them reciprocal access to the customer data”. I think this gives us a sensible outline manifesto for the next generation of PSD2/GDPR and such like: open, transparent and non-discriminatory pricing for API access to customer data (with the customer’s consent) irrespective of the nature of the organisation: bank, media, telecoms whatever.

Tim Richards and I will be running a workshop session on open banking and the strategies for incumbents, fintechs and competitors on Wednesday June 6th at Money 2020 in Amsterdam just a couple of weeks from now. Please do come along and join in the discussion and debate around this crucial topic. We look forward to seeing you there.

On Facebook, Open APIs and User Consent

Greyscale backing image

In the recent congressional hearing into how Facebook data has been misappropriated for political and probably nefarious purposes Mark Zuckerberg usefully confirmed that Facebook’s users own their own data:

 “Actually, the first line of our terms of service say that you control the information & content that you put on Facebook”

Of course there is a very similar example of customer-controlled data, currently stuck in a corporate silo, which is being opened up – the European Union’s PSD2 regulation which forces banks to implement APIs to allow access to their customer data. Actual third-party access to this data is controlled through consumer consent implemented via two factor authentication. In essence, banks are regarded as the custodians of the consumer’s financial transactional data, but not the owners.

Oddly, although Mr Zuckerberg’s statement appears to put Facebook in exactly the same position as the European legislators have put European banks, it’s not at all clear that the same rules apply. As it stands at the moment Facebook – not to mention Amazon, Google, Apple, etc – can, with the appropriate consent, access bank customers’ data but the banks can’t access Facebook’s data, not without Facebook permitting this. This asymmetry of information access is likely to lead to even greater asymmetry of market power than already exists.

This asymmetry isn’t even theoretical. Last year the UK insurer Admiral created an interesting scheme to allow people with limited credit histories access to insurance products using social media data. A social media profile is quite hard to fake if you know what you’re looking for – the strength of links to other real profiles and the depth of data mean that really faking a profile is really hard to do.

Admiral’s idea was that if people were willing to grant them access to this data they could perform a form of social identification and verification with an element of personality checking to identify people with traits conducive to good driving. You might think this invasive but if you’re a careful 18 year old then getting your insurance bill reduced by thousands of pounds might be worth giving up access for, at least temporarily.

To cut a very long story short the trial ended when Facebook blocked Admiral getting access to the data: https://www.theguardian.com/money/2016/nov/02/facebook-admiral-car-insurance-privacy-data

“In an embarrassing U-turn, the insurance firm pulled the product less than two hours before it was due to officially launch on Wednesday. The product, called firstcarquote, was launched later with “reduced functionality”: users can log in to the product with Facebook but it will no longer analyse their data”.

And:

“Facebook said protecting the privacy of its users was of the “utmost importance” and that it had clear guidelines about how information obtained from the site should be used.”

Listing the problems that this potentially raises would take a much longer article but let me raise just a few. Firstly, in what way does the Internet Giants’ control of personal, social data different from the banks’ control of personal, financial data? And if the banks are being regulated to allow third-parties access to their monopoly of financial data then why shouldn’t the likes of Facebook and Google be regulated to allow third-parties access to their monopoly of social data? Why can Facebook choose what third-parties do with this data while banks can’t? After all, as Mark Zuckerberg stated, it’s their users’ data, not Facebook’s.

Secondly, if PSD2 ensures that the users have control of the information and content held in banks via mandated APIs using two factor authentication to manage user consent why shouldn’t exactly the same rules apply to social media data?  Finally, the asymmetry of data access that PSD2 imposes will place more power in the hands of social networks at exactly the same time as the ability of these companies to handle that power is being questioned: is that what we want?

Regulation is not, and never can be, a panacea for all of the world’s ills. However, in PSD2 we have a template for ensuring that consumers can control and manage access to their data. It’s hard to see why what is mandated for banks shouldn’t be mandated for other organisations that have equivalent power. We predict that if Facebook and its cohorts don’t take responsibility for providing equal, fair and properly consented access to the data to they hold then they will be forced to do so. We already have a template, it’s just a question of how long it takes regulators to realise this.

TLS, DSS, and NCS(C)

Greyscale backing image

As I was scanning my list of security-related posts and articles recently, my eye was drawn by the first sentence of an article on (Google security engineer) Adam Langley’s blog, indicating that Her Majesty’s Government does not understand TLS 1.3. Of course, my first thought was that since HMG doesn’t seem to understand the principles of encryption itself, it’s hardly surprising that they don’t understand TLS. However, these aren’t the thoughts of an understandably non-technical politician but instead those of Ian Levy, the Technical Director of the National Cyber Security Centre at GCHQ – someone you’d hope does understand encryption and TLS. Now normally, I would read this type of article without feeling the need to comment. So what’s different?

Well, following the bulk of the article discussing how proxies are currently used by enterprises to examine and control the data leaving their organisation, by in effect masquerading as the intended server and intercepting the TLS connection, is the following throwaway line:

For example, it looks like TLS 1.3 services are probably incompatible with the payment industry standard PCI-DSS…

Could this be true? Why would it be true? The author provided no rationale for this claim. So, again in the spirit of Adam Langley, “it is necessary to write something, if only to have a pointer ready for when people start citing it as evidence.”

Adam’s own response – again following a discussion about how the problem with proxies is their implementation, not with TLS – is that

…the PCI-DSS requirements are general enough to adapt to new versions of TLS and, if TLS 1.2 is sufficient, then TLS 1.3 is better. (Even those misunderstanding aspects of TLS 1.3 are saying it’s stronger than 1.2.)

which would seem to make sense. Not only that, but

[TLS 1.3] is a major improvement in TLS and lets us eliminate session-ticket encryption keys as a mass-decryption threat, which both PCI-DSS- and HIPAA-compliance experts should take great interest in.

In turn, Ian follows up to clarify that it’s not TLS itself that could present problems, but the audit process employed by organisations

The reference to regulatory standards wasn’t intended to call into question the ability of TLS 1.3 to meet the data protection standards. It was all about the potential to affect (badly) audit regimes that regulated industries have to perform. Right or wrong, many of them rely on TLS proxies as part of this, and this will get harder for them.

So that’s alright. TLS 1.3 is not incompatible with PCI DSS. So what is the problem?  Well, helpfully, Simon Gibson outlined this in 2016:

…regulated industries like healthcare and financial services, which have to comply with HIPAA or PCI-DSS, may face certain challenges when moving to TLS 1.3 if they have controls that say, “None of this data will have X, Y, or Z in it” or “This data will never leave this confine and we can prove it by inspecting it.” In order to prove compliance with those controls, they have to look inside the SSL traffic. However, if their infrastructure can’t see traffic or is not set up to be inline with everything that is out of band in their PCI-DSS, they can’t show that their controls are working. And if they’re out of compliance, they might also be out of business.

So the problem is not that TLS 1.3 is incompatible with PCI DSS. It’s that some organisations may have defined controls with which they will no longer be able to show compliance. They may still be compliant with PCI DSS – especially if the only change is to upgrade to TLS 1.3 and keep all else equal – but cannot demonstrate this. So what’s to be done?

Well, you could redefine the controls if necessary. If your control requires you to potentially degrade, if not break, the very security that you’re using to achieve compliance in the first place, is it really suitable? In the case of the two example controls above, however, neither of them should actually require inspection of SSL traffic.

For the organisation to be compliant in the first place, access to the data must only be possible to authorised personnel on authorised (i.e. controlled) systems. If you control the system, you can stop that data leaving the organisation more effectively by prohibiting its access to arbitrary machines in the external world. After all, you have presumably restricted access to any USB and other physical storage connectors, and you hopefully also have controls around visual and other recording devices in the secured area. It is difficult in today’s electronic world to think of a situation where a human (other than the cardholder) absolutely must have access to a full card number without (PCI DSS-compliant) alternatives being available.

So TLS 1.3 is a challenge to organisations who are using faulty proxies and/or inadequate controls already. It certainly doesn’t make you instantly non-compliant with PCI DSS.

Given this, we, as humble international payments security consultants, are left puzzled by the NCSC’s line about TLS 1.3 and PCI DSS compatibility. At worst, organisations need to redefine their audit processes to use the enhanced security of TLS 1.3, rather than degrade their security to meet out of date compliance procedures. But, of course, this is the type of problem we deal with all the time, as we’re frequently called in to help payment institutions address security risks and compliance issues. TLS 1.3 is just another tool in a complex security landscape, but it’s a valuable one that we’re adding to our toolkit in order to help our clients proactively manage their cyber defences.

EMV tokens are more than just a faster horse…

Greyscale backing image

If I had asked people what they wanted, they would have said faster horses.

You’ve probably seen this quote (allegedly by Henry Ford) before. It is regularly cited as an example of how true innovation has to be something new; not just a better version of something we already have. In the early 20th century, when horses were the private transportation vehicle of choice, a car was something new.

Credit or debit cards are the existing vehicle of choice for retail payments, with 19 billion card transactions made in 2016 in the UK alone. Card’s are great in the face-to-face retail market for which they were originally designed, but not quite so great for use in the digital economy. Historically, a lot of the efforts made to improve the situation, such as address verification and card security codes have just been about trying to make the horse go faster. There is a need for something new, and there are many possible technologies that could provide it.

One such example is EMV Tokenisation. EMV Tokenisation is the underlying technology that has been used to delivery mobile contactless services such as Apple Pay and Google Pay. Exciting for payment nerds and tech giant fan-boys, maybe, but I’ve got a contactless card already. Aren’t tokens just a means to delivering a faster horse? If tokens were only applicable to contactless payments that could be the case, but Token Services such as Visa’s VTS and Mastercard’s MDES offer much more. Indeed, the likes of Apple and Google already use them for more, providing both in-app and browser based payments, but this is just the tip of the iceberg. The real innovation offered by token isn’t the delivery of mobile wallets, it is the removal of card details from the payments ecosystem.

In a nutshell, EMV tokenisation is designed to end the reliance we all have on the use of card numbers for card payments. Giving merchants the problem of securing card numbers belongs to the old world of horses. Instead digital merchants are given a token. The token cannot be used to derive the card number, and has security and usage controls such that merchants and customers alike no longer even need the card details, and so no longer need to fear a data breach. The card details are protected by the Token Service. Bye-bye PCI compliance, so long identity theft. Tokens are more than just a faster horse. They are an approach to payments designed for the digital age.

That’s why I was pleased to see the announcement from Mastercard that Flipkart have become the first online merchant in the Asia Pacific region to launch on the Mastercard Digital Enablement Service (MDES).

We’re starting to see big online merchant’s worldwide move away from storing card details, and look for smarter alternatives, and if the card schemes get their product propositions right, EMV tokenisation will be the technology that underpins many of those alternatives. I’m sure we will see many similar announcements from all the Token Services over the next year.

I’ve had the privilege of being involved in EMV tokenisation from the early days, working for a number of clients in understanding how to implement the specifications and respond to the opportunities. The likes of Apple Pay and Google Pay have enabled the delivery of the infrastructure, but it is the usage by online merchants, and delivery of new and innovative acceptance approaches that will deliver the real volume. And of course this will open up new opportunities for payment intermediaries to help merchants realise these benefits.

I’m convinced that EMV Tokens aren’t just a faster horse, but will they, like Henry Ford’s Model T, be the most successful car in the market? Anyone following developments in Open Banking driven by PSD2, or other initiatives such as the NPA in the UK will be well aware that other vehicles are definitely available. I’m looking forward to finding out.

Fraudsters Prefer the Easiest Option

Greyscale backing image

At Consult Hyperion we spend a lot of time worrying about the security of the PII and account information stored in the smartcard and mobile services we help our clients to build. Apart from the financial and reputational risks associated with any loss, consumers tend to stop using services they consider to be insecure. Both risk our client’s investment in their service.

Over the weekend the Daily Telegraph ran a story blaming the rise in contactless payment card fraud in the UK on the availability of devices on the Dark Web that can be used to steal card data from contactless cards. Contactless card usage in the UK is on the rise, whilst Cheque usage is on the decline, so it is not inconceivable that contactless card fraud has overtaken cheque fraud. However, the cause is much simpler than that suggested by the article.

Yes, you can read some information from a contactless card with an NFC-enabled mobile device. However, thanks to those clever cryptographers within the payment brands and Consult Hyperion the data that can be obtained from the card is time and device dependent. It cannot be used to manufacture a new card, so has limited value to the fraudster.

Rather thieves know that they can use a stolen card in the local store to buy goods up to the £30 limit in one or more locations, provided that they avoid the CCTV cameras. As the transactions are low value, the police tend not to investigate them. Any losses that the merchant and the cardholder may incur are covered by the Issuer and the Payment Brand, provided that they have complied with Issuer and Brand’s rules. So, the risk to the thief is low and the returns, say in terms of a good night out with friends, are high.

Contactless cards were introduced to replace cash in low value transactions. ‘Tap and Pay’ was seen to be as convenient as taking cash out of your pocket or purse. The risk that the card would be stolen and used by the thief was recognized and limited to an acceptable value in the UK by the contactless limit.

At Consult Hyperion we regularly help our customers to assess such risks and make such decisions. The drive towards the ‘frictionless transaction’, i.e. one in which there are no barriers that might get in the way of the consumer completing the purchase, has made these conversations more frequent and more difficult. However, we always focus on the reasons why the consumer will use your service, which maybe why consumers continue to use contactless payment cards.

Nordics, new technology and neo-banks

Greyscale backing image

The wonderful people from FinansNorge invited me to Oslo to give at talk at their FutureBank 2018 event. It was a very enjoyable day out at a bustling and very well-attended series of discussions about the impact on new technology of financial services.

I was there to talk specifically about the future of money and since the whole token and ICO space is a focus of great interest, I tried to explain why I thought that there may be good reasons for thinking that a regulated token world would be dynamic and beneficial. I don’t mean the EMV tokens that we are used to dealing with but the tokens built on top of cryptocurrencies. I focused on tokens rather than the underlying cryptocurrencies because tokens link to real-world assets and I am sceptical about the ability of cryptocurrencies themselves to become mass-market stores of value. For our clients, this is an area worth experimenting with. While the technology of tokens implemented using smart contracts on a blockchain of one form or another may have issues yet to be resolved (around scale, for example), the concept works well enough to be of interest for prototypes and pilots. In the long term, I think tokens means multiple “smart” monies that embody different values and might even mean money that won’t allow you to use it unless you are upholding its values!

In the afternoon, my colleague Dan Penn and I strolled over to the session on “neo-banking” because we are interested in the varying strategies of both bank and non-bank challengers. I have to report that the session on Neo-banking was absolutely rammed. There was barely standing room. I understand why: when genuine competition is coming, banks have to work hard to establish a strategy. It used to be really easy responding to competitors who were banks.If they decided to give away a record token for student account then you could counter with a Railcard. If they offered a 90% mortgage then you could offer a 95% mortgage. If they offered a credit card with cashback in British Airways miles then you could offer a credit card with cashback in Virgin miles. Competing with other banks might have been difficult at times because of capital requirements or shareholder demands or margins on transactions but at least you understood how that competition worked.
 
It’s all to do with theory of mind: you are a bank so you have a mental model of how banks think and you can imagine your competitor thinking within that framework. But how do you compete with non-banks and neo-banks? How do you construct a strategy for competition with people who do not share your model of the world and have no interest in your mechanisms for creating value because they create value in entirely different ways? How do you work out, for example, your transaction fee strategy when you are competing with people who don’t care about fees because their business model is founded on data? This is what much of the water cooler talk was about.

This highly competitive world that our clients are moving into is challenging, and not because of the challengers, if you see what I mean. Open banking means new competitors but, more importantly, it means new kinds of competition. There were a number of great discussions about this both on and off stage, but a super high-level summary is that competition from new players who know how to manage and manipulate large amounts of data is worrying for the incumbents.

Pascal Bouvier from Santander Innoventures forced to me to think, as always, but I remain unconvinced by his claim that cryptocurrencies are to banking what the printing press was to the Catholic church! Nevertheless, I enjoyed engaging with informed delegates on PSD2, in-app payments (very successful in the Nordics, whereas in the UK PingIt and Paym remain of niche interest) and other topics at the intersection of banking, technology and regulation. Many thanks to FinansNorge for inviting us along to this excellent event.

Subscribe to our newsletter

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

By accepting the Terms, you consent to Consult Hyperion communicating with you regarding our events, reports and services through our regular newsletter. You can unsubscribe anytime through our newsletters or by emailing us.