So Apple have finally adopted NFC, huh?  Big deal, Samsung have partnered with Visa and MasterCard to promote NFC for over a year, and included NFC chips in their devices long before that.

Apple’s wallet provides you options to choose which credit card you want to use. CREDIT CARD?! REALLY?! How is that innovation in payments?! The whole point of mobile payments is that you don’t need a branded card to make a payment, at least it should be the point!

Payments has been, and will always be, just an exchange of stored value for a service or product whose value is, in turn, entirely arbitrary. e.g. I work for an entire week for a value I have agreed with my employer, and I am now going to buy a designer suit for the same ‘price’. The fact that the suit was made for a fraction of the ‘cost’ I paid for it is why its value is arbitrary; because regardless of the price, I agreed to it.

So what have Apple done differently? You can now authenticate the payment with your fingerprint. Seriously? People barely trust the fingerprint to log into their phones, let alone authenticate a payment. And seeing as the value of the contactless transaction is set below £20 (for the UK) and authentication is not required at ALL, why would you add an extra step?

I can tell you now that the credit card brands will not accept biometrics any time soon to replace EMV for higher transaction values when even software PIN (as opposed to hardware) is still rejected. Couple the fact that Apple’s global market share for phones is less than 12%, with the US being their only viable new market (who love their credit cards), and you have a completely empty offering.

But, you may say, Apple has 800 million iTunes users! Irrelevant, because there are nowhere near 800 million iPhones in use. From their initial inception way back in 2007, Apple sold their 500 millionth iPhones in June 2014. That’s total sales, all models, in seven years. Estimates suggest that there are less than 300 million in use globally, compared to a total of 1.75 billion smartphones.

On top of Apple’s minimal – and shrinking – market share, the transition of credit card payments to direct bank account payments through a mobile device has, through necessity, started small. Security is absolutely an issue, which is why the back-end wallets generally consist of credit cards, which handle the fraud / loss liability. With your bank account, it’s YOUR money, and the banks have yet to accept the liability for loss though mobile apps. When they do, the card brands will have no benefit and the transition to mobile will accelerate.

So why DON’T the banks provide this function themselves? Because they make money from credit cards, plain and simple, and it will be a tough sell to charge the fees they do now when accessing your own funds, even if they do provide a ‘fraud resistant’ service. Besides, the money from credit cards is not from the cards themselves, it’s on the interest you pay for your LINE of credit, so the poor banks can still make their squillions. That’s a relief.

Besides, people take their phones for granted, just as they do water coming out of the tap (I know, 1st world problems), and people simply do not see the issue with continuing to use plastic, so how will the mass adoption of mobile payments really take off? Simple; value-add services and guaranteed security.

Value-Add Services: Retailers are the only ones who can make this happen, not phone companies, not card brands, and certainly not the banks. For retailers to make the enormous investment required to change from a credit card infrastructure to mobile / hybrid there needs to be a clear positive effect on the bottom line. Unfortunately, with the ridiculous number of choices related to loyalty schemes, instant coupons, e-wallets and so on, no retailer knows which to back.

Guaranteed Security: The reason credit cards still eclipse mobile payments is because if you use a credit card you are not liable for fraud, the issuer is. The so-called liability shift. If you take out this middle-man, who accepts the risk? The retailers? The bank? The mobile app service providers? Someone has to, because you can be damned sure it won’t be the consumer.

Which brings us to only relevant thing to come out of Apple’s announcement; NFC is now the technology of choice. All we need now is the consolidation of every other service, someone to accept the inevitable losses, and mobile payments can come into its own.

Yeah. Right.

I don’t think anyone in the payments arena has any doubt that credit/debit cards, in their current form, will die over time in favour of mobile devices. It’s a natural next step to replace something ubiquitous with something even more ubiquitous.

So where does that leave the SSC, and the card schemes themselves for that matter?

You only have to look at Visa Europe’s website Visa Vision to see that they are moving towards mobile (and other innovations), and articles like The Revolution is Here, do not even mention EMV, and the only reference to plastic is in a future past-tense.

It also begs the question as to why the card schemes are pushing EMV when they themselves see an end to their reign-of-plastic. But the answer is obvious, the cost of fraud over the next 5 – 10 years far outweighs the cost of the transition. The US alone saw $7.1B in credit card fraud in 2013 (according to Business Insider), and I have estimated that the cost of EMV transition in the US is ‘only’ $12B (Why the US Will Not Adopt EMV (Chip & PIN), EMV in the US, a 12 BILLION Dollar Mistake).

So why am I so anti-EMV? Because there are technologies NOW that can replace it, are in more hands, and more widely distributed than cards ever were. Your mobile phones.

So back to my point; what WILL the cards brands and the SSC do once the plastic dies? Clearly the brands have an enormous leg-up on any new player in the cashless game, and have massive amounts of capital to invest in meeting every aspect of this [so-called] disruptive innovation; research on innovation, testing proofs-of-concept, garnering adoption within the finance community, and of course, rolling it out to end users.

Mobile phone companies made a small play, and missed, banks could have done it, and didn’t, and large retail could have had a huge impact, and haven’t. Probably because in these three case – even banks – payments is not a core function. Being PAID is core, making the payment is not, so only the card schemes have payments as their entire reason-to-be, and therefore the most motivation.

OK, so if we assume that the card schemes are going to make a huge play in every cashless payment innovation from this point forward, where does that leave the SSC? Probably in exactly the same place, with only one change in title; From Payment Card Industry Security Standards Council, to Payment Industry Security Standards Council.

Regardless of the form of payment there HAS to be a security standard around the protection of the data. Not that the current standards are anywhere near adequate, even for cardholder data, but the SSC has significant experience adopting and implementing standards globally. From mobile apps, to software PINs, to identity management (for KYC, AML etc.) to crypto-currencies, everyone developing technologies must adhere to a minimum set of protective baselines.

So am I really proposing, after so many less-than-positive blogs related to the PCI DSS and the SSC, that they be a standards body for every form of payment globally? Well, no, I’m not, but I think that if they don’t TRY to be just that (with the card brand’s backing), there is no-where else for them to go.

Despite my voluble criticisms of the card brands and the SSC alike, they ARE well placed to do good. I hope they take the opportunity now, because it won’t come again.

[If you liked this article, please share! Want more like it, subscribe!]

I read a rather long but very interesting article the other day (thank you nephew) titled ‘The Coming Digital Anarchy‘ by Matthew Sparkes (Telegraph). Despite the rather dramatic title (I have done this egregiously myself from time to time), the concept regarding the future of ‘blockchains’ is sound, and is a far better researched and a far more encompassing version of my earlier article ‘On The Irrelevance of Money‘.

However, with the exception of one fairly cryptic phrase; “In [his] version of the future, identity and reputation will be the new currency.” the means by which this new order will be usable has not been addressed. Nor have I seen it addressed in any other articles of its ilk.

Regardless of the manner in which our data is stored, either the current file/database method, or the de-centralised / distributed method of blockchains (written for the crypto currency Bitcoin, but has much wider implications), we, the owners of the data, need to access its function securely, and put it to use in any scenario we choose.

If you can assume for the sake of argument, that the concept of the block chain is a valid method of storing and securing data, how can we access the data’s benefits in a method that’s equally secure? Your computer, mobile phone, static knowledge (username / password etc.), physical tokens (credit cards, RSA Tokens) are what we use now, and seeing as they are based on current methods of authentication, inherit their flaws. It is a hard enough stretch to get people to accept that their entire ‘Internet Worth’ (trying to coin this phrase) is not maintained by any institution, but to grant access to this without ensuring your identity is protected in the same way goes too far, even for me.

Your identity is all you have that’s truly yours, everything else is a universally agreed representation of value (money for example), so until such times as we can bring our full identity to bear we are reliant on small, and very specific elements of it. Elements that are relatively easy to steal, and duplicate.

It follows therefore, that the more of our identity were can securely distribute, the harder it will be for anyone to pretend they are us. Even in a scenario like Invasion of the Body Snatchers where they completely take over our physical bodies, unless the entirely of my life was instantly at the impostor’s disposal, AND they were able to duplicate my personality precisely, my family and friends would know there was something wrong. And if I’m honest, might actually prefer the new me.

Which brings me to the true value of your identity; Trust. You would not lend a stranger a £1,000 without significant rules in place, but you would think nothing of lending it a family member (assuming they’re not a douche-bag). Why? Because you have a lifetime of trust built up behind you.

How then do we duplicate a lifetime of trust in an electronic form, between two complete strangers? Well, if you’re reading this YOU can’t, probably it’s too late for most of us, but it’s NOT too late for those young enough to begin the process. All we need is the technology.

Oddly enough, I think that block chains provide the answer here too, but I am making a huge assumption based on limited knowledge of how they work. However, from what I know already, they are an ideal medium as their very nature is to record everything that ever happens from the beginning. It just needs to be worked out how to accept the input from everyone with whom the individual comes into contact, and how to represent that in terms of levels of trust. Much like a credit rating, but infinitely more difficult to explain.

In just the last few days Ghash has thrown a huge spanner in the works by controlling the magic ‘51%’ of Bitcoin, thus completely ruining the whole concept of de-centralisation. They have said that we should not worry, and to trust them, but so do the banks. There is clearly a lot of work left to be done.

Until people MUCH smarter than me can work out these issues, and we completely redefine the concept of Privacy (that’s the easy part, right?), this is all theory and speculation, but I cannot see any safer way to get where we are headed. Things change, whether we are ready or not.

Your identity as a baseline is both irrefutable, and cannot be duplicated, but it DOES mean you have to be a decent citizen your whole life or be ostracised. Is that such a bad thing if we have a global consensus on right and wrong?

[If you liked this article, please share! Want more like it, subscribe!]

Everyone loves toys, and IT/IS administrators are no different. However, it’s a very different thing to buy a new PlayStation for yourself, than it is to spend a considerable amount of your company’s money chasing after yet another buzz-phrase or a vendor-induced panic.

Worse than this is to mis-interpret a regulatory compliance standard (like PCI) and spend all your IT budget on technology, when the vast majority of these standards revolve around policy, procedure and standards. Like security should. Behind every security control, in every regulatory standard, is an intent, and until you have examined what that intent entails for your business, you simply have no justification buying anything.

Both IT and IT Security departments have only one purpose; to enable the business’s goals. That’s it. However, it the business’s responsibility to make those goals VERY clear, and fully support IT/IS when required. This does not happen without robust Risk Management process(es) maintained by a Governance Committee of some sort.

In every organisation for whom I have provided security guidance, they had the exact same dynamic; IT/IS massively overestimated their budgetary needs knowing full well the business side will reduce it as much as possible. Usually to point of making a lot of departments ineffective in any way that matters. Then things like PCI come along and suddenly IT/IS departments have ammunition to up their budgets to meet a supposed business requirement.

The smartest managers used this money to do things properly knowing that PCI compliance will fall out the back end of a security program done well. The majority however line up behind the security vendors like sheep buying exactly what PCI says. Every vendor of firewalls, anti-virus, DLP, FIM, IDS and all the other acronyms have made fortunes while the actual security posture in most organisations has barely improved, if at all.

Any consultant worth his/her salt has stopped a client from buying technology until they are satisfied that the client has the necessary processes in place to determine the ACTUAL need, perform a gap analysis, and exhausted all other options. That consultant also had in mind that buying ANY technology comes with a whole series of post-purchase events that must be complete in order to obtain any benefit from that purchase;

  1. Can existing staff actually USE the technology, or does some / all aspects of it’s running require outsourcing?;
  2. Does the product integrate seamlessly with the existing infrastructure management systems?;
  3. Is the increased security posture in-line with its on-going cost of ownership (management metrics)?;
  4. Has any thought been given to the products life cycle and future-proofing?;
  5. Does the product scale with the business?

…and so on.

The ages old (but still completely relevant) concept of Confidentiality, Integrity, and Availability (C.I.A.) ensures that every security program follows the law of negative returns; the more you have of one, the less you have of the others. This is equally true of the complexity of your program; the more complex your program, the less secure you are.

Technology has its place, no arguing that, but only technology in a business context is sustainable.

[If you liked this article, please share! Want more like it, subscribe!]

How much food do you throw away each year because it’s past the expiration date, or worse, you find it in the back of your fridge supporting a new furry ecosystem?

In my ever extending string of blogs based entirely on speculation, I would say that I throw away in the region of £400 – £600 worth per year. And I’m not saying it’s my wife’s fault (certainly not to her face anyway), although she does all the grocery shopping and cooking (don’t worry, it’s not like that, I do pretty much all the cleaning and jar opening). 🙂

There’s actually no blame here, it’s just that way WE are. We are not planners when it comes to our weekly meals, which would alleviate much of this issue. But, like everyone else in our brave new it’s-not-my-fault,-someone-else-should-do-something-about-it society, I want to have this take care of itself, automatically.

We can, and I believe we are not that far off, it just needs to be put together.

First, the actual growers of the produce need to take the first step by ensuring that their shipments are labelled with enough information to begin the countdown process. i.e. from ripe to rotten, we should by now have a pretty good idea how long a lettuce (for example) is going to last. I don’t care if it’s organic (which will clearly reduce its life cycle), with refrigeration, preservatives, and whatever else happens to our food without our knowledge, from farm, to supermarket shelf, to your fridge, to your plate, the lettuce has only x days to live (plus or minus).

Let’s say this is done with a QR tag, and each step in the logistics is added to the embedded information, by the time you scan the code in the supermarket you will have at your fingertips all the information you need to make an informed decision related to your purchase. These lettuces in this box are 2 days newer than those ones, but the older ones are half price and so on. Instant coupons is a given.

I won’t go into the payment method, I’ve written enough on the future of payments, but you will not only have an instant receipt, you have automatically added these items to a database of all the food in your house, along with its weight / quantity, expiration date, and so on.

Now everything edible in your house, from canned goods, to herbs & spices, to meats, to vegetables are all tracked in your database. All you need do now is set your alerts so that ANYTHING that is about to expire becomes an item in your next meal. Of course, you will need to tell this database whether or not you put something in the freezer, the fridge, to left it on the counter, but the smart-fridges or smart-cupboards of the very near future will be able to track this for you by scanning your groceries as you put them away. This will in turn be added to the database so you need never spend half an hour hunting for your Fingers of Fudge.

Not only that, because you have a complete record of everything, you can get immediate help on what to do with it. Every chef in the world will want to sign up to a service whereby they can apply their recipes to what you have available, or more importantly, what is about to expire. Yes, both the chefs and the providers of this service will try to get you to buy additional items to make an amazing meal, but you will always have a choice.

Also, if you DO choose a fancy menu, this can immediately alert your preferred supermarket who can tell you whether to not the items are available, then maybe even deliver them to you.

And we’re still not done. Beyond the immediate benefits of saving a butt-load of money, these are other advantages for every player in the cycle (in no particular order);

  1. You can have your weekly menus designed for you based on your preferences in terms of likes/dislikes, calorific intake, budget and so on.
  2. Growers will eventually be able to track global trends on food purchase, and possibly be able to adjust their supply to the demand.
  3. Supermarkets can automatically alert their customers to deals on soon-to-expire produce a hopefully reduce their waste. Maybe provide free delivery if you purchase enough of these items.
  4. You’ll learn to cook far more meals than you could have ever conceived yourself.
  5. You’ll be able to track your calorie intake if you follow the menus explicitly. Good for dieters, and excellent for diabetics.
  6. By having the ingredients of everything you buy available to you, you can ensure you never buy anything, or accept a recipe for meals that contain something, to which you or a loved one are allergic.
  7. You will undoubtedly stop buying things that sit in your cupboards for years on end, like that can of string beans that seemed like a good idea at the time.
  8. You can make your food database available to your friends so that you can create a meal together without having to buy everything yourself. Dinner party anyone?

I could go on all day, and I’m sure that if you have read this far you have had several ideas of your own.

All we need now is the supermarket chains to buy in …and the growers …and the name brand goods ….and …