The “hot five” retail transaction technologies for our clients in 2014

Greyscale backing image

Dgwb blog white border

It’s traditional in blogs of this kind to have a go at a “top N” set of predictions for the coming year, so I’ll give it a bash and have a go at what I think will be the “hot five” secure electronic transaction technologies that will have our clients updating their roadmaps in 2014.

Are gift cards a present to fraudsters?

Greyscale backing image

dgwb_blog_white_border.jpgThe BBC asked me to comment on the security of gift cards in connection with a story they were running on “You and Yours” (it’s about 35 minutes in if you are interested). The story was about a woman who had bought a gift card at Debenhams and given it to a relative. When the relative went to use the card, it was empty because it had already been used (in a series of transactions)

Keeping it low: contactless use is growing

Greyscale backing image

There are plenty of negative stories about contactless floating around (some of them from me) and the experience remains patchy and frustrating. I was thinking about this a few weekends ago, because it was the anniversary of the Olympics, which reminded me of Forum friend Gareth Lodge from Celent when he went off to the Olympic Park to see what was going on at first hand? It wasn’t pretty.

“I asked every till operator that I used, and watched the transactions in every queue I was in, and the results seemed very conclusive,” his post says. “It suggested the vast majority of payments were actually made in cash. In fact, I can recall very few payments made by card at all and I witnessed absolutely none made by contactless, let alone mobile contactless. Even the Visa ATMs were, at the times I passed them, unused.”

[From Digital Transactions]

Well, let’s be clear. Things have improved since then. In the UK, and some other countries (e.g., Poland and Australia) contactless has been growing steadily. It’s getting a foothold in places where it makes sense (e.g., the pub over the road from CHYP End). A good example is Quick Serve Retail (QSR).

contactless payments at convenience food retailer EAT has grown at 75% year on year and currently accounts for 60,000 transactions a month, making up half of all card payments.

[From Contactless Payments and NFC in UK Retail: A Report Précis – IDC Insights]

EAT isn’t alone. Listen to Pret a Manger’s director of IT, delivery and support, Andy Chalklin, He says

“Contactless payments in terms of our overall transactions have gone from single digits of probably between three to five per cent, to about 20 per cent in the last 12 months,” Chalklin told Computing in an exclusive interview.

“As a retailer it is faster, it is a guaranteed payment methodology; it is not subject to charge-back from the acquirer, it is accessible as people forget their wallets at home but not their phones. And, from a retailing perspective, it is cheaper at the moment; it is 50 per cent of the interchange rate of any chip-and-pin transaction,” he said.

[From Pret a Manger sees growing appetite for contactless payments – 06 Mar 2013 – Computing News]

To be honest, I imagine that that last point, the vastly reduced interchange rate, may have more to do with Pret’s enthusiasm than any excitement about ISO 14443 or NFC. We’ll come back to this in a minute.

According to ICM research, a third of people that have a contactless payment card have used it to purchase an item, which is equal to just 8% of all consumers… The ICM research found that from the 11 stores they visited, just three of them were promoting contactless payments.

[From NFCNews | SmartDebit responds to contactless payments useage in the UK]

Why is usage still growing so slowly? Is this all about consumer interia or are there other factors? In the US, where consumers already had no-signature swipe for low-value transactions and no-one is much that bothered about fraud, contactless has a mountain to climb. The set up of the POS, its configuration and ergonomics, mean that there is no advantage to contactless. And in the places where a sealed unit would have advantages over swipe (e.g., parking meters) I’ve never seen it used.

Even cardholders with contactless cards tend to swipe rather than tap.

[From Old Habits Swipe Contactless Adoption From Payments – PaymentsJournal]

But in the UK, where the dynamics are different and contactless has speed and convenience advantages, there’s something else going. It’s one thing for consumers to not understand contactless and not even know whether they have a contactless card or not, but it’s another thing for merchants to not understand contactless. Take a look at the example given on this very blog last week by retail expert Julian Niblett.

I tried to pay by contactless but I was told that my porridge was £1 so I couldn’t use my card and had to pay by cash. I tried explaining that my £1 porridge would only cost 1p in card fees as I had a contactless card and that the next customer using a debit card to spend £3 would cost them 8p! In the same scenario, contactless for £3 would cost half that.

[From A fresher way to pay?]

He points out that not all retailers are as confused, citing the example of Subway. Subway allows you to use contactless for any value transaction, but has a minimum for contact credit and debit. This makes sense (even though I’m sure that marketing experts will tell me that this is too complicated for the average British consumer) but it would make more sense as a sector-wide initiative. Suppose that the issuing banks agree to keep interchange on contactless transactions at a very low level for a reasonable period — like seven years or something — and in return the retailers agree to drop the minimum value requirement for contactless transactions. If consumers knew that they could always use contactless as a cash replacement at all retailers that would be a much simpler message to propagate and we might see a more rapid increase in cash displacement. Simpler is always better, isn’t it?

Even if we could police some kinds of spending, we shouldn’t

Greyscale backing image
[Dave Birch] A couple of the projects that we are involved in at the moment are at the intersection of financial and social inclusion, which is a topic that interests me greatly. One of the aspects of the technological changes afoot at the boundary (between financial inclusion and the beneficial social infusion that it facilitates that deserves more discussion) is that of control. Where should we set the “dial”? Remember this?

Birmingham council, which represents around 1 million people, said that from 1 April Monday it would give out crisis welfare payments in the form of prepaid cards that could be redeemed only in Asda supermarkets. The Labour authority said the cards – which Asda said were similar to their gift cards – would restrict spending to a list of predetermined goods, which would exclude tobacco, alcohol, phone-related expenditure and fuel.

[From Asda welfare cards to be given to Birmingham’s poor | Society | The Guardian]

You see the dynamics around this. If I were Asda, or any other retailer, I would be happy to cut a deal like this. I don’t want to deal with cash, and I don’t want to pay merchant services charges to banks, so running my own payment card suits me just fine. And better still, cutting a deal with a state agency to drive welfare recipients in through my door with money to spend is a win-win. This subject of control did come up a couple of times at the Tomorrow’s Transactions Forum this year because we had an excellent presentation from Claudia Wood, the deputy director of think-tank DEMOS. Claudia was discussing her excellent report for DEMOS on the use of prepaid cards in public services.

A particularly important thread in the report is the once concerning this issue of monitoring and control of card spending. The authors note that there might be benefits to using prepaid cards to deliver financial services to vulnerable groups and that we should begin a debate on balancing the complexities and ethics of safeguarding spending balanced against “nanny state” interference.

[From Prepaid and social payments make a genuine win-win]

Round about the same time that Claudia’s report was published, the Conservative MP for Elmet and Rothwell (no, I don’t know where that is either) had proposed a “ten-minute rule” bill in Parliament under which UK welfare claimants would be issued with a card instead of receiving their benefits in cash.

Benefits claimants should be banned from spending welfare handouts on alcohol and cigarettes, a Conservative MP has said. Alec Shelbrooke wants to prohibit benefits being spent on luxury items by introducing electronic cash cards which could only be used for essential items such as food and clothing. The cards would be similar to a chip and pin debit card but with a blocking function for non-essential items, the MP for Elmet and Rothwell told the House of Commons.

[From Tory MP calls for law change to prohibit state welfare being spent on non-essentials | Mail Online]

As I said at the time, you can’t do this with open-loop debit cards and basic bank accounts (“four-party schemes”) because the bank doesn’t know what you are buying. In the case of the Asda example, above, however, the retailer’s own three-party payment card has access to data that the four-party schemes do not: specifically, the “Level 3” POS data on what you’ve actually bought. So while Barclays could block my debit card by MCC and (potentially) by location based on Terminal IDs (TIDs), they can’t block by item. They can see that I’m shopping at Tesco not whether I’m buying own-brand value tea bags (which might be allowed under Mr. Shelbrooke’s stringent governance of benefit expenditure) or Duchy of Cornwall luxury leaf tea (which might be allowed under the wife of the Governor of the Bank of England’s stern governance of nature’s bounty). Even if it were possible, I’m not clear how the payment system would maintain and resolve these complex rules and interactions. Who would have precedence? The Health Czar might want people to buy gooseberries but the Benefits Czar might insist on blackberries and the Foreign Office might insist that Egyptian soft fruit is left to rot while Syrian soft fruit is pukka.

Untitled

I am allowed Duchy of Cornwall luxury leaf tea because I am not on welfare benefits.

I’m not advocating this blocking even when it is feasible. Just because we can do something, as in so many walks of like, it does not mean that we should do something. As reactionary a bastion of the establishment as I am, I still think it’s a bad idea to attempt to police the spending of benefit recipients in this way. It may well pander to our sense of moral rectitude but it would be ineffective at best.

All it means is that benefit recipients will have to trade (inefficiently and at a discount) to get the booze, fags and weed. Given the entrepreneurial nature of the criminal underclass, a likely outcome would be the invention of an intermediate currency for the black economy (e.g., detergent bottles).

[From Welfare dependence]

What this story is about, to me, is not the restriction of welfare recipient’s spending but yet another confirmation of some of my long-held views about the future of retail payments being more about a multiplicity of retailers apps that can provide more functionality in-store and the related drivers for multiple three-party payment schemes. Having half a dozen different retailer cards (that you have to manually load in the case of pre-pay) in your wallet is a pain, but having half a dozen different retailer apps using bank APIs to auto-load as required is not. And better still a retailer app that makes a noise when your welfare arrives and helps you to budget your spending and plan meals and spread the cost of school clothing and .. and.. and for double loyalty points, I’m in.

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers

A digital wallet isn’t a digital version of a physical wallet

Greyscale backing image
[Dave Birch] I gave a talk about digital wallets yesterday. And once again I tried to encourage the assembled delegates (from the banking sector) to develop serious wallet strategies based on a winning narrative: that is, not the narrative of emulation of physical wallets but the narrative of their obsolescence. In other words, a strategy that is based on doing something so much better than making an electronic version of our existing wallets. Better, as this recent piece by Karen Webster notes, means better for all the stakeholders.

I happen to think that the further we move away from thinking that we have to replicate our physical wallets on line and the closer we move to using the mobile device to reinvent the shopping experience in new ways, the more likely it is we will see a digital wallet vision materialize that all stakeholders can wrap their arms around relatively soon.

[From Commentary – Two Years And Five Insights Later… | PYMNTS.com]

Karen is absolutely spot on with this. This is why I am so keen on the “hyper wallet” thinking that I’ve written about here before and shared with clients over the last couple of years.

A hyper wallet doesn’t try and simulate a physical wallet: it meet the requirements for a wallet in the modern, online world. It doesn’t emulate the leather wallet, it blows the leather wallet away.

[From Wallets, mobile wallets and hyper wallets]

It’s a diversion from my main point (which follows) but the critical characteristic of a digital wallet that is sitting in a mobile phone is that it is connected all the time, and it is not only connected to banks and retailers but (and here is where the fun starts because we don’t know where it is going to take us) to other wallets. Wallets are part of the internet of things and (skating to where the puck will be, as our Canuck cousins often say) bank strategies should be forming around facilitating and exploiting that interconnection. If they want to stay in the payments business, that is. They could of course be content to adopt the strategy of becoming operationally efficient pipes to value-added services operators. I kind of think they have to pick one or the other, because digital wallets in mobile phones are an absolute inevitability.

According to the study, a large majority (83 percent) of respondents said they don’t want to have to carry a wallet and would prefer a digital payment method.

[From The wallet is doomed! | MobilePaymentsToday.com]

Now, I’m not one to pay any attention to the general public on any topic at all, but I can understand this exactly. I find it rather convenient to have everything in my phone, but when everything in my phone is properly interconnected I will find it compelling. What stops this from happening right now? Well, quite a few things. But one of the more important is that we lack identity and authentication tools to make it all work in a practical and convenient way and these really should be one of the focus areas for stakeholders hoping to make progress. I’ve no idea which strategy is most appropriate (e.g., the “front end” integration of a V.Me or the “back end” integration of a Braintree), but I do know that shaping this strategy is, in many ways, shaping the mobile commerce business models of a great many players.

This is the sort of thing that will be discussed at the Mobile Wallet and Retail Innovation conference in London on 18th-19th June. I’m going to be chairing on the 18th, so I hope you’ll come along and join the conversation. I am happy to be able to report that the magnificent people at Informa have given me a conference pass worth ONE THOUSAND THREE HUNDRED of your Earth pounds to award on this blog as prize in one of our popular blog competitions. So if you’ve going to be in London on 18th and 18th of June and you’d like to come along to the Mobile Wallet and Retail Innovation conference, all you have to do is reply to this post using the comment box below with the name of the noted French goalkeeper who once said “It’s a kind of spiritual snobbery that makes people think they can be happy without money”. Good luck. There will be a genuine random draw between all correct entries on Monday 10th June 2013. The competition is open to all except for members of my immediate family, employees or associates of Consult Hyperion and squad members of the Racing Universitaire Algerios U21 first team.

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers

The US surcharging mess

Greyscale backing image
[Dave Birch] There’s an interesting article about the ongoing retailers vs. schemes litigation in the May 2013 issue of “ISO & Agent“. It’s by Autumn Cafiero Giusti and it’s called “Merchant-Surcharging Worries” and it observes that

Consumers who pay with cash, check, debit or prepaid cards would not be subject to the acceptance fees, which would apply only to credit cards.

This is ludicrous. If we are going to have surcharging, it should not be on the basis of which set of lobbyists won in Washington but on a rational basis that aligns with the national interest. Credit card issuers and retailers are not the only two groups of stakeholders in the retail payments world and the interests of wider stakeholders should be considered. There is no doubt in my mind where that line of thinking would take us.

Debit cards, and pre-paid cards, deliver the minimum social costs. Therefore, they should be the zero point… Every other payment mechanism (including cash) should then be charged for.

[From Which payments should be surcharged and, more importantly, why]

PIN debit is the best option for society as a whole, Instead of allowing surcharging for credit cards only, I’d regulate the other way round. Make it a legal requirement that any retail price displayed by any retailer for any good or service must include the cost of payment by PIN debit. Leave it to the retailers to accept or reject, charge or not charge for anything else. This is the rational option for the USA.

Why then do we have the apparently irrational proposition to surcharge credit cards only on the table? Well, these are very political times. In the whole of the schemes vs. retailers smackdown, I’ll bet that considerably more money went on politicians than on, say, economists. Or, for that matter, consumer groups.

The banking industry and the merchants coalition have each hired more than a hundred former government officials to lobby for their interests, according to Sunlight Foundation.

[From Banking Groups Stir Consumer Fears on Debit Card Regulations via Twitter – ProPublica]

I doubt that much attention was paid to technologists either. If the Senate had asked, for example, me about this then I would have told them to focus on making it easier for competitors to enter the payments market and let the hand-grenade of mobile shake things up.

The intersection of government policy and innovation could result in regulations being made by lawmakers who do not fully understand the emerging mobile payment industry.

[From Card Not Present.com CNP Expo: Danger of ‘Over-Reactive’ Legislation in Payments – May 22, 2013]

Wait, “could?”. I’d say it was racing certainty. I was at this panel (which was excellent, by the way) and asked a big picture question at the end. I asked what the point of payments regulation was. What was the US’ goal? Is it to minimise social costs or selected private costs? To balance security and safety with expense? To distribute costs in a fair way? What? The answer was, if I understood it properly, that no-one knew. Payments regulation in the US is, as one of the panelists rather amusingly said, two fat guys fighting over dessert. The fat guys are the banks and the retailers, the ones with the lobbyists, and the dessert is interchange revenue. Surely this is no way to regulate such an important industry. In Europe, payments are edging toward more utility-like regulation and being separated further from banking regulation, as they should be. The US could do worse.

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers

Not just contactless, but M&S contactless

Greyscale backing image
[Dave Birch] I rather like contactless cards. I like contactless watches more. And I like contactless phones even more than that. I’m a contactless fan. I find it rather convenient to nip in to get a coffee without having to remember my wallet, since I’ve always got my phone in my hand. I’m quite attached to my splendid Barclaycard OnePulse card: it is a regular chip and PIN card, contactless card and an Oyster card all in one. When I head into London for the day, I don’t take my main wallet with me (I’ve explained my simple three wallet system before) just my hip wallet with the OnePulse and my coffee loyalty cards. I wish there were more places that I could use it – principally the nice coffee shop on the platform at Woking station – but there you go. In this, as in so many other things, I remain in a minority.

According to a new study conducted by retail banking and ePayments software provider, Compass Plus, only one-in-10 British consumers reported to making a purchase using a contactless card in the last month, and 40 percent don’t even know what NFC payments technology is.

[From 05 – Are UK Consumers Clueless About Contactless Cards? | PYMNTS.com]

One of the places where I use my card, watch, phone or whatever else I happen to have with me is Marks & Spencer. Which reminds me. Not just contactless, but Marks & Spencer contactless, has been in the news of late.

But customers who got in touch with the Money Box show on Radio 4 said they were charged when the plastic was in their purse and well away from the readers – meaning they unwittingly paid twice. And sandwich chain Pret A Manger is said to be investigating similar claims by a customer whose card was more than 11inches from a reader.

A victim of the M&S error, identified only as Rosemary, told Money Box her Smile card was activated about a foot away from the reader at a store in Chichester, West Sussex – even though she was paying with her Lloyds debit card instead

[From Customers charged twice for items because contactless cards were activated from their pockets | Mail Online]

As I told the BBC researcher when I was asked about these reports, I think it highly unlikely that M&S is a source of dark energy, cold fusion or electromagnetic fields that defy the laws of physics. I simply do not believe the claims that the terminals read cards that were a foot away from the readers and nor do I believe claims that customers were “accidentally” double-charged. As someone observed in response to The Guardian article on same,

Not wanting to accuse anybody in the article of telling fibs but this doesn’t add up. Surely if the till took payment via contactless payment, how does then ask for the same payment again via Chip and Pin; i..e once payment is receieved said till usually spits out a receipt. [From Contactless cards: how safe is your money? | Money | The Guardian]

So let’s deal with this double-charging first. As you know, we’re not Powerpoint-and-waffle consultants, we’re get out and get real consultants. So Stuart and I set off to M&S with a variety of cards and tried transactions in more than one terminal. And you just can’t accidentally double charge. If you put a contactless card in the read range of the terminal, it executes the transaction just as specified. You can’t then insert a chip and PIN card and do another transaction – there isn’t a transaction pending. In order to pay twice, you would have to ignore the receipt that’s been printed out by the terminal and proceed with another transaction. I don’t see how this can happen accidentally. Maybe it’s a matter of staff training. If I was the checkout person and someone said “can you ring that up again”, I might ask why.

I’m sure that’s what happening, but the idea that the terminal might read both the contactless and contact cards and charge both needed further testing. Just because we couldn’t make it work in M&S doesn’t mean we couldn’t make it work elsewhere. We got out a Vx820 (this is the Verifone terminal that is used by M&S) and tried to replicate the failure mode, but we could not. When the chip and PIN card is inserted, the contactless interface is turned off correctly. We couldn’t get both types of card read simultaneously.

Terminal Testing

So the problem must be that someone swings their purse or their handbag or wallet over the contactless reader while searching for a chip and PIN card but they can’t be double-charged without a non-accidental intervention. Incidentally, on the way back from M&S we popped into Starbucks and discovered to our surprise that they had Vx820s installed as well, so we tried the experiment there too.

Now on to the claims that the terminals are reading cards from people’s backpacks. Is it plausible that the configuration of the M&S terminals means that customers are resting their handbags, wallets, purses or whatever on the readers so that their contactless card gets charged? Yes it is. Is it plausible that they are reading them a foot away. No it isn’t. Although I have a theory (strictly speaking, I should say that Stuart deduced a theory from the evidence of our experiments) as to what is happening.

But first, I wanted some facts. Since Consult Hyperion knows very literally everything about EMV, contactless, NFC and retail payments (we work for the issuers, schemes, card manufacturers, terminal manufacturers, acquirers and everyone else in the value chain), I went back to the office and pulled a few strings, called in a few favours, made a couple of calls. Well, actually, I went to talk to Katie Facey, who runs the Consult Hyperion test laboratory if we had any Vx820s around. It turned out that we did because we were messing around with them for one of our international clients, so I asked her to put a Vx820 into Marvin and run a test cycle for me. Marvin is a our custom-built robot test rig for contactless and NFC. It’s a six-axis, laser-calibrated, computer-controlled marvel. With the Vx820 loaded, we set Marvin running to slowly bring contactless cards into range from different sides and measure how close the cards had to be to carry out a transaction.

Vx820 in test rig

Here are the test results.

Contactless Card Position Distance to Read
From Screen 7cm
From Keypad 1cm
Between Screen + Keypad 6cm
Screen Right 2cm
Keypad Right No txn
Screen Left 3cm
Keypad Left No txn
Reader Top 1cm
Reader Bottom No txn
From screen, back of reader 1.5cm
From Keypad, back of reader No txn
Between screen + keypad, back of reader No txn

So, the terminals work as advertised and the maximum read range is not 30cm-40cm but under optimal conditions only 7cm and then when the card is placed dead centre to the screen over the contactless symbol. I think the 7cm gives us a clue as to what is happening.

I wander into M&S a buy a vanilla fudge bar. I have my wallet in my hand. I open it to take out my chip and PIN card. At this point, I am holding my wallet over the reader, less than 7cm away. There’s a contactless card in my wallet and the terminal reads it. I don’t see it register a payment because my wallet is covering up the screen of the PIN pad. I put my wallet in my other hand, or on the counter, or in my pocket or wherever 30cm-40cm away. Now I put the chip and PIN card in the reader and I notice that the transaction has completed because the contactless card (now 30cm away) has been read, so I write to The Daily Mail. Mystery solved.

I think, by the way, that it doesn’t do any of us (in the industry) any harm to read some of the general public’s comments on this story. Here are a few of the comments on the Guardian’s version of the story. (In which Charles Arthur was kind enough to quote me.) I would not, for one moment, want to mislead you into thinking that people who respond to articles in The Guardian are in any way a cross section of the great British public, but nevertheless the comments are worth leafing through.

  • This is the first that I have heard of contactless cards” which seems to confirm that survey results that I started with.
  • Then there was the cautious “So far I have not been offered a contactless card. Just as well, as I would never consider using one – far too risky”.
  • I appreciated the Ocker vote of confidence: “You’re all a bunch of paranoid luddites (tautology?). Contactless payment has been the norm in Australia for a couple of years now (with a maximum purchase value of $100 without a PIN) and there have been no reported problems yet”.
  • There was also the untrue “apps exist which draw down the encrypted data, it’s not difficult to find code online which decrypts this data and re-writes it to a phone, blank card or even hotel key card”. All of this is incorrect. The data isn’t encrypted, although it does carry a digital signature formed from a private key inside the chip (this is why you can’t clone EMV cards – because there’s no mechanism for reading this private key). You can’t re-write this data to make a counterfeit magnetic stripe card because the data passed over the contactless interface isn’t the same as the data on the magnetic stripe. As an aside, years ago a friend of mine rewrote his debit card stripe onto a coffee card that he took with him on his travels a couple of times. Thus if the card got lost or stolen, it would not appear of any value to a criminal! Sadly, since the advent of chip and PIN this avenue of fun has been blocked off.
  • There was also the pragmatic “I just have my oyster card on the other side of my wallet to the contactless credit card”, reflecting on the problem that a number of people have remarked on where if you present a contactless card and an Oyster together to an Oyster reader then they don’t work.
  • I loved the realistic “For a shop, debit cards are cheaper than cash, unless they are factoring VAT and income tax into the calculations”. It’s shame that I have to “factor” income tax into my own salary, but I can see why some shops might prefer not to.

My favourite, of course, was this one:

if this guy said no way its not the cards, id be reassured, but clearly, this so called ‘consultant’ has no idea of the capabilities of NFC technology. he maybe a consultant, but not of payment technology, thats for sure.

Oh no. Rumbled. I’m afraid “toothbrushrampage” has seen through my obviously faked photographs, my bogus test results and my so-called “measurements” to uncover the conspiracy. Yes: the banks are in it with Marks & Spencer! The banks have been issuing cards that M&S terminals can spy on while you drive past in your car, thereby occasionally charging you twice for the same sub-£20 transaction and hoping that you won’t notice it. It was a brilliant plan, and we might have got away with it if it hadn’t been for you darn kids.

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers

Disruption is not about everyone having cards, it’s about everyone having terminals

Greyscale backing image
[Dave Birch] This time last year I was very flattered to be invited by the GSMA to moderate the session on Delivering Innovative Mobile Payment Services at the Mobile World Congress 2012. For those of you who haven’t been, MWC is the mobile industry’s gigantic annual trade fair in Barcelona with something 60,000 attendees. (The whole jamboree gets underway again next week, by the way, where I am again flattered to have been asked by the GSMA to chair a session, this time on Mobile Identity, Opportunities and Challenges.)

The payment session last year had an amazing line up: Bill Gadja (Global Head of Mobile, Visa), Osama Bedier (VP Payments, Google), Olivier Piou (CEO, Gemalto), Rodger Desai (CEO, Payfone) and David Marcus of PayPal. David was then the VP Mobile, but was about to become the head of the company. So a year on, have we seen any innovative services? At the time I remember thinking that I heard more about barriers to delivering innovative services at MWC than I did hear about innovative services — because of the emerging realisation of co-ordination costs and complexities between bank, handset, SIM, SE, TSM etc). Since that time however, mobile payments has continued to evolve as a sector, but it is on the acquiring side that we’ve seen real impact, real business change. And David and his team at PayPal have been at the forefront of this.

Pizza Express is to pilot the pioneering experiment in its 370 outlets this week, in partnership with online payment company Paypal… Customers will be able to settle their bill with just a few taps on their iPhone, meaning they can leave the restaurant whenever they like.

[From Pizza Express diners can use their iPhones to pay the bill and walk out | Mail Online]

You have been able to use PayPal at POS for some time. I think one of the first places was Home Depot. It’s certainly interesting that you can pay in a shop using PayPal (I’ve done this) but is it revolutionary? Not really. This from our friends at Glenbrook this time last year, for example.

It had and was not too surprising — other than seeing that Home Depot was passing line-item data about what I bought to PayPal. I would normally say passing line item data is a HUGE deal — in an offer targeting way, not a privacy paranoia way — except I can’t ever imagine PayPal being able to interpret what I bought from the line-item descriptions. The descriptions just weren’t that useful.

[From PayPal @ POS: My Field Trip Report — Payments Views from Glenbrook Partners]

Since then, PayPal has continued to evolve physical POS solutions, with some fascinating services and, I’m sure, a great deal of learning. They also launched their mobile acquiring solution “PayPal Here” in the US last March and in May went live with the “PayPal Local” solution. The competition between PayPal, Square, Intuit and others in the US has driven tremendous innovation in mobile POS (m-POS) over the last year. In the UK, we’ve been looking on jealously, held back by what we might call the “Chip and PIN innovation problem”. The problem is that while chip and PIN is much more secure than chip and signature, that security comes at a price. Making “PIN Entry Devices” (PEDs) that will meet the security standards for PCI-PTS and obtain the necessary scheme certifications is expensive.

What’s more, whereas is it acceptable to sign for a transaction using the screen of someone else’s smartphone or tablet (see below) it is not acceptable to do the same thing with PINs. I would never put my PIN into some random stranger’s phone down the market. Until we get trusted environments in the handsets, the handsets cannot meet the scheme requirements for PEDs.

Untitled

Hence for chip and PIN a different model is emerging. Instead of plugging a dongle into the phone or tablet and then using that phone or table for the cardholder authentication mechanism, in Europe we are seeing PED devices linked to the phone or tablet by Bluetooth. So when you buy something down the market, the market trader hands you the Bluetooth PED device and you put your card into it and punch in the PIN. You never take the trader’s phone and the trader never takes your card.

In the UK in the last couple of days we’ve seen two important announcements using this model. First, iZettle launched their chip and PIN solution and today PayPal have launched the chip and PIN version of PayPal Here.

PayPal Here launches in the UK

This is excellent news. These are both great offerings and I think they will grow card acceptance and card usage. Between them they could easily bring a couple of hundred thousand new SME and micro merchants into the card world over the coming year. Naturally we took a few calls from journalists on this! I told them that as far as I could see both PayPal and iZettle would be successful. They look similar, but they’re not quite.

Dave Birch, director at IT consultancy Consult Hyperion, said although PayPal and iZettle’s offerings appeared similar, they were pitched at different parts of the market.

[From PayPal enters UK mobile payments race – FT.com]

The iZettle solution will appeal to independent traders and micro-enterprises who want to get up and running quickly with card acceptance. I think PayPal’s is a slightly different play, which is more about ecosystem. PayPal’s special sauce is their API. They have a developer community that will build on their platform and integrate chip and PIN into value-added offerings (I expect to see a variety of offerings for specific verticals emerging over the next few months). I also expect that PayPal’s entry (because of their brand and existing merchant base) will grow the market for everyone, not only for PayPal themselves. GfK research by Ryan Garner would seem to indicate that PayPal’s brand will help to bring new groups (e.g., teenagers) on board.

For example my teenagers use and trust Paypal for making payments more than they do a traditional bank or credit card company. This was echoed in the GfK research which noted “PayPal, whose experience in delivering remote mobile payment services to consumers places it in a strong position in both financial and mobile spheres. As a brand it boasts high levels of trust and consideration. But, most interestingly, it has the highest brand preference of all those tested in this research”.

[From Mobile payments brand preference — Athenic]

So are we finally seeing some disruptive innovation in mobile payments? I think we are, and it’s not all because of PayPal. We’ve always said that the disruption will begin on the acquiring side. Getting rid of cash doesn’t mean everyone having cards, but everyone having terminals. And Square, iZettle, Stripe, Intuit, PayPal m-Powa, Adyen and many others are making this a reality.

In this rapidly evolving market even relatively young firms run the risk of being outpaced themselves by fresh and even more disruptive innovations. One such very new firm is Stripe, which has attracted investment from some of the original founders of PayPal and is trying to muscle in on PayPal’s online market.

[From Mobile payments: A wealth of wallets | The Economist]

I commented on this at a client meeting a while ago and I hope they won’t mind me repeating it here. When I go to a banking conference, PayPal are spoken of as an upstart, a revolutionary interloper. When I go to a technology conference, PayPal are seen by the teenage entrepreneurs as sclerotic, lumbering incumbents no different from Bank of America or MasterCard! I think the truth is that they are now a payments incumbent and their entry into the UK m-POS market will legitimise and grow the sector. But the real impact of their product will come from the integration of m-POS into the PayPal ecosystem, which is where there approach is more innovative, and here I expect to see genuinely new services introduced over the coming year.

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers

Is the nature of m-POS competition changing?

Greyscale backing image
[Gary Munro] I noted earlier this year that 2013 looked like being an important milestone in the establishment of mobile POS in the UK, enabling the micro-merchant community to accept card transactions, and that things were hotting up. Well today things just got hotter.

Stewart Roberts, UK Managing Director of iZettle, popped round to CHYP End this morning for a quick chat and to show off the new iZettle Chip & PIN reader which launched today in Europe. The new device is a fully secure and certified Miura chip and PIN reader, also used by Adyen and PayLeven in their recent mobile POS launches.

iZettle is not replacing the Chip & Signature device, rather they are providing both options for the merchant to decide which best suits their needs.  The Chip & Signature reader is “free” (£20 upfront with rebates over time) while the Chip & PIN device is £49 + VAT. Transaction fees are the same for both at 2.75%. We expect that only merchants with very low transaction volumes will continue with Chip & Signature and that Chip & PIN will become the primary device.

The big questions though are whether the mobile POS acquiring (m-POS) market is big enough to support all of these entrants (and there are more to come, by the way) and what the competition will mean for existing acquirers.

There are currently around 1.3 million card acceptance devices in the UK market. Some players in the US say that they have bought their last traditional POS terminal, and in the future mobile variants will be the route forward. However the bulk of the existing market is not the target for m-POS, or at least not today. In the UK, the “micro merchant” and “new to card” acceptance space is anticipated to be around 1 million new merchants such as: photographers; market traders; home sellers; charities; plumbers; seasonal holiday lets; farm shops – farmers markets; basically the merchant and mobile merchant for whom the traditional POS device does not make sense.

So how does it all work and how will the merchant chose between iZettle; PayLeven; Adyen; Intuit and new players such as mPowa all looking to provide mobile POS card acceptance, and how will the merchant choose which service to go for?

To some extent the players are positioning themselves based on the services they provide, subdividing the market:

  • Adyen are looking to provide a combined offer with m-POS complimenting e-commerce and traditional face to face payments, providing an enhanced purchasing experience in higher end retailers;
  • Intuit are offering the potential of linking mobile POS solution to their Quickbooks software;
  • mPowa want to provide infrastructure solutions to the major customers such as FNB & Portugal Telecom, with customers such as these targeting the micro merchant estate directly.

The micro merchant can therefore look for the m-POS provider who has the service which best meets their needs. Stewart said that customer service and the payment experience will decide who a merchant signs up to. So it is reasonable for iZettle to see the system and experience that they have behind them as they enter the chip and PIN space as a real advantage. They’ve worked hard on the customer experience (we used this last week, as we decided to use iZettle to accept payments at the London Barcampbank 6 unconference). The online portal is where a new merchant signs up for iZettle, and they reckon the whole onboarding process will take only three or four minutes (this was our experience) including 40 seconds for AML & KYC checks! No waiting for a week for approvals, the aim is to enable the merchant to take payments as soon as their reader arrives. The merchant can sign up as a business (enabling VAT functionality) or an individual private account. The interface is simple and functional, allowing the merchant to create product lists for photo driven menus, view various reports, add additional cashiers, view transactions, send duplicate receipts, most of the things a small merchant would want in a card payment system.

The iZettle app is available for both iOS and Android, though as Stewart admits the Apple version is more feature rich, with plans that the Android version will catch up. The reader connects to the smartphone by Bluetooth, and I was surprised how simple it was to get started. The iZettle system uses over-the-air provisioning to allow the merchant to use any phone/reader combination, ensuring that product lists are consistent.

For sales the merchant can enter amounts directly, select products from a list, offer discounts, accept cash or card and send receipts either by e-mail or to wireless printers. The receipts detail the transaction, show where it took place, what was purchased and for how much.

Existing acquirers who have yet to enter the micro merchant market must be concerned that these m-POS solutions may cannibalise the lower end of their merchant base, or indeed their traditional mobile POS estates. There are interesting times ahead in the low volume end of the market as there seems to be a shift in the nature of the competition. These new solutions offer simplicity, functionality and service as key to success, rather than the lowest price.

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers

The costs and benefits of PCI-DSS

Greyscale backing image
[Dave Birch] Now that I am officially the most influential European commentator on emerging payments, I suppose I am going to have to choose my words more carefully. So when I say that I am unconvinced about PCI-DSS as the best long term solution to the payment card fraud problem, I’d better explain myself…

There are, in essence, two ways that you can make it more difficult for criminals to use stolen cardholder data (card numbers, expiry dates billing addresses and the like). You can make it harder to steal cardholder data (the PCI-DSS route) or you can make it harder to use the stolen data by doing away with magnetic stripes in card-present (CP) transactions and one-factor card-not-present (CNP) transactions. In a world without the internet and mobile phones, the latter prescription would seem theoretical. Hence there was no choice for the industry in that world but to try and lock down cardholder data in all the places where it is stored. This led to the creation of the Payment Card Industry Data Security Standards. Let us put to one side what those standards actually are, because this isn’t relevant to the conversation.

Now, it is no secret that some people think that PCI has proven an expensive way to reduce fraud, if indeed it has. I would like to see some publicly-available statistics from a reputable source on this topic – pointers anyone? I don’t think I was breaking ranks or telling tales out of school when I mentioned that it might be time for a check point around the topic and perhaps some strategic refocusing. I stress this is not a new opinion. These, to give a specific example, are not my words.

“PCI has rapidly become a self-perpetuating, self-aggrandizing, profit-motivated authority. It has and will continue to stifle innovation by its often nonsensical rule making.”

[From StorefrontBacktalk » Blog Archive » Federal Reserve Listens To Security Vendor CEO Rip Into PCI]

On which topic, I was interested to see that my enjoyable and stimulating micro-debate with Jeremy King, the European Director of the PCI Security Standards Council, at the recent Westminister e-Forum on Mobile Wallets has attracted some attention. Jeremy got annoyed with me for saying that no-one cares much about card fraud. OK, I might have been exaggerating a bit. But come on – card fraud in the UK is a couple of hundred million quid, which is statistically not much different from zero, largely because of the money spent on EMV and 3D-Secure (3DS). I was arguing that that the costs of PCI-DSS are too high and that we (ie, the payment industry) should be looking for better solutions. For example: I don’t want my debit card to work in magnetic stripe ATMs or for CNP use and if it was blocked for these transactions then it wouldn’t matter is criminal gangs got hold of the card number and expiry date. Please, please, please Barclays — I couldn’t care less about the picture on my card, but I don’t want a stripe, I don’t want embossing, I don’t want my PAN printed on the card, I don’t want a signature strip and I don’t want my name, sort code and bank account number shown in the front of the card. And why can’t my credit card issuers just drop me a text when my cards are used outside of the UK. Or, for that matter, outside of England. Or, for that matter, at a merchant that I haven’t been to in the last year. Or whatever – surely that would be cheaper than phoning me up in the USA or writing off the chargebacks. I wasn’t arguing for this as a long-term solution either. t think that the industry should move from CP/CNP (EMV/3DS) to an identity-based “something present’ (SP) solution, but that’s an aside. Back to the debate.

Jeremy King, European director of the PCI Security Standards Council defended the standard, claiming that the average cost per record of cardholder data lost in the UK is £79 per record. If a company suffered a breach of 50,000 records – which is relatively small – it would therefore cost them £4 million. By comparison, the cost of PCI DSS is somewhere between $3 million and $4 million, depending on the size of the company.

[From PCI DSS: is the cure worse than the disease? | ITworld]

So a company is spending say $4m to avoid a potential loss of £4m? Surely it would make more sense, as one of the audience members pointed out during question time, for the company to just buy insurance instead? I don’t get it. As the representative of the British Retail Consortium pointed out, large retailers might finding themselves spending £50m on this but if they get hacked then they’ll still get fined. (Note that US retailers have started to file lawsuits around the rules and the fines.) It may well be worth it, but I haven’t yet seen the evidence that can help us to determine the right level of expenditure. Apart from anything else, despite the money spent on PCI-DSS in the UK, there were a third more data breaches in 2012 than there were in 2011.

Now, I accept that finding statistical evidence around this is difficult. For one thing, it is very difficult to attach any specific frauds to any specific breaches. It may well be that cardholder data stolen from Sony was used to create counterfeit magnetic stripe cards used in US ATMs, but how do prove it? How do you know that the specific card number was stolen from Sony or from somewhere else? Or that if the fraudsters hadn’t got the numbers from Sony they would have abandoned their criminal activities and not attempted to get the numbers elsewhere. This is a complex topic, well beyond the scope of this blog.

Often they risk confusing correlation with causality – ignoring the fact that, for any observed change in fraud levels, there may be explanations other than the breach at issue.

[From Analyzing Causation, Damages in Data Breaches, causation analysis in data breach matters, damages analysis in data breach matters, the role of statistics in data breach matters]

Some big acquirers are working hard to try and reduce the costs and complexity of compliance. Barclaycard, for example, have their new Risk Reduction Programme, which attempts to shift towards sliding scales that more closely link the expenditure to the likely risks. As an aside, when I interviewed Neira Jones (the head of security at Barclaycard, who incidentally made an excellent presentation about all this in January) for a podcast recently she made a very good point about all of this: much of what is required by PCI-DSS is required for any sound information security strategy so the incremental costs of PCI-DSS over “normal” security measures ought to be limited. Perhaps one of the reasons why the costs are high is that the security baseline in many organisations is just not good enough.

Anyway, the bottom line is this. Even if new approaches from the acquirers do help to reduce PCI compliance costs, and even if those costs were reducing data breaches, it still might be time for the payments industry to make safer, more secure products so that it doesn’t matter if teenage hackers can get into the Xbox network or not, because they can’t use the credentials that they steal. There’s an obvious way to do this, which is to switch to 2FA+ solutions that demand tamper-resistant hardware. Preferably solutions that are part of a generalised identity and authentication infrastructure, not something constructed solely for payments. Now, if only consumers had a portable device of some kind that contained some kind of smart chip together with some communications channels and perhaps a simple keyboard and screen…

These are personal opinions and should not be misunderstood as representing the opinions of 
Consult Hyperion or any of its clients or suppliers

Subscribe to our newsletter

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

By accepting the Terms, you consent to Consult Hyperion communicating with you regarding our events, reports and services through our regular newsletter. You can unsubscribe anytime through our newsletters or by emailing us.