Anyone who has read my blogs knows that I am very critical of credit cards and EMV as payment technologies. I am also equally critical of the card brands themselves for attempting to spread their use when there are so many other more convenient, safer, cheaper , and future-proofed options out there. With mobile applications, e-wallets, and whatever comes next, the piece of plastic with which we are all so familiar will die in its current form.
Then two products come along and I find myself having to adjust my thinking …somewhat. I still think the card brands are wrong, but I have reached my own internal compromise based on one difficult truth; I have become so enamoured with innovation, that I have lost touch with the only question that’s relevant;
Is it functional?
To me, there is no innovation without practical application, and no function without benefit and use. In other words, innovation is great, but if it’s not adopted, AND makes things better, it’s just a fad.
The two products that caused this revelation are pinCode and Coin:
pinCode is an awesome little product that covers a gamut of authentication mechanisms in a credit card sized token, and Coin allows you to load multiple credit / debit cards on – you guessed it – a credit card sized token.
Each has a fundamental flaw; pinCode cannot replace multiple cards, Coin does not authenticate payments.
Now imagine if you could combine the two.
You would no longer need multiple pieces of plastic you would have just one. Whether you load your credit cards, debit cards, branded, non-branded, or any other form of electronic payment information, it would now all be in one place, with authentication mechanisms built in that would cover every provider. No more chip and PIN, pinCode takes care of that, and no more thick wallets, Coin takes care of that.
Added benefits;
- The bluetooth technology in Coin could be adapted for non-NFC contactless payments, as well as its existing security feature of alerting you if the card is more than x feet away
o - Backwards compatibility with magnetic stripe only terminals, but each bank could add authentication mechanisms with the pinCode functionality
o - Continued use of existing credit accounts, but now without the need to issue credit cards. The information contained on a credit card magnetic stripe or the EMV integrated circuit (IC) can just as easily be sent or downloaded as long as the authentication is sound
o - Chip and PIN would be unnecessary globally. Therefore no requirement for expensive payment terminals, leading to a massive expansion of payment technology to emerging markets / micro-merchants
o - Every bank can be its own payments scheme and neither the cards, payment terminals, or back-end systems are tied to any particular card brand or region
o - Your ‘credit card’ can now be used for multiple authentication requirements; from a physical security pass, to 2 factor authentication, to call centre mutual authentication
o - Carrying a ‘spare’ credit card is now so much simpler. As a frequent traveller, I not only have a spare credit card, I have FOUR spare credit cards just in case (Visa Credit, Visa Debit, MasterCard, Amex). Being able to replace all the credit cards with a vastly improved one, as well as not having to worry about it being stolen makes me drool
However, and back to my original point, this MAY end up prolonging the life of the card brands, but even I can’t deny that there are literally hundreds of millions of people who are already used to carrying little pieces of plastic. As long as this ‘interim innovation’ can instil more security, greater functionality, and perhaps a little more competition, then so be it.
Mobile applications and smartphones will rule the day eventually, and the combination described above will actually begin the process of educating people that electronic payments and phones will no longer be as separate as they are now.
This is the perfect gap-filler between present and future, and it all points back to where it began; authentication.

Coin seems to be a way of replicating MSR data, but there are multiple points of concern: it wants a picture of both sides and a skim of the card, which it somehow syncs with the card; there is no explanation of the security design; the somewhat disingenuous answer to PA-DSS makes me nervous; no mention that this probably breaks your contract with the credit card provider.
pinCode links to me to Emue Technologies, which just seems to be an authentication service delivered with a ISO7810 end-point format.
EMV already supports multiple applications, but no provider is willing to have other providers apps on ‘their’ card, so consumer ease of use has already taken a back seat.
I tend to agree with you that we are not going to see any real innovation in the card payments space until the brands wake up to the threat from e-wallets and mobile apps, and I include PCI SSC in the scope of the card brands.
For me, they signed their own death warrant when the SSC came out and said that no consumer mobile device can be PCI-DSS compliant; the inescapable conclusion is that PCI-DSS compliance is (will be) irrelevant.
Very many thanks for your comments Mark, and I did want to address a couple of your points;
1. Re: Coin, I could not agree more, which is why an association with Emue would be good for both organisations. For me, security is of primary importance, not functionality, but most people not IN security do not feel that way. Which is why we have jobs in the first place. 🙂
2. Emue Technologies makes pinCode, but they are clearly a bunch of techies relying on channel / distribution partners to distribute their product. I say ‘clearly’, but maybe they WANT to be a silent partner in this.
3. From my perspective, the whole deal with offline authentication via an IC was a bad idea, and has resulted in an entire industry making VERY expensive PEDs just to comply. If you accept that there are other authentication mechanisms better than a physical chip, then there’s no reason EMV/Chip & PIN won’t die along with the card brands. At least in their current form.
4. Last two paragraphs, again, I can’t agree more.
Take care.
David