I read a rather long but very interesting article the other day (thank you nephew) titled ‘The Coming Digital Anarchy‘ by Matthew Sparkes (Telegraph). Despite the rather dramatic title (I have done this egregiously myself from time to time), the concept regarding the future of ‘blockchains’ is sound, and is a far better researched and a far more encompassing version of my earlier article ‘On The Irrelevance of Money‘.

However, with the exception of one fairly cryptic phrase; “In [his] version of the future, identity and reputation will be the new currency.” the means by which this new order will be usable has not been addressed. Nor have I seen it addressed in any other articles of its ilk.

Regardless of the manner in which our data is stored, either the current file/database method, or the de-centralised / distributed method of blockchains (written for the crypto currency Bitcoin, but has much wider implications), we, the owners of the data, need to access its function securely, and put it to use in any scenario we choose.

If you can assume for the sake of argument, that the concept of the block chain is a valid method of storing and securing data, how can we access the data’s benefits in a method that’s equally secure? Your computer, mobile phone, static knowledge (username / password etc.), physical tokens (credit cards, RSA Tokens) are what we use now, and seeing as they are based on current methods of authentication, inherit their flaws. It is a hard enough stretch to get people to accept that their entire ‘Internet Worth’ (trying to coin this phrase) is not maintained by any institution, but to grant access to this without ensuring your identity is protected in the same way goes too far, even for me.

Your identity is all you have that’s truly yours, everything else is a universally agreed representation of value (money for example), so until such times as we can bring our full identity to bear we are reliant on small, and very specific elements of it. Elements that are relatively easy to steal, and duplicate.

It follows therefore, that the more of our identity were can securely distribute, the harder it will be for anyone to pretend they are us. Even in a scenario like Invasion of the Body Snatchers where they completely take over our physical bodies, unless the entirely of my life was instantly at the impostor’s disposal, AND they were able to duplicate my personality precisely, my family and friends would know there was something wrong. And if I’m honest, might actually prefer the new me.

Which brings me to the true value of your identity; Trust. You would not lend a stranger a £1,000 without significant rules in place, but you would think nothing of lending it a family member (assuming they’re not a douche-bag). Why? Because you have a lifetime of trust built up behind you.

How then do we duplicate a lifetime of trust in an electronic form, between two complete strangers? Well, if you’re reading this YOU can’t, probably it’s too late for most of us, but it’s NOT too late for those young enough to begin the process. All we need is the technology.

Oddly enough, I think that block chains provide the answer here too, but I am making a huge assumption based on limited knowledge of how they work. However, from what I know already, they are an ideal medium as their very nature is to record everything that ever happens from the beginning. It just needs to be worked out how to accept the input from everyone with whom the individual comes into contact, and how to represent that in terms of levels of trust. Much like a credit rating, but infinitely more difficult to explain.

In just the last few days Ghash has thrown a huge spanner in the works by controlling the magic ‘51%’ of Bitcoin, thus completely ruining the whole concept of de-centralisation. They have said that we should not worry, and to trust them, but so do the banks. There is clearly a lot of work left to be done.

Until people MUCH smarter than me can work out these issues, and we completely redefine the concept of Privacy (that’s the easy part, right?), this is all theory and speculation, but I cannot see any safer way to get where we are headed. Things change, whether we are ready or not.

Your identity as a baseline is both irrefutable, and cannot be duplicated, but it DOES mean you have to be a decent citizen your whole life or be ostracised. Is that such a bad thing if we have a global consensus on right and wrong?

[If you liked this article, please share! Want more like it, subscribe!]

How much food do you throw away each year because it’s past the expiration date, or worse, you find it in the back of your fridge supporting a new furry ecosystem?

In my ever extending string of blogs based entirely on speculation, I would say that I throw away in the region of £400 – £600 worth per year. And I’m not saying it’s my wife’s fault (certainly not to her face anyway), although she does all the grocery shopping and cooking (don’t worry, it’s not like that, I do pretty much all the cleaning and jar opening). 🙂

There’s actually no blame here, it’s just that way WE are. We are not planners when it comes to our weekly meals, which would alleviate much of this issue. But, like everyone else in our brave new it’s-not-my-fault,-someone-else-should-do-something-about-it society, I want to have this take care of itself, automatically.

We can, and I believe we are not that far off, it just needs to be put together.

First, the actual growers of the produce need to take the first step by ensuring that their shipments are labelled with enough information to begin the countdown process. i.e. from ripe to rotten, we should by now have a pretty good idea how long a lettuce (for example) is going to last. I don’t care if it’s organic (which will clearly reduce its life cycle), with refrigeration, preservatives, and whatever else happens to our food without our knowledge, from farm, to supermarket shelf, to your fridge, to your plate, the lettuce has only x days to live (plus or minus).

Let’s say this is done with a QR tag, and each step in the logistics is added to the embedded information, by the time you scan the code in the supermarket you will have at your fingertips all the information you need to make an informed decision related to your purchase. These lettuces in this box are 2 days newer than those ones, but the older ones are half price and so on. Instant coupons is a given.

I won’t go into the payment method, I’ve written enough on the future of payments, but you will not only have an instant receipt, you have automatically added these items to a database of all the food in your house, along with its weight / quantity, expiration date, and so on.

Now everything edible in your house, from canned goods, to herbs & spices, to meats, to vegetables are all tracked in your database. All you need do now is set your alerts so that ANYTHING that is about to expire becomes an item in your next meal. Of course, you will need to tell this database whether or not you put something in the freezer, the fridge, to left it on the counter, but the smart-fridges or smart-cupboards of the very near future will be able to track this for you by scanning your groceries as you put them away. This will in turn be added to the database so you need never spend half an hour hunting for your Fingers of Fudge.

Not only that, because you have a complete record of everything, you can get immediate help on what to do with it. Every chef in the world will want to sign up to a service whereby they can apply their recipes to what you have available, or more importantly, what is about to expire. Yes, both the chefs and the providers of this service will try to get you to buy additional items to make an amazing meal, but you will always have a choice.

Also, if you DO choose a fancy menu, this can immediately alert your preferred supermarket who can tell you whether to not the items are available, then maybe even deliver them to you.

And we’re still not done. Beyond the immediate benefits of saving a butt-load of money, these are other advantages for every player in the cycle (in no particular order);

  1. You can have your weekly menus designed for you based on your preferences in terms of likes/dislikes, calorific intake, budget and so on.
  2. Growers will eventually be able to track global trends on food purchase, and possibly be able to adjust their supply to the demand.
  3. Supermarkets can automatically alert their customers to deals on soon-to-expire produce a hopefully reduce their waste. Maybe provide free delivery if you purchase enough of these items.
  4. You’ll learn to cook far more meals than you could have ever conceived yourself.
  5. You’ll be able to track your calorie intake if you follow the menus explicitly. Good for dieters, and excellent for diabetics.
  6. By having the ingredients of everything you buy available to you, you can ensure you never buy anything, or accept a recipe for meals that contain something, to which you or a loved one are allergic.
  7. You will undoubtedly stop buying things that sit in your cupboards for years on end, like that can of string beans that seemed like a good idea at the time.
  8. You can make your food database available to your friends so that you can create a meal together without having to buy everything yourself. Dinner party anyone?

I could go on all day, and I’m sure that if you have read this far you have had several ideas of your own.

All we need now is the supermarket chains to buy in …and the growers …and the name brand goods ….and …

 

OK, so money isn’t irrelevant …yet, but it will be. Like so many things that are in existence, they are only still used because they have either achieved global ubiquity, or there is nothing better to replace them, or both.

Money, in all its forms, is probably the definitive example of this, but I can actually see a time in the not too distant future when it will be replaced with what it has always represented; Value.

Let me take a step back here and say that this subject is wayyy too complex for me to do true justice, and I have no intention of reading any books on economics to ensure it’s factually accurate, but by its very nature, money is limiting to the continuation of globalisation. Like it or not, the world is getting smaller and less unique across traditional borders both physical and political. People are starting to want the same things, and while not all of things they want are good, the common ground between them is once again driven by value.

Money simply cannot keep up with the changes, and the massive complexity of producing cash, providing debit and credit services, exchange rates, inflation, and a plethora of other things I have made it my goal to never understand, will eventually drive a requirement for something new;

I’m calling it ‘Digital Identity and Virtual Value Management’.

Errr, what?

Another step back; In the past, if you were a wheat farmer and needed meat, you would exchange wheat for meat at a ratio you agreed directly with the person standing right in front of you. You would then each go on your way happy that you have received fair value for your goods. However, if you wanted dairy products, carpentry skills, metal working skills or a whole host of services, you had to repeat this process, and of course, the representative values would always change depending on your immediate needs.

Now, in a massively over-simplification of history and probably fact, it was decided in the year [mumble-mumble] that it would make sense to replace the bartering system with a universally agreed (i.e. by the ‘government’) meaningless object (money), which would represent the VALUE of every commodity so that the holder of this meaningless object was owed the value of it in any commodity they chose.

Great, so now instead of carrying around huge quantities of wheat, our farmer can now walk up to any provider of goods and exchange their meaningless objects for whatever they want.

Eventually these meaningless objects became paper-based, then plastic, and now it’s digital, but it’s still meaningless. Only the VALUE of what it represents means anything, and you SHOULD be able to spend that any time, any place, anywhere, without the need for a meaningless object.

Your identity should replace the meaningless object, and your value should replace money in all it’s forms.

But who sets your value? Who is to say that the services of a lawyer are more valuable than those of a plumber?

You do.

Currently, if you accept £50,000 / year for your employment, YOU are the one who set that value, not your employer. If you think you’re worth more, go somewhere else, or, what you should do is increase your value by improving yourself in some way (education, experience, work harder, you name it). And herein lies one of the biggest mistakes people make their whole lives; focussing on money when what they SHOULD be focusing on is improving their own worth, their VALUE to others.

So, what is Digital Identity? It’s the unequivocal ability for you to prove that you are you, to anyone, anywhere. If everyone in the world KNEW that you were you, then you would not need money, passports, or any physical form of identity. Whether this is effected by biometrics and knowledge verification or [more likely] a combination of these and other yet-to-be invented factors is unclear, but the digitalisation of everything will continue until this form of Identity Management is commonplace.

And Virtual Value? This you can see happening already with Bitcoin and its brethren. What’s missing is the input of non-monetary value, or in other words, I have no way of entering my self-determined worth into a virtual environment, then have others validate it for my actual work in a way that I can spend on something else. But this is coming too, it almost has to.

I can imagine a time when I perform a piece of work for someone, immediately be ‘credited’ with the agreed virtual value, then be able to walk into a store, pick up what I want and walk out again without performing any manual payment transaction whatsoever. My Digital Identity will be confirmed the second I walk into the store, the value of the goods will be automatically calculated based on my choices, and the value of those good will be deducted from my virtual net-worth (or Internet-worth! :)) as soon as I step back out into the street.

Seems rather ridiculous that we still use credit cards, doesn’t it?

For those who don’t know what the Rosetta Stone is, it’s a tablet found in 1799 that greatly assisted the translation of ancient Egyptian Hieroglyphs [subsequently] to every modern language.

So why do I use this as an analogy for non-cash payments?

Hieroglyphs​ had puzzled scholars for centuries until the Rosetta Stone unlocked them enough for the translation to move forward to completion. Having a software PIN will effect the exact same unlocking of the transition of non-cash payments from plastic to mobile. We have had payment cards for 60+ years, with nothing in that time anywhere near ubiquitous enough to disrupt them​, now ​we do. And while mobile devices are in no way perfect, and in many ways even less secure than payment card, ​they ​​are​ already far more prevalent​. ​Despite all ​of mobiles’s flaws, they ​are being used ​today as a payment medium​, a trend that will continue until plastic is replaced completely (at least in its current form).​

Th​ere are too many reasons​ for the continuity​ to go into​ here​ (sheer functionality being the top one), but it has been slow because until now every mobile payment innovation was just a little too much for people to accept, just a smidge too radical to gain the necessary momentum.

This is probably because none of those innovations kept the most widely used of the authentication mechanisms in the world; the PIN. The enormously complex and expensive chip & PIN (EMV) used for credit cards is accepted globally (if they can afford it), but up till now there has been no way to effect an acceptable level of security on a device that is never going to be as secure as a system built for purpose.

But ‘as secure’ is not the point, ‘secure enough’ is. You’re not fighting for perfection and zero loss through theft, you’re fighting for making it too difficult for thieves to bother. This can only be effected by layers of security, the so-called defence-in-depth. EMV put all of its security controls into a single factor (they had no choice), but mobile devices have access to numerous – and ever expanding – options:

  1. Geolocation/Geofencing: Whatever you want to call it, and whatever buzz phrases vendors will come up with next, they all mean the same thing; are you where you should be? Should you be paying for something in Glasgow if you live in London? Maybe, but when you set the areas from which payments can be made, you are removing the majority of the bad guys’ ability to process a fraudulent transaction.
    Yes, there can be privacy issues, but most vendors have dealt with that now.
    o
  2. Device Authentication: Every mobile phone has a serial number, IMEI number, and other built in identifiers. If your device is registered it’s very difficult to use another device to get in the middle. Not impossible, just difficult.
    o
  3. Application Signing and Authentication: Minimal security in and of itself, but is another security layer which ensures as much as possible that only known good apps are used. Apple and Google have their own ways of doing this for downloads, neither of which is adequate. Ongoing application verification can be relatively useful though.
    o
  4. App Blacklisting / Malware Detection: Very early days yet for mobile devices, but in the same way that operating systems anti-virus vendors have made untold fortunes regurgitating known bad things into signatures, mobile devices will have the ability to blacklist apps that should never be running on devices secure enough to authenticate payments. OS hardening guides (SELinux for example) and version control (Android must be at v4.2 and above for example) are fundamental baselines.
    o
  5. PIN Image ‘Watermarking’: Most internet banking sites now have a facility whereby you can upload a personal image to ensure that your open communication is actually with your bank and not redirected to a bad guy. Mobile devices make this factor possible and can even be configured into the PIN pad image.
    o
  6. Encryption (Packet and Transport Layer): Obvious stuff, and relatively trivial to circumvent when you have access to the base operating system kernel (where all jailbreaks take place), but still a very valid concept, especially when you consider the very clever technology surrounding things like Secure Remote Password protocol (SRP).

​Even today there are more options than this, and even implementing all of them at once is seamless to the end user once they have registered their device​. Any one of these by itself is clearly inadequate, but can you really see a bad guy sitting in Starbucks cracking ALL of these in the few moment it takes you to pay for your coffee?

By their nature, mobile devices will always be insecure and limited (bloated OSs, battery life, delicacy, theft and so on) and cannot be seen as a long term solution in payments the way the credit cards were, but I don’t think anyone can deny that they will replace plastic. Mobile devices will take payments to places credit cards can never reach, and the functionality and distribution of payment innovation through mobile devices will grow exponentially over the next 5 – 10 years, it just needs something to help everyone make that transition;

The software PIN.

[If you liked this article, please share! Want more like it, subscribe!]

For generations – quite literally – credit cards have ruled the non-cash payments world, but it’s now time to start saying goodbye to the ‘plastic’.

At the time of their introduction (way back in the late 1950’s early 60’s) they were a fantastic innovation, and they have rightly had their decades in the sun. Until now, there has been nothing to replace them, nothing anywhere near as widespread, ubiquitous, incredibly versatile, and still growing as a market.

Now there is.

I am talking of course about the mobile phone, but as I will try to demonstrate here, I’m convinced that this is just a reactive and brief stepping stone, and it will not be 60 more years before that next transition comes about.  Actually, it’s already happening.

The table below represents my thoughts on the next steps, and are not based on anything resembling research, known statistics, and maybe even reality. This is just a visual representation of what I believe;

Screen Shot 2014-03-20 at 10.27.12

Credit Cards – Began way back when, and have enjoyed an enormous growth over the years. However, the up-front nature of the card itself has required a massively expensive infrastructure to accommodate it, leaving half the planet un-covered and un-banked. Beginning this decade we will see a rapid decline in their use as consumer choices expand, and issuer’s profits drop.

Mobile Phone – Enormous and unprecedented growth and owned by more people than any electronic product in history. Anyone who believes that the inherent insecurity and inconvenience of battery life will prevent the transition of payments onto this platform is going to be left behind. Nevertheless, these limitations WILL ensure that the transition to what’s next in payments comes much faster than the move from plastic. Rapid advances in battery technology and OS security will maintain the trend for a few years.

Non-Invasive Biometrics – As I’m calling it, but I basically mean wearables and anything else that comes up that starts doing away with the keyboard and begins the process of identity management through non-static authentication (passwords, secret information), and learning the wearer’s physical profile to effect the majority the functionality. Voice at first I assume.

Invasive Biometrics – Implants in other words. There will be those who say this is a ridiculous concept, that it will never take off, but I believe that the next generations will not see this as outrageous, and WILL see the mobile phone as antiquated and inconvenient. Anyone who has seen the 2012 version of Total Recall and the phone implanted into Colin Farrell’s hand either said “NO WAY!”, or like me said “I WANT ONE!”. Batteries will always be a limitation, but the human body IS a battery (of sorts), and it will be harnessed accordingly (hopefully not like in The Matrix).

Cumulative Identity Profiling – Again, this is what I’m calling it, but it’s basically the culmination of the trend toward a totally different idea of privacy, and one that I cannot see clearly because I’m not of this yet-to-be-born generation. Anyone who is the parent of a teenager knows that their kids have never NOT had a mobile  phone, and that almost their entire life is recorded online. The are never unplugged. We are horrified for them, but that’s our judgement, not theirs, and theirs will win. Identity Management and authentication will be a sum total of your life’s experiences, and therefore almost impossible to fake, or duplicate. The whole concept of privacy will be turned on its head.

There are those who say that this can only happen in industrialised nations, those with the money to afford such things, and yes, there will always be a portion of the population who will be out of the loop for a while. However, Mozilla (for example) are releasing a $25 smartphone, and it is estimated that within a few years Africa with have a 50% smartphone adoption. This trend will cover almost everyone, eventually.

The innovation involved with payments is really at the beginning of its evolution, and I’ll probably look back on this post in 5 years time and laugh at my naivety. Nevertheless, the card brands know its coming (hence NFC, HCE etc.), the terminal manufacturers know its coming (hence the rise of phone based mPOS), and the retailers know its coming (hence the push back on EMV), so the only thing left is for the consumer to start making demands and there will be no looking back.

The average consumer will forgo security for convenience, it will be up to the payments innovators to make sure enough security is built in to protect people from themselves. Which I think is unfortunate, but it’s that or educate 7 billion people.