Merchants, payments and the open banking ecosystem

Greyscale backing image

A major focus for the entire merchant payments ecosystem in the coming year, will be the new threats, opportunities and players in the emerging open banking world. Starting with the U.K.’s move to open banking in January (the implementation of the Competition and Market Authority’s “remedies”, or the “CM9”) and moving ahead with PSD2 across Europe, the ability for trusted organisations to access consumer bank accounts to not only obtain transaction information but also to instruct payments, will inevitably change the landscape.
 
There are new opportunities for acquirers to become broad-spectrum merchant service providers (MSPs) to facilitate interaction between the open banking infrastructure and the merchant community. This very appealing vision of the future (for merchants) will draw them towards a once in a generation change at point of sale. Merchants can easily afford to incentivise customers to switch to account-to-account “instant payments” and at the same time offer considerable customisation based on customer account data.
 
Merchants definitely need some help, and it’s not all about payments. A recent Consult Hyperion survey found that more than 90% of merchants want to use PSD2 to reduce card fees, three-quarters of them also want to use it to reduce the impact of fraud and data breaches. An Accenture survey last year also found that half of the retailers they surveyed want to use customers’ bank account data to provide special offers and customised services at POS.
 
Apart from anything else, we expect to see a resurgence of interest in the “decoupled debit” proposition whereby platform-provided strong authentication to retailer apps will allow them to bypass the existing card infrastructure (with some projections indicating that a third of European card volume could disappear in the coming years) and perhaps even the physical POS itself. It’s easy to imagine self-scanning around the supermarket and hanging up the scanner at the end, to see the store app popping up on the customer phone with the total, prompting touch ID to confirm, and the merchant instructing an instant payment from customer account to merchant account.
 
As a customer, the instant payment proposition seems just as familiar as a debit proposition: customer walks out of the merchant and the money walks out of the customers account. The fact that it never goes near the existing rails isn’t something a customer knows nor cares about. This, as is often pointed out (by me), is a great opportunity for new players (eg, Google, Apple, Facebook and so on) to join the ecosystem. These are players with a business model built on data, not merchant service charges, and thus the business models in the ecosystem will reorient. This was one of the key themes picked up at last year’s Merchant Payment Ecosystem conference in Berlin, and I wrote at the time that my impression was that some of the big plays coming would be big data, analytics and machine learning.
 
Having said that the existing rails may be bypassed, open banking also provides an opportunity for the schemes to reinvent themselves and their propositions. (As we think that the UK is about to become an interesting, exciting and unpredictable laboratory experiment in open banking, it seems to us that Mastercard’s work with VocaLink should be a focus of industry attention in this regard.) After all, a payment scheme isn’t just a data switch that connects consumers, banks, merchants and retailers. If it was, there wouldn’t be any. Rates, rules and rights are fields in which Visa, Mastercard, Amex, Discover et al have decades of experience to leverage through both their existing relationships and the new ones that will arise.
 
The retailers themselves, especially the millions of small retailers, will also benefit from this transition because a variety of new products and services will spring up to help them to manage their bank accounts, funding requirements and general financial services needs. I’m no expert on small business financing but the ability to see the details of a retailer’s bank account will surely lead to new opportunities for specialist financial services providers.
 
All things considered, 2018 is going to be a pretty interesting year and we are very much looking forward to learning about the new possibilities at Merchant Payment Ecosystem 2018 in Berlin. If you want to meet me or our Principal Consultant in the POS field, Gary Munro, at the the event then just drop us a note and we’ll see you there.

Who would have ex-Spectre-d this?

Greyscale backing image

At Consult Hyperion we’re always interested in the latest news in cyber security and in case you haven’t heard, 2018 has started with the news that the most processors found inside current computers, tablets, phones and cloud servers are vulnerable to a new class of attack. These attacks have been named Meltdown and Spectre, and are caused by common optimisations built into modern processors. Processors designed by Intel, AMD and ARM are all affected to varying degrees and, as it is a hardware issue (possibly dating back to 1995 if some reports are correct), it could affect any operating system. It’s likely the machine you’re reading this on is affected – whether it’s running Windows, Macs, iOS, Android or is in “the cloud”!!

At a basic level, these vulnerabilities break down the fundamental security barriers between an application and the operating system (OS). This means that a malicious application running on your processor may be able to read your, or your OS’s, secrets which may include passwords, keys or possibly payment data, present in processor caches or memory.

I’m not going to discuss how the vulnerabilities achieve what they do (there’s plenty of sites which attempt to do this), however I’d rather consider its impact on people, such as our clients, who may be handling sensitive data on mobile devices – e.g. payments, banking information. If you do want to understand the low-level details of the vulnerabilities and how they work, I suggest looking at https://spectreattack.com/ which has links to the original papers on both Spectre and Meltdown.

So, what can be done about it? The good news is that whilst the current processors cannot be fixed, several operating system patches have already been released to try and mitigate these problems.

However, my concern is that as this is a new class of attack, Spectre and Meltdown may be the tip of a new iceberg. Even over the last week, the issue has changed from it only affecting Intel processors, to now including AMD and ARM to some extent. I suspect that over the coming weeks and months, as more security researchers (and probably less savoury characters as well) start looking into this class of attack, there may be additional vulnerabilities discovered. Whether they would already be mitigated by the patches coming out now, we’ll have to see.

It should also be understood that for the vulnerability to be exploited, there are a few conditions which must be met:

1. You must have a vulnerable processor (highly likely)
2. You must have a vulnerable OS (i.e. unpatched)
3. An attacker must be able to execute their malicious code on your device

 
For point 1, most modern devices will be vulnerable to some extent, so we can probably assume the condition is always met.

Point 2 highlights two perennial problems, a.) getting people to apply software updates to their devices and b.) getting access to appropriate software updates.

For many devices, software updates are frequent, reliable and easy to install (often automatic) and there are very few legitimate reasons for consumers to not just take the latest updates whenever they are made available. We would always recommend that consumers apply security updates as soon as possible.

A bigger problem for some platforms is the availability of updates in the first place. Within the mobile space, Microsoft, Apple and Google all regularly release software updates; however, many Android OEMs can be slow to release updates for their devices (if they release them at all). Android devices are notorious for not running the latest version of Android – for example, Google’s latest information (https://developer.android.com/about/dashboards/index.html – obtained 5th January 2018 and represents devices accessing the Google Play Store in the prior 7 days) shows that for the top 81% of devices in use:

• 0.5% of devices are running the latest version of Android – Oreo (v8.0, released August 2017)
• 25% are running Nougat (v7.x, released August 2016)
• 30% running Marshmallow (v6.0, released October 2015)
• 26% running Lollipop (v5.x, released November 2014).

 
It should be noted that Google’s Nexus and Pixel devices have a commitment to receiving updates for a set period of time, and Google is very keen to encourage OEMs to improve their support for prompt and frequent updates – for example, the Android One (https://www.android.com/one/) programme highlights that these devices get regular software updates.

If you compare to iOS, it’s estimated (https://data.apteligent.com/ios/) that less than a month after it was released in December 2017, over 75% of iOS devices are already running iOS 11.

The final requirement is Point 3 – getting malicious code onto your device. This could be via a malicious application installed on a device, however, the malicious code could also come via a website as it’s been shown that even JavaScript sandboxed in a browser can exploit these vulnerabilities. As its not unheard of for legitimate websites to unwittingly serve up 3rd-party adverts which contain malicious code, a user doesn’t have to be accessing malicious websites for the problem to occur. Several browsers are receiving patches to try and prevent Meltdown and Spectre working via this route. Regarding malicious applications, we’d always recommend that applications are only ever installed from legitimate sources, however malicious apps still regularly appear in legitimate app stores, so this is not fool-proof.

Thinking specifically about mobile banking and HCE payment applications, which is what interests many of our customers – these applications should already be including protections to prevent, or at least detect, malicious attacks. These protections typically include numerous measures such as root/jailbreak detection, code obfuscation, data minimisation, white-box cryptography and so on.

If anything, these latest vulnerabilities are a useful reminder that security is not a single task within a project plan, ticked off when complete before moving onto the next sprint or task. Rather, it is an ongoing concern for the lifetime of the system – something that Consult Hyperion quietly helps its customers with. A year ago, few would have considered this class of attack to either have been possible, let alone something which needs to be actively mitigated.

China’s PSD2 SCA

Greyscale backing image

QR codes are everywhere because anyone can read them, anyone can use them, anyone can write them. This is in part because there is no security infrastructure. The result in China, where there was little card infrastructure in place beforehand, was the near-ubiquity of QR in the world’s biggest mobile payments market.

“Ogilvy & Mather and Ipsos concluded in a survey of China’s mobile payment market that ‘[Chinese] mobile payment has permeated all aspects of life and changed basic, everyday habits.’”

From “How Chinese Mobile Payments Are Quietly Conquering the World“.

It seemed to us that fraud would be an inevitable consequence of this QR-centric approach, that is indeed what happened. Last year, for example, the South China Morning Post reported that in March 2017 some 90m Yuan were stolen via QR code scams in Guangdong alone (a suspect in one case was found to have replaced merchants legitimate bar codes with fake ones that embedded a virus to steal personal information) and that in China as a whole, a quarter of viruses and trojans were coming in via QR.

Now, while even the man who invented QR codes says that they are an interim technology, there’s no denying that they are here to stay. Hence it makes sense to find a way to make them more secure, and the obvious way to do this is two-factor authentication (2FA). It turns out that the Chinese regulators have come to the same conclusion and have implemented the equivalent of the European Union (EU) Second Payment Services Directive (PSD2) Regulatory Technical Standards (RTS) on Secure Customer Authentication (SCA).

“Under new rules released by the People’s Bank of China [in December 2017], all transactions over 500 yuan (US$76) will be subject to additional levels of verification. As the transaction value passes each trigger point – 1,000 yuan, 5,000 yuan and unlimited – so the security checks will increase.”

From “China’s central bank tightens security“.

Introducing further authentication methods makes obvious sense. Just as in the UK we have contactless for low-value payments but 2FA for higher-value payments (ie, chip and PIN for cards or CDCVM for mobile), QR will be used for low-value payments but 2FA will be required for higher-value payments. Of course, in the Chinese system, QR works just as well on-line as in-person whereas in our system we don’t use chip and PIN online.

This is where we (ie, the industry) should focus our efforts in 2018, since card-not-present fraud is currently growing at 9% per annum in the UK. So what is the way to use chip and PIN online? Well, we already know – it’s the combination of web and mobile browsing with mobile wallets for transactions. When I see a web form asking me to type in my card details – in 2018 already! – my heart sinks. I’ve used ApplePay in-browser a couple of times now (which is the equivalent of using chip and PIN online, as it uses the token in the wallet on the iPhone to complete a web transactions) and I’m already frustrated that more web sites don’t use this kind of solution. If we put our minds to it, we can have online payments that are as ubiquitous as in China, but more secure.

Our live five for 2018

Greyscale backing image

It’s that time of year again. I’ve had a chat with my colleagues at Consult Hyperion, gone back over my notes from the year’s events, taken a look at our most interesting projects around the world and brought together our “live five” for 2018. Now, as in previous years, I don’t expect you to pay any attention to our prognostications without first reviewing our previous attempts, otherwise you won’t have any basis for taking us seriously! So let’s begin by looking back over the last year and then we’ll take a shot at the new one!

Goodbye 2017

This was the “live five” of technology-driven changes in the secure transactions field that we thought would have a real business impact over the previous year. In the spirit of openness and honesty and disclosure that we are famed for, let’s see how those predictions fared.

  1. RegTech. I think we did pretty well with this prediction. Interest in regtech has grown throughout the year and the ability of regtech to make real differences in major markets is established.
  2. Digital Identity. As we noted, one of the key regtechs, if not the key regtech, is digital identity. It did shoot up the agenda over the year and some interesting initiatives opened up.
  3. PSD2 (still). No commentary is needed!.
  4. Paying on the Go. We thought that a key use of open APIs will be payments, and very likely mobile payments. MasterCard’s purchase of VocaLink would tend to support this view!
  5. Invisible POS.  The shift from “check out to check in” paradigms is underway but it is fair to observe that we did not see the number of launches we were expecting as many of the projects remain in beta and will be holding to wait for the arrival of PSD2 (and CMA remedies in the UK).

Not bad. In fact, pretty good. So now let’s take a look at where we think the action will be in the coming year in our corner of the transactions treehouse. My guess is that you’ll agree with four out of the five – if not… let us know!

Hello 2018

From the perspective of our home base in the UK, the really big trend is easy to predict and wholly uncontroversial, since open banking is going to transform our industry. Thinking around this opens up a couple of adjacent areas as well. So…

  1. Open Banking. In the UK, the regulators’ determination to bring real competition to the financial services world means that we are about to see major disruption in the space. Last year I called this before a “crossing of the streams” (in an hommage to Ghostbusters!) because there are three different initiatives coming together.The first stream is the PSD2 provisions for access to payment accounts. As you may recall, these include a set of proposals that are due to come into force in 2018. A group of those proposals are what we in the business call “XS2A”, the proposals which force banks to open up to permit the initiation of credit transfer (“push payments”) and account information queries. Even at a pure compliance level these PSD2 regulations pose significant questions for the structure of the existing payments industry. While PSD2 does not mandate APIs (I think – it’s all gotten a bit complicated but as far as I know the screen-scrapers have fought a decent rearguard action) an open banking API is the obvious way to implement the PSD2 provisions.

    The second stream is Her Majesty’s Treasury’s push for more competition in retail banking. This led to the creation of the Open Banking Working Group (OBWG), which published its report in 2016.  It set out was a four part framework, comprising:

    • A data model (so that everyone knows what “account”, “amount”, “account holder” etc means);
    • An API standard.
    • A security standard.
    • A governance model.

    The third stream is the CMA report that triggered the remedies mentioned above. This envisages APIs to improve competition in retail banking by focusing on the use of APIs to obtain access to personal data that can be shared with third-parties to obtain better, more cost-effective services.

    These streams are coming together to create an environment of what is now called Open Banking. And it’s a big deal. And it begins in January 2018 when the nine biggest banks open up their APIs and the UK becomes a fascinating and exciting laboratory for new services. Who will take advantage of this new environment? Well, in our opinion, it’s not the fintechs. And we are not the only ones who think this.

    Much has been made of the rise of fintech [but] according to a report by the World Economic Forum (WEF), traditional banks are more vulnerable to competition from another source: tech giants like Amazon, Facebook, and Google.

    From Tech firms like Amazon (AMZN), Facebook (FB), and Google (GOOGL) are the biggest competitive threats to the banking industry — Quartz

    As we have pointed out for some time, it is not all obvious that what we refer to as the “challenger” banks in the UK (i.e., the new banks who have obtained licences in recent years) are really challengers at all. The era of the “challenger banks” is coming to an end as the internet giants compete to be the front end to the customers transactional financial services.

  2. Conversational Transactions. One class of application that will exploit API integration with banking and payment systems is chat, whether through standard messaging applications or “chatbot” interfaces. This is hardly a wild prediction, but we think that the early steps (e.g., Facebook Messenger’s recent UK payments launch) indicate a major shift in 2018. Right now, when my sons at University ask me for money on WhatsApp, I have to switch to Barclays Pingit to send the money. Not for much longer. And it is important to understand the roadmap here, because the link between conversational commerce and voice commerce is straightforward. It’s all small step from typing “Send £20 for the ticket” to saying “Send £20 for the ticket”.
  3. The Internet of Cars. Anyone who visited Mobile World Congress or CES or, I’m sure, many other events throughout the year, couldn’t have failed to notice the amount of work going on in the “internet of things” (we all understand just how important that will be) and how much of the IoT focus is on the automobile sector. You can see why this is: cars are expensive, so they can stand the cost of adding smart technology that can deliver new functionality. However, as Consult Hyperion have always said, doors are easy but locks are hard. It’s easy to connect the myriad systems in the modern car to the world, but it’s really hard to secure them. This is a great opportunity for organisations with skills in encryption, authentication, key management, operational security and so on to help the automobile industry,It’s one thing when your bank account gets hacked (because the bank has to give you your money back) but when the hackers are crashing cars for fun it’s another thing altogether. If we want our cars to engage in transactions then we have to be sure that the security infrastructure for those transactions is absolutely solid.
  4. Artificial Intelligence. Well, when it comes to money, and indeed absolutely everything else, there is no doubt that AI will be the most disruptive technology of our generation. We may be a long way from Terminators and HAL 9000, but the massive AI investments pouring into financial services around the world mean that the technology is going to our business, and soon. If you examine where banks are spending their AI budgets right now, machine learning is the main focus. An Infosys poll earlier in the year showed that two-thirds of banks were already spending in this area and this is no surprise. Banks have large quantities of data that in the past they have found difficult to extract wisdom from and they have large transactional flows that they find it difficult to manage in the context of increasing regulatory burdens. Machine learning systems excel at finding patterns and exceptions in such data, provided that they can be fed the voracious quantities of raw material, so the main use of the machine learning systems is currently fraud detection and prevention. This throws up an interesting strategic challenge for banks in the new Open Banking world, because there is a threat to risk management, information analysis and sales/marketing processes in the new environment where they may not get to see the data held by third-party providers but those providers have access to bank accounts.
  5. Tokens/ICOs.  Well, those first four predictions are mainstream. But it’s fun to pick something out of left field (as our American cousins would say) by looking where technology might mean very different kinds of assets being used in transactions. We might well see a new kind of money emerge in the coming year.  Not Bitcoin, but “tokens” (the basis of Initial Coin Offerings, or ICOs). When the current craziness is past and tokens become a regulated but wholly new kind of digital asset, a cross between corporate paper and a loyalty scheme, they will present an opportunity to remake markets in a new and better way. One might imagine a new version of London Alternative Investment Market (AIM) where start-ups launch but instead of issuing equity they create claims on their future in the form of tokens. The trading of these tokens is indistinguishable from the trading of electronic cash (because they are bearer instruments with no clearing or settlement) but there will be an additional transparency in corporate affairs because aspects of the transactions are public.  The transparency obtained from using modern cryptography (e.g. homomorphic encryption and zero-knowledge proofs) in interesting way iss, as an aside, one of the reasons why we tend to think of the blockchain as a regtech, not a fintech.

All in all, the coming year will see much more disruption than might be apparent at first because the shift to open banking, starting in the UK, is what will drive the reshaping of the sector while at the same time the advance of AI into the transaction space (transactions of all types, from buying a train ticket to selling corporate bonds) begins to reshape the way we do business.

Open Banking Revolution

Greyscale backing image

I can’t stress enough just how big a deal the UK’s transition to Open Banking is. The writer Wendy Grossman posted an excellent piece about this in her “net.wars” series recently.
 
She says…

The financial revolution due to hit Britain in mid-January has had surprisingly little publicity and has little to do with the money-related things making news headlines over the last few years. In other words, it’s not a new technology, not even a cryptocurrency. Instead, this revolution is regulatory: banks will be required to open up access to their accounts to third parties.
 
From net.wars: Regulatory disruption

 
As Wendy notes, Wired had published an excellent article about this (written by Rowland Manthorpe) in October. Having talked to some of the key players and explained some of the key concepts, he draws an important conclusion, which is that Open Banking is not “just a technical fix, or even a solution specific to banking, but a new way of dealing with the twenty-first century’s most sought-after resource, personal data”.
 
He is spot on. Identity is the new money. Banks are about to be transformed from places that store Sterling into places that store Digital Identities. Gone are the days where households hold valuable demand deposits with their banks. Now, this is hardly a new idea and it isn’t only techno-crackpots like me who keep going on about it. Banks know this to be the case, they just haven’t done anything about it yet.
 
Back in 2014, the Financial Times was reporting that “Britain’s high street banks believe their future role will be as repositories of more than just money: they want to be the safe place where customers store their digital identities”. This makes complete sense as a strategy and as the European Banking Association (EBA) white paper of the time puts it, “banks are well positioned” to be a crucial, supporting, positive part of their customers online lives.
 
Some others have also suggested that banks would let this slip through their fingers and hand digital identity to Apple, Facebook, Google, Amazon and Microsoft. Well, we’re going to start finding out in January, because I can’t help but feel that the major beneficiaries of the regulators pressure to open up the banks will not be nimble fintech startups but the internet giants who already have the customer relationships. Rowland speculates that Open Banking may expose some institutions to change and competition that they simply cannot respond to and that banks may well fail because of it.
 
This is the sort of thing that they must have been mulling over down at Open Banking Limited, the entity set up to implement open banking in the UK.

[Implementation Trustee at Open Banking Limited, Imran Gulamhuseinwala] doesn’t have much sympathy for failing banks
 
From To change how you use money, Open Banking must break banks | WIRED UK

 
Now, having sat next to Imran at dinner, I can confirm that he is one smart cookie (and a very nice guy too). He’s got a point about the competition that open banking should unleash.
 
Wendy’s words are well chosen; Open Banking is a revolution, and all we can say for sure is that there is going to be change. But as to who the winners and losers are… well, the UK is about to become an interesting, exciting and unpredictable laboratory experiment in banking regulation. In a year or two, we may at least have a signpost to the future of retail banking in place.

Can the automotive industry learn from the retail payments sector?

Greyscale backing image

Trying to balance security and convenience provided by technological advancements isn’t new news. Nor is the latest hubbub around keyless vehicle entry and the obvious security risk. A recent video issued by West Midland Police, shows two criminals using information gathered from the electronic key to enter, start and drive away a car. Research reveals that this is a simple “Ghost and Leech” attack, where the boxes held by the thieves extend the read range of the key.  When the keyless entry system on the car was initially designed, the cost and size of these boxes confined the fraud to laboratory conditions.  Now however, the boxes are readily available on the internet, are smaller and require less power thus making them portable and a convenient tool for organized criminals.

Are the automotive OEMs or their suppliers recognizing these risks and developing countermeasures?

As any information security expert will tell you, you need to understand the threat landscape in which your vehicle will operate and ensure that all cost-effective countermeasures are included in its design prior to commercial launch. It is likely that that countermeasures will have to change over the lifetime of the vehicle, as new functionality is added, e.g. in-car payments, or, as highlighted above, the criminals find new ways of attacking of the car. And so, future proofing becomes front of mind.

The long development and product lifecycles associated with the automotive industry, compared with say smartphones, combined with high certification requirements surrounding any change to the vehicle, makes this difficult. The reputational and financial costs of recalling vehicles to insert a new piece of hardware or load new software, for examples, make the business case for such interventions difficult. Many owners are reluctant to upgrade their vehicles fearing that it will impede its performance. Others are prone to litigation on the grounds that the vehicle is not performing as advertised.

Even in the advent of software advances, there is still the problem of ensuring that the software upgrade is correctly implemented across all vehicles. The mobile network operators (MNOs) are working closely with the automotive OEMs to ensure that software upgrades can be remotely downloaded over the air to connected cars; this is still in its nascent stages. We know of electric car owners that have had to wait for 30 minutes in the morning whilst their cars rebooted and others that have had the functionality of their vehicle changed when the vehicle showed signs of being imported into a different country.  Does this process introduce new information security risks as criminals take advantage of inconsistencies in the version of the software loaded into different vehicles?

At Consult Hyperion we use the return on the criminal’s investment in the fraud to determine the probability that it will be committed; always low when the keyless entry system was initially designed and now, many years later, high.  The reputational or financial gains from such attacks allow us to evaluate the cost of a countermeasure against the potential losses if it is not implemented. Our clients’ risk appetite determines whether or not they make the investment.  We use our understanding about how technology is likely to evolve to assess how and when the current level of risk is likely to change and therefore when the investment in a countermeasure becomes crucial.

Consult Hyperion has around 20 years experience of managing information security risks within distributed systems deployed primarily within the global financial services industry. Whist the context in which the criminals deploy them is different, the techniques the criminals use are the same. The Ghost and Leech attack posed a potential threat to the use of contactless payment cards following the introduction of NFC technology in smartphones. The UK press ran multiple stories about how the phones could be used to collect account information from contactless cards in peoples’ wallets. Consult Hyperion was commissioned to analyze the data that could be collected by devices snooping on the contactless card transaction at the Point of Sale and the opportunity to use that data to buy other goods in another store. As a result of this analysis the UK banks agreed to add additional countermeasures into their systems, all of which had been recommended by the international card schemes. Their introduction was coordinated by APACS, now part of the UK Payments Administration, who had commissioned some of the earlier analysis.

Using Big Data to Identify Fraudulent Transactions

Greyscale backing image

With Thanksgiving upon us and the drive for mass consumption to continue through the Black Friday and Cyber Monday purchasing frenzy in the US, we regularly hear the comment from US merchants that the migration to EMV (contact) payment cards has driven the increase in Card Not Present (CNP) fraud. I guess to a small extent they’re correct; smartcards are more difficult to clone so the fraudsters have been forced to look for alternative sources of income. However, I would suggest that the main driver has been the increase in the efficiency with which fraudsters collect and use PII (personal identifiable information) and account information.

The days of shoulder-surfing people at the ATM for their PIN and/or stealing a phone for the PII and account information stored within it are confined to the minor or opportunistic criminals. Today the specifications for PANs, test PAN numbers and real PII and account information from data breaches within the many high street names, can be purchased on the internet. These are used by organized criminals as the basis for attacks in which a range of PAN and CVV numbers are sent to multiple merchants to identify valid combinations. Valid account information is the then used to procure goods from a range of merchants.

Luckily for the merchants and banks that Consult Hyperion work with, there is a wealth of information available to determine whether or not a transaction is valid. The mobile network operators, either directly or through brokers such as Payfone (USA) and Enstream (Canada), can provide the location of the account holder’s mobile phone, which should be close to the location from which the payment transaction is initiated. The account holder’s behavioral patterns can be monitored to determine whether or not the transaction is out of character. Device fingerprinting companies such as InAuth and mSignia can tell them if the transaction has been initiated from a new device, or one with odd characteristics, such as a foreign keyboard.

However, not many companies understand the scope of the information that they have in their possession or how it can be used to mitigate the risks associated with fraudulent transactions. Recognizing the opportunity, a number of third parties are offering AI based services to help such organizations to use the patterns in their data to identify fraudulent transactions. Consult Hyperion’s customers have benefited from a more rigorous analysis of the data in their possession and how it is generated, before they started working with these third parties.

My colleagues at New York and Guildford, UK, have a detailed understanding of the messages passed between the Merchant and Issuer and all parties in between in a retail payment transaction. Over the last 15 years, we have used this knowledge to de-bug or optimize the flow of information between all parties. More recently we have been asked to evaluate how patterns in the data can be used to identify fraudulent transactions. You would be surprised how often the PAN number is included in the transaction message. Comparing each instance of the PAN will allow you to check that the criminals have not tampered with those messages.

The results of our analysis helped our clients to focus their engagement with prospective vendors. They now have a better understanding of how the different parts of their authorization systems interact with each other, what data can be monitored and why. Their initial discussions with third parties have moved from “Is this possible?”, to “This is what we want to do”.

I hope that you have a Great Thanksgiving if you are in the US or London this weekend and that between them, Uber, Equifax et al have left you with sufficient credible payment credentials to allow you to enjoy the consumer fest that follows. Me, personally, I am heading somewhere I can be off-grid for the weekend, if only to stay away from all those tempting offers.

PSD2, Curtains for Direct Carrier Billing?

Greyscale backing image

The Second Payment Services Directive, aka PSD2, contains much that is admirable, some that is debatable and yet more that is downright mysterious. As we await the forthcoming final version of the  Regulatory Technical Standards (RTS) on Strong Customer Authentication (SCA), putting everyone on a 21-month implementation cycle, I thought I’d cast an eye over one of the, as yet, largely undiscovered areas of the directive; namely the exclusion from SCA for direct carrier billing (DCB). Like so much in PSD2 no exemption comes without penalty.

It’s the directive itself that excludes direct carrier billing from regulation, in Article 3, where it specifically excludes:

(f) payment transactions by a provider of electronic communications networks or services provided in addition to electronic communications services for a subscriber to the network or service:

(i) for purchase of digital content and voice-based services, regardless of the device used for the purchase or consumption of the digital content and charged to the related bill; or

(ii) performed from or via an electronic device and charged to the related bill within the framework of a charitable activity or for the purchase of tickets;

provided that the value of any single payment transaction referred to in points (i) and (ii) does not exceed EUR 50 and:

— the cumulative value of payment transactions for an individual subscriber does not exceed EUR 300 per month, or

— where a subscriber pre-funds its account with the provider of the electronic communications network or service, the cumulative value of payment transactions does not exceed EUR 300 per month;

If you care to deconstruct this it means that PSD2 doesn’t apply to direct carrier billing – payments made using a subscriber’s existing mobile account – if the subscriber doesn’t spend more than €300 a month or pay more than €50 on any single payment. Which is a useful exclusion for network operators and providers of DCB services, but does rather put a limit on any ambitions to extend and grow these services into genuine competitors for consumer payments.  The exclusion also doesn’t apply to physical goods, limiting any expansion plans in that area.

Fail to meet those conditions and DCB automatically falls into the jaws of the RTS on Strong Customer Authentication, requiring two factor authentication to be applied, subject to the normal exemptions not being invoked. Given that banks, who have a track record of applying authentication to consumer payments, are finding meeting the SCA requirements challenging it’s not immediately obvious how mobile operators are going to address this, although you’d imagine that they could use the mobile handset itself as the possession factor.  Nonetheless, forcing customers to enter passwords or implementing a handset based biometric through an app isn’t going to do anything for the customer payment experience which hitherto has largely been invisible.

The problem is that doing nothing is not an option. Not implementing SCA means capping the amount customers can spend each month and failing to do that will mean customers have the automatic right to apply for a refund as payments over the limit will, in PSD2 terms, be unauthorised. T&Cs will need to be rewritten to make sure the operators can get their money back, although in the absence of regulatory guidance it’s not clear that the directive might not override that – if PSD2 is about one thing it’s about the pre-eminence of consumer rights. Oh, and go over that limit and the operator will find themselves considered a payment service provider under the regulatory conditions of PSD2 with all that it entails.

Some DCB providers have already taken the initiative and become Electronic Money Institutions, which means they don’t have to worry about the restrictions but do have to suffers the slings and arrows of Strong Customer Authentication, outrageous or otherwise.  Others seem so far less bothered, although no doubt the proposed regulatory penalties when published will concentrate minds. What’s really interesting is that the other side of PSD2 – the so called XS2A, Access to Account, via bank implemented APIs – actually opens up a real opportunity for any mobile operator or DCB player smart enough to spot it. After all, if you can connect to any consumer’s bank account to draw funds or examine their spending patterns you’re halfway to a pervasive retail consumer payments solution.

As for the other half, well that’s what we at Consult Hyperion are paid to solve. We think that the elements to allow this are already in place, all it needs now is someone with the foresight to take advantage of them. At that point the European Commission may well get the kind of innovation and competition in consumer payments that it desires, but in the meantime we’ll just continue twiddling our thumbs waiting for the RTS.

Money 2020: debates, discussions and doubling down

Greyscale backing image

Wow. Another Money 2020 in Vegas. A peculiar combination of exhaustion and exhilaration. Days of back-to-back meetings, serendipity, dinners with old and new friends, learning and (why would I lie to you?) a few drinks and a few hours of blackjack. Back in the land of signing for card transactions, ready to explore the future of financial services.

Money 2020 Signature

Last year, I said that all the interesting stuff at Money20/20 was actually about identity and that all of the fintech stuff would have less impact than all of the regtech stuff. I still think this is true. Fintech has become mainstream, there’s no doubt about that. There was a lot of corridor talk (they don’t have water coolers and I couldn’t find the free ice cream) about how the fintechs are integrating with the key players (as if the mammals interbred with the dinosaurs rather than replaced them). The fintechs aren’t what the incumbents were really worried about. What they were worried about (other than regulatory change) were the strategies of the Google-Apple-Facebook-Amazon-Microsofts (GAFAMs) and the Baidu-Alipay-Tencent (BATs) and that (as we will return to later in this discussion) is because of the fight for data.

Perhaps I’m reading too much into coincidences of scheduling, but it seems to me that Sunday is being used to explore new topics and then in the following year some of those topics move from the experimental or exploratory sphere into the mainstream discussion. Last year at Money20/20, for example, I chaired the session on financial inclusion with Professor Lisa Servon and this year I couldn’t help but notice that financial inclusion reappeared in a number of mainstream panels and presentations, including in the superb Monday keynote from Dan Schulman of PayPal. So, if financial inclusion was making its way from the edge to centre last year, there is no doubt that it was artificial intelligence playing that role this year. I chaired the artificial intelligence panel at Money20/20 Europe in Copenhagen this year and it was absolutely stormed. In Vegas, I heard many, many people say that the AI discussion on Sunday was first rate and left them in no doubt that it would be the key mainstream topic next year.

The money going into AI is already huge and if you look at where banks are directing the cash right now, machine learning seems to be the target. This is no surprise. Banks have large quantities of data that in the past they have found difficult to extract wisdom from and they have large transactional flows that they find it difficult to manage in the context of increasing regulatory burdens. Machine learning systems excel at finding patterns and exceptions in such data, provided that they can be fed with enormous quantities of the raw material, so the main use of the machine learning systems is currently fraud detection and prevention (DBR Research, October 2017).

(This, as an aside, throws up an interesting strategic challenge for banks as they shift to AI-centric strategies, because there is a threat to risk management, information analysis and sales/marketing processes in a world of open banking where the banks may not get to see the data held by third-party providers but those providers have access to bank accounts.)

The impact is not only on retail banking. The Bank of England’s recent working paper (no. 274, September 2017) on machine learning at central banks explored the particular case study of banking supervision in an environment of imperfect information (what you and I would call “the real world”!) and came to very optimistic conclusions. In other words, AI is not only a fintech that can help individual organisations to shift improve profitability (both by reducing costs and increasing revenues) but also a regtech that can help jurisdictions to create better financial services sectors by improving the quality of regulation at lower cost.

On Monday I was up on the main stage where I had the privilege and pleasure of moderating the debate between Brett King of Moven and Steve Ellis of Wells Fargo. They are both great guys (and I’m not just saying that for form) and they made it fun for me and for the audience. Wells Fargo put Steve’s perspectives on their web site so you can read them here. As an aside for future conference organisers, I thought this was a great format because both of them made serious and substantial points – someone told me later that he didn’t realise how much his was learning during the debate! – but in an engaging structure that help to wind the day down. Big props to Money20/20 for this idea.

Money 2020

Several people said that what stuck out for them on the Monday was the difference between the Alipay keynote, which was all about the colossal numbers and opportunities, and the ApplePay keynote, which conspicuously failed to include any usage numbers. Now, as we’ve long maintained, this doesn’t really matter because the long-term play is #appandpay not #tapandpay, but there was certainly as suspicion abroad amongst uncharitable persons (of whom I am not one) that ApplePay’s usage at retail POS may be underwhelming at a time when negotiations about renewal contracts with issuers are on the horizon. Jennifer Bailey of Apple also mentioned the coming Apple Cash (which will allow P2P payments via iMessage or whatever it is called now). I don’t know enough about the US market, but I would have thought that in the European markets they will implement API access to bank accounts with access to instant payment networks and that this will come to dominate across platforms, but I wouldn’t bet against Apple on anything as a rule. Anyway, enough of that, let’s go play blackjack with some crypto-folks because they have all the money.

Money 2020

On Tuesday, Talking about inclusion, again, Kosta Peric from The Bill and Melinda Gates Foundation was in town. I went off to have a chat with him to find out all about their new open-source software for the unbanked, Mojaloop. This uses technology from Ripple to deliver interoperability between financial institutions, payment providers and other firms that offer such services to the poor and unbanked. (It uses the Interledger protocol.) This all came out of the Gates Foundation’s Level One Project, which Kosta has championed, so I was keen to understand the roadmap and how it might connect to some of our work in inclusion. Unfortunately, as so often happens, we got sidetracked by giant killer robots.

Money 2020

Last year’s general talk about blockchain this and blockchain that was less in evidence, although with Bitcoins at $6,000 there was a fair amount of cryptocurrency talk (and misunderstandings) swirling around. The blockchain discussions were more focused (there was a good panel on blockchain consortia with JP Morgan, R3, Microsoft and Hyperledger) and I thought there was less of the crazy talk about blockchains fixing everything, although it did continue to irritate me that most of the solutions being discussed were not actually blockchains at all but shared ledgers (and before anyone writes to complain, I refuse to call them distributed ledgers because in at least one example that I discussed there, there was only one node and no consensus algorithm at all).

The big difference from last year was that the main topic of discussion in the crypto space was the token/ICO gold rush. Consult Hyperion hosted a couple of dinners for friends and clients in Vegas and at one of them Arthur and Kathleen Breitman, the people behind one of the highest profile token raises of all (Tezos, now worth more than $400m), came along. Now, I am far from being an expert on the subject, but I genuinely think that when the token/ICO market is regulated correctly (and that must come soon) it is going to be absolutely massive, because it will create a new asset class and (I hope) a new and more transparent marketplace. I might even go so far as to say that it might be one of the most important long-term outcomes of the Crash.

Money 2020

There were a couple of other themes that caught my attention wandering in and out of the conference sessions. Conversational commerce, and therefore conversational payments, is on the rise. Facebook was there, as were other players, and I definitely picked up more buzz about chat and chat bots. Although I didn’t hear it discussed at the event, it seems to me that there is a strong relationship between conversational commerce and the impending shift to Open Banking in the UK. Giving, for example, Facebook API access to your bank account means that you’ll be able to check your balance, look at your transactions, send money to people all without ever leaving WhatsApp. What’s more, given the amount of payment fraud in the UK, this is probably really good news. If your lawyers continue to use e-mail instead of Signal for house purchases, they are borderline negligent.

The big day for Consult Hyperion was Wednesday, because of the “Wednesday Workshops”.  I really like the idea of the Wednesday morning 90-minute deep dive sessions on specific topics. This year I was asked to run the “Identity is Fundamental” workshop, which was a genuine honour, and I had an absolutely great set of speakers and panelists to open up the subject. Here they are in the identity cage, waiting to be released at 8.30 sharp…

Money 2020

Considering it was the early morning of the last day of the event, it’s a testament to the intuition of the organisers and the quality of this panel that the ballroom was full. I thought that identity would be a key topic, and I expected a reasonable turnout, but I was surprised to find a full room with people standing at the back when I walked out on stage. I’d like to think that it’s mainly down to Consult Hyperion’s reputation at the forefront of population-scale identity projects (going all the way back to the days of the world’s first smart identity card in Hong Kong), but I think the size of the audience also reflects just how high up the bank agenda digital identity is now. 

Money 2020

We divided the workshop into two parts. The first section was about authentication, and Brett McDowell from FIDO Alliance MC’d with input from Intel, Javelin, Diebold Nixdorf and Samsung. I thought these guys delivered a very positive message. Not that things are fixed, but there is at last the potential to fix them. As panelist Al Pascual from Javelin said earlier in the year, commenting on the news that identity theft and fraud in the US was up 16% this year and is now at the highest levels they have ever recorded, “all of the underlying types of fraud we measure are up”. But with smart phones, biometrics and strong authentication frameworks coming into place, there is light at the end of the tunnel. Perhaps it’s a slight exaggeration, but I was left with the impression that strong authentication for transactions is basically a solved problem if you plan out the system properly. We have the architecture, devices and standards to make it all work. 

Money 2020

The second part of the workshop was about identification and it closed with a great, great case study. SecureKey and TD Bank took us through the multi-bank digital identity scheme under development in Canada.

Money 2020

If the identity workshop wasn’t the most talked about thing on the final day, Barclaycard’s announcement of the Uber Card probably was. I have to say that it is a beautifully executed product. Uber gives customers the option to apply for the card form inside the app and populates the application form from data on file. Once the customer applies, they get confirmation (or otherwise) within a few minutes and can immediately begin charging rides to the new line of credit. A few days later the plastic card arrives in the post. Folks also can apply for the card online. There are some sweet flashbacks to launch the card, including four percent in restaurants, three 3 percent on on hotels, two percent back on online purchases and one percent on all other purchases. No wonder it got such attention on social media.

Anyway, after three solid days of this I needed to get away so I took up an invitation to visit the futurist Heather Vescent in her dome at Twenty Nine Palms, which turned out to be in the desert. A perfect way to clear my head and to enjoy a mini road trip involving (as it did) highways and diners.

Desert flowers

After relaxing and discussing Heather’s new book, the “Cyber Survival Manual“, I said goodbye to the desert and set off back to the daily grind. Thanks once again to the great people at Money 2020 and here’s looking forward to 2018.

Password security

Greyscale backing image

The publication by NIST of an updated version of its digital identity guidelines marks a significant change in its approach to identity management. It highlights the importance of implementing digital identity in context, with three different elements replacing the previously monolithic Level of Assurance. These Levels are the Identity Assurance Level for identity proofing, the Authenticator Assurance Level for authentication and the Federation Assurance Level for use in a federated environment. Criteria for each Assurance type run from Level 1 to Level 3. This is intended to provide greater flexibility in implementation, for example combining pseudonymity with strong authentication for privacy purposes. Although optional, federation is positively encouraged for reasons of user experience, cost and privacy.

Risk management features prominently in the guidelines, with risk assessments used to determine appropriate identity choices according to system requirements. Although the requirements are technology agnostic, they are prescriptive regarding the assurance levels required for particular purposes. One area in which the guidelines are particularly refreshing is in their approach to passwords. Drawing on research into passwords exposed during data breaches, the use of unwieldy complexity rules is discouraged. Instead, it is suggested that users should be allowed to make passwords as long as they wish, encouraging the use of pass phrases and excluding very short passwords.

Faced with restrictive rules, many users will select predictable passwords which just meet the system requirements but are easily guessed. It is suggested that passwords should be checked against a blacklist of obvious choices and known compromised passwords, to filter these out. Randomly-generated secrets are therefore preferred to user-generated secrets.

The guidelines also highlight the importance of usability, supporting the use of password managers and only requiring passwords to be changed when there is evidence of compromise. There is some flexibility regarding displaying passwords on screen, depending on the context. In order to maintain an adequate level of security, a mechanism for limiting the number of possible failed authentication attempts is required.

This new, more person-centric approach from NIST follows on from UK government guidance published by GCHQ in 2016, advising ‘dramatic simplification’ of password management policies. This guidance also focused on achieving security by implementing processes which are easier for people to follow and therefore less susceptible to being undermined by users attempting to take short cuts through the system.

CHYP’s involvement in research has highlighted for us the difference between the way people say they behave and how they actually behave online. This kind of performativity may take the form of people describing how careful they are online (perhaps repeating recent official advice), while doing something conflicting on screen even as they are speaking. A similar effect can be seen when comparing figures produced from a user survey by the Gambling Commission, to usage statistics reported by gambling companies. The companies are able to draw statistics directly from their systems, while the survey figures are composed of gamblers’ reporting of their own behaviour. These discrepancies highlight the importance of observation when developing policies based on user behaviour.

It is encouraging to see a more effective approach to combination of privacy, security and usability in Identity Management being promoted at the highest levels. Even in local hospitals, it is now common to see screens showing simply ‘tap your pass or enter your passphrase’, where previously unpredictable processes were in place. Organisations such as FIDO have done a great deal to promote standardisation.

For a standalone organisation to adopt the new NIST rules would seem both positive and achieveable. They are in any case intended to be used within the US government. However, where organisations are already working in partnership and have existing legacy agreements regarding security requirements, it may be necessary to revisit these and agree a new set of password rules to replace existing, outdated approaches. Standardisation and education can go a long way towards supporting this process, although for larger organisations and those with multiple partners, it may take longer.

Publications such as ‘Why Johnny can’t encrypt’ and ‘Users are not the enemy’ have long been recognised for highlighting enduring issues with implementing security software. While education is important, attempts to fundamentally change people will inevitably fail, resulting in escalating support costs and unpredictable security risks. People are simply not equipped to adjust that quickly. In comparison, machines are generally designed by people and comparatively easily modified. Even with the advent of AI, machines are likely to remain reasonably malleable.

Where most user interaction involves people and machines, security tends also to involve mathematics. The NIST guidelines prescribe the use of appropriate cryptography at every stage. This is essential to securing the system but does not of itself guarantee that the system will remain secure. Appropriate system design and implementation are crucial to ensuring secure operations. This is exemplified by the recent flaw discovered in the WPA2 WiFi protocol. A mathematical proof is available for the security of the protocol but there is a vulnerability in the key management, which is not covered by the proof.

As in any system, a mathematical proof has to be ‘situated’ to be useful. Effective risk modelling will take into account the wider context of the system, focusing in on the most critical areas for greater attention. This process may have to be revisited over time, as the surrounding environment evolves. The increasing interconnectedness of the Internet of Things will require greater attention to disconnection technologies to preserve system integrity over time.

Subscribe to our newsletter

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

By accepting the Terms, you consent to Consult Hyperion communicating with you regarding our events, reports and services through our regular newsletter. You can unsubscribe anytime through our newsletters or by emailing us.