Category: Mobile Payments
Cash is King especially when the battery dies or the power goes off
Digital payments are growing, but consumers aren’t ready to abandon real money
Cash is king let us never forget it. Cash has always been the primary form of payment. It was until very recently accepted everywhere. Most likely will once again be accepted everywhere especially given the need to make sure we do not disenfranchise the unbanked and underbanked will remain the default form of payment
This said, what always amazes me is how so many authors forget Apple Pay, Google Pay and the other NFC based mobile phone based payment solutions are simply another device capable of carrying your debit and / or credit card credentials.
What many of these authors are starting to remember is how much it costs a merchant to accept these alternate forms of payment. I wonder when they will also begin to appreciate how many if not all of these alternate forms of payment only work when the power is on. Our always on society assumes power never goes off. We dream of everything in our mobile phone and forget when we last could not use our phone because the battery was empty. Or the store clerk who could read your card because the power went down.
This is one of the redemining facts about cash. Cash exists without power and can be used whenever.
What Happens When the Lights Go Out
Since 1984, when I was told I needed to carry this mobile phone with me, there has been that nagging issue of needing to make sure it had enough life to get me to the next charge point. My first phone was luck if it could last a half a day so they gave me two, one was always being charged while the other hung on my shoulder. In 1993 while working on the development of the EMV Specifications we focused on the ability to authorize a transaction when the Point of Sale POS device was unwilling or unable to reach the issuer. In 2013 I listened to Visa representatives explain how 100% of all payment transactions could be executed online. Then I ponder getting a Tesla Model 3 and learn it is only capable of traveling a maximum of 310 miles, it make me wonder; how do I finish the last 19 miles to my fathers home.
Today, I was reading an article emanating from the Money 2020 event when IDEMIA spoke of the idea of the mobile drivers license and that nagging feeling emerged. What happens when the power goes off after the hurricane hit and someone asks me for my drivers license. Its locked securely inside my dead mobile phone. I then saw that their competitor Gemalto and even NIST are working on this concept of the mDL.
We live in a world where electricity is becoming as essential as water and food. Yet, we hear of power outages that last weeks and even months.
It is like with Mobile Payments, if the phone is dead and in order to pay it must, then what?
The card remains the essential element of a successful payment transaction.
I dream of the day when I can merge my leather wallet and my mobile device into one. Yet, I appreciate there are technical challenges like the need for electricity. Until we lead with these technical challenges and not simply the dream. Exciting concepts and ideas will go where so many have gone before.
Digital Identity
Question for all those who advocate migration from card to electronic
We all are aware and many of us dream of a time when all of our physical identity artifacts are digital. We dream of consolidating these credentials in our electronic wallet, otherwise known as our mobile phone.
Today while visiting an outpatient imaging center, I was asked for my driver’s license. She would only accept the physical document, I offered to send an image by email. Her goal to scan my identity document into the electronic patient file she was creating. The idea of an image of the driver’s license in an email, well.
Sure the system could easily be changed to record digital credentials delivered by NFC or BLE. The first question, given the expensive medical system we have here in America; at whose cost?
Time could not be argued as a saving, she would only have saved a second or three of time to pass the card back to me.
People discuss contactless cards and contrast them to the convenience of a Mobile Wallet. What we often forget is the reality. As long as we need to carry other physical identity artifacts, the convergence of our leather wallet into our electronic device is not happening.
In my humble opinion, it is an all or nothing situation. Yes, I will add digital credentials into the mobile wallet. But, unfortunately, the leather wallet is still part of my attire.
Better still, it does not need to be recharged. My leather wallet still works after the phone’s battery has died.
Mobile Payment – Thoughts after listening
Thoughts resulting from The webinar Doug King of the Atlanta Federal Reserve gave on “Future Proofing Payments”
The long standing question of the future of Mobile Payments, again discussed and again similar conclusions.
- Will the American market embrace the idea of mobile payments?
- Is it a question of when or a question of why?
- Why do emerging markets embrace new ways and mature markets resist?
- Is it all about acceptance and the merchants investment in contactless reader capability?
- Is it an all or nothing concern?
- Could it be simply reality, as ling need our wallet with other cards e.g. our drivers license, why eliminate payment cards from the physical wallet?
Doug touched on all of these questions. He shared relevant statistics demonstrating the slow and possibly indistinguishable grow in usage of mobile wallets. He shared the success of several of the merchant proprietary mobile payment approaches.
Which leads me down the path of another question. What is the value proposition that will ignite the use of our phone and devices as carriers of our means of payment? The possibility to create value simply with a electronic wallet carrying only means of payment, does not create an exciting proposition.
Our mobile phones and connected devices provide us with such value
We have embraced dozens of apps. They help us to navigate, shop, explore, play and learn. Our phones are beginning to become security devices, taking advantage of sensors to integrate biometrics into how we access and authenticate ourselves as we browse and explore the ever increasing digital place we now call cyber space.
There is another phenomena emerging as a result of how we are transforming how we engage. Some called it the “Uberization” of payments, the ability to make payments frictionless. A change so profound we must stop and reflect and ponder what next.
I recognize there is a repetitive theme to my musing.
When physical world merchants fully embrace the concept of omni channel and build their virtual and physical experiences to complement and augment one another, then, with the ability to integrate payment seamlessly into the shopping experience a value proposition emerges.
What is EMVCo goal with the release of their SRC framework
October 2017 EMVCo published version 1.o of their Secure Remote Commerce Technical Framework. Today I decided to read and appreciate what they are trying to accomplish and then consider how it ties into what I remember and think we need to do moving forward.
Clearly the challenge links back to the now infamous New Yorker Cartoon.
We have not successfully established a means of assuring the identity of an individual when presenting payment credentials (the PAN, Expiry date, name, billing address and CVV. The first attempt, still not 100% implemented, was the introduction of CVV2, CVC2 or CID a 3 or 4 digit number printed on the back or the front of the payment card.
We then developed something called SET or Secure Electronic Transactions and unfortunately the payment networks were not willing to allow Bill Gates and Microsoft to earn 0.25% of every sale for every transaction secured by SET he proposed to build into Microsoft’s browser. Without easy integration into the consumer browser, the challenges of integrating SET into the merchant web pages and the Issuer authorization systems caused this effort to fail the death of some many other noble but complicated attempts to create a means of digital authentication.
Next came 3D-Secure, a patented solution Visa developed. It offered what was considered a reasonable solution to Cardholder authentication. Unfortunately, given the state of HTML and the voracious use of pop-ups, the incremental friction, led to abandon shopping carts and consumer confusion. Another aborted attempt at Internet fraud mitigation.
Yet 3D-Secure was not a total failure. Many tried to enhance it, exploit it and avail themselves of the shift of liability back to the Issuer. Encouraging consumer engagement and adoption was futile in some markets mandated and cumbersome in others.
Now let’s consider what EMVCo is attempting to do with their Secure Remote Commerce Technical Framework. As I started to read, I ran into this:
“As remote commerce becomes increasingly targeted and susceptible to compromise, it is important to establish common specifications that protect and serve Consumers and merchants.”
Clearly the authors do not have institutional memory and cannot remember the various attempts alumni of these same organizations spent time on and encouraged many to invest in their implementing. Clearly this lack of historic context will leave some pondering the purpose of this paper.
I then read this sentence and reflect back on a recent hearing on “Social Security Numbers Loss and Theft Prevention” in front of The House Ways and Means Subcommittee on Social Security
“Over time the Consumer has been trained to enter Payment Data and related checkout data anywhere, making it easy for bad actors to compromise data and then attempt fraud.”
Once again, I stand troubled by how the Payment Data clearly printed on the face of the card and especially the PAN, 11-19 digits, designed to simply be an identifier, was converted into an authenticator. Like the social security number, the drivers license number, the passport number and your library card number, the PAN and other “Payment Data” was never designed to be an authenticator. It was meant to be data a merchant could freely record.
The secure features of the card
now the EMV cryptographic techniques otherwise referred to as the Application Request Cryptogram “ARQC”
were meant to offer the “What You Have” factor in a multi-factor authentication scheme.
As I began to appreciate the scope of this document, the term “Consumer Device” becomes critical. I began to wonder if a PC is a consumer device or if a consumer device is only something like a mobile phone, watch or other like appliance. Fortunately, later in the document, the definition clears up any confusion created by the earlier use of this term.. This said, I then wonder about the difference between what they define as Cardholder Authentication and Consumer Verification?
After reading through all the definitions, I ponder why the authors had to change terminology? Why could they not embrace known and recognized nomenclature. Do we need a new vocabulary?
I wondered:
If this is another attempt to create a revenue stream for the payment networks?
Or, is this the effort of a “closed standards” body to reduce the potential value of the W3C WebPayments activity?
In search of an answer to this last question, I found this discrete comment inside the SRC FAQ.
9. Are any other industry bodies working in this area?
EMV SRC is focused on providing consistency and security for card-based payments within remote payment environments.
EMVCo aims to work closely with industry participants such as W3C to capitalise on opportunities for alignment where appropriate.
Having read bits and pieces of this and the WebPayments efforts one does wonder what is EMVCo trying to do. We shall see?
Will Wal-Mart Pay surpass Apple Pay, Samsung Pay and Android Pay
Walmart Pay to surpass from pymnts.com – from the Washington Post. – and another
To open the news and find more than a press release in fact true commentary describing the success of a merchant mobile payment solution. This is big news and speaks to the value of loyalty and the power of largest global merchants willingness to focus and innovate.
ISIS the new Mobile Commerce JV … What next
This goes back to november 2010 when the announced ISIS (renamed SoftCard now dead and buried)
Over the last week many of us have read and attempted to understand what are the goals and objectives of Isis and its owners AT&T, Verizon and T-Mobile.
Visa reacted, pundits speak of ISIS becoming a new payment brand/system and Google, Ericson, Apple and RIM all are embracing NFC and speaking to inclusion in the mobile phone.
To include all these links would take more space than appropriate. A simple Google search with key words like ISIS Mobile Commerce etc. will quickly get you to more than you could digest.
Doc: EPC 220-08, Version 1.0 January 2010
What occurred to me is that Isis could set itself up as a “Trusted Service Manager” TSM, taking on a trust function supporting Issuers and Mobile Network Operators MNO and why not the merchant; who all all talk about the capabilities of the mobile phone and will want to dematerialize their cards and install their certificates, data and applets within the context of a mobile wallet. ISIS can then derive their revenue from fees assocaited with “Trust” and assuring the identity of the owner of the phone,.
I do not see ISIS becoming a new means of payment. I see them becoming an enabler that helps build the business case to drive the necessary investments merchants and carriers must make to assure the consumer that they can move all their cards into their mobile phone. Mobile Commerce is the key words that leads me to think about coupons, loyalty, rewards, push marketing …
As we all know contactless and NFC are not getting the traction one might have expected. Mobile loyalty, Mobile commerce, services branded as a means of enhancing the customer experience those I do imagine will excite merchants and consuemrs to demand NFC capabiliites. Imagine walking into a store and getting coupons and discounts as you tap and add to your shopping cart. Clearly merchants appreciate that they can drive consumers to buy more it they can excite them.
Payment – Mobile Payments – Connectless payments and an opening to further discussion
Each day I receive a variety of articles on the subject of mobile payments and find countless opinions about the evolution, risks and capabilities of mobile payments.
As is always good form a definition is in order. I could begin by suggesting a mobile payment is any time that while moving about I can purchase something from someone using some recognised means of payment or currency. So at the most basic level of understanding carrying cash in our pockets was and still remains a form of mobile payments. Yet this is not what we mean when we discuss mobile payments. What we have done is combined two words from two worlds into a new thought. Mobile emerging from the arena of telephony and the use of the concept of a phone that does not need to be connected with a piece of wire. Wireless, cellular and mobile all are terms that we associate with the use of radio waves to connect a telephone to a network allowing us to make phone calls from someplace that is in proximity to a receiver or cell tower or satellite. Now I’m sure all of my readers know these things and are wondering what is the point.
The point is that we also talk about contact-less payments that concept of waving a card in front of an antenna, thus allowing the card to receive power through induction and then communicate with the device controlling the antenna. Some people call it that “Tap and Go” feeling others refer to it a PayPass, Visa Wave, Express Pay card and if we travel the world we will find an assortment of other brand names such as Dexit. In many cities transit agents discovered that by employing contact-less cards interfacing with – terminals they could create efficiencies, improve information about ridership and maybe even reduce fraud.
So now we have to discuss the application of the technology. This brings us to the idea of closed loop and open loop systems. Neither are new thoughts, charge cards issued by department stores are closed loop they only work at that companies stores. Open loop refers to systems that are widely accepted because someone has gone out and branded a concept, convinced merchants it is convenient and then offered a “Card” to you and I so that we can be identified and employ this “Means of Payment”. Classic brands that we think of as Open Loop systems include money, MasterCard, Visa, Interac, PIN, eurocheque and an assortment of national brands.
Yet all of these systems have inherent inefficiencies. Inefficiencies that some see as benefits and others see as highway robbery. Then there is that class of people who enjoy getting something for “nothing” they like the idea of counterfeiting money, replicating credit and debit cards, capturing our PIN and ultimately stealing our identity and more importantly our hard earned money. I could also mention merchant discounts, late fees, interest charges, interchange but those are all for another day.
The operators of these systems understand or learn about these various methods of “Stealing” identity and money and have built systems to mitigate the risk, eliminate no minimize yes. In Europe and throughout the world (except the USA) the members of MasterCard, Visa and the various domestic systems are working to reduce these threats by introducing Smart Cards or Chip Cards all cards employing the EMV specification that have a computer embedded within. The benefit is that PIN can easily be introduced on credit cards, the cost of telecommunications can be reduced by allowing the computer in the card to make intelligent decisions when ever that card is used to effect a payment.
This movement to secure payment cards with the technology and specifications defined within the EMV specifications began first in France where they went out on their own developed their own specifications and proved to the world that smart cards or chip cards can and will reduce the level of card present fraud and can if employed properly also reduce the cost of telecommunications. their success can easily be seen in this chart that tracked their progress and success.
![]()

Remarkable success, yet they were now faced with an issue. First the criminals understood if they disabled the chip (computer) the merchant could still swipe the card and read the magnetic stripe. This one easily could be solved by eventually not allowing cards that should have a chip to be swiped through the magnetic stripe reader. But what about when these cards were used in Holland, England or anywhere that had not, and at the time no one had, adopted the same means of defense. The net result fraud migrated from being a domestic issue to the cards being used in neighboring countries. Obviously the French became proponents of a global migration to smart cards and convinced Visa, MasterCard and Europay to develop the EMV specifications, recognising that they would have to eventually convert.
I could continue to digress from my main theme and talk about how each country went through its decision making process. I could then go on and talk about how far along they are in their implementations. Suffice it to say some are finished, others are diligently working towards completion and others are moving at a pace that does not cause undue expense and allowing natural replacement cycles to drive the timescale for implementation.
Here in the country where I live they also have a Chip Migration strategy. Canada is inpilot or a trial depending on how the lawyers interpret the efforts of banks potentially colluding together. By the summer cardholders in the Kitchener Waterloo area will be using these chip cards and the media, banks, merchants, processors and associations will be monitoring and learning how the Canadian’s feel about and their willingness to embrace the change.
The following chart outlines Interac’s schedule for deployment. MasterCard is playing along without committing. Whereas Visa has stated that they will push the liability for fraudulent transaction not protected by EMV to the Acquirer if their merchants are not compliant by October of 2010.
So how does all of this affect the introduction of Mobile Payments or Contact-less Cards. A mobile payment is simply, today, a contact-less payment performed using a mobile phone with the contact-less interface inside as apposed to to using the card as the form factor.. Well some will say not at all, the drivers are different the business case is not the same. Yet the core technology is a computer in the card. So why worry, eventually all of this could come together. Or will the USA decide to take another path all together.
So to end this particular blog I ask a simple question, based on the premise that the mobile and contact-less payments that we see emerging are all about speeding up low value <$25 dollar transactions. What happens when I want to use my contact-less mobile phone for a payment for say a $1,500 hotel bill. Will I tap my contact-less device “mobile phone”. Have to find a place to put it while I either enter my PIN or sign the receipt. Today the clerk typically holds the card for me while I sign the receipt tomorrow what. Or will they decide to merge contactless and EMV creating a more interesting problem. I’ll need to keep that phone near the antenna while my PIN is verified and the transaction is authorized.
Or should we go on and talk about the security concerns that everyone has described in countless articles and numerous logs. The idea that the criminal will walk down the street reading the content of your purse or wallet with their hidden antenna.
Or should we talk about who is going to pay the price of adding the contact-less antenna to the merchants point of sale equipment.
Let me hold those for another day and another flow of thought.
Legacy infrastructure impedes truly innovative disruption
An interesting thought – Is the USA behind in adopting payment technologies.
Areas that one could ponder are:
* Payment Card Security
* P2P Mobile Payments
* P2P and P2B Electronic Funds Transfer as part of Home/Mobile Banking
* Elimination of Checks including Check images
* A/R and A/P electronic payments integration
* …
What would be interesting is to eventually be able to catalog the global differences and define the ultimate payment capabilities a country should adopt.
Please let’s share and explore.

