Before I can answer that questions, I need to define what I think Identity is. Too often authentication is used interchangeably with identity, but that’s like saying a bank account and money are the same thing.

In its most basic terms, authentication is the what-of-you, identity is the WHO-of you. You can authenticate via password to log into your computer or buy a cup of coffee, but if you want a mortgage, considerably more background information is required. I could give you 5 usernames & passwords, 5 forms of biometrics, and have 5 different hardware tokens and you would still not know to any degree of certainty if I’m good for a loan.

Example: Two people are standing in front of you, one’s a stranger and one’s a close friend. You know [for the sake of this hypothetical] that they are both who they say they are, but do you feel equally comfortable lending them your car?

I would assume the answer is no, you would NOT be comfortable loaning a stranger your car, so what’s the difference? Trust, pure and simple. You trust your friend because you know WHO they are, not WHAT they are.

Unfortunately you will never be able to know everyone on the planet as well as your friends, so how can you assure a sufficient level of trust to do business of any sort? Currently, authentication is enough, but it’s almost entirely one way. If you want to buy something on the Internet YOU have to complete the login details (often including a permanent account), you have to enter all of your payment details, and you have to accept the risk that the merchant will send the goods as promised.

With an identity, built over the course of time and receiving input from many sources, every individual and every organisation can build a demonstrable level of trust so that both sides have the assurance they need to conclude the transaction. Fraud in e-commerce is rampant because we simply don’t have this 2-way assurance.

From the individual side: Credit score, confirmation of available funds, payment history, and any number of other factors can build a Trust Assurance Score (TAS), and it will be up to both the buyer and the seller to agree on the level of score required to complete a purchase. e.g. on a scale of 1 – 100 (100 being a perfect TAS) the merchant needs a score of 5 to buy the ubiquitous cup of coffee, but a score of 50 to rent a car, and a score of at least 75 to get a mortgage.

From the merchant side: Time in business, corporate credit rating, ratings and reviews and so on can build their TAS, so you can decide up front the level of risk you are prepared to accept to conduct the business at hand.

Clearly there are many challenges with this; How do you build a rating in the first place (the young and new businesses should not be unfairly advantaged)?; How do you provide instant access to this rating without exposing all of the detailed information behind it?; How do you tie in the level of authentication required to even request a TAS? And so on.

I’m not proposing a way to fix this, I’m simply trying to demonstrate that the reason we don’t HAVE identity built into transaction authentication is that these issues have not been addressed yet. And until we have identity built into transactions, we won’t have the levels of trust required to make significant change. Payments for example will move from plastic to mobile, but authentication (even multi-factor) is not enough to significantly reduce fraud.

I suspect block-chains (the technology behind crypto-currencies) has a big chunk of the answer, but I can’t even conceive on how this will be done. I just know it needs to.

[If you liked this article, please share! Want more like it, subscribe!]

In October of this year, any merchant in the US who does not demonstrate the ability to accept EMV transactions can be deemed liable for the fraud associated with counterfeit cards.

That’s only 5 months from now.

Most people in the EU can’t really understand the confusion this has generated – we’ve had chip & PIN for well over a decade – but for the population of the US, swipe & signature is as natural as handing over cash. Retailers are rightly concerned that adoption will be a slow and painful process, but that may not be their biggest concern.

Estimates of the cost of transition from magnetic stripe to chip range from 12 (mine) – 33 (the press) billion USD, and the lion’s share of this will fall to the retailers who must replace their existing payment entry devices (PEDs) with chip compatible ones. The chances are good that this expense was not in their long-term costings, and bringing forward the end-of-life of their PED infrastructure is simply not an option in an industry where profit margins are razor thin.

But the thing that few people realise is that while the chip alone is a positive factor in fraud reduction (anti-counterfeit), the greatest benefit of the roll-out of EMV is only achieved when in conjunction with the use of a 4 digit Personal Identification Number (PIN). This effectively adds a second factor of authentication (the card is something you have, your PIN is something you know) making card present transactions significantly more secure. PIN alone would have significant positive impact as well.

It follows therefore that while organisations scramble to comply with the letter of EMV, there already exists in almost everyone’s pocket the capability to provide not just a PIN, but multiple forms of authentication and value-add services that far exceed the benefits of the chip; the mobile phone.

Even the loss of the Primary Account Number (PAN), which is the largest cause of card related fraud, is meaningless if the thief can’t complete the transaction. Add to this the numerous benefits of instant coupons, loyalty programs and even ratings & reviews, and the retailer now has the capability to enhance the customer journey while meeting the intent of EMV.

Neither the card issuers or even the card schemes themselves are fixated on EMV itself, they are only truly interested in reducing fraud. Retailers share this goal, even if they do not entirely agree with the way to get there.

It is up to authentication vendors to provide alternatives, and get those alternatives tested, real-world proven, and on the table. This will not be authentication vendors alone, or mobile device manufacturers alone, and the result will not be a decision made by card schemes alone. This will be a collaboration between ALL players, and will only work if everyone comes away a winner.

Especially the consumer.

[If you liked this article, please share! Want more like it, subscribe!]

Looking at this as objectively as I can (given my current career focus), I fail to see how the sheer number of authentication factors a mobile devices is capable of doesn’t make authentication of card-not-present transactions at least as, if not more secure than card present transactions.

Well, they SHOULD be more secure, the technology is available, but the payments and mobile industries cannot seem to get out of their own way.

Let’s examine the card present transaction: I walk into a shop, choose my items, then go the counter. The shop assistant rings in my stuff, I place my chip & PIN card into the terminal, enter my PIN and I’m done.

The only things ‘guaranteeing’ that I’m an authorised user of the card is that I have the card in my possession, and a 4 digit PIN number. Yes, some cards have photos on them, but they are few and far between, so the real security in a card present environment is the difficulty of obtaining the card and the PIN from the true owner. I will not underestimate just how difficult this is, but other that the true owner finding the card missing and reporting it, there are very few checks and balances.

Now let’s consider what you currently have to do to buy something online, and everything a mobile phone COULD be doing to provide security. Traditionally:

  1. To create a new account with most e-commerce retailers, you just need a valid email address – May or may not require confirmation from email address used.
  2. To add a payment card you need a valid billing address, and a mobile phone number – May or may not be validated in the back-end.
  3. To make a purchase, you log into your account, choose your stuff, then go to the checkout. You select the saved payment card you wish to use, then enter your CVV2 code and / or your 3-D Secure password.

All of this is far easier to fake / bypass than in card present environments, hence the higher rates of fraud.

Now, imagine a scenario where you have registered your mobile phone and tied it to the payment card in question. At your disposal you have all of these available to you;

  1. PIN / Password – the most ubiquitous form of authentication on the planet, and while it’s not the best, it most certainly adds a significant layer of complexity for the bad guys.
  2. Fingerprint – If you have an iPhone 5/6 or a later version of Samsung, you have fingerprint biometrics. This facility will only increase as time goes on.
  3. Voice Recognition – Nowhere near as prevalent as fingerprint, but gaining ground.
  4. Retina / Face Recognition – Combine these two because they both use the camera in a very similar way. Not a huge fan of these so far, they are rather ungainly.
  5. Geo-Fencing – a transaction request comes in from a Nigeria-based IP address and your phone is in Wandsworth, is that legit?
  6. Social Media Profiling – Not common at all …yet, but you could choose to add your social media profile to the purchase decision. e.g. you’re a rabid Arsenal (UK folks) / Redskins (US folks) fan, would you really be buying Spurs or Eagles merchandise respectively? Maybe, but I assume only to burn it.
  7. Reputation Profiling – Again, not common, but another growing form of identity management.
  8. Device Profiling – App layouts and such.

…and so on.

The vast majority of these will require an initial set-up and configuration, but will then be largely invisible to the user during use. Innovation without practical use is just a dream, and in this case practical use means that everyone can use it without inconvenience.

Done correctly, the integration of all of these factors during a transaction will take no more effort than a user expends in the normal use of their mobile device, but so far the individual vendors of each service and mobile device are trying to corner the market for themselves.

Digital transactions account for trillions of €/£/$ annually, there is room for everyone in the EVOLUTION (not revolution) of payments from Plastic & PIN to Mobile & Multi-Factor, and disruptive innovation will do nothing but delay the end goal;

Frictionless and ultra-secure mobile payments.

[If you liked this article, please share! Want more like it, subscribe!]

I am in no way against biometrics, they are absolutely intrinsic to the future of non-cash payments and the implementation of true identity management in general. What I’m completely sick of is the “Password is dead, biometrics is here!” hype perpetrated by those with a blatant self-interest.

If the password was dead, we would not have a multi-TRILLION £/$/€ industry currently predicated on the 4 digit PIN; the branded payment card. Organisations up and down the payment card food chain, from the schemes to the end merchants would not be spending billions on the perpetuation of the technology if the password was actually dead.

The payments industry is not trying to reach the < two billion people with biometric-enabled smartphones, they are  trying to reach the SEVEN billion people with money, half of whom have no access whatsoever to formalised banking as we know it, let alone a £400 mobile device.

Yes, there are ongoing fraud issues, and yes there are viable alternatives, but ask the average person on the street if they need mobile payments authorised through some form of biometrics and they will simply ask what’s wrong with their credit card? Too many biometrics companies are trying to change the world without applying common sense to the real issues. They are not solving a problem, they are trying to create a demand.

The challenges the payments industry face are myriad, and include;

  • Enormously complex and expensive infrastructure geared towards current payment methods and protocols – [There’s no starting over from scratch]
  • Global acceptance of current operational standards by all country’s financial authorities – [Requires amendments to most laws and regulation]
  • Older technology that does not port securely onto consumer controlled mobile devices – [You cannot exclude the card brands from this move.]
  • Difficult transition path from legacy infrastructure to new – [Where do you start, and what direction do you go in?]
  • Increasing pressure from retail to provide improved customer journey / experience –[Retail and consumers expect more.]
  • …and so on.

Fraud due to poor authentication is not the problem, it’s an inconvenience, the real problem is that payments are heading from ‘plastic & PIN’ to ‘mobile and multi-factor’ whether we like it or not, and the only practical and secure way of doing so is to do it properly from the beginning. This will be an industry wide effort or it will fail, and no biometrics company on the planet has the answers alone.

Battling fraud is not just about proving that you are the one attempting a transaction, it’s about being able to attribute your entire identity into the desired result. Just because I can prove I’m trying to buy a TV does not mean I have any intention of paying back the loan I took out to get it.

So smart phones have the ability to turn the industry standard Personal Identification Number (PIN) into a Personal Identification Vector (PIV), one that is not only TRULY personal (i.e. fully consumer customisable) but builds in a multitude of other authenticators into each transaction. It is here that biometrics really comes into its own; being able to seamlessly add the something-you-are authentication factor to EXISTING processes.

Biometrics tells us what you are, is does not define WHO you are, and it’s the who-of-you that defines the future of your payment options.

[If you liked this article, please share! Want more like it, subscribe!]

According to Business Insider, approximately $4 TRILLION worth of merchandise will be abandoned in online shopping carts this year, of which only 63% is recoverable for those retailers with the necessary “savvy”.

The reasons behind this abandonment are as myriad as the individuals making the purchases, but to truly understand the root cause, you must examine the people themselves. From an online purchasing perspective, they fall roughly into these 5 categories:

  1. Mind-Changers – People change their minds all the time, which is much easier when you’re online than when you’re face-to-face with a sales rep. The longer the purchase process, the more time retailers are leaving open for this category to have second thoughts;
    o
  2. Distractors – For those who don’t really care about their purchase, the slightest distraction will cause them move on. Long and complicated check-out processes will see these folks following the next shiny thing;
    o
  3. Impatient – Again, long check-out processes will see the impatient group give up fairly quickly even though it means starting again. The issue is that they will undoubtedly start again on a competitor’s site;
    o
  4. Private – Asking a significant number of questions unrelated to the transaction itself, or forcing them to create an account first is not an option for this category.; and
    o
  5. Frustrated – Too many steps and customers become frustrated and lose interest in purchasing the item.

Other reasons include hidden fees, unreasonable shipping & handling cost, loss of bandwidth and a multitude of others, but these are mostly issues with the merchant, not with the buyer.

The simplest and quickest checkout process helps mitigate these all-too-common behavioural flaws. However, it’s just not that easy when both the merchant and their underpinning acquiring bank(s) have responsibilities that go far beyond customer convenience.

Anti-fraud, anti-money laundering, and significant numbers of industry specific regulations mean that sellers must be reasonably sure that the purchaser is who they say they are. Currently this is performed by authentication; payment card details including the Card Verification Value (CVV) etc.

However, as a direct result of increasing online fraud rates banks now require digital shoppers to prove who they are with more than just their card details. For example, 3D Secure was introduced in 2005 to help combat this fraud by adding another layer of authentication, but the oft-quoted “significant abandonment rates” experienced as a direct result have forced many e-commerce retailers to turn the service off during peak seasons (e.g. Christmas), or even cancel the service altogether.

So far the uncertain balance between convenience and security has only been good for the bad guys.

The Holy Grail of digital commerce is a frictionless checkout. This is only possible if the many disparate inputs are seamlessly integrated and made invisible to the consumer. The only device that has a chance to combine all of this into a process that basically mirrors the every-day behaviour of the consumer is the mobile device. It also just happens to be the one thing that can combine many forms of authentication that far exceed every regulation in the industry.

No-one doubts that e-commerce and m-commerce will continue to enjoy enormous growth, but it is only by getting the convenience vs. security balance right that the full potential of these markets can be reached.

Only authentication holds all the cards.

[If you liked this article, please share! Want more like it, subscribe!]

[Ed. Written in collaboration with www.myPINpad.com]