Each day we are bombarded with headlines about successful attacks against mobile payments and the massive rise in mobile payments fraud in general. Yet none of this should be a surprise, and the reasons are simple.

First, we need to understand that the reason we read so much about the losses in the press is that negativity is often the only thing that makes the news. When was the last time you saw the headline; “Mobile Applications Work, Hackers Thwarted!”

The fact remains that for every transaction lost, thousands or even millions of transactions work just fine. However, this sells neither newspapers nor security products.

That said, mobile applications are notoriously insecure. Some of the weaknesses are entirely avoidable and others will be resolved only with a significant shift in both payment methods and the capability of authentication and identity mechanisms.

Avoidable challenges include:

  1. Poor Business Needs Analysis: Too many Fintech organisations follow the latest trends and buzz-phrases without performing both a proper business needs analysis and its subsequent risk assessment. The implementation of every new process or function must meet established business goals, and not be a result of competitive fear or a CEO’s desire for shiny things and ‘game changers’.
    o
  2. Swiss Army Approach: The second symptom of poorly defined business needs is the desire to build in as much functionality as possible, hoping that the ‘feature rich’ app will become some kind of de facto standard. The vulnerabilities in an application are directly proportional to the complexity of it, and simple is almost always better.
    o
  3. Insecure Coding: Often a follow-on from 1., if the business needs aren’t properly defined, it’s unlikely that the application’s function(s) will be either. When the race to market is the number one priority, things like robust software development life cycles and secure coding techniques tend to fall by the wayside.
    o
  4. Acceptance of Payment Details: The ‘more’ secure mobile payment apps never actually touch the payment details. However, it’s still very common for apps to accept full cardholder data (credit card number, etc.) through the app itself. The better apps will only process a transaction when an e-wallet or equivalent is available in the back-end.

Unavoidable challenges include:

  1. Older Payment Technologies: There’s no getting away from this one any time soon, we have had these technologies for decades and they will be around for a while longer. The only thing to be done is to ease the transition from these technologies into the innovations of the present slowly and securely. There is little room for total disruption in the payments space.
    o
  2. Inadequate Authentication of Identity: Last, but certainly not least, Identity Management and Authentication represents not only the limiting factor in almost all current mobile payment methods, but holds the key to supporting everything to come. There is no silver bullet, no single-function remedy, the only way to resolve this challenge is to build as many authentication factors into every transaction as possible, ideally without creating friction in the payment process.

Secure authentication of identity is the key to reducing mobile fraud, but no solution will be accepted that gets in the way of people actually using it. Only by ‘bridging’ the established with the new, implementing new technologies seamlessly behind/alongside old ones, and making room for everything to come can we stay ahead of the thieves.

[Ed. Written in collaboration with www.myPINpad.com]

The time will come when you will be able to walk into any shop, chose what you want, pay for it where you are standing, and walk out with it without having to go through the nonsense of lining up. The same will apply to getting through airport security/immigration, into a concert, onto public transportation and so on. Each of these ‘transactions’ will happen in the background.

The time will also come when whom you are is enough to make all of these transactions happen almost seamlessly, and biometrics will be an enormous part of that. However, WHAT you are does not equal WHO you are, and that’s where biometrics vendors miss the point. No form of static authentication (of which biometrics is one, same as passwords) can encompass your entire identity. Your likes, dislikes, hopes, fears, ambitions, friends & family interactions, even your reputation. The things that make you human, and 100% unique.

Also, what biometrics cannot do is replace every other form of authentication in the near term. Certainly not the authentication of payments for example when you consider that all payment card schemes globally are united behind the PIN.

“But that’s already happening!” you may say, and you’re right, you can authenticate payments with a fingerprint via your mobile device (Apple Pay for example). Then again, I can spend £20 (£30 from this September) at a time with my Visa / MasterCard contactless card with typically no authentication at all.

Ultimately, what we’re trying to get to is the universal demonstration of the one thing upon which all the transactions above rely; trust.

No single form of authentication (biometrics included) is going to get you a car loan, or a mortgage, but it WILL get you a cup of coffee, because authentication is just a sub-set of the overarching principle related to the demonstration of trust; Identity Management. The who you are, or more to the point, who you have been, is what gets you the mortgage, all your face is going to do is give the lender reasonable assurance that they are talking to the right person.

Authentication is not the answer that addresses the trust challenges we face today in a distributed world. Trust is not built on how you authenticate, it’s built on a irrefutable representation of your life; your credit history, criminal record, work history, references, social media profile, public statements of opinion (blogs, etc.) and so on. You are not going to place trust in someone you will likely never meet in person until you are reasonably satisfied that they will keep their end of the bargain.

Even multi-factor authentication is only going to give more certainty that the person you’re dealing with is the person you expect, it does nothing to ensure that your transaction will go as planned. Only identity can give you that kind of assurance.

Every transaction in the future will be a combination of identity management and authentication, and how much you need of each will be agreed by both sides, up front. This is a complete departure from today where trust is mostly one way, and should address the majority of the current challenges we have related to fraud.

[Ed. Written in collaboration with www.myPINpad.com]

Demand generation is defined as; “The focus of targeted marketing programs to drive awareness and interest in a company’s products and/or services.”

Done responsibly it can be a very effective tool in any organisation’s marketing/PR tool-set, and I applaud anyone doing it well. Done irresponsibly it can lead target organisations to make very poor decisions that they will end up bitterly regretting. Yes, each organisation is responsible for making their choices, and for performing proper due diligence, but in an industry as complex as payments, vendors are often seen as the experts.

This position must NEVER be abused!

The example of demand generation that I invariably use is that of the smartphone. Until I saw one I had no idea I needed so much functionality in a mobile device. Now, quite literally, I cannot do my job without it.

Off the bat, that suggests 3 things:

  1. Smartphone manufacturers were justified in their aggressive marketing efforts …eventually;
  2. The drive by each vendor to win the entire market for themselves, while promoting competition, has left us with an enormous variety of devices and technologies that are difficult to adopt for fear of backing the wrong horse, and;
  3. I’m not smart enough to be a futurist.

But what if they had worked together on standardisation in the beginning (like with bloody power adapters for example!), how much better off would we be?!

Now biometrics vendors are the vultures over the kill, and the password is the corpse (harsh I know, but the alternative is wolves, but they work in unison for the good of the pack).

Biometrics companies are spending vast sums on marketing and PR resources to become the next big thing in authentication, All the while completely ignoring the fact that they are offering something little different (single-factor, static authentication), and side-stepping the most basic of practicalities; ease of adoption, and future-proofing.

The FACT remains that implementation of effective biometrics is extremely difficult. Distribution, false positive rates, disability support, privacy issues and a plethora of other challenges will continue to ensure that single-factor authentication with biometrics will not replace the 4 digit cardholder PIN any time soon. Nor should it.

It’s not about replacing the PIN, it’s about seamlessly combining the PIN with other forms / factors of authentication like biometrics. Anything else is irresponsible in the extreme given that most smart phones are capable of all 3 authentication factors multiple times each! Passphrase, PIN, fingerprint, voice recognition, iris, geo-fencing, device registration, device profiling, social media profiling you name it, can all be entered into a mobile device through normal and already established consumer use.

The following is not necessarily an endorsement of Fast Identity Online (FIDO) Alliance, but you can see from their Mission that they fully appreciated the importance of evolutionary change, not revolutionary change:

“The Mission of the FIDO Alliance is to change the nature of online authentication by:

  • Developing technical specifications that define an open, scalable, interoperable set of mechanisms that reduce the reliance on passwords to authenticate users.
  • Operating industry programs to help ensure successful worldwide adoption of the Specifications.
  • Submitting mature technical Specification(s) to recognized standards development organization(s) for formal standardization.”

Reliance on single factor authentication with biometrics is a mistake, so avoid any organisation who adopts the ‘password is dead’ stance and just do your homework based on a business need, not a buzz-phrase.

An almost 50 year old concept is now all the rage in the payments space; disintermediation, which according to Wikipedia is; “…the removal of intermediaries in a supply chain, or “cutting out the middlemen.

It might be a cliché, and I hate any buzz-phrase not invented by me, but in the payments space this one makes perfect sense.

For example, to make a branded card payment you have not one, but several middlemen, all of whom add cost to the overall price of the goods you buy;

1. Terminal Manufacturers – those devices you slide / swipe your card into are a cost, If they are PTS and SRED compliant, a significant cost. Target, for example, spent $100 MILLION to replace theirs after their well publicised breach.

2. Acquiring Banks – The bank who authorises the payment charges roughly 0.02% of the total value of each transaction.

3. Issuing Banks – The institution who issued the card itself charges the lion’s share at a very rough average of 1.7% of the transaction value.

4. Card Schemes – The brands (Visa, MasterCard etc.) vary in the slice they take, but for the sake of argument, let’s say it’s around 0.1% of the transaction value.

5. Your Bank (in general) – May or may not charge you for the ‘privilege’ of having a card, mine does, but let’s ignore this for now.

According to statista.com the volume of credit card transactions in  2012 was around $6,000,000,000,000 (or 6 TRILLION USD), so let’s put that into perspective:

Terminal Manufactures – I cannot even begin to guess how many payment terminals there are worldwide. But I’m going to put my reputation on the line and say it’s a lot. Manufacturers have also received a very significant boost in the last year or so with the enforcement of EMV on our US brethren. For the sake of this blog, we’ll just assume many millions are spent by retail merchants on these devices.

Acquiring Banks – 0.2% of $6 trillion is $12 billion.

Issuing Banks – 1.7% of $6 trillion is $105 billion.

Card Schemes – 0.1% of $6 trillion is $6 billion.

In other words, the cost associated of using credit cards exceeds 120 billion USD!

This is actually not meant as a criticism. They provide a service, many services in fact (including paying for the inevitable fraud), and we are all very likely utilising the benefits of the non-cash services on a daily basis. My point is that we ALREADY have the ability to remove the majority of these middlemen sitting in our pockets; our mobile phones.

Your bank wants to be paid for storing, protecting, and providing access to your worth. The phone company wants to be paid for providing the bandwidth to get to your worth. That’s fair, but why should anyone else be paid? It certainly isn’t the retail merchant who’s absorbing the middleman costs, it’s us, the end consumer. And it’s about time we start demanding more options.

The disintermediation of the non-cash payments systems will be a slow process of disruptive innovation. One side will try desperately to hold on to what they have, and the other side is trying to move too fast to change everything. BOTH sides need to understand that things WILL change, but can only do so when the replacement mechanisms are truly fit for purpose. We simply aren’t there yet.

Card Schemes need time to turn their enormous ships onto a new course; banks need to take over the fraud loss liabilities; and biometrics companies need to shut the hell up about the death of password and the ridiculousness of their single factor solutions. Most of all, the consumers need to ask for something they don’t even know they need yet.

So yes, disintermediation in payments is coming, but likely not any time soon. Even with PSD2.

[If you liked this article, please share! Want more like it, subscribe!]

In a recent post (Digital Anarchy? Not Without Identity Management) I posited that eventually Identity Management would consist of a construct of your entire life. From the beginning, all the way through your to your present day, and continuing without pause until the end. The premise is that the more that is known about you, the harder it becomes to pretend to be you. Most fraud mechanisms work on making value judgements related to ‘normal’ behaviour, so why don’t we help that process along?

Privacy and profiling issues aside of course! 🙂

So it occurred to me that if all potential employers knew exactly what I believed in, and – assuming they agreed with me – how I could provide benefit to their organisation, then a CV is almost unnecessary.

LinkedIn already provides the factual information about my previous employment, and as much detail regarding my functions / achievements as I deem fit to share. Employers can do a background check based on my online presence long before approaching me directly. So add a blog on top of that, and what else could they possibly need to make a decision regarding next steps?

References? Background Investigations? Yes, but these are final steps, as the only purpose a CV serves is to get you that first interview. As such, it is VERY hit and miss, and a shining gem of a CV to one HR pro is a not-so-polished turd to another. In the end, HR are not even your final audience, but every candidate is expected to know all about writing CVs and cover letters, as well as interview techniques and etiquette. All you end up doing is filtering out the worst candidates, not narrowing down the best.

A blog, on the other hand, shows many things, all of which have good and bad elements depending on your point of view:

  1. Communication Skills – Writing is not easy, and even doing an average job of it takes a level of skill. If you cannot get your point across in 500 – 1000 words, AND in a way that the majority can understand, you either need to work on your writing skills, your knowledge of the subject, or both.
    o
  2. Subject Matter Expertise – Blogs on specific subjects should be written by people who have relatively significant experience in their chosen profession. But that does not mean they are alway right. A blog from a ‘security expert’ with whom I vehemently disagree will be dismissed just as quickly as would a blog on intelligent design.
    0
  3. Desire to Help – While my blog [for example] was initially started because my wife told me to, it soon became an integral part of my weekly tasking. The skill-set I have (such as it is) does no good to anyone until everyone can follow the guidance I am trying to impart. Security expertise [for example] is NOT something that should be used just as a competitive advantage. There is plenty of opportunity to make a living while giving as much as you can back.
    o
  4. Thought Leadership …Or Not – One of the fastest growing buzz-phrases / clichés, but the concept is sound; Are you a person who creates the new, improves the old, or sustains the present? All of these things have their place, any one of them is not necessarily better than the others, but you need to know which you are, and so do your potential employers.
    o
  5. Skin In The Game – A phrase I’m borrowing from our American friends, it means that you are actually taking part in something, and not just sitting on the sidelines watching. Good if you’re contributing positively, bad if you’re an idiot.

Anything that fights against “But we’ve always done it this way!” is to me a good thing, and that’s where a blog really comes into its own. All of your ideas, concepts, or even random thoughts need to be put down into words that others can follow, which mean YOU have to clarify them first. Ideas catch on, but only the ideas that see the light of day.

For good or bad my blog is now my CV, let’s see how it pans out! 🙂

[If you liked this article, please share! Want more like it, subscribe!]