This week saw an announcement from the UK Cards Association that the transaction limit on contactless cards had been raised from £20 to £30 to cover the average supermarket spend of £25. This is also in response to the news that the first half of 2015 saw £2.5bn spent on contactless transactions, compared with £2.3bn for the whole of 2014. Apple Pay has followed suit, although some retailers are considering scrapping the limit altogether given the authenticated nature of the transaction.

This remarkable growth is to be welcomed as it demonstrates the willingness of consumers to embrace new payment methods. Contactless is a swift and easy way to make payments and it is clear that consumers are, finally, adopting the technology, albeit mostly with the continued use of ‘plastic’.

Yet, a closer look at the statistics shows that the use of contactless is still limited and far from reaching its full potential. Figures, again from the UK Cards Association, show that the average spend on a contactless transaction is £6.98. Yet, the average debit card purchase in 2014 was £43.45, over SIX times greater!

Contactless is used, by and large, for small purchases. Even before the raising of the transaction limit to £30, the average spend represented just over a third of the transaction limit. Consumers use it to buy their morning coffee and lunchtime sandwich, and while contactless is growing in consumer popularity and  merchant acceptance, there are still significant gaps in capability distribution.

A look at a list of the companies that accept contactless payments is an impressive who’s-who of household names, but with the exception of Waitrose and Marks and Spencer, large supermarkets are noticeable in their absence.

In part, this could be due to the fact that supermarkets are focussed more on securing consumers’ higher value weekly shops rather than smaller baskets on grocery essentials, but not all PED/terminal estates are even capable of accepting contactless. Just about all new terminals are Near Field Communication (NFC) capable, but older models are not. Cost of replacement must be in line with infrastructure end-of-life, not desire for new capability.

Mobile Commerce (or m-commerce) has also added significant complexity to the retailer’s decision-making process. Traditional (and most legacy) terminals are built for purpose; the acceptance of branded payment plastic. The enormous flexibility and functionality of the MUCH cheaper mobile payment acceptance devices can significantly improve the entire consumer shopping journey, something that no retailer can afford to ignore.

Contactless cards don’t require any initial authentication to use them with the exception of mandatory PIN entry after a specified number of uses (usually 5 in the UK). This limits their usefulness to brick & mortar retail as the risk of fraud and chargebacks is fairly significant. With the use of contactless via a consumer mobile device, the number of authentication factors and modes can make contactless payments as secure as chip & PIN.

When consumers have the ability to seamlessly authenticate themselves to make a payment, the limits on how, and how much they spend, are removed.

So, while it is encouraging to see contactless payments become more popular, it is inevitable they will only reach their true potential via consumer mobile devices, and not plastic cards.

[Ed. Written in collaboration with www.myPINpad.com]

…is the appearance of innovation.

Well, it certainly seems that way; Can’t sell services over the Internet? Call them The Cloud. Can’t sell Risk Assessments and Vulnerability Management? Call it Operational Resilience. Can’t sell data management and access control on mobile? Call it BYOD.

When it becomes clear that there is no-where left to go with your existing product or service, the appearance of innovation seems to be the go-to place for institutions staring down the barrel of obsolescence. Instead of working on their customer service, value-adds, or – God forbid – actually improving their offerings, too many organisations resort to smoke and mirrors to stay competitive.

And the worst part? We let them.

The payments sector is perfect target for this blog, especially given the fact that I know little else. Take these two examples from the last few month; There’s a New Way to Pay With a Selfie, and TD, MasterCard and Nymi Pilot Heartbeat-Authenticated Contactless Payments.

Where is the innovation here, we’ve had biometrics for years? The only thing new is the ability to actually bring the biometrics to bear, which is an advance in mobile technology, not payments. The payment itself  hasn’t changed, we’re still stuck with the same primary account number (PAN) being used by the same intermediaries (Acquirer, Issuer & Card Scheme), over the same systems we’ve had for decades. Even if you build in tokenisation with these systems they’re still mapped to a PAN in the back-end somewhere.

If you accept that a payment is just a transfer of value from one place to another, true innovation must involve the complete disintermediation of almost every player in the current ecosystem except the banks. Sure, there can be service provider intermediaries, but they will be providing true benefits to consumers and banks alike in the fields of identity management / authentication, anti-fraud, customer service, loyalty and reward programs, ratings and reviews, big data analytics and host of others services of which I can barely conceive.

To be worthy of the term ‘innovative’, any service or product offering must have the following attributes:

  1. Be of practical use, and not just theoretical
  2. Provide long-lasting benefit to all stakeholders
  3. Cannot knowingly stifle or exclude competition

For payments, there are a few more:

  1. Be available to the largest portion of the population possible (including those with disabilities)
  2. Be frictionless to the average consumer, or better yet, invisible
  3. Maintain appropriate confidentiality, integrity and availability of all underlying sensitive data, to meet – or exceed – all current legislation, regulation and best practices

Not one, or even ALL of these things at once should be too much to ask, but it’s never that simple. There will always be those existing players whose power and position can make some of these requirements all but impossible for newcomers. And the newcomers themselves rarely do themselves any favours; disruptive innovation, competitive advantage, and blatant greed all prevent true innovation from reaching the mainstream.

In payments, like most industry sectors, collaboration is the key to significant and beneficial change, and in a market worth tens of TRILLIONS of £/€/$, I would have thought there was enough to go around.

 

Thanks to Apple Pay, then Samsung Pay, biometrics companies have seen a tremendous surge in consumer interest, to the point where they are now falling over themselves trying to be seen as the authentication standard that replaces the password.

No doubt the numerous breaches that were apparently the result of weak password authentication will have these same companies in a feeding-frenzy of finger-pointing and I-told-you-sos. This is more than a little inappropriate, as biometrics not only has some of the same weaknesses, it adds layers of complexity and risk far above those to which passwords are exposed: at least you can change a password.

If you take 1800s transportation as an analogy, the answer was not to breed faster and stronger horses. You repurposed what you had (including the horses), coordinated a huge array of other industries and innovations, and worked TOGETHER to build something exponentially better.

Authentication now finds itself at a crossroads, and like most things in the Digital Age, there is no one right answer. The only certainty is that it will be the mobile devices that will be at the center of taking payments and authentication innovations to the mainstream. If you can’t put your authentication mechanism on a smartphone it simply won’t be adopted.

One answer which is simple, and brings the benefit of using both passwords (in the form of customer PIN) AND biometrics (in all its forms) is now available. No single factor of authentication is enough, and each one has its strengths and weaknesses. By combining multiple factors, you not only negate the limitations of each, you ensure that security is significantly more robust. The whole, in this case, is much greater than the sum of the parts.

The longer the password is, and the more of them you have, the more difficult it becomes to keep track. But the simpler the password, the easier it is to crack. Biometrics is relatively more convenient, but is prone to false positives, and once known from a physical perspective, can never be changed. So each factor is not ideal by itself, but combining a simple password, like a PIN, with biometrics, device registration and geo-location, presents a much more resilient hurdle.

We believe that poor design can lead to overly complicated solutions, and authentication mechanisms are no exception. Making a payment should actually be simple, as it’s just a transfer of value from one place to another, it’s the fact that we have MADE them complicated that makes them unsecure.

The average consumer is used to entering a PIN or a password and their smartphones should now be able to take care of the rest in a way that they hardly even notice it happening. Only in this way can we achieve the security we need, with the convenience required to make implementation practical.

For the payments sector to build the next generation of consumer solutions, individual vendors need to stop focusing on themselves and be more collaborative.

[Ed. Written in collaboration with www.myPINpad.com]

In short, yes, they WILL be, but like everything worthwhile there is a significant cost involved. In this case, the currency will be your identity, and the more invisible you want payments – or any transaction for that matter – to become, the more of your identity you will have to spend. In this case, there is a direct correlation between your identity, and your privacy.

First, what is an invisible payment? Seeing as Wikipedia hasn’t even got a listing yet, I’ll take a stab at defining what invisible payments are to me;

A payment can effectively be called invisible when there is limited to no interaction required by the payment initiator (consumer) to complete the authorisation and settlement of a transaction.”

Any fan of Star Trek has seen this in play for decades. When was the last time you saw Captain Kirk reach into his pocket for a 10 spot or a credit card? Did he have to use biometrics or a swipe card to get onto the bridge? Maybe, but we saw none of it, and that’s the point.

Imagine this scenario; You walk into Sainbury’s and pick up a basket, then walk up and down the isles choosing your items. Once you have finished shopping, you walk out to your car [optionally] without any further interaction whatsoever.

What was the process?

  1. As you walked in, any number of authentication mechanisms were at play; from smartphone proximity (NFC), to facial and/or gait recognition, to whatever biometric innovation comes next;
  2. Both the shopping carts and the baskets could be easily be fitted with fingerprint, vein, hand geometry recognition sensors in order to assign the subsequent basket contents to you;
  3. As you place items in the basket, they are scanned and optionally listed on your mobile device for a running total / loyalty benefits / instant coupons and the like;
  4. Walk through a final scanner into a bagging area, or just go straight to your car, either way your final tally is calculated and the funds directly charged to the payment option of choice. It’s up to you if you want to authorise the final payment with a PIN number and/or biometric on your smartphone; and
  5. Everything you just purchased is now available on your home database for tracking of ingredients for a meal, expiration dates and so on.

While the majority of the technology behind this transaction is more in the realm of the Internet of Things (IoT), the payments aspect is an extremely simple form of Identity Management on smartphones. What’s more, all of this technology is available today, the only thing missing is the demand.

There will be 2 extreme camps to the above scenario; 1) Where do I sign-up!? and 2) Never in a million years!

Most of us will be somewhere nearer the middle, and it should be clear that the further you get in to the ‘sign-up’ camp the more of yourself you have had to share. When it comes to invisible payments – and IoT for that matter – the convenience described above came at a cost to your privacy. And until security catches up with technological innovation, that cost is seen by most to be too high.

That’s the demand I mentioned above, and while scenarios like this will be common place one day, we’re not quite there yet.

[If you liked this article, please share! Want more like it, subscribe!]

In a recent article on PYMNTS.com; 68 PERCENT OF PAYMENTS PROS SAY NEW TECH INCREASES RISK; “68 percent of [payment-systems professionals] say pressure to migrate to new payment systems puts customer data at greater risk instead of making it safer, according to a new survey by Experian and the Ponemon Institute.” This relates to EMV and mobile payments, but it is unclear exactly to which technologies they refer.

What it does not say is whether the insecurity is due to the pressure of the migration itself (which is implied), or to the inherent insecurity of the underlying technologies. These are two radically different concepts, from which the reader can draw wildly different conclusions.

As in any business, the pressures of maintaining a competitive advantage can lead to some very poor business decisions, and without a robust governance function unsecure systems can easily find their way into production untested. However, if the article is suggesting that it’s the new payment systems themselves that are the issue, we would strongly challenge that argument.

There exists today payment technologies whose security is far in advance of those possible for the legacy non-cash and non-chip based payment infrastructures. Mobile devices alone are capable of multiple multi-factor authentication mechanisms through every-day use. Integration of this technology is held up by many factors, but perceived insecurity of the data should not be one of them. EMV is also far more secure than mag stripe (for example), and the combination of chip and PIN is even more secure.

It is difficult to understand how you could introduce EMV unsecurely given its self-contained nature, but mobile payments is something altogether different and is easily addressed by the implementation of appropriate products and due diligence. This may well be what is of the most concern to those surveyed.

With regards to technology in general, and retail especially, neither the payment method itself nor security are core functions. Being paid for the goods is. It’s not surprising that that; “Only 51 percent of the Experian/Ponemon respondents agreed that “the security of electronic payments is a top priority issue” for their organizations.” In fact, we suspect the only reason it’s that HIGH is because Experian/Ponemon were talking to payment-system professionals and not the CEOs.

EMV roll-out in the US was never going to be completed by this October, and even 2020 is doubtful. The reasons for this are myriad; from the expense (which is significant), to investment only in technologies that are not future-proofed, to analysis-paralysis related to loyalty and value-add services, and to a trend toward competitive edge based on customer service alone all play a part in a decision that can quite literally make or break an organisation.

A payment, in its simplest terms, is a transfer of value from one place to another. Getting those payments transferred is a multi-trillion €/£/$ industry which has yet to provide the kind of leadership merchants are looking for. In the end the only thing that matters is that the consumer is able to securely authenticate themselves and make the transfers they want, when, where, and however they want, and it’s clear that current technology falls short.

EMV and tokenisation are security patches while the payments ecosystem transitions to mobile, and delays in implementation of either of these technologies is a direct result of retail’s inability to double their investment in payment acceptance channels, as well as their inability to know which of the technology horses is going to win the race.

[Ed. Written in collaboration with www.myPINpad.com]