Reputation, ratings and currency

Greyscale backing image

I had the great pleasure of sitting next to Cory Doctorow once. We were taking part in some sort of roundtable about privacy and surveillance. I was excited about this because of my Edwardian policy on Twitter: I only follow people that I’ve met. I don’t follow companies, celebrities or computers. I only follow people, and I only follow people that I’ve met. Hence, there are lots of people that I want to follow, but I can’t because I’ve never met them. Needless to say, I was very happy to be able to start following him. I’m embarrassed to say that I can’t remember what the event was, but I do remember that Cory made some typically insightful and very well-phrased comments. He makes me think, and he did again with his recent piece for Locus Online.

Reputation is a terrible currency.

From Locus Online Perspectives » Cory Doctorow: Wealth Inequality Is Even Worsein Reputation Economies

Now, as you can imagine, since I’m very interested the concept of reputation currencies and the potential to find better ways to implement the functions of money in our connected future (or, to put it another way, identity is the new… well, you know) I was most distressed to read this headline. But it’s a brilliant piece, and it helps me to develop and clarify my own thinking still further, which is why I cannot resist sharing the thinking to test it further. But first, a bit of nitpicking since I am blinded by terminology, a reflect of my technological perspectives in contrast to Cory’s.

Currencies need to serve as units of account – so you can price every thing from vintage Star Wars figures to anti-fungal cream and calculate their total worth. They need to serve as media for exchange, so that someone who has Ken ner Star Wars figures and needs anti-fungal cream can convert one to the other. They need to serve as stores of value – so you can convert your action figures to something more stable that you can use in your dot age, in case Star Wars ceases to be cool in another 50 years.

From Locus Online Perspectives » Cory Doctorow: Wealth Inequality Is Even Worsein Reputation Economies

I’m not sure about this. A currency is a unit of account, but money can be a store of value (e.g., gold) without being a unit of account. None of the prices in my local Waitrose are quoted in gold, despite the fact that I intend to bury gold in my back garden in response to to government economic policies. Similarly, money can be a means of exchange without being a unit of account. In fact, for most of history, payments were commuted from stores of value that people didn’t have via a unit of account into a medium of exchange that they did have. The example that I use in a book I’m writing on the topic uses the example of the American Colonies where the unit of account was the Pound Sterling (which most of them had never even seen) and payments were commuted from gold (which no-one had) into wampun, the medium of exchange of the indigenous population.

Right, that’s got that out of the way. Now on to the actual point of Cory’s post.

Reputation is pretty much useless for any of these things. Instead, they’re literally popularity contests: ‘’more people like me than you, so I win and you lose”… The Internet has been trying to figure out how to make reputation work for decades now. Those scores that appear next to Ebay sellers’ names and on the profiles of ‘‘sharing economy’’ workers profile pages – Uber, Lyft, Airbnb – attempt to establish a basis for strangers to trust one another.

From Locus Online Perspectives » Cory Doctorow: Wealth Inequality Is Even Worsein Reputation Economies

I think these examples are excellent, and they illustrate a couple of key issues about the different between a real reputation economy and a “review economy” that Cory quite rightly suggests cannot function as a money substitute.

Ebay’s reputation system is one of the oldest surviving ones, and it’s a good example of how explicit reputation systems fail to solve their major problem. Most people who buy and sell on Ebay do a good job of it, because most people aren’t crooks. A few people do very badly, and get downranked and eventually punted off the system – something that a normal complaints tipline would handle just as well.

But reputation is useless as a hedge against the real nightmare of a setup like Ebay: the long con. It doesn’t cost much, nor does it take much work, to build up sleeper identities on Ebay, fake storefronts that sell un-remarkable goods at reasonable prices, earning A+++ GREAT SELLER tick marks, even for years, until one day, that account lists a bunch of high-value items on the service, pockets the buyers’ funds, and walks off.

From Locus Online Perspectives » Cory Doctorow: Wealth Inequality Is Even Worsein Reputation Economies

If I have behaved well for years and then leg it with your cash, that’s not a failure of the reputation economy, that’s just fraud. A failure of the reputation economy is that I can fraudulently claim a reputation that does not belong to me and you cannot tell. But suppose we had a genuine identity infrastructure so that when people register as sellers, even with multiple identities, they cannot forge reputations?

I don’t want to get diverted into technicalities at this point but I can see in outline how this sort of thing might work properly. I register with eBay, eBay bounces me to my bank (which of course implements strong customer authentication, SCA, in accordance with the relevant European legislation) and I successfully authenticate myself to the bank, at which point I’m bounced back to eBay with a unique virtual identity from the bank. The virtual identity isn’t “Dave Birch” (in fact it contains no identifying information whatsoever: it simply has a set of relevant attributes associated with the pseudonymous virtual identity: is_a_person, is_over_18, is_UK_resident, has_bank_account, or whatever else) it’s just a unique ID. If I set up another account with eBay, my bank will return the same ID. If I set up an account with AirBnB, my bank will return a different ID. Now when you buy something from me on eBay you can be comfortable that even if eBay doesn’t know who I am, they know someone who does. More than that, they know someone who had a legal requirement to put me through know your customer, anti-money-laundering and other filters.

I written about this many times before because I think bringing real reputation into eBay, airBnB, and goodness knows who else in the sharing economy, but doing so in a privacy enhancing way, would be of great benefit to everyone. In essence it would turn reputation into a currency because there will be marketplaces that I would not be able to enter, exchanges I would not be able to make, without that reputation. Money wouldn’t be enough.

Here’s a thought experiment to finish with. What if we take the concept of the reputation currency to another stage, a cross between Edward de Bono’s “IBM Dollar” and Nectar points. Why shouldn’t I be able to buy things with “Bank of Dave Money”? Obviously, it would trade at a pretty substantial discount to, say, “Bank of Madonna Money” because the public want Madonna to do things more than they want me to do things. Nevertheless, with computers and laser beams we should be able to work out the price of something in Waitrose. Perhaps instead of social security or a national minimum income in Sterling, the government would simply put a reserve price on its citizens’ currencies, so that it would guarantee a minimum price to Waitrose for “Bank of Dave Money” in payment of taxes. Stranger things have happened.

Open-loop payment in transit

Greyscale backing image

In my previous blog, I talked about the trends in smart ticketing systems leading to account-centric and open-loop payments which I want to consider in more detail in this blog.

‘Open-loop’ Payments

‘Open-loop’ is the term used for transit payment instruments which can also be used for generic payments outside of the transit system. By contrast, traditional transit payment smart cards (such as Oyster in London) have required customers to convert their money to transit-only funds stored in a transit account and used to pay for travel. Customers have been prepared to do this because of the benefits of speed of access to the transit system without having to stop to purchase tickets. However, the down-side is that they have to periodically load funds to their CTCs, such funds then being unavailable for other purposes unless a refund from the CTC is sought.

There are many payment instruments emerging, but the one which is currently most ubiquitously accepted by merchants is EMV, the smart debit and credit standard used by the large payment networks including MasterCard, Visa and American Express whose members are the banks. These Payment Schemes are currently lobbying the transit sector for their open-loop cards to be accepted as payment instruments within transit.

This approach has the obvious benefits that (i) fewer CTCs need to be issued by the transport operator, and (ii) customers can arrive in a city from anywhere in the world and travel using the bank cards in their pockets.

The leading example of open-loop payments in transit is London where all Oyster readers have accepted contactless EMV (cEMV) payment cards from across the globe since 2014. Other transit schemes already committed to rolling out acceptance of cEMV open-loop payments include the national OV-Chipkaart scheme in the Netherlands and MTA in New York.

UKCA Transit Framework Model

The country with the most practical experience of a large-scale open-loop payment transit deployment is the UK, and, in particular, Transport for London which now sees more than one million journeys per day using ‘contactless payment cards’, the generic term used to described all EMV-compliant contactless devices, including ApplePay.

The deployment in London was pioneering and occurred before any models existed for cEMV use in transit. Subsequently, a payment model framework has been developed by the UK Cards Association (UKCA) in conjunction with the transport industry. The Association’s members issue the vast majority of debit and credit cards in the UK.

UKCA has identified three models which are described below. Two of the models are ‘pay as you go’ (PAYG) and the third model assumes that a ‘travel right’ or PAYG balance has already been purchased.

The important point to understand is that UKCA models 1 and 2 exploit EMV payments and are therefore bound to EMV-issuing banks, which are communicated with via the Merchant Acquirer. These models are different from transit account-centric solutions which could accept pre-payment from any payment instrument, not just bank cards. Furthermore, the ‘token’ used to identify the passenger in the account-centric solutions can be either an open-loop (CPC) or a closed-loop (CTC) token.

This last point is important in relation to ‘unbanked’ passengers. It has been shown (e.g. Ventra in Chicago) that cEMV technology cards can be issued to the unbanked and used as smart ticketing ID tokens to access pre-purchased transit products.

Tokens, For You, From Issuers

Greyscale backing image

Tokenisation is evolving. What started as a merchant-side technology for protecting cardholder details has morphed into a network centric solution for protection of card transactions. The next step will be to move to issuer-side tokenisation but that’s only a partial solution; ultimately tokens will be owned by consumers, and how they’re used will be for the consumer to decide. Merchant tokens were a step forward in security and network tokens opened up digital transformation of payments issuer tokens but it will be personalized issuer tokens that really change the landscape for digital transactions.

Today payment tokens suffer the burden of a payment system legacy. In existing card payment schemes PANs are not just card numbers, they’re proxies for cardholder accounts and, ultimately, proxies for cardholders. When PANs are replaced by tokens this breaks these links and exposes them as the separate use cases they really are. Why should I, as a consumer, give a merchant my personal details in order to make a payment? Why should my bank account details be shared with PSPs and acquirers and other third-parties in the four party payment model just so they can track my behaviour and manage my risk?

Historically merchant side tokens were simply a way of scrambling PANs so that they weren’t sitting around in databases where hackers could scrape them and use them for making card transactions. In face to face use cases across most of the world we solved this problem by using EMV, where simple possession of the card details wasn’t enough to make a payment. Unfortunately we solved this problem just as the world went online, where using EMV was at best difficult and at worst impossible. So finding ways of protecting PANs in merchant-side databases became important, which is where the idea of tokens came from.

However you can’t transact with a merchant token, it’s simply a safer way of storing card details, albeit one that can be used across different merchants if it’s supported by their common acquirer or PSP.

To transact using tokens we needed networks or issuers to be able to generate tokens and recover them on the fly in the middle of a transaction. And these tokens offer real advantages for all parties, because a network token can express all sorts of constraints that a PAN cannot: transact today only, transact only in New York, no adult purchases, transact at this merchant only, transact using this device only, etc, etc.

It’s easier for networks to do this than it is for issuers because, it turns out, PANs are used for all sorts of important network side functionality like billing, chargebacks, risk and fraud management. In fact, using payment tokens causes all sorts of problems for all parties involved in the 4-party model because, by an invisible process of scope creep, PANs have been co-opted for all of these things; so dematerialising the PAN into a token breaks all sorts of processes. Which is why we’ve now got the Payment Account Reference (PAR) being added to network messages as we inexorably add layer upon layer of patches to the existing networks to keep them running.

But under new-style push payments, which we’re already seen be successfully employed in Europe and Asia and which will shortly become insanely popular in Europe due to the European Commission’s PSD2 regulation, due to be implemented by an issuer near you by January 12th 2018, I no longer need give my PAN or any proxy of my account to a merchant in order to make a payment. I will, instead, authenticate myself to my issuer who will provide an identity token to the merchant, which the merchant can use to trigger a push payment. An identity token is pseudonymous, it doesn’t require me to provide my personal details to the merchant. If the merchant is anxious to find out personal information from me, in order to build loyalty or to sell my details to some online marketing company, then they’ll have to figure out some way of persuading me to do so separate from the payment transaction.

By analogy I could ask my issuer to provide anonymised identity tokens for any number of purposes that aren’t anything to do with payments. Obviously other parties could provide such tokens – credit reference agencies or government passport offices for instance – but as issuers already have to do the basics in terms of ID&V for KYC and AML then it’s an obvious extension to the set of APIs that they are surely already thinking about providing. And, of course, nothing stops networks or acquirers or PSPs or other parties from offering similar services.

Inexorably tokenisation is moving from being a niche, merchant side security technology into being a core, issuer side identity technology. The opportunity for issuers is huge, but if they don’t accept the challenge then there are plenty of other companies who’d be happy to take up the slack.

Putting biometrics in context

Greyscale backing image

Last week, the Biometric Alliance Initiative (BAI), a European-funded project aiming at conjugating mass-market biometrics with bespoke certification processes, has just announced the availability of its new evaluation and certification benchmark. To anyone like me, who, at one time or another, got involved in biometric implementation deep enough to appreciate the Tower of Babel this actually is, the BAI is a stepping stone in easing up the process.

The benchmark, for biometric technologies used in biometric-based non-governmental solutions, aims to enable the evaluation and certification of biometric technologies in a consistent manner that encompasses all their various aspects while establishing a common approach for laboratories.

[From: Biometric Alliance Initiative Press Release- December 2015]

You can see why this is need. Biometric solutions, as most identification solutions you would say, were not initially engineered for the mass-market. They work brilliantly in closed-loop sovereign solutions where security is of utmost importance and where the convenience parameter can be considered as trivial.

The challenge with mass-market biometrics is not just a question of trade-offs between convenience and security, but also managing a range of issues from interoperability to environment. Not to mention the ageing factor, which could well be unkind to mass-market biometrics in the coming years, were the current roll-outs not sufficiently well designed. I thought it would be helpful to set out a few of the issues that might seem obvious but stand as challenges for mass-market biometrics.

Environment factors are complex. In contrast to most other verification methods, biometrics need to be split into a two-parameter equation: The biometric trait, and the biometric device. The biometric trait and the sensing device are both characterised by behaviours which are dependent on the environment. Some optical fingerprint sensors, for instance, which technically take a picture of the fingerprint, might give very poor results under direct sunlight. With that in mind, how about an access control for a building which does not work in spring and autumn, between 8h-9h and 16h-17h? And you having dry skin certainly does not help. That is just a simple picture. The underlying technologies of other sensors can make them prone to other settings like moisture or dirt, just as your biometric traits are. With that in mind, if you try to picture a small-scale solution consisting of varying technologies being translated by a multi-national company into all of its branches, I think you are currently grinning sarcastically.

Performance in terms of both transaction speed and precision (biometric error rates) are implementation dependent. The specifics of each use case might dictate bespoke operational ranges. The performance of a biometric match which is not only inherent to the biometric modality, but also to the form factor, might be perfectly acceptable for a use case (e.g payment) and fatal to another one (e.g transit). Try to think of hypothetical biometric gateways at London Waterloo tube station during peak hours, with some people not managing to go through due to false rejections, others taking ages to match and you’ll appreciate the need for some thorough testing and fine-tuning in that sense.

Interoperability builds mass markets, but biometric data formats, the way the biometric “image” is coded, are not always interoperable. With open ISO standards on one side of the spectrum, and an ever increasing panel of innovative offers in vendor-specific biometric and solution-specific encrypted biometric data formats on the other, the biometric market offer can be confusing. Incompatibility which might exist between different versions of the ISO standards makes things even worse. Rolling out a biometric solution without prior analysis of the supported formats might feel like inserting a video CD in a video tape recorder- there is certainly a film on the video CD, and the video CD can certainly be inserted (but not sure of getting it back though) into the VCR, but you wouldn’t be able to watch the movie.

Security, or rather insecurity in biometrics is not as straight-forward as it seems to be. The brilliance of Tsutomu Matsumoto or the Chaos Computer Club cannot be denied…but, because there is always a but, gelatine cannot fool all types of sensors, nor can they be a threat in all use-cases. Fake fingerprints certainly did work for Sean Connery in “Diamonds are Forever” to get past Tiffany Case’s fingerprint scanner back in 1971, but I highly doubt a particular set of materials would be sufficient to fool all sensors with all types of users ( I’m thinking of people like me with an abnormally high number of minutiae). Furthermore, security is not just the ease of fooling the sensor, it also invokes other factors linked to the authentication (multiple-factor solutions), the configuration chosen ( more restrictive, at the expense of security, or the opposite) or even the setting (assisted solution or automated).

Context is critical. Buying a cup of coffee and launching nuclear missiles are different contexts. The underlying technologies behind different biometric solutions are sensitive to different settings and to different requirements. And they are interdependent: some fancy solution exposed to an exotic environment could be more prone to security breaches, while being non-interoperable with other systems and slow.

The BAI framework takes up a new modus operandi in addressing these specifics. The expertise of well-established players in the field of testing and certification like Elitt and Paycert has helped implement the biometric factor into a feasible, transparent and repeatable testing and certification infrastructure. Other members, coming from varying perspectives, ranging from potential-end users to regulators, have largely contributed in giving their respective viewpoints on the feasibility and efficiency of each aspect of this framework hence giving an empiric tint to this framework.

Setting standards for any types of technology can be challenging. Setting the associated certification infrastructure is also challenging as it needs to be transparent, technically sound and of course repeatable – with consistent results when testing. For the payments industry, its major challenges will be technical compatibility – particularly the ability for the certification to adapt to use across all types of cards and payments devices – and security. Cardholder information is incredibly sensitive, and with high consequences for breaches, security will always be a high priority for users.

[Ludovic Verecque, Paycert’s view on the BAI]         

This approach aims at instilling high levels of trust not only amongst the wide spectrum of actors of the biometric market, but also amongst indirect players. The FIDO alliance, for instance, which delegates the verification method of the authenticator (which could be biometric) to open implementation, while focusing its post-verification protocols, can only be strengthened if the biometric factor has been properly tried, tested and deemed fit for the context. The whole chain of trust could hence be made stronger, right from the biometric device through the whole of the FIDO protocols.

Ensuring context-appropriate implementations is the key to sustainable biometric solutions, and this is what the Biometric Alliance Initiative — to which I have been contributing for the past two years — is all about. I expect this benchmark to lead to a much wider use of a much wider range of biometrics in the mass market in the coming year.

 

 

 

A mix-up around what is new in identity

Greyscale backing image

Quite a few people tweeted or posted about the announcement of IBM’s “new” technology in the identity space, now available to developers on its Bluemix cloud platform. Here’s a typical example.

Back in January — on Data Privacy Day, no less — IBM announced Identity Mixer, a new technology for protecting users’ personal data during authentication.

[From New IBM tech lets apps authenticate you without personal data | Computerworld]

If this new “Identity Mixer” technology sounds familiar to you, it may be because five years ago it won a well-deserved prize.

Munich, Germany, 5 May 2010—IBM Research was honored with the Best Innovation European Identity Award 2010 from Kuppinger Cole, an analyst firm focused on information security, identity, and IT governance. IBM’s Identity Mixer technology was recognized for its pioneering work that offers simultaneously both strong authentication and privacy.

[From IBM Research – Zurich | News]

Now, don’t get me wrong. I think Identity Mixer is a great technology, and IBM’s Zurich research laboratory has done some great work in this space, and I wholeheartedly agree with the idea of using pseudonymity as a means to deliver both security and privacy into the mass market in an effective way.

In its simplest form, Identity Mixer works similar to traditional attribute-based credentials with a few crucial differences. Each user has a single secret key but can have multiple public keys that correspond to it. In a way, this secret key is the user’s secret identity, and users can derive as many public identities from it as necessary.

[From Identity Security and Privacy for Electronic User Authentication]

This is a good model for identity. If it sounds familiar, it’s because you will have read something similar in “A Model for Digital Identity” by Neil McEvoy and me in that seminal tome “Digital Identity Management: Technological, Business and Social Implications“, edited by yours truly (Gower: 2007). It’s on pages 95-104, for ready reference. In that chapter, Neil and I put forward the idea that digital identity as a bridge between mundane and virtual identities makes sense in many different ways, one of them being that the use of multiple pseudonymous virtual identities (what the above article means by “many public identities”) is a great way to move forward and a great way to think about identity in an online world. Now, back in 2007, we weren’t the only people thinking this way, because IBM announced a great new technology that was built on the same lines. 

Armonk, NY, and Zurich, Switzerland, 26 Jan 2007—IBM (NYSE:IBM) today announced software that allows people to hide or anonymize their personal information on the Web, ensuring protection from identity theft and other misuse. Developed by researchers at IBM’s research laboratory in Zurich, Switzerland, the software—called Identity Mixer—will enable consumers to purchase goods and services on the Internet without disclosing personal information.

[From IBM Research – Zurich | News]

Note that when this announcement was made in 2007 the IBM version of the concept was already more than five years old. You can read about it in Camenisch, J. and E. V. Herreweghen (IBM Research, Zurich), “Design and implementation of the idemix anonymous credential system” in the Proceedings of the 9th ACM conference on Computer and communications security (Washington DC, 2002). The new technology that people were telling me about this week has been around for at least 14 years and probably longer.

So, whatever Identity Mixer is, the one thing it is not is new. Hence one is forced to ask the question that if it is such a good idea, how come we’re not using it? Why doesn’t my iPhone allow me to log in to apps and services while selecting dynamically between Dave Birch (my personal ID), David G.W. Birch (my work ID), Leadbelly Gutbucket (my games ID) and Lord Tantamount Horseposture (my ID for arguing with people in newspaper comment sections)? Is the concept of multiple identities and pseudonymity just too difficult for the mass market? I’m genuinely curious to hear what you think!

Let’s take on takeover

Greyscale backing image

I have a client who is a looking to improve their authentication processes. I imagine they are like a lot of organisations. They have a mixed customer base – some comfortable with technology, but others not. They have customers with whom they have regular contact but many who they only see occasionally. Often those customers forget or cannot find their passwords, PINs and other tokens. Consequently many customers end up going through a cumbersome authentication reset process every time they get in touch. Is there a better way?

Well yes, of course there is. We all have strong authentication tokens we use every day – payments cards and mobile phones. Why can’t they be used to log onto other services?

The UK government’s identity assurance programme has set out to solve this very problem. Can I be issued with a digital identity that can be federated across many services – both public and private? To date the programme has focused on public sector services but their attention is now also starting to shift towards the private sector. Actually this is really important for government – they want to be able to share the cost of digital identity with the private sector.

To this end a series of consultation meetings are being held with relevant private sector groups:

https://identityassurance.blog.gov.uk/2015/09/30/private-sector-needs-for-identity-assurance-workshop-dates/

Getting authentication to work for consumers is a big deal. We all grapple with the frustrations of the fragmented approach to authentication every day. But it’s worse than that.

“…112% year-over-year increases in account takeover (ATO) attacks”

[From Information Age: What happens to my data once it’s stolen]

Here’s a real life example of an account takeover a friend of mine suffered recently:

From:  <Redacted>
Date: Wed, Aug 5, 2015 at 7:19 AM
Subject: Re: Follow Up
To: <Redacted>

Legit
—–Original Message—–
From: Steve Pannifer <Redacted>
To: <Redacted>
Sent: Tue, Aug 4, 2015 9:59 pm
Subject: Re: Follow Up
Hi <Redacted>,
Pretty sure this is a phishing email. You might want to double check your email hasn’t been hacked.

Cheers,
Steve

On 4 Aug 2015, at 12:23, <Redacted> wrote:
Hi
I tried several times to send the attachment using PDF but it won’t work so I am sending you the attachment using Google doc, CLICK HERE and sign in to view the attachment.
Hope it works.
Thanks!
<Redacted>

Not only was my friend’s account used to send out spam, I got a reply from the attacker when I challenged it. Also my friend’s financial adviser received a well crafted message instructing the transfer of a significant amount of funds from one of his accounts.

There are actually two issues here:

Firstly, the reason the phishing works is that when you follow the link it’s difficult to tell that the site you are visiting is fake. This is not a problem that the identity assurance programme is currently trying to solve.

Secondly, the reason phishing is done is that the passwords that are collected can then be used to log into other sites that employ weak authentication. And this is where identity assurance comes in.

I hope to see some of you at the consultation events. There is a long way to go and many unanswered questions but this is a problem we need to keep working on.

Technology roadmapping

Greyscale backing image

In 2005 when we performed an update to our biometrics and identification technology roadmap for the UK police, body odour was a ‘technology’ that was looking interesting, but not mature enough. The idea was that if dogs can do it, why might it not be automated. And identical twins have a unique smell, apparently.

Police biometrics techs 2005

We identified policing applications of biometrics and identification technologies, one of which was automated identification of police officers. At that time, each Force had it’s own warrant cards (so there was no confidence in what they should look like) and there was no way of using them with machines to authenticate the cardholder as an ‘officer of the lieu’ and grant them access to building and machines.

Automated identification of police officers

We foresaw the benefits of a national police warrant smart card and were retained to specify the standard which is used today across the Forces.

More recently, the technology roadmapping I have been involved in has been for transport applications. As well as the usual technologies in this space (mobile apps with 2-D bar-code; contactless payment cards; NFC mobile devices emulating contactless cards) we have also been thinking about more interesting stuff. Such as USB contactless readers used at home for fulfilment of tickets or value direct to smart cards. Or mobile devices with Bluetooth Low Energy (BLE) interacting with beacons waking the app up to present the appropriate form of ticket for the time and place. And, or course, NFC devices with the Host Card Emulation (HCE) API allowing them to escape the tyranny of the Secure Element (SE) and Trusted Service Managers (TSMs).

You’ll not be surprised to hear that we are still tracking the technology of person identification via body odour. I look forward to being sniffed by a transit gate before being allowed onto the train platform in the near future.

Tokenising Trust

Greyscale backing image

Research over the last 50 years has revealed that we’re subject to a bewildering array of psychological biases which often only become obvious when we start dealing with money. Famously, Amos Tversky and Daniel Kahnemann showed that people are risk averse in the presence of a gain and risk seekers in the presence of a loss – which is exactly the wrong thing to do when you’re doing something like trading stocks. It’s an example of a behavioural bias known as the disposition effectbut there are literally dozens, if not hundreds of them as the Big List of Behavioral Biases demonstrates.

Research by Brad Barber and Terry Odean in Are Investors Reluctant to Realize Their Losses went on to show that when people traded stocks the ones they sold went on to outperform the ones they kept. Worse, this effect is exacerbated by the internet because it makes it easier to trade. In fact, the internet and social media exaggerate many of these biases because of network effects where we all follow the same small number of opinion setters.

Although research into this area – behavioural economics as it’s known – has only been around for a few decades the underlying human behaviour has been understood by advertisers and marketers for a lot longer. Repeatedly exposing someone to a message – buy Whizzo washing powder – is more likely to make them buy it: the mere familiarity effect as it’s known. But this type of knowledge has evolved, piecemeal, as people and companies have figured out how to sell stuff by trial and error by exploiting our brains’ primeval logic failures when exposed to the modern world. Banks are no different in this and they’ve developed various ways of confusing people, often by introducing minute differences in products and then charging differently for what are essentially the same services.

Enter the big internet companies and you suddenly get a step change in this approach: they’re not evolving towards selling techniques, they’re designing them into their systems and operations by systematically using the research into behavioural bias. Here’s a doozy – product and service companies will deliberately introduce mid-range offers that make no sense and which won’t ever sell. Why would they do that? Because we are afflicted by a bias that causes us to cost things by comparing features and prices against reference points. And by introducing some truly and obviously stupid mid-range offers we can be induced to go for more expensive options:

There are times when the profitability of a product line can be increased by adding a (dominated) alternative that virtually no one ever chooses. The effect of a dominated alternative is to draw attention to a more profitable item rather than to generate direct sales.

[From Adding Asymmetrically Dominated Alternatives: Violations of Regularity and the Similarity Hypothesis]

It’s called the decoy effect, and it’s very effective.

So our poor benighted Millennials are being fooled by a bewildering array of marketing ploys designed to appeal to their generation while kidding themselves that they’re somehow different to everyone else. And, in a way, they are, because the brain is plastic under development in those first 24 years and their exposure to mass connectivity has changed the way that they’re wired. But that’s true in every generation – whether it’s my internet connected kids, my own TV exposed youth, my parents’ automobile based upbringing or my grandparents’ horse drawn cart and plough. That’s just programming, under the surface we all run the same operating system and, boy, does it makes DOS look advanced.

Beyond this, of course, is a question: in whom do we trust? And we’re getting idealist answers from technologists, as people hark back to the good old days when everyone knew everyone else and ostracism was the ultimate punishment: go back far enough and ostracism from the group meant death so it’s unsurprising we’re built to regard it as a serious issue. But the idea that we can reinvent this local world using the internet, and that we can rely on word of mouth (or at least Facebook likes) and reviews on websites to determine who we should trust is just plain silly. In a technological world everything can be gamed, and we are being socially engineered on a massive scale. Let’s face it, there was a time when burning witches was socially acceptable; now we out them on Twitter. In neither case can we be sure that the connected crowd is particularly wise, let alone correct.

Trust on the internet can’t be achieved without proof of identity and we have a massive problem as people are giving away their identities on social networking sites for free. To overcome this we get providers like Ashley Madison using credit card details to establish identity, or at least eligibility, and in the process storing a whole range of superfluous information which has now been hacked and distributed for all and sundry to poke around with. And now the witches are burning.

Here, oddly, we come full circle. Because regulation means that banks have to establish identity – and if they establish and manage identity then they can create proxy identities for any variable of the data that they hold by issuing tokens. My credit card can be tokenised to reduce to a value that says I’m over 24 and can be trusted to have an opinion – and my bank can authorise this token just as it authorises a tokenised credit card payment. I can’t do this with a social identity, I need to establish my real identity with my bank.

Banks are fusty old anachronisms in a world which is rapidly changing. They’re protected by regulation from the worst effects of competition and they’re not really much good at innovating, at least in the payments arena. But by re-purposing payments to support digital identity through tokenisation banks have an opportunity to establish themselves as guarantors of trust in a post-Millennial world: and, of course, to make themselves relevant to a whole new generation.

It’s time to do away with my dongle

Greyscale backing image

Dgwb blog white border

Banks are under pressure to do something abut security, so now that everyone has a smartphone it’s probably time to rethink the hodge-podge of measures we have now and standardise around the handset.

Subscribe to our newsletter

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

By accepting the Terms, you consent to Consult Hyperion communicating with you regarding our events, reports and services through our regular newsletter. You can unsubscribe anytime through our newsletters or by emailing us.