Why, in the face of threats, do we humans either spend an inordinate amount of time blaming others, or insist on patching the symptoms instead of solving the root cause?

  • Target: I had my credit card data stolen, so let me buy millions of dollars of new PEDs
  • ICO: The NHS lost some data, so let’s fine them.
  • Rest of the World: The NSA is reading our emails, so let’s encrypt them.

Every one of these reactions has completely missed the point, and are the definitive closing the barn door after the horse has bolted.

Question: Do you tell your deepest secrets to your loved ones in a very loud voice in the middle of a room crowded with strangers? Or do you wait until you’re alone, and even then talk quietly just in case?

And yet you think you should have privacy on the Internet?  You could not yell any louder than that. Forget your RIGHT to privacy, focus on YOUR ability to KEEP things private.

Even with encryption, who has the best equipment and expertise; you, or the NSA? Or worse; you, or organised crime? They are extremes, so let’s bring it closer to home; you, or your IT admin? How about; you, or your children?

So now, instead of solving the problem, security vendors are going to inundate you with offers to encrypt your data, encrypt your communications, encrypt your very identity, and they will all fail. 2014 should be the Year of Identity Management & Authentication, or to put it more facetiously; The Year of Only You Being You.

Here’s a ridiculously long and complicated analogy of your identity;

Imagine that you are a 1,000 piece puzzle, and when all of the pieces are together, only then can you see the full picture. As the puzzle is broken up and distributed across many hundreds of separate locations, the picture fades from each piece until it’s just plain white. Anyone stealing even a couple of hundred pieces will never be able to re-create you, never know what the picture is, or even where to find the rest of it.

Now, image that access to your most private information was tied to the complete picture, would that not be infinitely better than a username and password, or a 4 digit PIN?

Your true identity, the everything that is you, is made of things that cannot be put into a mechanism for authentication. Yet all we have right now is 3 factors: something you know (password), something you have (physical token), and something you are (biometrics). What about your likes and dislikes? Your future plans? Your everyday interactions?

All of theses things and infinitely more make up your true identity, and until we can come up with a way to get a whole bunch of them into a practical and seamless method of authentication, your data will be at risk, regardless of encryption. Yes, encryption may add a layer of security, somewhat akin to building your fence higher than your neighbours, but any commercial encryption product that will be pushed for home PC or mobile users will be practically useless.

Instead, privacy will come from the exact same source as identity managements’ will; very wide distribution of data with extremely limited ability to piece it all together. Some may disagree with my previous blog on the benefits of ‘profiling’, but you cannot have a robust identity without it. Bitcoin has proved that you do not need single databases/sources of storage for this stuff, the interconnectivity of the Internet’s individual systems can provide that with the right front end.

So, bottom line; don’t waste your money on expensive encryption solutions unless those solutions are performing the above distribution (bitcloud for example), but then it’s not encryption as we know it, it’s the next generation of privacy.

Just about everyone who writes on information security has had ample blodder from the Target / Neiman Marcus et al breaches, myself included. Some blame the PCI standards or the card brands themselves, some blame the retailers for not doing enough, and those that are a little more charitable, just blame the thieves.

In the end, it’s not about blame, it’s about learning the lesson, making the necessary adjustments, and moving on responsibly. Unfortunately, this will NOT include being able to move on from credit cards or from the PCI DSS v3.0 any time soon, so organisations wanting to avoid becoming the next Target (excuse the pun), had better pay more attention to their enterprise-wide security program, not just their annual compliance ‘projects’.

Just as importantly, they need to pay VERY close attention to innovation in the payment / authentication space, and advances in more real-time security measures / technologies.

Nothing in the PCI DSS is anything other than a bare minimum, and represents enough security for the card brands to say they are doing what they can. But any organisation who thinks this is enough will eventually lose data, and I for one have no sympathy.

You can look at every single requirement and come up with two choices: 1) Good enough for PCI, and 2) Appropriate for the business. 9 times out of 10, the second option is more difficult to implement, but in almost every instance, it is both easier to maintain, and more secure.

For example;

PCI DSS Requirements 1.X are all about networking, firewalls, segmentation and the like, and while it does stress that every service/protocol/port must have a business justification, it does not state specifically that every individual in-scope device must have least-privilege inbound and outbound rules applied.

  1. 1.1.6.a – Verify that firewall and router configuration standards include a documented list of all services, protocols and ports, including business justification for each
  2. 1.2.1.a – Examine firewall and router configuration standards to verify that they identify inbound and outbound traffic necessary for the cardholder data environment.
  3. 1.2.1.b – Examine firewall and router configurations to verify that inbound and outbound traffic is limited to that which is necessary for the cardholder data environment.

Yes, we can imply it means each device (especially 1.2.1.b), and yes, it’s the right thing to do, but no QSA can enforce anything that is not specifically written within the standard. If they had just replaced “the cardholder data environment” with “each in-scope system” DSS Section 1 would be VERY different, and instil a significantly better security posture.

However, if they DID change it to least privilege for every device, is it actually possible to implement and maintain it? Same goes for more robust configuration standards (DSS Section 2), or real-time logging (DSS Section 10), what should be done is very different from what the DSS requires.

In answer to the question, yes, it is possible, and it all boils down to one thing; baselines

Security is not about crunching big data to determine patterns, that’s only truly relevant in forensics when it’s already too late. Real security is knowing exactly what something SHOULD look like performing normally, and reporting everything outside of that. Keep it simple, or it cannot be monitored, maintained, or measured, but the PCI DSS can never go this far.

Hypothetical: If you knew every running service, listening port, and permitted connections each in-scope device should maintain to perform its function, then anything NOT those things should be investigated. That’s a baseline. Security would dictate that you have alerts based on these anomalies for all systems, not a sample of them and certainly not once a year (point-in-time).

How difficult would it be to automate this process so that EVERY system (not just PCI ones) reports back on a daily/weekly/monthly – or ANY period of time less tun a year! – basis to a centralised management console to perform the baseline comparisons? Then what’s to stop you comparing the device’s listening ports to firewall rule sets to make sure they are properly defined? Or comparing them against enterprise policies and standards, or known business data flows?

Not one organisation or security vendor is doing this properly, at least not that I have seen, or not yet. Some vendors do bits of this, but the last thing you want to do is patch together a bunch of separate, non-integrated systems, as the effort to do so will usually outweigh the risk mitigation, or the cost-to-benefit ratio.

However, none of this can happen until you have centralised and accurate asset management, and seeing as the PCI DSS just added that as a requirement in v3.0, most organisations have a long way to go before they can ever achieve this ultimate in security; continuous compliance validation.

First, any discussion on ‘mobile payments’ needs to start with a explanation of what I mean by it. There are many definitions and types of mobile payment; anything from SMS, to direct mobile, to mobile web, and from NFC to QR can all be labeled a ‘mobile payment’.

However, from my perspective, there are really only two main categories of mobile payment:

1. A mobile device is used in authenticating the individual making the payment, the transaction happens in the background (e.g. e-wallets), and;

2. An application on the mobile device passes the sensitive payment details (e.g. paying with credit card through a web browser)

Clearly 1. is better than 2., as mobile phones will probably never be as secure as we’d like them to be.

Second, I think it must be understood that ‘payments’ in general is NOT about the payment itself, that’s just detail, it’s about the authentication of the individual making the payment. Whether you have a checking account, a line of credit, an e-wallet, etc. as your source of funds, you don’t care how you get to it as long as doing so is safe, convenient, widely available, and value for money.

However, safety and convenience have always been, and will always be, a balance of mutual exclusivity. In other words, the more you have of one, the less you have of the other.

The reasons mobile payments are nowhere near as ubiquitous as credit cards […yet], are myriad and include;

1. Credit cards are familiar to, and used by, a large chunk of the planet. There are approximately 7bn of them out there and they have been around for over 60 years

2. They are very widespread, and the use of them is a well establish process

3. Smartphone use is not as great in some regions as it is in the US / Europe, significantly limiting the available payments functionally

4. Large retail have not adopted them significantly, and the card brands are making things difficult

5. People just don’t trust them yet, and they are more complicated for the ageing portions of our population

However, this will not stop the trend, and these two ‘statistics’ pretty much say it all;

1. The average time it takes to realise you’ve lost a credit card is 11 days, the average time it takes to realise you’ve lost you mobile phone is 4.5 MINUTES.

2. By the end of 2014, there will be more mobile phones in use than there are people on the planet (>7bn).

Unfortunately  the transition of the non-cash payments ecosystem to mobile will be from credit cards, which requires the support of the card brands, who, for obvious reasons, are loathe to provide it. Both the PCI DSS and the PA DSS standards stifle innovation by making any form of compliance for mobile payments on Cat 3 mobile devices (phones, tablets etc.) exceedingly difficult, and in some cases, impossible.

I have to assume that once the card brands are ready to roll-out their OWN mobile payment infrastructures, the transition will happen much faster. This must involve alternatives to EMV, and any solution must be scalable, and future-proofed, so they’ll need a couple more years to get themselves sorted.

The card brands employ a lot of VERY smart people, and I have to further assume that there are entire departments dedicated to digging them out of the hole they have spent decades creating. From the physical infrastructure (PEDs, back-end servers, credit cards etc.) to sector dependencies (PSPs, acquirers, service providers etc.)  the credit card payment ecosystem is enormous, and enormously complicated. The transition of plastic to mobile will take a long time, but I think the brands have a lot to offer in the space if they decide to play fair.

In the end, mobile applications will rule the day, at least until the next thing comes along. It most certainly won’t take 60 years like the cards-to-mobile transition – and I suspect will involve some sort of implant – but entire fortunes are there for the taking in this space. The functionality, convenience, and yes, even the safety of mobile applications mean that they will be the next big thing. Competition will be massive, which can only benefit the most important factor; the consumer.

[It’s clear that this topic has wayyyy too much material for just a blog, so at some point I’ll back this up with a white paper or some such. Please accept this as an amuse-bouche];

Today, the savvy buyer does their homework on all major retail expenses, ensures they have they the funds for it (debit or credit), and finds the best deal BEFORE buying.

The non-savvy, or impulse buyer, tends to get hosed, which may result in several things; the buyer either changes their minds and returns the item (and/or gets into financial difficulty), the merchant has a second-hand system to get rid of AND has the hassle of a charge-back, and the financial institution behind the payment runs the risk of non-repayment of the resulting bad debt.

While you’re never going to get away from consumers making bad decisions, you CAN make level the playing field, and make the experience for all parties less risky, more efficient, and potentially cheaper all round.

Two of the challenges we face today are:

  1. The vast majority of new businesses in the payments space are innovators, and have a very narrow focus. i.e. see a need, fill a need from a niche perspective. So if you’re looking around for those types of services, you have hundreds of small organisations from which to choose, and you either gamble, or wait until the market settles down and risk missing out entirely on a potential competitive edge.
    o
  2. Every player in the payments ecosystem is either a dependent, or in competition, leaving everyone worse off, especially the consumer. You just have to look at the number of e-wallets, coupons, or loyalty point systems to see that 99% of them are unsustainable. The corollary is that new innovations in the retail space are very slow to be adopted, if at all.

So how do you choose the right combination of payment services for YOUR business?

Choose the right one(s) and the benefits are clear and ongoing, choose the wrong one(s) and you’ve potentially damaged your brand reputation. How many times have you collected loyalty points (for example), and never had the opportunity to enjoy the benefits?

The biggest issue the payments ecosystem faces it that the true cost of an expense if rarely apparent up front, and your payment options are limited to the offers of either your existing financial institutions, or of the retailers themselves.  Instead, what if the banks made available enough information at the time of purchase for you to choose the RIGHT payment option?

Bob Mackman wrote a short white paper How to Pay: The Future for Mobile in m-Commerce, in which he posits that for a mobile application to;

…weigh up the advantages of each [payment method] by looking at things such as: available credit, due date, interest rates and any loyalty schemes and give them the pros and cons of each for this particular purchase at this moment in time. Perhaps putting them into an order of preference.

…that the background financial institutions would first need to provide;

“…direct access to the information from the bank and card accounts being used. If the providers made API’s available for even just some basic transactions then this would be possible.”

You can imagine how often his happens currently.

But, if the banks could see the amazing potential this provides, then this would not be the “pipe dream of a romantic“, as Bob puts it, but a reality in which anyone NOT providing these services is left behind.

Like most things, it’s not that easy. For this to truly work you have to consider all of the following and many more:

  1. Authentication – ALWAYS the primary consideration in payments
  2. Ratings & Reviews integration – against financial services, retailers, products etc.
  3. Big data analytics and customer profiling resulting in targeted displays / coupons based on instant access to metadata of preferences (e.g. material / colour / designer)
  4. Existing payment technologies – PEDs, EMV, NFC, e-wallets and so on…
  5. New[er] payment technologies – Bluetooth beaconing, geolocation, bio-metrics and so on…
  6. Payment choices / instant credit through existing financial institutions (which has dependencies on single purchase interest rates and unaffected credit ratings etc.)

So who’s going to be able to put this all together? No-one currently, but in much the same way that the enormous growth of telecoms options resulting in a spin-off industry of consultants providing consolidation / savings services, the soon to be exponential growth of payment technologies will spurn a new breed of consultant; the payments Service Provider Integrator (SPI).

From banks, to payment gateways, to ratings & reviews, to loyalty, to anti-fraud, the SPI will be able to seamlessly integrate all the niche providers into a whole-istic solution designed to meet an organisations goals.

Here I must stop, but this will continue in more detail in the pending white paper.

If you have any ideas around this stuff, please share, I’ll make sure to build it in.

 

Anyone who has read my blogs knows that I am very critical of credit cards and EMV as payment technologies. I am also equally critical of the card brands themselves for attempting to spread their use when there are so many other more convenient, safer, cheaper , and future-proofed options out there. With mobile applications, e-wallets, and whatever comes next, the piece of plastic with which we are all so familiar will die in its current form.

Then two products come along and I find myself having to adjust my thinking …somewhat. I still think the card brands are wrong, but I have reached my own internal compromise based on one difficult truth; I have become so enamoured with innovation, that I have lost touch with the only question that’s relevant;

Is it functional?

To me, there is no innovation without practical application, and no function without benefit and use. In other words, innovation is great, but if it’s not adopted, AND makes things better, it’s just a fad.

The two products that caused this revelation are pinCode and Coin:

pinCode is an awesome little product that covers a gamut of authentication mechanisms in a credit card sized token, and Coin allows you to load multiple credit / debit cards on – you guessed it – a credit card sized token.

Each has a fundamental flaw; pinCode cannot replace multiple cards, Coin does not authenticate payments.

Now imagine if you could combine the two.

You would no longer need multiple pieces of plastic you would have just one. Whether you load your credit cards, debit cards, branded, non-branded, or any other form of electronic payment information, it would now all be in one place, with authentication mechanisms built in that would cover every provider.  No more chip and PIN, pinCode takes care of that, and no more thick wallets, Coin takes care of that.

Added benefits;

  1. The bluetooth technology in Coin could be adapted for non-NFC contactless payments, as well as its existing security feature of alerting you if the card is more than x feet away
    o
  2. Backwards compatibility with magnetic stripe only terminals, but each bank could add authentication mechanisms with the pinCode functionality
    o
  3. Continued use of existing credit accounts, but now without the need to issue credit cards. The information contained on a credit card magnetic stripe or the EMV integrated circuit (IC) can just as easily be sent or downloaded as long as the authentication is sound
    o
  4. Chip and PIN would be unnecessary globally. Therefore no requirement for expensive payment terminals, leading to a massive expansion of payment technology to emerging markets / micro-merchants
    o
  5. Every bank can be its own payments scheme and neither the cards, payment terminals, or back-end systems are tied to any particular card brand or region
    o
  6. Your ‘credit card’ can now be used for multiple authentication requirements; from a physical security pass, to 2 factor authentication, to call centre mutual authentication
    o
  7. Carrying a ‘spare’ credit card is now so much simpler. As a frequent traveller, I not only have a spare credit card, I have FOUR spare credit cards just in case (Visa Credit, Visa Debit, MasterCard, Amex). Being able to replace all the credit cards with a vastly improved one, as well as not having to worry about it being stolen makes me drool

However, and back to my original point, this MAY end up prolonging the life of the card brands, but even I can’t deny that there are literally hundreds of millions of people who are already used to carrying little pieces of plastic. As long as this ‘interim innovation’ can instil more security, greater functionality, and perhaps a little more competition, then so be it.

Mobile applications and smartphones will rule the day eventually, and the combination described above will actually begin the process of educating people that electronic payments and phones will no longer be as separate as they are now.

This is the perfect gap-filler between present and future, and it all points back to where it began; authentication.