Looking at this as objectively as I can (given my current career focus), I fail to see how the sheer number of authentication factors a mobile devices is capable of doesn’t make authentication of card-not-present transactions at least as, if not more secure than card present transactions.

Well, they SHOULD be more secure, the technology is available, but the payments and mobile industries cannot seem to get out of their own way.

Let’s examine the card present transaction: I walk into a shop, choose my items, then go the counter. The shop assistant rings in my stuff, I place my chip & PIN card into the terminal, enter my PIN and I’m done.

The only things ‘guaranteeing’ that I’m an authorised user of the card is that I have the card in my possession, and a 4 digit PIN number. Yes, some cards have photos on them, but they are few and far between, so the real security in a card present environment is the difficulty of obtaining the card and the PIN from the true owner. I will not underestimate just how difficult this is, but other that the true owner finding the card missing and reporting it, there are very few checks and balances.

Now let’s consider what you currently have to do to buy something online, and everything a mobile phone COULD be doing to provide security. Traditionally:

  1. To create a new account with most e-commerce retailers, you just need a valid email address – May or may not require confirmation from email address used.
  2. To add a payment card you need a valid billing address, and a mobile phone number – May or may not be validated in the back-end.
  3. To make a purchase, you log into your account, choose your stuff, then go to the checkout. You select the saved payment card you wish to use, then enter your CVV2 code and / or your 3-D Secure password.

All of this is far easier to fake / bypass than in card present environments, hence the higher rates of fraud.

Now, imagine a scenario where you have registered your mobile phone and tied it to the payment card in question. At your disposal you have all of these available to you;

  1. PIN / Password – the most ubiquitous form of authentication on the planet, and while it’s not the best, it most certainly adds a significant layer of complexity for the bad guys.
  2. Fingerprint – If you have an iPhone 5/6 or a later version of Samsung, you have fingerprint biometrics. This facility will only increase as time goes on.
  3. Voice Recognition – Nowhere near as prevalent as fingerprint, but gaining ground.
  4. Retina / Face Recognition – Combine these two because they both use the camera in a very similar way. Not a huge fan of these so far, they are rather ungainly.
  5. Geo-Fencing – a transaction request comes in from a Nigeria-based IP address and your phone is in Wandsworth, is that legit?
  6. Social Media Profiling – Not common at all …yet, but you could choose to add your social media profile to the purchase decision. e.g. you’re a rabid Arsenal (UK folks) / Redskins (US folks) fan, would you really be buying Spurs or Eagles merchandise respectively? Maybe, but I assume only to burn it.
  7. Reputation Profiling – Again, not common, but another growing form of identity management.
  8. Device Profiling – App layouts and such.

…and so on.

The vast majority of these will require an initial set-up and configuration, but will then be largely invisible to the user during use. Innovation without practical use is just a dream, and in this case practical use means that everyone can use it without inconvenience.

Done correctly, the integration of all of these factors during a transaction will take no more effort than a user expends in the normal use of their mobile device, but so far the individual vendors of each service and mobile device are trying to corner the market for themselves.

Digital transactions account for trillions of €/£/$ annually, there is room for everyone in the EVOLUTION (not revolution) of payments from Plastic & PIN to Mobile & Multi-Factor, and disruptive innovation will do nothing but delay the end goal;

Frictionless and ultra-secure mobile payments.

[If you liked this article, please share! Want more like it, subscribe!]

This could potentially be my most contentious blog yet, but the very thing I am railing against [somewhat] is the very thing that allows me to post this in the first place; human rights, as enforced by my country’s laws and/or societal norms. MY society anyway.

My issue is not with human rights per se, they are a concept that should only become more important as the world gets smaller. Shared information available to an enormous distribution of mobile devices will, in theory, help combat the rampant ignorance across the globe, often enforced by oppressive government entities themselves. Just look at the ridiculous Twitter ban in Turkey for one of the milder examples. When everyone on the planet knows that they shouldn’t have to live under any totalitarian regime, human rights will provide the long-term road map for progress towards the freedom most of us take for granted.

My issue with human rights is the equal enforcement of them. As an extreme; why does someone convicted of multiple homicides have the same rights as someone who spends their whole life helping others? Yes, the killer may lose their freedom, but their rights as a human being are still in full effect. You take from someone everything they will ever have, and in my opinion, you are giving up some – and potentially all (depending on your crime(s)) – of your rights to be treated equally AS a human.

No, this is NOT a case for capital punishment, that’s too specific a judgment, this is about the fact that as species, there is no way we human beings will EVER reach a 100% consensus on anything, and we need to stop pretending that we can. The majority opinion must rule, as long as it’s not MOB rule, and the losing minority needs to abide by the prevailing decision. Criminals of every sort ALL have an opinion different from the majority, and it’s one they have likely acted upon. They think they are somehow exempt from doing the right thing, and in most ‘civilised’ nations those right things are instilled from childhood and reflect an accepted standard of ‘common decency’.

Do NOT steal, do NOT kill, do NOT take anyone by force and so on, but what about those countries where the established norms – if not the actual laws – are different? Can anyone reading this blog POSSIBLY justify the murder of the 11 people working for Charlie Hebdo just because they printed satirical matter and images related to their deity? Or any of the hundreds of terrorist attacks perpetrated for religious or political reasons across the globe? These things are REAL, but what makes US right? What makes US the arbiters of that common decency?

We’re the majority, that’s what gives us the right to condemn their actions. Anything other than treating everyone as you would wish to be treated yourself should be unacceptable in any society.

So we clearly need to stop pretending that as a species we are that evolved OR that civilised, and neither religion nor government should have the final say in what’s right and what’s wrong. We are all born with rights, but from that point forward they become a privilege every individual has the responsibility to maintain. All of our freedoms and all of our rights come at a cost, we must all be prepared to pay those costs.

In the end, humans are just another mammal, the attribution of instincts above layer 4 of Maslow’s Hierarchy of Needs is admirable, and certainly an aspiration, but fighting a sociopath with rules is no different than making a wish by blowing out candles on a birthday cake. I will live my life by a simple set of self-imposed laws, and would hope everyone around me does the same;

The 5 Laws of Human Rights:

  • Everyone starts out in life with the same rights;
  • Everyone may utilise their rights to their own unqualified ends as long as those actions do not infringe on the rights of others;
  • Infringement of the rights of others will result in a loss of your rights equal to that inflicted on the other party(ies);
  • Use of rights for one’s own benefit comes with a risk of loss, everyone will accept personal responsibility for this loss; and
  • No-one shall take their rights for granted.

We need to stop pandering to those living outside the globally accepted norms of common decency, they have no place here with the rest of us.

[If you liked this article, please share! Want more like it, subscribe!]

First a caveat; this blog is not aimed at all acquirers, nor is it aimed at every individual at any one acquirer, there are some very professional, knowledgable, and pragmatic acquiring banks out there who are providing excellent advice and guidance to their merchant base.

Then there are the others who not only seem to have no idea what they are talking about, but are actually making things actively worse in terms of both resource effort and overall expenditure for their merchants. This is suppose to be a program of APPROPRIATE security, not just compliance.

The latest, utterly inexcusable example of this is a Level 3 merchant I know who, wanting to do things properly, hired a QSA company to come in and help them prepare for the completion of their SELF Assessment Questionnaire (SAQ).

The first thing the QSA had to do was get the merchant to ask the acquirer which SAQ they wanted, as the acquirer had left that to the merchant. For those who don’t know, it’s the acquiring bank’s responsibility to determine the correct SAQ based on the merchant’s business processes and card transaction volume. The acquirer should NEVER point at a QSA for this decision, and should most certainly not be leaving it up to the merchant.

After spending a significant amount of time and money, this particular merchant completed 2 compensating controls, which were then required to be signed off by a QSA!! Are you kidding me!? It’s a SELF assessment!! You show me a QSA who will sign off on a compensating control without the context of a FULL Level 1 assessment or a million caveats and I’ll show an idiot.

Now try to imagine this merchant’s frustration  when he knows another similar merchant had just filled out an SAQ by themselves, got an ASV scan, and received no questions from the same acquirer? The original merchant tried to do it properly, tried to ensure they could answer every question properly, and were even honest about the things they could not do. Their reward for this was additional expense getting another QSA to come in and help them translate the PCI rules back to the acquirer.

Here I am now 4 short weeks later and I have another merchant being told that the acquirer would “accept a SAQ D” for their reporting requirement. Bear in mind that this client is an e-commerce merchant who has implemented a full redirect to a PCI compliant service provider and you can again imagine the frustration. Add to this that the merchant, who will be reporting full compliance within a month, was also “encouraged” to complete a Prioritized Approach Tool spreadsheet as well, and the whole thing becomes a farce.

I have a lot of sympathy for acquirers, their PCI  headaches are multiplied by as many merchants and service providers they acquire for, but this is no excuse to provide anything but the most pragmatic guidance as they can. PCI cannot be driven from behind a desk, and practical guidance can only come from those who have been in front of a client as a QSA. I can read a book on emergency appendectomies for example, but I would suggest you go to a real doctor.

Merchants: If you do want to do PCI properly, hire a good QSA or industry expert for ONE day to set the game-plan with your acquirer and your internal teams, then get on with it.

Acquirers; Hire ex-QSAs with good reputations to run your merchant-facing PCI Programs, you’ll save yourselves and your clients a Hell of a lot of pain.

I am in no way against biometrics, they are absolutely intrinsic to the future of non-cash payments and the implementation of true identity management in general. What I’m completely sick of is the “Password is dead, biometrics is here!” hype perpetrated by those with a blatant self-interest.

If the password was dead, we would not have a multi-TRILLION £/$/€ industry currently predicated on the 4 digit PIN; the branded payment card. Organisations up and down the payment card food chain, from the schemes to the end merchants would not be spending billions on the perpetuation of the technology if the password was actually dead.

The payments industry is not trying to reach the < two billion people with biometric-enabled smartphones, they are  trying to reach the SEVEN billion people with money, half of whom have no access whatsoever to formalised banking as we know it, let alone a £400 mobile device.

Yes, there are ongoing fraud issues, and yes there are viable alternatives, but ask the average person on the street if they need mobile payments authorised through some form of biometrics and they will simply ask what’s wrong with their credit card? Too many biometrics companies are trying to change the world without applying common sense to the real issues. They are not solving a problem, they are trying to create a demand.

The challenges the payments industry face are myriad, and include;

  • Enormously complex and expensive infrastructure geared towards current payment methods and protocols – [There’s no starting over from scratch]
  • Global acceptance of current operational standards by all country’s financial authorities – [Requires amendments to most laws and regulation]
  • Older technology that does not port securely onto consumer controlled mobile devices – [You cannot exclude the card brands from this move.]
  • Difficult transition path from legacy infrastructure to new – [Where do you start, and what direction do you go in?]
  • Increasing pressure from retail to provide improved customer journey / experience –[Retail and consumers expect more.]
  • …and so on.

Fraud due to poor authentication is not the problem, it’s an inconvenience, the real problem is that payments are heading from ‘plastic & PIN’ to ‘mobile and multi-factor’ whether we like it or not, and the only practical and secure way of doing so is to do it properly from the beginning. This will be an industry wide effort or it will fail, and no biometrics company on the planet has the answers alone.

Battling fraud is not just about proving that you are the one attempting a transaction, it’s about being able to attribute your entire identity into the desired result. Just because I can prove I’m trying to buy a TV does not mean I have any intention of paying back the loan I took out to get it.

So smart phones have the ability to turn the industry standard Personal Identification Number (PIN) into a Personal Identification Vector (PIV), one that is not only TRULY personal (i.e. fully consumer customisable) but builds in a multitude of other authenticators into each transaction. It is here that biometrics really comes into its own; being able to seamlessly add the something-you-are authentication factor to EXISTING processes.

Biometrics tells us what you are, is does not define WHO you are, and it’s the who-of-you that defines the future of your payment options.

[If you liked this article, please share! Want more like it, subscribe!]

I could not help but laugh while having drinks with a friend of mine yesterday. He kept looking at his watch, and before I understood why I was starting to get annoyed he said that he had an incoming call.

To people of my generation and above (not many of those left) looking at your watch frequently is a sign of impatience, and that you have somewhere you need, or would rather, be. For those sensitive to these non-verbal clues, it signals the end of a conversation, date, meeting, and so on, often resulting in stilted conversation and perhaps even resentment.

Ironically, if he had been looking at his phone that frequently, I would not have thought twice as I do the exact same thing myself. We are both busy, he the CEO / Founder of a successful security company, me an insecure addict of social media affirmation (please like this).

I have tried to figure out why I found this so amusing, but have not reach a conclusion yet, but seeing as this would be a very short blog otherwise, here are some thoughts:

  1. My laughter contained at least a hint of nostalgia, it’s clear that I was remembering a simpler time. And by ‘simple’ I mean utterly disconnected from anything not immediately in front of me. A time without mobile phones. A time when the ‘Like’ button was a smile on your friend’s face;
    o
  2. My laughter also contained chagrin. I thought I was as up to speed with technology and innovation as anyone, but clearly my values and reactions to everything around me were formed in a time very different from this one. I now know that part of me will always stay there;
    o
  3. Jealousy that I didn’t have one because I have not seen one I like, and I have the wrists of a 7 year old girl;
    o
  4. Frustration that ALL of this can’t be replaced by a contact-lens-driven heads-up display;
    o
  5. Several large Woodford Reserve bourbon and ginger ales.

I don’t think anyone can deny the enormous impact mobile devices (especially smart phones) have had on both work and personal interactions. And we mostly agree that because this change has been so profound in so remarkably short a period of time indicates that we are actually only at the beginning of bigger changes to come (Internet of Things for example). Where people differ is their reaction to it; from abject fear and utter rejection, to excitement and complete embracement. Most of us are somewhere in-between.

What I do know is that to reject this change is to be left behind, and to stick with traditional concepts of privacy will exclude you from the conveniences to come. I’m not judging this in a negative way, I’m sure you are perfectly happy to BE ‘left behind’, and to do things the ‘old way’ but I’m also saying that I will not be one of those, I’m too bloody lazy not to have as many things done for me automatically as possible.

I am also happy to accept the consequences, and I will likely be laughing all over again when it all goes horribly wrong! 🙂

[If you liked this article, please share! Want more like it, subscribe!]