So Apple have finally adopted NFC, huh?  Big deal, Samsung have partnered with Visa and MasterCard to promote NFC for over a year, and included NFC chips in their devices long before that.

Apple’s wallet provides you options to choose which credit card you want to use. CREDIT CARD?! REALLY?! How is that innovation in payments?! The whole point of mobile payments is that you don’t need a branded card to make a payment, at least it should be the point!

Payments has been, and will always be, just an exchange of stored value for a service or product whose value is, in turn, entirely arbitrary. e.g. I work for an entire week for a value I have agreed with my employer, and I am now going to buy a designer suit for the same ‘price’. The fact that the suit was made for a fraction of the ‘cost’ I paid for it is why its value is arbitrary; because regardless of the price, I agreed to it.

So what have Apple done differently? You can now authenticate the payment with your fingerprint. Seriously? People barely trust the fingerprint to log into their phones, let alone authenticate a payment. And seeing as the value of the contactless transaction is set below £20 (for the UK) and authentication is not required at ALL, why would you add an extra step?

I can tell you now that the credit card brands will not accept biometrics any time soon to replace EMV for higher transaction values when even software PIN (as opposed to hardware) is still rejected. Couple the fact that Apple’s global market share for phones is less than 12%, with the US being their only viable new market (who love their credit cards), and you have a completely empty offering.

But, you may say, Apple has 800 million iTunes users! Irrelevant, because there are nowhere near 800 million iPhones in use. From their initial inception way back in 2007, Apple sold their 500 millionth iPhones in June 2014. That’s total sales, all models, in seven years. Estimates suggest that there are less than 300 million in use globally, compared to a total of 1.75 billion smartphones.

On top of Apple’s minimal – and shrinking – market share, the transition of credit card payments to direct bank account payments through a mobile device has, through necessity, started small. Security is absolutely an issue, which is why the back-end wallets generally consist of credit cards, which handle the fraud / loss liability. With your bank account, it’s YOUR money, and the banks have yet to accept the liability for loss though mobile apps. When they do, the card brands will have no benefit and the transition to mobile will accelerate.

So why DON’T the banks provide this function themselves? Because they make money from credit cards, plain and simple, and it will be a tough sell to charge the fees they do now when accessing your own funds, even if they do provide a ‘fraud resistant’ service. Besides, the money from credit cards is not from the cards themselves, it’s on the interest you pay for your LINE of credit, so the poor banks can still make their squillions. That’s a relief.

Besides, people take their phones for granted, just as they do water coming out of the tap (I know, 1st world problems), and people simply do not see the issue with continuing to use plastic, so how will the mass adoption of mobile payments really take off? Simple; value-add services and guaranteed security.

Value-Add Services: Retailers are the only ones who can make this happen, not phone companies, not card brands, and certainly not the banks. For retailers to make the enormous investment required to change from a credit card infrastructure to mobile / hybrid there needs to be a clear positive effect on the bottom line. Unfortunately, with the ridiculous number of choices related to loyalty schemes, instant coupons, e-wallets and so on, no retailer knows which to back.

Guaranteed Security: The reason credit cards still eclipse mobile payments is because if you use a credit card you are not liable for fraud, the issuer is. The so-called liability shift. If you take out this middle-man, who accepts the risk? The retailers? The bank? The mobile app service providers? Someone has to, because you can be damned sure it won’t be the consumer.

Which brings us to only relevant thing to come out of Apple’s announcement; NFC is now the technology of choice. All we need now is the consolidation of every other service, someone to accept the inevitable losses, and mobile payments can come into its own.

Yeah. Right.

For those who don’t know what the Rosetta Stone is, it’s a tablet found in 1799 that greatly assisted the translation of ancient Egyptian Hieroglyphs [subsequently] to every modern language.

So why do I use this as an analogy for non-cash payments?

Hieroglyphs​ had puzzled scholars for centuries until the Rosetta Stone unlocked them enough for the translation to move forward to completion. Having a software PIN will effect the exact same unlocking of the transition of non-cash payments from plastic to mobile. We have had payment cards for 60+ years, with nothing in that time anywhere near ubiquitous enough to disrupt them​, now ​we do. And while mobile devices are in no way perfect, and in many ways even less secure than payment card, ​they ​​are​ already far more prevalent​. ​Despite all ​of mobiles’s flaws, they ​are being used ​today as a payment medium​, a trend that will continue until plastic is replaced completely (at least in its current form).​

Th​ere are too many reasons​ for the continuity​ to go into​ here​ (sheer functionality being the top one), but it has been slow because until now every mobile payment innovation was just a little too much for people to accept, just a smidge too radical to gain the necessary momentum.

This is probably because none of those innovations kept the most widely used of the authentication mechanisms in the world; the PIN. The enormously complex and expensive chip & PIN (EMV) used for credit cards is accepted globally (if they can afford it), but up till now there has been no way to effect an acceptable level of security on a device that is never going to be as secure as a system built for purpose.

But ‘as secure’ is not the point, ‘secure enough’ is. You’re not fighting for perfection and zero loss through theft, you’re fighting for making it too difficult for thieves to bother. This can only be effected by layers of security, the so-called defence-in-depth. EMV put all of its security controls into a single factor (they had no choice), but mobile devices have access to numerous – and ever expanding – options:

  1. Geolocation/Geofencing: Whatever you want to call it, and whatever buzz phrases vendors will come up with next, they all mean the same thing; are you where you should be? Should you be paying for something in Glasgow if you live in London? Maybe, but when you set the areas from which payments can be made, you are removing the majority of the bad guys’ ability to process a fraudulent transaction.
    Yes, there can be privacy issues, but most vendors have dealt with that now.
    o
  2. Device Authentication: Every mobile phone has a serial number, IMEI number, and other built in identifiers. If your device is registered it’s very difficult to use another device to get in the middle. Not impossible, just difficult.
    o
  3. Application Signing and Authentication: Minimal security in and of itself, but is another security layer which ensures as much as possible that only known good apps are used. Apple and Google have their own ways of doing this for downloads, neither of which is adequate. Ongoing application verification can be relatively useful though.
    o
  4. App Blacklisting / Malware Detection: Very early days yet for mobile devices, but in the same way that operating systems anti-virus vendors have made untold fortunes regurgitating known bad things into signatures, mobile devices will have the ability to blacklist apps that should never be running on devices secure enough to authenticate payments. OS hardening guides (SELinux for example) and version control (Android must be at v4.2 and above for example) are fundamental baselines.
    o
  5. PIN Image ‘Watermarking’: Most internet banking sites now have a facility whereby you can upload a personal image to ensure that your open communication is actually with your bank and not redirected to a bad guy. Mobile devices make this factor possible and can even be configured into the PIN pad image.
    o
  6. Encryption (Packet and Transport Layer): Obvious stuff, and relatively trivial to circumvent when you have access to the base operating system kernel (where all jailbreaks take place), but still a very valid concept, especially when you consider the very clever technology surrounding things like Secure Remote Password protocol (SRP).

​Even today there are more options than this, and even implementing all of them at once is seamless to the end user once they have registered their device​. Any one of these by itself is clearly inadequate, but can you really see a bad guy sitting in Starbucks cracking ALL of these in the few moment it takes you to pay for your coffee?

By their nature, mobile devices will always be insecure and limited (bloated OSs, battery life, delicacy, theft and so on) and cannot be seen as a long term solution in payments the way the credit cards were, but I don’t think anyone can deny that they will replace plastic. Mobile devices will take payments to places credit cards can never reach, and the functionality and distribution of payment innovation through mobile devices will grow exponentially over the next 5 – 10 years, it just needs something to help everyone make that transition;

The software PIN.

[If you liked this article, please share! Want more like it, subscribe!]