In the near future, most of us will want to:

  1. be able to walk into the supermarket, collect our stuff, and walk straight out with the payment already processed in the background
  2. receive instant coupons, or 2-for-1 offers, or other value add services WHILE shopping
  3. receive a warning if an item contains something to which we are allergic
  4. receive a reminder from your fridge / freezer / cabinets that you are low on certain products while you are walking down the relevant aisle
  5. …and so on.

However, you cannot have any of these things unless you made the necessary information available to the supermarket chain you are in. And they will not make these things available TO you unless they have good assurance that you, are in fact, you.

To enable just those 4 things listed above, you had to release a significant amount of personal data, all of which can have privacy implications:

  1. requires a number of things – from biometrics (facial recognition for example) to financial account access
  2. requires a comprehensive and always growing record of your choices, preferences, and habits
  3. requires details of certain bits of medical data
  4. requires your entire kitchen / bathroom / bedroom to be enabled for the Internet of Things, as well as a highly detailed geolocation on your whereabouts
  5. …and so on.

Are you OK with that?

I am, but I know many who are not, and I also know that as the generations progress, there will be less and less concern over these ‘conveniences’, as they will have become common place. I will go as far as to say that within the next 10 years, any supermarket NOT providing some of all of these services will not be able to compete, and possibly become Internet-Free corner stores where you’ll find the world’s ‘privacy paranoid’ shopping for their tin-foil helmets and electronic cloaking devices.

The bottom line is that the concept of privacy itself is changing. The generation of kids in secondary schools today has never known life without the Internet, and in most industrialised nations, every kid has a mobile phone. They are always plugged in, always connected, and, as never before, a vast majority of their lives is recorded somewhere online. They are active on social media, SMS, chat, email, and every other technology designed to stay in touch 24/7.

Our idea of privacy is not theirs, and everything from racial prejudice to the stigma attached to nudity will standardise and globalise, and I cannot help but think for the better. Your children’s education will no longer be tied entirely to the doctrines of the previous generations, and self perpetuating ignorance has no place in a time when every piece of knowledge is at your fingertips. Not that this will stop those determined to be an arse.

I’m certainly not talking about some utopia here, ignorance in all its forms will never go away, but if the vast majority of your life is an open and available book, your complete identity becomes an ultimate form of authentication, and the security OF your identity only gets better as your life progresses.

The current ability to authenticate only against static data will no longer suffice (passwords, secret questions etc.), and the coming methods of identity management and authentication will completely change the face of privacy.

I see this as a good thing, but I’ll leave it to the folks hiding away in Faraday cages to make sure that Big Brother doesn’t get everything his way.

 

In continuation of my crusade against EMV in general, the card schemes have announced an end to issuer-only fraud liability for non-chip transaction starting in October 2015. The so called ‘liability shift’.

For those who don’t know, it’s the issuers of the credit card that accept the liability for fraud during a branded credit card transaction, which is why they receive the lion’s share of the fees associated with the transaction (interchange fees). But now, if the merchant does not upgrade their point-of-sale terminals to those capable of accepting chip cards, it’s the merchant who suffers the fraud loss. Same thing goes for a consumer who wants to continue using swipe  & signature cards.

While I assume that those with disabilities, and / or the elderly will be given the option to not change to chip & PIN, the fact remains that the enormous cost of the transition to this ‘new’ technology will not be born by those who have basically created the problem over the course of over 60 years; the card brands. It will be the consumer …eventually, because the merchants / retailers will have to re-coup their up front costs.

And all this just to keep taking credit cards!

Why do retailers and banks STILL see credit cards as the only form of non-cash payment? Why DO the card brands have so much power over end-user payments technology when there are ‘only’ ~6 billion credit cards in the world and >7 billion mobile phones? On top of that, mobile phones have a far wider distribution than an EMV infrastructure can EVER hope to duplicate, and you have what I would see as a very simple choice in how to transition away from plastic.

I’ve said it repeatedly; payments is NOT about the FORM of payment, it’s about authentication of the individual to the organisation holding the funds (usually a bank), and NO form of account-detail-up-front (read credit card number, even a token of one) can ever be as secure as one protected by proper identity management. Yes, even on a mobile device.

What the US retailers are going to do is spend an absolute fortune on a payment acceptance technology that will be impossible to upgrade to anything else, nor will it be anywhere near as flexible for those retailers wishing to innovate in new forms of value-add services and marketing drives.

I have no problem with the card brands making a ton of money, that’s business and they do have a lot to add in the payment arena, but to continue the push for EMV is as horrendously self-serving as it is pointless. If it’s not them pushing for it, and it’s actually the Fed, then THEY should do their homework and talk to the retailers.

However, if the retailers aren’t going to do anything about this, then it pretty much serves them right.

For example; What card brand or issuer is going to tell Walmart that they can’t use an EMV alternative that has been shown to have a similar security profile AND infinitely greater business benefits? Can you really see them giving up a multi-million dollar revenue stream just to enforce a patch on a 60+ year old technology?

No, neither can I.

First, any discussion on ‘mobile payments’ needs to start with a explanation of what I mean by it. There are many definitions and types of mobile payment; anything from SMS, to direct mobile, to mobile web, and from NFC to QR can all be labeled a ‘mobile payment’.

However, from my perspective, there are really only two main categories of mobile payment:

1. A mobile device is used in authenticating the individual making the payment, the transaction happens in the background (e.g. e-wallets), and;

2. An application on the mobile device passes the sensitive payment details (e.g. paying with credit card through a web browser)

Clearly 1. is better than 2., as mobile phones will probably never be as secure as we’d like them to be.

Second, I think it must be understood that ‘payments’ in general is NOT about the payment itself, that’s just detail, it’s about the authentication of the individual making the payment. Whether you have a checking account, a line of credit, an e-wallet, etc. as your source of funds, you don’t care how you get to it as long as doing so is safe, convenient, widely available, and value for money.

However, safety and convenience have always been, and will always be, a balance of mutual exclusivity. In other words, the more you have of one, the less you have of the other.

The reasons mobile payments are nowhere near as ubiquitous as credit cards […yet], are myriad and include;

1. Credit cards are familiar to, and used by, a large chunk of the planet. There are approximately 7bn of them out there and they have been around for over 60 years

2. They are very widespread, and the use of them is a well establish process

3. Smartphone use is not as great in some regions as it is in the US / Europe, significantly limiting the available payments functionally

4. Large retail have not adopted them significantly, and the card brands are making things difficult

5. People just don’t trust them yet, and they are more complicated for the ageing portions of our population

However, this will not stop the trend, and these two ‘statistics’ pretty much say it all;

1. The average time it takes to realise you’ve lost a credit card is 11 days, the average time it takes to realise you’ve lost you mobile phone is 4.5 MINUTES.

2. By the end of 2014, there will be more mobile phones in use than there are people on the planet (>7bn).

Unfortunately  the transition of the non-cash payments ecosystem to mobile will be from credit cards, which requires the support of the card brands, who, for obvious reasons, are loathe to provide it. Both the PCI DSS and the PA DSS standards stifle innovation by making any form of compliance for mobile payments on Cat 3 mobile devices (phones, tablets etc.) exceedingly difficult, and in some cases, impossible.

I have to assume that once the card brands are ready to roll-out their OWN mobile payment infrastructures, the transition will happen much faster. This must involve alternatives to EMV, and any solution must be scalable, and future-proofed, so they’ll need a couple more years to get themselves sorted.

The card brands employ a lot of VERY smart people, and I have to further assume that there are entire departments dedicated to digging them out of the hole they have spent decades creating. From the physical infrastructure (PEDs, back-end servers, credit cards etc.) to sector dependencies (PSPs, acquirers, service providers etc.)  the credit card payment ecosystem is enormous, and enormously complicated. The transition of plastic to mobile will take a long time, but I think the brands have a lot to offer in the space if they decide to play fair.

In the end, mobile applications will rule the day, at least until the next thing comes along. It most certainly won’t take 60 years like the cards-to-mobile transition – and I suspect will involve some sort of implant – but entire fortunes are there for the taking in this space. The functionality, convenience, and yes, even the safety of mobile applications mean that they will be the next big thing. Competition will be massive, which can only benefit the most important factor; the consumer.

[It’s clear that this topic has wayyyy too much material for just a blog, so at some point I’ll back this up with a white paper or some such. Please accept this as an amuse-bouche];

Today, the savvy buyer does their homework on all major retail expenses, ensures they have they the funds for it (debit or credit), and finds the best deal BEFORE buying.

The non-savvy, or impulse buyer, tends to get hosed, which may result in several things; the buyer either changes their minds and returns the item (and/or gets into financial difficulty), the merchant has a second-hand system to get rid of AND has the hassle of a charge-back, and the financial institution behind the payment runs the risk of non-repayment of the resulting bad debt.

While you’re never going to get away from consumers making bad decisions, you CAN make level the playing field, and make the experience for all parties less risky, more efficient, and potentially cheaper all round.

Two of the challenges we face today are:

  1. The vast majority of new businesses in the payments space are innovators, and have a very narrow focus. i.e. see a need, fill a need from a niche perspective. So if you’re looking around for those types of services, you have hundreds of small organisations from which to choose, and you either gamble, or wait until the market settles down and risk missing out entirely on a potential competitive edge.
    o
  2. Every player in the payments ecosystem is either a dependent, or in competition, leaving everyone worse off, especially the consumer. You just have to look at the number of e-wallets, coupons, or loyalty point systems to see that 99% of them are unsustainable. The corollary is that new innovations in the retail space are very slow to be adopted, if at all.

So how do you choose the right combination of payment services for YOUR business?

Choose the right one(s) and the benefits are clear and ongoing, choose the wrong one(s) and you’ve potentially damaged your brand reputation. How many times have you collected loyalty points (for example), and never had the opportunity to enjoy the benefits?

The biggest issue the payments ecosystem faces it that the true cost of an expense if rarely apparent up front, and your payment options are limited to the offers of either your existing financial institutions, or of the retailers themselves.  Instead, what if the banks made available enough information at the time of purchase for you to choose the RIGHT payment option?

Bob Mackman wrote a short white paper How to Pay: The Future for Mobile in m-Commerce, in which he posits that for a mobile application to;

…weigh up the advantages of each [payment method] by looking at things such as: available credit, due date, interest rates and any loyalty schemes and give them the pros and cons of each for this particular purchase at this moment in time. Perhaps putting them into an order of preference.

…that the background financial institutions would first need to provide;

“…direct access to the information from the bank and card accounts being used. If the providers made API’s available for even just some basic transactions then this would be possible.”

You can imagine how often his happens currently.

But, if the banks could see the amazing potential this provides, then this would not be the “pipe dream of a romantic“, as Bob puts it, but a reality in which anyone NOT providing these services is left behind.

Like most things, it’s not that easy. For this to truly work you have to consider all of the following and many more:

  1. Authentication – ALWAYS the primary consideration in payments
  2. Ratings & Reviews integration – against financial services, retailers, products etc.
  3. Big data analytics and customer profiling resulting in targeted displays / coupons based on instant access to metadata of preferences (e.g. material / colour / designer)
  4. Existing payment technologies – PEDs, EMV, NFC, e-wallets and so on…
  5. New[er] payment technologies – Bluetooth beaconing, geolocation, bio-metrics and so on…
  6. Payment choices / instant credit through existing financial institutions (which has dependencies on single purchase interest rates and unaffected credit ratings etc.)

So who’s going to be able to put this all together? No-one currently, but in much the same way that the enormous growth of telecoms options resulting in a spin-off industry of consultants providing consolidation / savings services, the soon to be exponential growth of payment technologies will spurn a new breed of consultant; the payments Service Provider Integrator (SPI).

From banks, to payment gateways, to ratings & reviews, to loyalty, to anti-fraud, the SPI will be able to seamlessly integrate all the niche providers into a whole-istic solution designed to meet an organisations goals.

Here I must stop, but this will continue in more detail in the pending white paper.

If you have any ideas around this stuff, please share, I’ll make sure to build it in.

 

Anyone who has read my blogs knows that I am very critical of credit cards and EMV as payment technologies. I am also equally critical of the card brands themselves for attempting to spread their use when there are so many other more convenient, safer, cheaper , and future-proofed options out there. With mobile applications, e-wallets, and whatever comes next, the piece of plastic with which we are all so familiar will die in its current form.

Then two products come along and I find myself having to adjust my thinking …somewhat. I still think the card brands are wrong, but I have reached my own internal compromise based on one difficult truth; I have become so enamoured with innovation, that I have lost touch with the only question that’s relevant;

Is it functional?

To me, there is no innovation without practical application, and no function without benefit and use. In other words, innovation is great, but if it’s not adopted, AND makes things better, it’s just a fad.

The two products that caused this revelation are pinCode and Coin:

pinCode is an awesome little product that covers a gamut of authentication mechanisms in a credit card sized token, and Coin allows you to load multiple credit / debit cards on – you guessed it – a credit card sized token.

Each has a fundamental flaw; pinCode cannot replace multiple cards, Coin does not authenticate payments.

Now imagine if you could combine the two.

You would no longer need multiple pieces of plastic you would have just one. Whether you load your credit cards, debit cards, branded, non-branded, or any other form of electronic payment information, it would now all be in one place, with authentication mechanisms built in that would cover every provider.  No more chip and PIN, pinCode takes care of that, and no more thick wallets, Coin takes care of that.

Added benefits;

  1. The bluetooth technology in Coin could be adapted for non-NFC contactless payments, as well as its existing security feature of alerting you if the card is more than x feet away
    o
  2. Backwards compatibility with magnetic stripe only terminals, but each bank could add authentication mechanisms with the pinCode functionality
    o
  3. Continued use of existing credit accounts, but now without the need to issue credit cards. The information contained on a credit card magnetic stripe or the EMV integrated circuit (IC) can just as easily be sent or downloaded as long as the authentication is sound
    o
  4. Chip and PIN would be unnecessary globally. Therefore no requirement for expensive payment terminals, leading to a massive expansion of payment technology to emerging markets / micro-merchants
    o
  5. Every bank can be its own payments scheme and neither the cards, payment terminals, or back-end systems are tied to any particular card brand or region
    o
  6. Your ‘credit card’ can now be used for multiple authentication requirements; from a physical security pass, to 2 factor authentication, to call centre mutual authentication
    o
  7. Carrying a ‘spare’ credit card is now so much simpler. As a frequent traveller, I not only have a spare credit card, I have FOUR spare credit cards just in case (Visa Credit, Visa Debit, MasterCard, Amex). Being able to replace all the credit cards with a vastly improved one, as well as not having to worry about it being stolen makes me drool

However, and back to my original point, this MAY end up prolonging the life of the card brands, but even I can’t deny that there are literally hundreds of millions of people who are already used to carrying little pieces of plastic. As long as this ‘interim innovation’ can instil more security, greater functionality, and perhaps a little more competition, then so be it.

Mobile applications and smartphones will rule the day eventually, and the combination described above will actually begin the process of educating people that electronic payments and phones will no longer be as separate as they are now.

This is the perfect gap-filler between present and future, and it all points back to where it began; authentication.