For generations – quite literally – credit cards have ruled the non-cash payments world, but it’s now time to start saying goodbye to the ‘plastic’.

At the time of their introduction (way back in the late 1950’s early 60’s) they were a fantastic innovation, and they have rightly had their decades in the sun. Until now, there has been nothing to replace them, nothing anywhere near as widespread, ubiquitous, incredibly versatile, and still growing as a market.

Now there is.

I am talking of course about the mobile phone, but as I will try to demonstrate here, I’m convinced that this is just a reactive and brief stepping stone, and it will not be 60 more years before that next transition comes about.  Actually, it’s already happening.

The table below represents my thoughts on the next steps, and are not based on anything resembling research, known statistics, and maybe even reality. This is just a visual representation of what I believe;

Screen Shot 2014-03-20 at 10.27.12

Credit Cards – Began way back when, and have enjoyed an enormous growth over the years. However, the up-front nature of the card itself has required a massively expensive infrastructure to accommodate it, leaving half the planet un-covered and un-banked. Beginning this decade we will see a rapid decline in their use as consumer choices expand, and issuer’s profits drop.

Mobile Phone – Enormous and unprecedented growth and owned by more people than any electronic product in history. Anyone who believes that the inherent insecurity and inconvenience of battery life will prevent the transition of payments onto this platform is going to be left behind. Nevertheless, these limitations WILL ensure that the transition to what’s next in payments comes much faster than the move from plastic. Rapid advances in battery technology and OS security will maintain the trend for a few years.

Non-Invasive Biometrics – As I’m calling it, but I basically mean wearables and anything else that comes up that starts doing away with the keyboard and begins the process of identity management through non-static authentication (passwords, secret information), and learning the wearer’s physical profile to effect the majority the functionality. Voice at first I assume.

Invasive Biometrics – Implants in other words. There will be those who say this is a ridiculous concept, that it will never take off, but I believe that the next generations will not see this as outrageous, and WILL see the mobile phone as antiquated and inconvenient. Anyone who has seen the 2012 version of Total Recall and the phone implanted into Colin Farrell’s hand either said “NO WAY!”, or like me said “I WANT ONE!”. Batteries will always be a limitation, but the human body IS a battery (of sorts), and it will be harnessed accordingly (hopefully not like in The Matrix).

Cumulative Identity Profiling – Again, this is what I’m calling it, but it’s basically the culmination of the trend toward a totally different idea of privacy, and one that I cannot see clearly because I’m not of this yet-to-be-born generation. Anyone who is the parent of a teenager knows that their kids have never NOT had a mobile  phone, and that almost their entire life is recorded online. The are never unplugged. We are horrified for them, but that’s our judgement, not theirs, and theirs will win. Identity Management and authentication will be a sum total of your life’s experiences, and therefore almost impossible to fake, or duplicate. The whole concept of privacy will be turned on its head.

There are those who say that this can only happen in industrialised nations, those with the money to afford such things, and yes, there will always be a portion of the population who will be out of the loop for a while. However, Mozilla (for example) are releasing a $25 smartphone, and it is estimated that within a few years Africa with have a 50% smartphone adoption. This trend will cover almost everyone, eventually.

The innovation involved with payments is really at the beginning of its evolution, and I’ll probably look back on this post in 5 years time and laugh at my naivety. Nevertheless, the card brands know its coming (hence NFC, HCE etc.), the terminal manufacturers know its coming (hence the rise of phone based mPOS), and the retailers know its coming (hence the push back on EMV), so the only thing left is for the consumer to start making demands and there will be no looking back.

The average consumer will forgo security for convenience, it will be up to the payments innovators to make sure enough security is built in to protect people from themselves. Which I think is unfortunate, but it’s that or educate 7 billion people.

In continuation of my crusade against EMV in general, the card schemes have announced an end to issuer-only fraud liability for non-chip transaction starting in October 2015. The so called ‘liability shift’.

For those who don’t know, it’s the issuers of the credit card that accept the liability for fraud during a branded credit card transaction, which is why they receive the lion’s share of the fees associated with the transaction (interchange fees). But now, if the merchant does not upgrade their point-of-sale terminals to those capable of accepting chip cards, it’s the merchant who suffers the fraud loss. Same thing goes for a consumer who wants to continue using swipe  & signature cards.

While I assume that those with disabilities, and / or the elderly will be given the option to not change to chip & PIN, the fact remains that the enormous cost of the transition to this ‘new’ technology will not be born by those who have basically created the problem over the course of over 60 years; the card brands. It will be the consumer …eventually, because the merchants / retailers will have to re-coup their up front costs.

And all this just to keep taking credit cards!

Why do retailers and banks STILL see credit cards as the only form of non-cash payment? Why DO the card brands have so much power over end-user payments technology when there are ‘only’ ~6 billion credit cards in the world and >7 billion mobile phones? On top of that, mobile phones have a far wider distribution than an EMV infrastructure can EVER hope to duplicate, and you have what I would see as a very simple choice in how to transition away from plastic.

I’ve said it repeatedly; payments is NOT about the FORM of payment, it’s about authentication of the individual to the organisation holding the funds (usually a bank), and NO form of account-detail-up-front (read credit card number, even a token of one) can ever be as secure as one protected by proper identity management. Yes, even on a mobile device.

What the US retailers are going to do is spend an absolute fortune on a payment acceptance technology that will be impossible to upgrade to anything else, nor will it be anywhere near as flexible for those retailers wishing to innovate in new forms of value-add services and marketing drives.

I have no problem with the card brands making a ton of money, that’s business and they do have a lot to add in the payment arena, but to continue the push for EMV is as horrendously self-serving as it is pointless. If it’s not them pushing for it, and it’s actually the Fed, then THEY should do their homework and talk to the retailers.

However, if the retailers aren’t going to do anything about this, then it pretty much serves them right.

For example; What card brand or issuer is going to tell Walmart that they can’t use an EMV alternative that has been shown to have a similar security profile AND infinitely greater business benefits? Can you really see them giving up a multi-million dollar revenue stream just to enforce a patch on a 60+ year old technology?

No, neither can I.

In the most ridiculous decision possible, Target have agree to ACCELERATE their ‘smart card rollout’ to the tune of about $100M;

Target to accelerate $100 million chip-enabled smart card program: CFO, Reuters, Feb 03, 2014

Let me say that again; ONE HUNDRED MILLION DOLLARS!

How exactly are these new smart cards (which is EMV / Chip & PIN obviously)  going to reduce “cyber theft” when they do absolutely nothing except prevent card present fraud? It’s not as though this amazing chip-enabled technology actually encrypts the cardholder data point-to-point (that’s a terminal function, if available), so it doesn’t stop Target saving the data post-auth. And because not ALL US retailers and merchants are going to accelerate THEIR programs, Target have done nothing to prevent the real menace; card NOT present fraud.

What are they going to do when their customers start demanding other forms of payment, like mobile? Or when they start losing market share because value-add services won’t integrate with their shiny new static-function payment terminals? Spend ANOTHER $100M?

I’ve said it a hundred times, payments is NOT about the payment functionality itself, it’s about the AUTHENTICATION of the individual trying to MAKE the payment. In that, Target are completely missing the point.

If this is pressure from the card brands shame on them, if it’s pressure from ‘Government regulators’, shame on THEM, but if this is just Target being short-sighted and throwing good money after bad, then I hope their share-holders wake up before it’s too late.

I for one would be really pissed if had a vested interest in this.

First, any discussion on ‘mobile payments’ needs to start with a explanation of what I mean by it. There are many definitions and types of mobile payment; anything from SMS, to direct mobile, to mobile web, and from NFC to QR can all be labeled a ‘mobile payment’.

However, from my perspective, there are really only two main categories of mobile payment:

1. A mobile device is used in authenticating the individual making the payment, the transaction happens in the background (e.g. e-wallets), and;

2. An application on the mobile device passes the sensitive payment details (e.g. paying with credit card through a web browser)

Clearly 1. is better than 2., as mobile phones will probably never be as secure as we’d like them to be.

Second, I think it must be understood that ‘payments’ in general is NOT about the payment itself, that’s just detail, it’s about the authentication of the individual making the payment. Whether you have a checking account, a line of credit, an e-wallet, etc. as your source of funds, you don’t care how you get to it as long as doing so is safe, convenient, widely available, and value for money.

However, safety and convenience have always been, and will always be, a balance of mutual exclusivity. In other words, the more you have of one, the less you have of the other.

The reasons mobile payments are nowhere near as ubiquitous as credit cards […yet], are myriad and include;

1. Credit cards are familiar to, and used by, a large chunk of the planet. There are approximately 7bn of them out there and they have been around for over 60 years

2. They are very widespread, and the use of them is a well establish process

3. Smartphone use is not as great in some regions as it is in the US / Europe, significantly limiting the available payments functionally

4. Large retail have not adopted them significantly, and the card brands are making things difficult

5. People just don’t trust them yet, and they are more complicated for the ageing portions of our population

However, this will not stop the trend, and these two ‘statistics’ pretty much say it all;

1. The average time it takes to realise you’ve lost a credit card is 11 days, the average time it takes to realise you’ve lost you mobile phone is 4.5 MINUTES.

2. By the end of 2014, there will be more mobile phones in use than there are people on the planet (>7bn).

Unfortunately  the transition of the non-cash payments ecosystem to mobile will be from credit cards, which requires the support of the card brands, who, for obvious reasons, are loathe to provide it. Both the PCI DSS and the PA DSS standards stifle innovation by making any form of compliance for mobile payments on Cat 3 mobile devices (phones, tablets etc.) exceedingly difficult, and in some cases, impossible.

I have to assume that once the card brands are ready to roll-out their OWN mobile payment infrastructures, the transition will happen much faster. This must involve alternatives to EMV, and any solution must be scalable, and future-proofed, so they’ll need a couple more years to get themselves sorted.

The card brands employ a lot of VERY smart people, and I have to further assume that there are entire departments dedicated to digging them out of the hole they have spent decades creating. From the physical infrastructure (PEDs, back-end servers, credit cards etc.) to sector dependencies (PSPs, acquirers, service providers etc.)  the credit card payment ecosystem is enormous, and enormously complicated. The transition of plastic to mobile will take a long time, but I think the brands have a lot to offer in the space if they decide to play fair.

In the end, mobile applications will rule the day, at least until the next thing comes along. It most certainly won’t take 60 years like the cards-to-mobile transition – and I suspect will involve some sort of implant – but entire fortunes are there for the taking in this space. The functionality, convenience, and yes, even the safety of mobile applications mean that they will be the next big thing. Competition will be massive, which can only benefit the most important factor; the consumer.

For the purposes of this blog, I’m going to assume the rumours are true, but if they’re not, both the premise and the message to large retail is still largely valid.

Apparently, Target will be replacing their current point of sale / terminals with a Verifone ‘solution’ capable of Point to Point Encryption (P2PE), and I assume, EMV and NFC as well. So it wasn’t bad enough that they lost 40M credit card numbers – the repercussions of which will cost them millions – they are now going to spend even more multi-millions to continue to accept the root cause of their troubles; the credit card.

Yes, the new Payment Entry Devices (PEDs) may encrypt the cardholder data from the swipe onwards, and this MAY take the large portion of the authentication channel out of scope for PCI, but nothing fundamentally has changed. The only significant payment channel is a custom built, exceedingly expensive system that can only accept credit cards. I estimate that $25,500,000 would be required to replace the PEDs alone (1,700 locations X 30 lanes per store X $500 per PED)!

Forget the fact that they will also have to pay for the P2PE service, as well as fundamentally change every business process relating to payments, they will STILL have to pay the card brands astronomical sums in fees! Their 2013 net revenue was ~$73 billion, so let’s say (conservatively), 15% was credit card revenue, and that Target have a preferred interchange rate of 1%, that means in 2013 alone, Target paid the card brands $109.5 MILLION just for the ‘privilege’ of letting the customers use a credit card.

$25.5M + $109.5M = $135M, how many innovations in payments could that fund? Or more to the point; how many alternative methods of payment AUTHENTICATION could that fund which would vastly improve the security of the transactions, and render the card brands’ 60+ year old technology obsolete once and for all?

Now imagine if they got together with Walmart, and Metro, and Aldi, and Costco and the rest of the world’s top 10 retailers, who, using the above maths, pay the card brands a combined $1.7 BILLION in fees, just how much influence do you think they would have?

And that’s really the point; the retailers don’t seem to know just how much power they have. They in fact hold ALL the cards, but not one of them wants to be the first to play them for fear of losing the competitive edge to the others. If they could only put aside their differences for a while, they could, all by themselves, create the necessary momentum to change the way we perform non-cash payment on a global basis.

The card brands won’t do it, it’s 100% of their business, the banks won’t do it, they make their own profits, and no-one else who has a vested interest in the status quo will make any effort to provide alternatives. Can’t say as I blame them, business is business, and it’s not as though the average consumer is clamouring for choice. But the retailers, they have by far the most to gain, and they have by far the most direct influence on how people shop.

Someone has to go first, and Target now have the perfect opportunity to spend their money future-proofing their payment infrastructure, but only if they finally understand that payments are NOT a core function, selling stuff is, and that their customers will adopt ANYTHING that’s cheaper, easier, and safer.

They have an image to fix, but this is not the way to go about it.