Why us?

Greyscale backing image

Our good friends at ACI Worldwide have just released their annual Global Card Fraud Survey, which contains some rather bad news: the UK has more card fraud than many other countries. We’re up there with the US, with three times as many people affected than in Germany and the Netherlands. So a third of us have been victims of card fraud compared to only a tenth in Netherlands. Why? Are the Dutch more honest than Brits? Are their cards more sophisticated? No. I think there are two main reasons for this discrepancy.

First of all, while chip and PIN has cut fraud on the high street, card-not-present fraud is still a big problem. In the UK, cards still account for a big portion of online payments. In the Netherlands, and some other countries, they don’t. More than two-thirds of Dutch e-commerce purchases are made with iDeal, a bank-based scheme that has no equivalent in the UK (or the US, or pretty much anywhere else for that matter).

Second, UK credit cards have high limits. In the last couple of weeks, both of my main card issuers have written to me raising credit limits (I didn’t ask for this in either case). If you’re going to steal some card details, you’d go for cards that are likely to be some way from their limit.

The survey wasn’t all bad news, by any means. I found it interesting that the proportion of people who had been victims of card fraud but were satisfied with the response of their issuer had actually increased slightly, to almost four-fifths, which isn’t bad. Personally, like the majority of people surveyed, the last time there was a strange charge on my card, the bank took off the charge then cancelled and reissued the card.

The agent informed me that new cards for me and my wife would be Fed-Ex’d, to arrive today or tomorrow. What followed were a series of texts from merchants that have my credit card on file for automatic billing, delighting me with the knowledge that I won’t be able to use such services as the Bay’s FasTrak toll lanes or uninterrupted cable service until I update my records.

[From I’m a five-time ID Fraud victim; How crazy is that? – Javelin Strategy & Research Blog]

Think how expensive this all this though: cancelling and re-issuing cards, call centre seats, letters and whatever else. So we still need to do better. Only around a third of people (fewer than before) said that they would switch financial institutions because of card fraud, which is bad news for people trying to sell anti-card fraud solutions to high street banks.

The poll of 970 UK adults, part of the bi-annual global Unisys Security Index, reveals that cyber-security is the public’s chief concern, with 85% of respondents worried, and over 50% “seriously concerned”, about bank card fraud and identity theft.

[From Finextra: Brits switching banks over security and privacy concerns – Unisys]

This is odd, I think. I couldn’t care less about bank card fraud, since it’s the banks’ problem and not mine. I never use a debit card for anything, offline or online, so I’m totally protected by the legislation around credit cards. I’m more worried about identity theft, because it’s more time consuming to put right, but that’s a different issue (being discussed at the CSFI yesterday, as it happens).

The press release also noted that 81% of people have confidence in their issuer protecting them from fraud. I think that this may be a little simplistic, for that very reason: had I been asked for the survey, I would have said that I don’t really care about Barclays’ ability to prevent fraud on my splendid OnePulse credit card because it’s their problem.

Time to do something about ATMs

Greyscale backing image

There has been another spate of cash machine fraud, near where I live, entirely coincidentally. The police have instructed us to… well, let them tell you.

Officers have advised members of the public that if possible they should not leave the scene if their card is retained

[From BBC News – Cash machine users in Woking warned over thefts]

So, essentially, if an ATM keeps your card (this has never, ever, happened to me) then you should stay by the machine and call for help. Who you are supposed to call is not made clear, but I will call one of our local police stations. These are open from 8am to 10pm. As an aside, when I last went to one of our local police stations, I was ushered into a small room with a telephone, from where you are connected to the same call centre as if you had just stayed at home and phoned them, so come to think of it I may just as well call the call centre directly. Perhaps it’s time to rethink the “hello 1966” card plus 4-digit PIN system and either get rid of ATMs completely or improve their security.

Perhaps we should look further afield for ideas for new ATMs.

The Intelligent ATM comes equipped with a camera that recognises the customer’s face and sends details of the facial dimensions to a database for verification… Its use could also reduce the now common incidents where carjackers force their victims to empty their accounts at gunpoint, often taking the card and the personal identification number (PIN).

[From Daily Nation: – News |Your face is all you’ll need at an ATM]

I think this is unlikely: it would simply replace customers being forced to hand over their ATM card at gunpoint with customers being forced to go to an ATM at gunpoint, which strikes me as being more dangerous! Relatively few people are carjacked and shot dead in Woking at the moment — this generally happens up the A3 in South London — but it could all change. Mind you, you’ve got to be pretty brave to use an ATM at all in the UK.

‘We were surprised by our results because the ATM machines were shown to be heavily contaminated with bacteria; to the same level as nearby public toilets… In addition the bacteria we detected on ATMs were similar to those from the toilet, which are well known as causes of common human illnesses.’

[From Cash machines ‘as dirty as public toilets’ | Mail Online]

Yuk. It’s time to stop the silly 1960s fashion for putting things in slots and touching filthy keypads. This might help prevent fraud as well as the propagation of intestinal disorders.

The future may lie with RFID chips and mobile phones. If a mobile phone replaced the ATM card and withdrawals could be performed only by placing an RFID phone near an ATM then cell site analysis (plus E911 and E112 compliance) would greatly limit the scope of fraud against banks. But such a secure deployment needs investment – and in these difficult times this looks doubtful.

[From Forensic Computing Expert and Barrister – Automated Teller Machines]

Maybe Barclays, who have issued millions of contactless debit cards in the UK, might want to start experimenting with ATM de nos jours. After all, I want to leave home without a wallet, with only a phone, but there are still backward and underdeveloped parts of the world (eg, Woking) where many retailers do not yet have contactless terminals and so there is the need for occasional recourse to the hole in the wall, but it’s difficult to get my iPhone in the slot, especially when it is fitted with anti-fraud devices. Consider this appealing alternative: take splendid new Barclaycard/Orange mobile phone with NFC, open card application and enter numerical passcode and amount of money required. Then hold phone next to ATM and wait for the money to come out.

Having another go

Greyscale backing image

The UK’s last attempt to introduce a national identity infrastructure, the national ID card, failed pretty badly and left everyone involved under a cloud (except for the management consultancies who billed tens of millions of pounds to the project).

The Home Office slipped out the final report of the Independent Scheme Advisory Panel (ISAP) this week, more than a year after it was written. The ostensibly independent report, which reveals how the ID system had been compromised by poor design and management, was submitted to the Home Office in December 2009.

[From Henry Porter – Home Office suppressed embarrassing ID cards report]

The report says that there are no specifications for usage or verification (which we knew – this was one of my constant complaints at the time) and, revealingly, that (in section 3.3) that “it is likely that European travel” will emerge as the key consumer benefit. This, I think, is an interesting comment. As I have pointed before in tedious detail, what the Identity & Passport Service (IPS) built was, well, a passport. It had no other functionality and, given the heritage, was never going to have. Hence my idea of renaming it “Passport Plus” and selling it to frequent travellers (eg, me) as a convenience.

As an aside, the report also says (in section 5.5) the “significant” number of change requests after the contracts had been awarded would likely increase risk, cost and timescale. Again, while this is a predictable comment, it is a reflection on the outdated consultation, specification and procurement processes used. Instead of a flagship government project heralding a new economy, we ended up with the usual fare: incomplete specifications, huge management consultant bills, massive and inflexible supply contracts.

The report repeated the same warnings ISAP had given the Home Office every year since the system blueprint was published in December 2006 by Liam Byrne and Joan Ryan, then Home Office Ministers, and James Hall, then head of the Identity and Passport Service (IPS).

[From Home Office suppressed embarrassing ID cards report – 1/7/2011 – Computer Weekly]

How did it all go do wrong? Liam Byrne should have known something about IT as he used to work for Accenture, as did James Hall (Joan Ryan was a sociology teacher who later became famous for having claimed for more than £1,000,000 in MP’s expenses). Yet somehow the “vision” that emerged was profoundly untechnological, backward-looking and lacking in inspiration. What’s different now?

Well, a key change is that the new administration is heading more along the lines of the US (with USTIC) and the Nordics, where people use their bank IDs to access public services. We’re working on a project with Visa Europe and our good friend Fred Piper at Royal Holloway to develop a pilot implementation right now.

Consult Hyperion, working with Visa Europe and Codes & Ciphers, is the industry lead for a Technology Strategy Board funded research project; Sure Identity, for Secure Authentication of Online Government Services. This innovative pilot scheme will investigate the security and cost benefits of consumers using new bank-issued electronic Visa debit cards to securely access online government services

[From Digital Systems – DS KTN Member receives funding from Trusted Services Competition for research into the secure authentication of online Government Services – Articles – Technology Strategy Board]

It’s possible to at least imagine some form of “UKTIC” that is interoperable with the US version, certainly to the extent that an American with a US bank account might be able to open a UK bank account, things like that. And it’s possible to imagine a kind of EUTIC that sets certain minimums in place so that UKTIC can interoperate with France TIC and Germany TIC and so on. I already have one or two ideas about where UKTIC may differ from USTIC. Let’s go back to the EFF’s comments on USTIC.

A National Academies study, Who Goes There?: Authentication Through the Lens of Privacy, warned that multiple, separate, unlinkable credentials are better for both security and privacy. Yet the draft NSTIC doesn’t discuss in any depth how to prevent or minimize linkage of our online IDs, which would seem much easier online than offline, and fails to discuss or refer to academic work on unlinkable credentials (such as that of Stefan Brands, or Jan Camenisch and Anna Lysyanskaya).

[From Real ID Online? New Federal Online Identity Plan Raises Privacy and Free Speech Concerns | Electronic Frontier Foundation]

If we were to make UKTIC something like USTIC but with the addition of a class of unlinkable credentials that might be mandated for certain uses, then we could take a really important step forward: instead of a physical national identity card, the administration could trumpet and virtual national privacy card. (Actually, I’d be tempted call it a Big Society Card in order to get funding!)

The magic number

Greyscale backing image

William Long and Kai Zhang, from our friends at Sidley & Austin, present a typically good summary of the main issues raised in the consultations preceding the implementation of the new E-Money Directive (EMD) in the UK in the recent issue of E-Finance & Payments Law & Policy (December 2010).

Generally speaking, things look very positive. The capital requirements are being relaxed so that anyone who wants to provide e-money services probably can do with too much trouble, so I predict that you’ll see some major companies moving in now. The prime candidates to offer services are probably telecommunications operators and retailers, but transit operators, event managers, corporate “campus” suppliers and others will surely seize the opportunity. Some have already declared their intentions.

O2 will apply for an e-money licence this year, signalling its commitment to support contactless payments in the UK in the near future.

[From O2 to apply for e-money licence to support NFC payments – 2/2/2011 – Computer Weekly]

The French operators announced a similar move this week. I can’t resist noting that this is precisely the strategy that we recommended to mobile operators a couple of years ago (that is, use the upcoming PSD/ELMI changes to start their own payment businesses). Competition is good for innovation, and bringing these new players into the payments business will be very positive for all of us.

The interest of mobile operators is natural, and they have to move quickly to avoid being cut out of the loop by handset-based secure element providers (eg, Apple) who may move quicker than the UICC-based secure element providers (eg, mobile operators). The interest of the transit operators is also natural, since they have the cards out there in peoples’ pockets. I still think that we’ve yet to see the really big plays yet: these will come from the retailers, just as they are in the US.

Kmart has begun testing check cashing, money transfers and prepaid cards in stores in Illinois, California and Puerto Rico, with plans to roll out the services nationally later this year. Best Buy has installed kiosks in its stores for shoppers to pay utility, cable and phone bills. Wal-Mart has opened roughly 1,500 MoneyCenters that process as many as 5 million transactions each week.

[From Retailers offer financial services to ‘unbanked’]

The use of retailer-issued e-money pre-paid products as a low-cost alternative to bank accounts for the excluded is a win-win. It takes unprofitable customers away from the banks and gives those customers more convenient services. And the retailers could steer customers to use these products at POS, thus saving on their payment processing costs. Personally, I think the prepaid market is not competitive enough (the charges are still too high) but new entrants enabled by the ELMI, new entrants with economies of scale (such as high street retailers), could open up the market and drive down costs very quickly.

Finally, I was also very excited to note in the article that the Treasury is considering my idea of making the balance limit for simplified due diligence (under the Third Anti-Money Laundering Directive) for low-value electronic money “accounts” the same as the value of the largest banknote: in this case, €500. Although they are only looking at this for non-reloadable devices, I think this should be the guiding principle for reloadable devices as well. The link between the two, the “magic number”, is entirely symbolic: it doesn’t mean anything at all, but it’s a good focus for debate.

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

Ageing problem

Greyscale backing image

The simple and prosaic case of age verification has always been a litmus test for digital identity infrastructure and it’s taken on new dimensions because of social networking. We need some clear thinking to see through fog of moral panic, made worse by the turbocharging impact of the mobile phone, because it is such an individual and personal device. The spectre of legions of perverts luring children via their mobile phones is, indeed, disturbing. If only there were some way to know whether your new social networking friend is actually a child of your age and not an adult masquerading as such.

A mobile phone application which claims to identify adults posing as children is to be released. The team behind Child Defence says the app can analyse language to generate an age profile, identifying potential paedophiles.

[From BBC News – Researchers launch mobile device ‘to spot paedophiles’]

Of course, it ought to work the other way round as well. One of my son’s friends told me that members of his World of Warcraft Guild (all 13- and 14-year olds) enjoy pretending to be “grown ups” online (by pretending to have jobs and wives). But this seems an odd way to move forward, as well as something that will surely be gamed by determined perverts.

Why on Earth can’t we just do this properly, at the infrastructural level. If we had a half-decent digital identity infrastructure, there would be no need for this sort of thing. Look, here’s a simple of example of this, in Japan. If you want to use social networks via your mobile phone then it is the operator who verifies your age to the social network service (SNS) provider. Since the operator has the billing relationship, this makes sense.

KDDI announces age verification service for mobile SNS platforms; Gree, Mixi and MobaGa to start at the end of Jan

[From Mobile SNS Age Verification Service by Wireless Watch Japan]

Note that this has no implications for privacy. The operator could require you to come to one of their outlets and prove that you are, say, 18. Then they set a flag for service providers to tell them that you are over 18. It doesn’t tell them your age, or your name or where you are. Just that you are over 18. Note that this system hasn’t been invented for social networking: it is already used to prove age at vending machines (you can’t buy cigarettes or sake or whatever unless your phone says that you are old enough). It ought to be simple enough to do the same thing but using proper technology. Suppose that your Facebook page came with a red border if you have not provided proof of age? Then you could provide that proof of age and have your border changed to blue for under 18 or green for over 18 – then make the rule that anyone with a red border is only allowed to connect to people with green borders.

You see what I mean. Have something that is understandable at the user level and implement it using certificates, digital signatures and keys in tamper-resistant storage (in, for example, mobile phones). There would be no need to try and explain to people how PKI actually works (which killed it in the mass consumer market last time), just show them how to log in to things using their phones. There’s a waiting mass market for this sort of thing if you can be clear to consumers that it will protect their privacy and that market is adult services: porn and gambling, primarily, either of which should generate a decent income stream for the successful service provider. Simple. As a complete aside, there’s another connection between the adult world and social networking.

The surprise relationship between social networking and adult-themed sites came last September, when total page visits for social networking sites for the first time eclipsed that of adult sites.

[From BBC NEWS | Technology | Porn putting on its Sunday best]

So the internet isn’t all about porn after all!

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

Mobile challenges to the financial sector

Greyscale backing image

What’s big in payments right now? I don’t think we have to guess. Our good friends at PaymentsNews have already pointed out that

Two payment-related themes are emerging from NRF conference being held this week in New York: POS encryption/tokenization and mobile payments acceptance.

[From Payments News from National Retail Federation BIG Show 2011]

One of these themes is all about reducing costs (the costs of PCI-DSS compliance are very high, but I don’t want to talk about them in this post), the other about creating new opportunities. It’s hard to argue with this prioritisation: mobile has to be the no.1 strategic issue. But new opportunities for who? The mobile operators? The international payment schemes? The banks? Chetan Sharma’s survey says that it will be the schemes. I’m not so sure, because it would mean that current value networks will be substantially unchanged through the transition, which doesn’t seem right to me.

Can the current payments landscape of banks issuing cards being accepted at merchants being acquired by other banks translate into the mobile environment? We (the industry) used to think that banks and mobile operators would eventually get around to being pals and would sort things out to set the new value network in motion. Will they? Who knows: but the barbarians are at the gate. Eric Schmidt, the Google CEO, writing in the Harvard Business Review, set out Google’s strategic priorities for the coming year:

Second, we must attend to the development of mobile money.

[From Preparing for the Big Mobile Revolution – HBR Agenda 2011 – Harvard Business Review]

Wow. Mobile money is Google’s second-highest priority. In fact, as Eric notes, Google top three strategic priorities are all about mobile. They are going to be a big part of the mobile marketspace from now on.

In last year’s survey, Google/Android narrowly missed out to be the biggest story of the year but this year, the verdict was clear that Google will continue to dominate the headlines with Android devices and new updates and apps.

[From Always On Real-Time Access » 2011 Mobile Predictions Survey Results]

There’s a particular interest there for those of us who have long thought that NFC is going to be a gamechanger because customers find the convenience of contactless so attractive: it energises all sorts of applications, not only payments (actually, payments are rather dull – probably not the application that drives people into the stores to get NFC handsets).

Google is building a mobile wallet nicknamed “Cream,” which it plans to integrate with Android NFC phones that consumers could tap to pay in stores

[From Google Building an NFC Mobile Wallet; U.S. Banks Are Interested | NFC Times – Near Field Communication and all contactless technology.]

You can see where this is going. Banks will be offered a choice of loading their payment applications to the operator-controlled UICC or to the embedded secure element in Android phone, iPhones (rumoured to have NFC soon) and Blackberries (the first Blackberry devices with NFC are about to launch). Not only will these not be controlled by the bank, they won’t be controlled by the operator either. If the infrastructure for accepting NFC payments is simply more mobile phones, even mobile phones with knobs on, there’s no barrier to new types of payments sitting in those secure elements.

Anyway, back to the competitive landscape. If you were being negative about mobile operators, you might conclude that they’ve blown it: a couple of years ago they had the chance to get NFC moving on their terms, but they wouldn’t order the handsets. Now they’re going to have to work hard to get back into the value network. And a particular issue will be the basis of competition: what are they going to offer on their NFC platforms? I’ve mentioned before that I think identity is an area where innovation might generate something new for them, so perhaps the operators are developing new propositions around digital identity (the mobile passport or whatever), or couponing and loyalty, or sports, or event ticketing and management.

And so it is that accountants, banks and mobile phone companies see themselves as engaged in intense competition while customers think they are all the same. Competition as businesses perceive it is not at all the same as competition as consumers perceive it.

[From John Kay – Radical innovation rarely comes from within]

John is typically thought provoking, and surely correct. In the specific case of mobile, though, there’s another aspect: the operators ability to innovate, even if they wanted to, is being constrained.

The Verizon iPhone is exactly the same as the AT&T iPhone, just on a different network — and not even on Verizon’s fastest, latest network, which could have showcased Verizon’s strengths.

[From Why Verizon’s iPhone spells the end of the golden age for carriers | VentureBeat]

There’s a difficult line to tread when blogging: after all, we provide consultancy services to the industry and I have to try to balance the display of corporate expertise and depth of understanding with sensitivity to clients plans. I hope I won’t get in to trouble for saying that I think it is a real problem for some of our clients that their strategy people think about competition in conventional terms: operators, banks, schemes. These aren’t the people who will put them out of business — or, more likely, reduce them to pipes (for bits, money, data), which could still be a good business if they are operationally efficient — if they do nothing to respond to the challenge coming from the outsiders. Its going to be a fun year in mobile.

If you’re interested in learning more about this kind of thing, Consult Hyperion’s Head of Mobile Money, Paul Makin, will be presenting on the challenges that mobile presents to the financial services sector at Mobile Financial Services in London on March 15th-16th 2011. Do come along and join in the discussion.

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

Benjamin 3D

Greyscale backing image
[Dave Birch] The US is soon to release a new $100 bill. But why? What do they do with $100 bills? They’re not, as you might imagine, needed to support commerce and trade.

In 2001 the Federal Reserve estimated that 90 percent of the $100 bills ordered by the Federal Reserve (which accounts for the overwhelming majority of C-notes ordered nationwide) were paid out to foreign banks

[From Hundred-dollar bills are for criminals and sociopaths. Why do we still print them? – By Timothy Noah – Slate Magazine]

Around two-thirds of all of the US dollars in “circulation” are not in the US at all and are unlikely to be repatriated. This represents a tremendous interest-free loan from the rest of the world to Uncle Sam. But is this income sufficient to outweigh the negative effects of cash?

So why do we keep printing $100 bills? As with any valuable export, we worry that if the C-note ceased to be available to foreign criminals and dictators, another paper currency would take its place. The leading candidate would be the 500 euro note,

[From Hundred-dollar bills are for criminals and sociopaths. Why do we still print them? – By Timothy Noah – Slate Magazine]

Well, that’s true, and the conspiracy theory that the European Central Bank (ECB) only had the 500 euro note printed in order to replace the $100 bill in the stashes of drug dealers and tax evaders is widely recirculated. But that’s a reason to scrap 500 euro notes, not to print more $100 bills, especially when the $100 bills have to be completely re-designed anyway.

But the biggest upgrade is a blue “3D Security Ribbon”… The strip contains a series of images of bells and digits; tip the note, and the images come into 3D relief. “It only takes a few seconds to check the new $100 note and know it’s real,” says Larry R. Felix, Director of the Treasury’s Bureau of Engraving and Printing.

[From US Treasury: New 100 dollar bill needs 3D tech – CSMonitor.com]

Sounds exciting. But why bother? Why not just forget about the $100 (and, for that matter, the $50 bill)? After all, high-denomination notes have been withdrawn before, and for much the same reason. We have to weigh up the overall impact on society and try to make the right decision, and sometimes that decision might mean a radical change.

In 1969, the Treasury stopped issuing $500, $1,000, $5,000 and $10,000 bills specifically to impede crime syndicates — the only entities that were still using such large bills after the introduction of electronic money transfers.

[From Turn In Your Bin Ladens – NYTimes.com]

And before I get deluged with e-mails calling me a New World Order stooge intent on introducing the Mark of the Beast across the USA, let me merely point out that if the public were to desire anonymity for payments (they don’t, by the way) then it’s possible to create anonymous electronic money: this is an implementation choice, not any sort of technological constraint. Of course, the fact that the US government stops producing high-denomination notes doesn’t necessarily mean that they will disappear…

Malaysian police have arrested a Lebanese man allegedly carrying fake currency with a face value of $66 million after he tipped a hotel staff with a $500 note, an official said Friday.

The largest U.S. note currently in wide circulation is a $100 bill. But police found bundles of $1 million, $100,000 and $500 notes in the man’s hotel room in Kuala Lumpur on Sunday, said Izany Abdul Ghany, head of the city’s commercial crime unit.

[From $500 Tip Leads Police to $66 Million in Fake Bills – ABC News]

If only all counterfeiters were that good!

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

Internet driver’s license?

Greyscale backing image

Last year I said that I thought that the US National Strategy for Trusted Identities in Cyberspace (NSTIC) was heading in the right direction. I’m very much in favour of the private sector providing multiple identities into a framework that it used by the public sector and vice versa. I’m in favour of choice: if I choose to use my Barclays identity to access the DVLA or my DWP identity to access O2 it shouldn’t matter to the effective and efficient use of online transactions. There was one area where I felt it could have presented a slightly different vision, and that’s in the use of pseudonyms, which I think should be the norm rather than the exception.

People should consider it normal to get a virtual identity from their bank or their mobile phone operator in a pseudonymous name so that they can browse, transact and comment without revealing anything about themselves other than the facts relevant to a transaction.

[From Digital Identity: USTIC]

James Van Dyke, when discussing NSTIC (which seems have become known unofficially as “Obama’s Internet Identity System”) warned about

Apocalyptic fear-mongers. Yes I’m ending with the crazies here, but hear me out. The extreme cable networks and televangelists will surely jump on this as the digital incarnation of the Mark of either the Beast or “(gasp!) Obama liberals. Historians will recall that social security numbers were supposed to be an apocalyptic conspiracy.

[From Obama’s Internet Identity System: Could This Change Everything? – Javelin Strategy & Research Blog]

I don’t think the danger is the crazies — although I feel a little sheepish writing this a couple of days after a crazy did, in fact, murder several people and seriously injure a congresswoman — but the journalists, politicians, commentators and observers who don’t really understand the rather complex topic of digital identity. Or, as “Identity Woman” Kailya Hamlin (who some of you may remember from the first European Internet Identity Workshop that Consult Hyperion sponsored with our friends from Innopay and Mydex back in October) said about NSTIC:

I am optimistic about their efforts and frustrated by the lack of depth and insight displayed in the news cycle with headlines that focus on a few choice phrases to raise hackles about this initiative

[From National! Identity! Cyberspace!: Why we shouldn’t freak out about NSTIC. | Fast Company]

She’s bang on with this. Here’s a couple of typical examples from the blogosphere:

CNET reported on January 7, 2011 that Obama has signed authority over to U.S. Commerce Department to create new privacy laws that require American citizens to hold an Internet ID card.

[From Internet Anonymity: Obama Pushes for an American Internet ID]

And

President Obama has signaled that he will give the United States Commerce Department the authority over a proposed national cybersecurity measure that would involve giving each American a unique online identity

[From Obama administration moves forward with unique internet ID for all Americans, Commerce Department to head system up — Engadget]

As far as I can see, NSTIC being managed by the Commerce Department has nothing to do with “privacy laws” and the idea that it will require Americans to have an “Internet ID” is a journalistic invention. The actual situation is that NSTIC is to go from being an idea to an actual system:

The Obama administration plans to announce today plans for an Internet identity system that will limit fraud and streamline online transactions, leading to a surge in Web commerce, officials said. While the White House has spearheaded development of the framework for secure online identities, the system led by the U.S. Commerce Department will be voluntary and maintained by private companies,

[From Internet Identity System Said Readied by Obama Administration – BusinessWeek]

What this means is not that Americans will get an “Internet Driver’s License” but that they will be able to log in to their bank, the Veteran’s Administration, the DMV and their favourite blogs using a variety of IDs provided by their bank, their mobile phone operators and others.

[White House Cybersecurity Coordinator] Howard Schmidt stressed today that anonymity and pseudonymity will remain possible on the Internet. “I don’t have to get a credential, if I don’t want to,” he said.

[From Obama to hand Commerce Dept. authority over cybersecurity ID | Privacy Inc. – CNET News]

As long as it’s a matter of choice, I really don’t see a problem with this. The idea of NSTIC is that it is the infrastructure that is standardised, and this is good. We need standards for credentials and such like so that I can use my Woking Council ID to log in central government services and my Barclays Bank ID so that I can log in to do my taxes online: but I might pay Barclays for an additional ID that has some key credentials (IS_A_PERSON, IS_OVER_18, IS_NOT_BANKRUPT, that sort of thing) but does not reveal my identity. This sort of Joe Bloggs (or, for our cousins over the water, John Doe) identity would be more than adequate for the vast majority of web browsing and if other people want to wander the highways and byways of the interweb with a Manchester United, Prince or BBC ID, then it’s up to them. Let a thousand flowers bloom, as they say (well, as Chairman Mao said).

If the crazies want to be concerned about a single ID mark of the e-beast infocalypse, they’re perfectly entitled to, but I don’t understand why they are convinced it will come from the government in general or Obama in particular – there are half-a-billion people out there (including me) who have already handed over their personal information to a single unaccountable entity.

Facebook Login lets any website on the planet use its identity infrastructure—and underlying security safeguards. It’s easy to implement Facebook Login, simply by adding few lines of code to a web server. Once that change is made, the site’s users will see a “Connect with Facebook” button. If they’re already logged into Facebook (having recently visited the site), they can just click on it and they’re in. If they haven’t logged in recently, they are prompted for their Facebook user name and password.

[From Facebook Wants to Supply Your Internet Driver’s License – Technology Review]

Now, at the moment Facebook Connect just uses a password, so it’s no more secure than banks or government agencies, but it could move to a 2FA implementation implementation in the future. Widespread 2FA access to online services really should have become a business for banks or mobile operators already (think how long Identrus has been around) but it just hasn’t happened: I can’t use my Barclays PINSentry to log on to Barclaycard, let alone the government or an insurance company. But suppose my Facebook login required access to my mobile phone so it was much more secure: you know the sort of thing, enter e-mail address, wait for code to arrive on mobile phone, enter code (a proper UICC-based digital signature solution would be much better, but that’s another topic). Then I could use Facebook Connect for serious business. This would have an interesting side-effect: Facebook would know where I go on the web, which seems to me to be much more like the mark of the e-beast.

An interesting side benefit for website operators is that Facebook Login provides the site with users’ real names (in most cases) and optionally a variety of other information, such as the users’ “friends” and “likes.”

[From Facebook Wants to Supply Your Internet Driver’s License – Technology Review]

Which is, of course, why I don’t use it. On the other hand, if Facebook decided to use cryptography to secure and protect this sort of information, they could at a stroke create a desirable internet passport: by “blinding” the passport to prevent service providers from tracking the identity across web sites Facebook could significantly improve both convenience and privacy for the average users.

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

Resolution no.1: stop making predictions

Greyscale backing image

Osama Bedier, VP of Platform, Mobile and New Ventures at PayPal, joins the tradition of making predictions for the coming year. I’m always loath to do this, for two reasons:

  1. because it’s a dangerous game as a consultant. Consult Hyperion are working on plenty of client projects that are confidential and relate to new products and services that will be announced during the year and I don’t want to mess up and accidentally “leak” any of these;

  2. because it’s really difficult and wrong predictions come back to haunt you.

In Osama’s case, however, I think at least four of his five key trends are spot on and the fifth is probably right. Let’s join in the New Year fun and have a look at what he said.

Mobile, mobile, mobile. Wallet in the cloud. The digital wallet. Call it what you want, but mobile devices are poised to become a primary form of payment for millions of people around the world… Consider that PayPal saw a 310 percent increase in mobile payment volume on Black Friday 2010 compared to the previous year, and a 292 percent increase in mobile payment volume on Cyber Monday 2010 compared to Cyber Monday 2009. Without a doubt, mobile payments are here to stay and will see significant innovation in the coming year.

[From Five payment trends to watch in 2011 | VentureBeat]

This is impossible to contradict and anyone who doesn’t think that mobile is central to the evolution of the entire payments market this coming year is absolutely 100% wrong. I’ve consistently said — for a decade — that mobile payments will be more important than web payments and I absolutely stand by this. I think I might go further and say that the biggest mobile payments story of the year will be the arrival of Android phones with NFC interfaces, and these will transform the payments landscape.

T-commerce. TV will go from a passive (viewing-only) experience to a highly interactive activity as more and more apps are developed specifically for the platform.

[From Five payment trends to watch in 2011 | VentureBeat]

One of the very first reports that I ever wrote about payments and the new media said the companies should focus on t-commerce as well as m-commerce because in the medium term these would become the key channels. I was wrong about the TV side of things: it has take much longer to develop than I thought, probably because the sector remains focused on “traditional” business models around subscription and advertising. Surely it’s going to change this year.

Appification’. IDC issued a new report that says, among other things, over the past three years the mobile apps space has seen an “appification” of “broad categories of interactions and functions in both the physical and the digital worlds.” And this only stands to continue — in fact, the same IDC report projects mobile app revenue to grow from $4.9 billion in 2010 to $35 billion by 2014.

[From Five payment trends to watch in 2011 | VentureBeat]

In the smartphone world, payment apps are going to be big, but I think we all recognise that they are one part of a new value-adding ecosystem that involves vouchers, coupons, loyalty and so on as well as the basic payment itself. This is why I suspect that simply porting exiting payment mechanisms (eg, credit cards) to the mobile platform will not be sufficient to obtain competitive advantage.

A Cashless Society. Now let’s not go crazy here, I’m not suggesting that by this time next year we’ll be living in a cashless society. Far from it. That said, 2011 will undoubtedly see several significant steps that will take us closer to such a world.

[From Five payment trends to watch in 2011 | VentureBeat]

I think he’s right about this, even though plenty of other people are sceptical. In many places, these first steps have already been taken and I think the pressure to reduce the amount of cash in circulation over the coming year will come not from the electronic payments industry but from governments, law enforcement agencies, trade unions and others who want to make a start on reducing crime and tax evasion. The trigger, however, is mobile. It is the arrival of mobile payments that makes cashlessness a realistic possibility and means that the industry can respond to these pressures.

Social shopping is clearly poised for significant growth… Among the key drivers of this trend are micropayments and digital goods. Along the same lines of merging physical world experiences with digital activity, the ability to make quick, small purchases for online content represents a huge opportunity for both content producers and providers.

[From Five payment trends to watch in 2011 | VentureBeat]

This is the one I’m not sure about, and that’s because while we tend to focus on what’s happening at Facebook and the like, I think we’re still in the very early stages of social media and I don’t think we really understand how the sector is going to develop. The role of mobile, NFC and other connectivity technologies in the evolution of social media is still changing and the disconnection technologies are still awaiting standardisation and mass deployment. So while I agree that social shopping will continue to grow, I’m not sure whether it will change the payments space or simply use the products coming from the payments space (or, to put it another way, will Facebook credits break out into new markets?). Perhaps there’s another possibility for this fifth spot. Over at the Financial Services Club, someone whose opinions I always takes seriously highlights something else:

Major investments in creating agile infrastructures and platforms to respond to regulatory requirements.

[From The Financial Services Club’s Blog: Six key technology developments for banks in 2011]

I’m sure Chris is right. The changing regulatory environment is bound to be a big influence on the technology spend for the coming year. New platforms that help to make compliance, in particular, easier to manage will be very attractive to financial institutions. You only have to look at what’s been happening in the cards world to see this.

He noted that PCI compliance has been a significant burden, costing an average of $20,000 for merchants that average only $32,000 in pretax profits; they will gravitate to solutions that reduce PCI scope (tokenization, point-to-point encryption, etc.).

[From Tidbits and Sound Bites from the 2010 Chicago Fed Payments Conference — Payments Views from Glenbrook Partners]

Scatchamagowza! Compared to the cost of renting the terminal, merchant fees and other costs associated with accepting cards payments, this is huge. Shaving a tiny amount off of fees won’t tip a business model anything like as much as making a significant cut to compliance costs, so this must be a priority area for investment and new services that can help will find a ready market.

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

Announcing London BarCampBank4

Greyscale backing image

I’m a big fan of the unconference format, where the agenda is set on the day by the participants, so I’m very excited to announce that the 4th BarCampBankLondon “Unconference” will be held on 31st January 2011. The facilities will be provided by NESTA at their offices at 1 Plough Place, London EC4A 1DE with support from Consult Hyperion and BullionVault. Look forward to seeing you there!

This year, there will be a special focus on the role of financial services and institutions and their potential to help local communities unlock currently underutilised capacity to meet currently unmet needs. Why? Well, the new coalition government in the UK has an initiative called “The Big Society”: The Big Society is about helping people to come together to improve their own lives and putting more power in peoples hands. There is real interest – both within and outside of government – around the potential of ‘people helping people’ models such as complementary currencies and timebanking. The recent “giving” green paper consultation launched by the Cabinet Office makes particular reference to the potential of complementary currencies and raises questions around scaling local timebanks on a national scale.

New complementary currencies mean new institutions and my particular interest at the event will be to explore potential institutional arrangements. What would it mean to make complementary currencies part of the financial services landscape? What new kinds of financial institutions are need for the new economy? Questions like these deserve examination from a range of perspectives and I hope that we can exploit the opportunity to explore decentralisation, locality, community in financial services. New technologies — everything from mobile phones and smart cards to Facebook and Twitter — have a key role to play here, both in terms of stimulating new organisational models and and scaling up working alternative models to regional and national scale.

The number of tracks running in each session naturally depends on the number of participants and what they want to talk about but for BarCampBankLondon4 we hope to run 3-4 parallel sessions both before and after lunch. The topics to be covered in each track depend on you, the audience, but I expect them to range across new ideas for financial services businesses, ways to use new technology (with a big focus on social media), banking regulation and industry structure, community banking and a wide range of related issues.

The proposed agenda for the day is simple:

10am Welcome and introductions

10.30am Agenda-setting and ice-breaking

11am – 12.15pm First Session

12..15-12.30pm Report and review

12.30pm-1.30pm Lunch and networking

1.30-2.30pm Second Session

2.15-2.30pm Report and Review

2.30-3.30pm Third Session

3.30-4pm Report and Review, Closing Discussion.

See you at at NESTA on 31st January 2011. We hope to see 50-60 people there but space is limited, so please register right away here via MeetUp. There is a nominal booking charge of £10 and all delegates will receive copies of the latest Digital Money Reader with the compliments of Consult Hyperion and When Money Dies with compliments of BullionVault.

Subscribe to our newsletter

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

By accepting the Terms, you consent to Consult Hyperion communicating with you regarding our events, reports and services through our regular newsletter. You can unsubscribe anytime through our newsletters or by emailing us.