The Dual Interface Business Case

These cards and often times the terminals are more expensive than a classic “Dip” EMV card

How much, is dependent on volume, complexity and the pure skill of negotiation. This incremental expense is the first factor one must quantify when building the business case

  • for enabling, in the case of the terminal
  • adding in the case of the card, the contactless antenna
  • upgrading the software by adding the contactless terminal kernels or selecting the appropriate chip software and profile

This then must be compared to the incremental value
For the merchant, issuer and ultimately the cardholder

To explore the benefits lets think about

  • The user experience
  • Availability of merchant contactless acceptance
  • The intersect of the cardholder base with the contactless acceptance infrastructure

As we look around the world and consider what stimulates dual interface card issuance and merchant NFC enablement. Two scenarios emerge.

  • A country made a collective decision and drove NFC terminal enablement and dual card issua.
  • A merchant segment, typically transit, decided to introduce electronic fare-collection.

The first scenario is often driven:

  • By the payment schemes
  • The belief NFC “Near Field Communications” mobile payments will happen
  • A country simply wants to start dual interface and prepare for mobile payments

Which ever option they select, the merchant and financial institutions, within the country, typically migrate together.

In the case of the second scenario, merchant driven migration. We can look to the United Kingdom as a perfect example. “Transit For London” made the decision to migrate from paper tickets to an electronic fare-collection solution based on NFC. The initial deployment was a closed loop payment card, branded the Oyster Card, they quickly decided to upgrade the solution to support Open Loop e.g. Visa, MasterCard and American Express enable dual interface cards and NFC enabled mobile phones.

Given the importance of public transit to the urban demographic. Their decision to embrace open contactless fear collect, becomes a driving factor for issuers and therefore a ripple effect on merchant enablement.

America, as is true in many things, is different.

Contactless was tried last decade without much success.

Issuers did not see any significant lift in consumer spend nor did the merchant see any real increase in revenues. This experiment did not create a perception of a real benefit for either the merchant of the cardholder. Later in this same period, Starbucks launched their QR code mobile payment solution. From its original deployment to now it has been a resounding success.

Around the same time and based on the work of GSMA and the European Payment Council, major telecom operators began toying with NFC based mobile payments. Here in the United States two pilots emerged, the original Google Pay pilot and ISIS (SoftCard) offer. The results were intriguing, the commitment half hearted and frankly both solutions had issues. Google Pay tried to model its solution after de-coupled debit. Whereas the mobile network operators behind SoftCard, wanted to charge the issuers rent and load fees associated with the payment credentials they would store within the SIM.

Merchants Attempted to Create a new Payment Scheme

Major retailers in their continued quest to improve the customer experience and reduce the cost of payments; came together to create MCX the Merchant Commerce eXchange. The hope, merge their existing private label charge card programs together into a Mobile App capable of working across the family of MCX merchants.

Terms where written, in particular one agreeing these merchants would not accept another competing Mobile Wallet. Net result, the merchants agreed not to enable the NFC interface for any of the Visa, MasterCard, Discover or American Express contactless cards or NFC enabled mobile payment devices.
MCX slowly faded into oblivion, as the merchants struggles with the idea of sharing customer relationships and transaction data. Some merchants notably Walmart, Target, Macy’s and Kohl’s set out to build their won mobile wallets embracing QR codes and other none NFC based techniques.

The Introduction of HCE

While this was going on, north of the American border, the idea of HCE “Host Card Emulation” was created by the founders of Simply tapping 2011. It was ultimately by Android and released as part of KitKat in version 4.4 of the Android operating system. With HCE now inside the Android Operating System it unlocked the NFC interface from dependence on the SIM and MNOs. Now any application could take advantage of the NFC interface, once supported by the internarional payments schemes, enabling wider deployment of NFC enabled mobile payments. Google moved ahead to expand its payment ecosystem and Royal Bank of Canada embraced HCE. As Issuers enabled the ability to authorize the load of EMV secured Payment Credentials into the OEM Mobile Wallet or the Issuer’s own mobile app. Consumer now had the opportunity to experiment with mobile payments that communicate with the POS, just like a dual interface card.

Let’s not forget Apple Pay.

Given their brand value and total control of the Apple operating environment, Apple was able to turn to Issuers and suggest they enable the load of EMV secured Payment Credentials into the Apple Pay Wallet. They came at payments with all guns loaded. They knew the value of their brand and were able, unlike the MNOs to ask for a 0.15% of the issuers’ interchange revenue. Most importantly, they facilitated Visa and Mastercard domination of the role of the Trusted Service Manager TSM-SP or better said the Token Service Provider TSP.

Merchant Acceptance Is Key

As has been true with any solution designed to serve a two sided market, issuance and acceptance must grow together to assure the operator success and prosperity. Without a national imperative and with the experience of the original ZIP (Discover), Express Pay (Amex), PayPass (MasterCard) and PayWave (Visa), the merchant must determine if it is worth the effort to enable the NFC interface and train their staff to support Contactless payments.

Transit, like has been true around the world, absolutely sees the value of using contactless, for fare collection and are busy engaging with Visa and MasterCard to embrace and assure acceptance of bank branded dual interfaces cards. Urban areas such as Chicago (CTA), Salt Lake City (UTA), LA Metro, Portland OR (Trimet) and Philadelphia (SEPTA) are live with deployments. Others are in various stages of planned, including the MTA in New York City.

The Business Case

For issuers, where transit is seeking to exploit open loop contactless payments, at the turnstile, there is a revenue opportunity to deploy dual interface cards.

In rural areas or urban communities where public transportation does not exist. The business case is dependent on what local merchants do and if they intend to or will be forced to enable the NFC capabilities of their POS.

This is the big question. Does the merchant see value? Do they believe contactless will increase revenue, reduce time at checkout or do they believe Apple Pay, Android Pay and the other mobile NFC enabled devices are the future?

  • If the answer to these questions is yes then Issuers should seriously consider deploying dual interface cards.
  • If the jury is still out then the investment in dual interface cards may not yet be worth it!

What is the Future Payment Credential Carrier

One cannot discuss contactless payments without thinking about how Apple Pay, Android Pay, Samsung Pay, OEM Pay, Issuer Pay … Device Pay play into the future of cards. Some years ago there were three belief systems

  1. Cards are here to stay the mobile device is a fad
  2. The wallet is replaced by the mobile device
  3. The card is the token of last resort

I think we know mobile devices are not a fad. Until mobile devices never run out of power they will not replace the wallet or all of the cards.

To say much more, given the fogginess my crystal ball, would be to wild a bet.

The following articles produced by the Secure Technology Alliance offer a series of perspectives on the value of migrating to a dual interface card.

Alliance Activities : Publications : Contactless Smart Cards

Alliance Activities : Publications : Payments : Contactless Payments

Alliance Activities : Events : Webinar: Contactless EMV Payments: Issuer Opportunities

Alliance Activities : Events : Webinar: Contactless EMV Payments: Merchant Opportunities

of Identity and Authentication in a Connected World of things.

Various engagement and conversations pull me into thinking about the realities and the necessities, of this emerging world of connected people, objects and thoughts.

Looking back, this topic has been part of my life since 1982 when I was first introduced to the concept of a smart card. At that time we spoke of using the smart card to securely configure a trading deck on Wall Street and in the City of London. The goal securely and automatically configure the voice, video and digital support a particular market trader.

In 1993 to when I was tasked to drive the development of EMV, we could have talked about the fact we were creating a means of secure digital identity. A trusted Identity document based on the trust that existed between the cardholder and the financial institution.

Instead We talked about:

  • Card Authentication “the CAM” now Data Authentication to assure the card was unique and genuine.
  • Cardholder Verification “the CVM” to verify the right user was presenting the card.
  • Card risk management to allow the issuer to support authorization in a offline world.
  • Should we include an electronic purse to support low value transactions?

Today the Debit card could easily be enabled as a secure means of digital identification, with the Financial Institution being the trusted party. Simply knowing the public key of the international or domestic debit card payment scheme allows the party reading the card will know the person was issued this card by that financial institution.

While we in financial services focused on our requirements, the telecom industry was working on the SIM & GSM specifications under ETSI leadership. They created another form of Secure Digital Identity. They focused on securing the identity of the communications channel and were less worried about making sure the right consumer was present, although there is the ability to allow the user to lock the SIM and now even the mobile phone.

2013 I had the opportunity to join the FIDO Board. Within that body, the objective was to separate the concept of identity from the act of authentication. It works from the premise that as digital relationships expanded, the use of passwords and PINs are becomes an issue. The FIDO Alliance also recognized that the only way to secure our digital world, like we secured payments and mobile communications was with the introduction of multi-factor authentication rooted in the belief that the first factor had to be “what You Have” a secure element / enclave, TEE, TPM … capable of generating and or storing secret (symmetric) and private (Asymmetric) keys unique to the object and more importantly unique to the relationship.

Clearly identity and authentication are essential to secure relationships. And, in a digital world, communication is the mechanism that connects people and things together.

Helping consumers manage their relationships assuring privacy is an interesting angle. If I am understanding your platform, at least at the level of the subscription for telecommunications services this you are helping to manage.

Anyway. Back to the pitch. I would like to see about scheduling another conversation and figure out if there is anything I can do to earn an income and create revenue for you.

The Future of EMVCo Next Gen

Back in 2011, when I was part of American Express, I was part of the team responsible for our involvement in the work of EMVCo.  At this stage in the work of EMV the discussion had turned to the confusion the multiple contactless kernels was creating in the market and more importantly the challenges we would face as the external threats increased demanding that the length of the RSA keys increase accordingly.  Ultimately we collectively determined the best course of action was to begin the work on what began know as “Next Gen”.  From the beginning it was well understood the migration from where we are today to the “Next Gen” technology solution, both in the card and on the terminal, would be complex and expensive.  In September of 2014 an initial specification was released and my understanding is that a draft has been issued to subscribers and Associates for review and feedback.

This post stems from a conversation with a good friend, he asked me if I thought there was still relevance to what is now being called 2nd Gen.  In that discussion we reviewed the genesis of the work, the baseline for EMV and the unfortunately reality of how contactless was implemented.  Our conversation then turned to the question of what makes the most sense live with what we have today or suffer the expense of the migration to a new solution.

Thinking back to the original reason for “Next Gen” was to consolidate the 7 contactless kernels into one common kernel and replacement  RSA with what was called XDA or Elliptic Curves.  When I think about these two requirements one can only wonder why in the most recent EMVCo Stated EMV® 2nd Generation there is no  reference to enhanced cryptography.  In fact the only thing the document describes is the creation of one unique kernel.

Referring back to the September 2014 Net Gen Specification there is clear reference to enhanced security with specific call out of “an elliptic curve Diffie-Hellman key establishment protocol with blinding applied by the card”.  I then remember hearing about issues with Elliptic Curves and wonder why there is no reference to enhanced cryptograph in this most recent EMVCo document.

Back to the question raised in our conversation.

Do I see value in the world investing in the migration to 2nd Generation?

The answer is I am not sure anymore. 

When EMV started we had four agreed requirements, summarized on this slide I initially created back in 1994.  Offline Authorization, in other words, the issuer’s ability to securely approve a transaction without requiring the terminal to request an expensive online authorization request was the reason Offline Authentication was part of the original design of EMV.

  • If the value of offline authentication, given the ubiquity of wired and wireless telecommunications networks, is deprecated.
  • If  the performance efficiencies, original seen in Elliptic Curves, is no longer as significant, given the increased threats and vulnerability.

Then why make the investment in changing the software in both the card and the terminal to support XDA?

Next

  • If most if not all terminal manufacturers have addressed the complexity of the multi-kernel configurations, compounded by the existence of various unique national contactless kernels.

Then why demand the investment in supporting a complex migration from multiple kernels to a single EMVCo Licensed kernel?

Finally

The threat of quantum cryptograph suggests that most if not all asymmetric cryptographic algorithms commercially available will be broken.

It does beg the question.

What is the business case for driving the world into a expensive, long and complicated migration?

What we created in 1994, and EMVCo has maintained, is a very effective Online Authentication mechanism, the ARQC.  A mechanism based on symmetric cryptography which, as far as I can tell, will remain under the control of the Issuer and is not, as of yet, threatened by quantum computing.

I look forward to your feedback.

 

 

 

 

 

 

The case for Identification and Authentication

As we continue to explore the case for Identification and Authentication I share the below article.

What is becoming clear is standards are being embraced.

In the Payment space

Will it be W3C WebAuthN, 3DC and Webpayments or EMVCo SRC & Tokenization?

My guess depends on if standards bodies can play well together. EMV (contact or contactless) will remain the many stay for physical world commerce, until the App takes over the Omni Channel shopping experience. then the merchant will properly authenticate their loyal customer and use card on file scenarios for payments. The question of interchange rates for CNP will see a new rate for “Cardholder Present&Authenticated/ Card Not Present.”. In time when a reader is present I can see an out of band “tap to pay” scenario emerging using WebPayments and WebAuthN.

In the identity space

I contend the government and enterprise market will go for a pure identification solution with the biometric matched, in the cloud, in a large central database. In order to maintain a unique and secure cloud identity, they might probably make use of various opportunities that come their way (you can hover over at this website to learn more).

However, does that mean it includes what you know username, email address or phone number? Maybe! If it is simply the captured image or behavior, then it is a 1 to many match. If it is with an identifier, it is classic authentication with a one-to-one match.

In the pure authentication space where the relying party simply wants to know it is the person they registered. Then, the classic FIDO solutions work perfectly and will be embedded into most of our devices. Additionally, the use of a visitor sign in sheet synced with the security database could expedite the sign-ins of visitors. It could also see its applications with employee log authentication and verification. Or, as we’ve seen with some enterprises, the relying party will embrace U2F with be a FIDO Key, like what Yubico and Google recommend.

The classic process needs to be thought about in respect to what can be monetized.

  • Enrollment = I would like to become a client or member
  • Proofing = Ok you are who and what you claim, we have checked with many to confirm your Identity – This is where federation comes in.
  • Registration – Verification = Ok, now we confirm it is you registering your device(s)
  • Authorization & Authentication = Transaction with multiple FIDO enabled relying parties using your duly registered authentication.

How Microsoft 365 Security integrates with the broader security ecosystem-part 1

by toddvanderark on July 17, 2018

Today’s post was coauthored by Debraj Ghosh, Senior Product Marketing Manager, and Diana Kelley, Cybersecurity Field CTO.

This week is the annual Microsoft Inspire conference, where Microsoft directly engages with industry partners. Last year at Inspire, we announced Microsoft 365, providing a solution that enables our partners to help customers drive digital transformation. One of the most important capabilities of Microsoft 365 is securing the modern workplace from the constantly evolving cyberthreat landscape. Microsoft 365 includes information protection, threat protection, identity and access management, and security managementproviding in-depth and holistic security.

Across our Azure, Office 365, and Windows platforms, Microsoft offers a rich set of security tools for the modern workplace. However, the growth and diversity of technological platforms means customers will leverage solutions extending beyond the Microsoft ecosystem of services. While Microsoft 365 Security offers complete coverage for all Microsoft solutions, our customers have asked:

  1. What is Microsofts strategy for integrating into the broader security community?
  2. What services does Microsoft offer to help protect assets extending beyond the Microsoft ecosystem?
  3. Are there real-world examples of Microsoft providing enterprise security for workloads outside of the Microsoft ecosystem and is the integration seamless?

In this series of blogs, well address these topics, beginning with Microsofts strategy for integrating into the broader security ecosystem. Our integration strategy begins with partnerships spanning globally with industry peers, industry alliances, law enforcement, and governments.

Industry peers

Cyberattacks on businesses and governments continue to escalate and our customers must respond more quickly and aggressively to help ensure safety of their data. For many organizations, this means deploying multiple security solutions, which are more effective through seamless information sharing and working jointly as a cohesive solution. To this end, we established the Microsoft Intelligent Security Association. Members of the association work with Microsoft to help ensure solutions have access to more security signals from more sourcesand enhanced from shared threat intelligencehelping customers detect and respond to threats faster.

Figure 1 shows current members of the Microsoft Intelligent Security Association whose solutions complement Microsoft 365 Securitystrengthening the services offered to customers:

Figure 1. Microsoft Intelligent Security Association member organizations.

Industry alliances

Industry alliances are critical for developing guidelines, best practices, and creating a standardization of security requirements. For example, the Fast Identity Online (FIDO) Alliance, helps ensure organizations can provide protection on-premises and in web properties for secure authentication and mobile user credentials. Microsoft is a FIDO board member. Securing identities is a critical part of todays security. FIDO intends to help ensure all who use day-to-day web or on-premises services are provided a standard and exceptional experience for securing their identity.

Microsoft exemplifies a great sign-in experience with Windows Hello, leveraging facial recognition, PIN codes, and fingerprint technologies to power secure authentication for every service and application. FIDO believes the experience is more important than the technology, and Windows Hello is a great experience for everyone as it maintains a secure user sign-in. FIDO is just one example of how Microsoft is taking a leadership position in the security community.

Figure 2 shows FIDOs board member organizations:

Figure 2. FIDO Alliance Board member organizations.

Law enforcement and governments

To help support law enforcement and governments, Microsoft has developed the Digital Crimes Unit (DCU), focused on:

  • Tech support fraud
  • Online Chile exploitation
  • Cloud crime and malware
  • Global strategic enforcement
  • Nation-state actors

The DCU is an international team of attorneys, investigators, data scientists, engineers, analysts, and business professionals working together to transform the fight against cybercrime. Part of the DCU is the Cyber Defense Operations Center, where Microsoft monitors the global threat landscape, staying vigilant to the latest threats.

Figure 3 shows the DCU operations Center:

Figure 3. Microsoft Cyber Defense Operations Center.

Digging deeper

In part 2 of our series, well showcase Microsoft services that enable customers to protect assets and workloads extending beyond the Microsoft ecosystem. Meanwhile, learn more about the depth and breadth of Microsoft 365 Security and start trials of our advanced solutions, which include:

Legacy the American disease

When we look at what this market have done my own journey parrallels.

The adoption of something new it is a human process influenced by culture.

1976 first programming job and exposure to OCR and timeshare

1978 cash management, electronic money transfer, ACH & Wire

1982 Digital, video and voice integration.

What happened to Marginal Satisfaction?

1986 fiber across the Atlantic

The wall

1994 Stir EMV, drive WWW payments, cryptography, MFA

1996 Convergence of leather and technology

2001

2003 EMV in Canada

2008 Lehman went bankrupt

2015 US EMV Liability Shift

2018 WebauthN Web payments Web of things

Now we think next. What next?

Europe Led the way with EMV yet Europe appears to prefer cash

Europeans still love paying cash even if they don’t know it

Interesting to reflect on how much we allow Europe to lead as we think about EMV and the technology we use to secure our payment cards.  Maybe American’s need to embrace and take over the management of these key standards that drive an economy.

In the News as the Vice President of Oberthur Technologies

Oberthur Technology seeks to educate and support the migration to EMV

 

 

An Interview with George Peabody of Glenbrook

 

 

From a merchant perspective Oberthur offers thoughts for consideration

 

Healthcare is in need of secure authentication an Interview with Karen Webster

 

 

An Article published by Pymnts.com as we consider the last days before the migration

 

 

Digital Identity is what we require to secure our world an interview with Karen Webster

 

 

W3C and the WebCrypto Working group considering payments and Same Origin Policy

 

 

Why EMV and Why Now with Pymtns.com

 

 

A Founders of EMV’s view of the US migration to EMV

 

 

Understanding EMV in Our Digital Future an interview with Karen Webster

 

 

Counting Down to the migration to EMV

 

 

The ABCs of EMV

 

 

An interview with the Atlanta Constitution

 

Is recent EMV announcement the catalyst the U.S. needs to catch up?

August 22, 2011

Is recent EMV announcement the catalyst the U.S. needs to catch up?

During this past year, the team at Portals and Rails has published several articles exploring the growing risks in card-based payments and the need to move to a more sophisticated and secure enabling technology. But overhauling a payment system is no easy task, as there are many players that need to collaborate, from the card networks to the bank issuers and merchants. How does the industry organize itself to orchestrate a much-needed transition?

http://portalsandrails.frbatlanta.org/2011/08/lessons-from-mario-brothers-finding-keys-to-fighting-fraud.html

Interesting question for the industry as we go through this transformation to a fully connected world where everything happens between our mobile phone and the merchant, friend, family, phone or cash.

 

 

The path for the USA to EMV

http://www.finextra.com/community/fullblog.aspx?blogid=5875

EMV: Let the planning begin

 

There’s no way around it – EMV transition planning will be complicated. However, while EMV is a complex specification, the good news is that it can grow over time. Thus the key is to implement an infrastructure that lets you start with a simple, single portfolio that can expand and mature with you. Looking forward, the goal is to do it once, do it properly and avoid the pain of re-doing it when it’s time to move into mobile payments

I agree totally with this sentiment. Mobile is here. EMV addresses the requirement to include Dynamic data in a payment transaction to address questions of identity and irritability.

Update 02/22/2012

Having had a chance to sit inside EMVCo working group meeting and being fully aware of those words read every time that reminded us of our confidentiality and sharing of patent and secrets that might jeopardize the future of EMV.

What I saw was the successful release of the EMV contactless specifications and type approval processes capable of testing tap if one remembers the distance has to be 2 cm instead of 10.  Otherwise the protocol and security will last us until 2025.  Plans where underway as I left that where focusing on expanding the standardization of mobile and the development of a next generation or EMV 2.0.  They are talking about 2015 and 2017 for probably dates that these new specifications and processes would be in place to allow widespread adoption so that circa 2030.  If hey are right we have a new and transparent solution that opens and never hinders access to whatever we have the right to access.  what about the next 17 years,

Well, EMV works.  It already includes mobile and contactless.

Visa and MasterCard have said yes.  Amex is OK, discover has had lots of ads for payment people with EMV knowledge and such titles.

The Federal Reserve seems to be on-board and Global Platform, NFC and Mobey forum seem to be OK.

Looks like a plan to me.

What next for Smart Card and Mobile Phone

Why not start implementing EMV in the USA. It is the right thing to do. One global standard.

“Chip and PIN”, EMV … ISO 7614

The New York Times, in the previous post, looks at the issue from the obvious perspective.  The result is as one would expect.  Remember when France first introduced smart cards 1984or mandated then back in 1992 and the acceptance nightmare.

In the past I have written on the idea –

Push PCI/EMV into one coherent electronic and secure smart card reader and PIN Pad.

Mandate all new 1 July 2010; with the understanding that the reality –  every piece of equipment will be replaced in a reasonable period, say 7 to 10 years.

VARs should easily be able to do that.

The incremental ($8/device) on the device side goes down over time, as equipment becomes more affordable.

On the system side, most international providers have a solid EMV implementation they can port over to the US platform over that same 7 year time frame.

At the Network switches, gateways and IPSPs; data formats should be changed sooner, say three years from day one.

Issuers can then decide, when to embrace one  global two factor authentication solution; using contact and contact-less EMV  cards to support card authentication [Factor 1] and card holder verification processes (eg. Chip and PIN) [Factor 2] .

Biometrics were understood when EMV was created.  The mechanisms are in place to introduce an agreed, more secure, biometric verification process [Factor 3].

American Banker Reports

Europe to Eye Mag-Stripe Ban

Cardline Global  |  Friday, June 26, 2009

European banks may consider banning the use of magnetic stripe credit and debit cards, according to Gerard Hartsink, the chairman of the European Payments Council.

Hartsink, who is also a senior executive vice president at ABN Amro in Holland, said that European financial companies will have largely completed the transition to the EMV Integrated Circuit Card Specification by 2011, and the council, which is driving the transition to the Single Euro Payments Area, could then advise its members to stop accepting magnetic stripe cards, which are considered less secure than those that use EMV.

“My feeling is, although it has not yet been decided, the [council] will take a decision in 2011, maybe 2010, to only use chip cards,” he said in comments during a presentation this week at the Contactless Cards and Payments conference in London.

The council has no enforcement power, but if banks in Europe went along with such a decision, it could leave U.S. cardholders in the lurch when they traveled to Europe and tried to use cards for purchases or ATM withdrawals.

“If [Americans] visit Europe, it’s not such a problem; their institution could issue an EMV card,” Hartsink said.

Payments council members will probably debate the issue in 2010 or 2011, he said.

Hartsink is not the only person suggesting a ban on magnetic stripe cards, according to Dave Birch, a director at the U.K. research company Consult Hyperion. In a recent blog post, he cited comments from a financial regulator in Singapore pressing for a “concerted, global effort to phase out magnetic stripe technology entirely.”

America needs to embrace the Future

Back in 1993 I had the opportunity to help in forming the working group who developed and ultimately published the EMV Smart Card Specifications for Credit and Debit Cards.  Since then, as a member of the Europay and Visa Canada executive teams I promoted the virtues of smart cards and the business case for EMV. 

As a consultant, one of the focuses of my practice is EMV.  In both Europe and Canada I counseled executives on the what, how, when, business value and future opportunities of EMV, smartcards. mobile payments and internet payments

One question has always been asked of this American – “when will the USA migrate”.  Up until recently I was stuck, giving bland answers.  I suggested that we would have to wait until after fraud migrated to the USA,  away from EMV protected countries.  I tried to explain to people, committing comparable sums of money, that  the size of the investment required of US Issuers, Acquirers and Merchants is enormous and frankly cannot be justified. 

Why they ask,  simple economics I answered.  I explained that when one looks at the  quality of the fraud management systems in place, the level of on-line authorization and the losses incurred; it simply does not make sense.

Debit is the real reason to Migrate to EMV

In 2007 I was working with “The Exchange”, a Canadian network that supports sharing of ATM services such as deposit, bill pay and account to account transfers.  The focus of my work was to help them to understand the implications of EMV and to work with them to develop their go forward strategy. 

Part of the research led me to talk with the Fiserv, the Brand owner and their strategic partner.  While discussing what the Canadian entity needed to do with the America responsible for the USA Exchange and Accel network; the conversation drifted to when will the USA move to EMV.

What sat front and center inour discussion is the American banks that issue PIN Based Debit Cards have a much stronger rational to migrate to EMV than the credit card and signature based Debit issuers.  In the PIN Based Debit arena the “reputational risk” has and will continue to be the real justificationfor the migrate from magnetic stripe to Chip and PIN.

Why you may ask.  My answer is simple.  The cost to a criminal to install a fascia and PIN hole camera on an ATM, capture the magnetic stripe and PIN; offers these international criminals a very rewarding business case.  They are also funding aggressive operations that embed people into factories that produce magnetic stripe and PIN Pads with the imbedded capability of capturing and transmitting the magnetic stripe and associated PIN to the Mafia

Reputational Risk is the catalyst

 

So how does this affect “Reputational Risk”? 

1.       When the criminal perpetrates debit card fraud, they focus the attack at ATMs the cardholder would probably visit.  The Issuers’ fraud management systems are finding it hard to differentiate between a valid transaction and a fraudulent transaction, so out pops the cash, 100% fungible no need to fence the goods and cheaper and more profitable than robbing the bank

2.       Weeks later the cardholder notices that there is not as much money in their checking account as they expect and they call the Bank’s call center.  The argument follows – But only people who know your PIN can withdraw funds from your account, who did you tell your PIN to, your ex, your children …

3.       Eventually after a lot of time explaining, crying, shouting and generally getting on each other’s nerves; the Bank’s customer service agent will final accept that the cardholder did everything to protect the PIN and card; so the bank will reluctantly restore the funds to the cardholders account.

4.       Bottom line the cardholder feels that the bank does not care; their systems are not safe and the cardholder is now afraid to use their debit card.  The Bank and its ATM network are now at “Risk”.

No one should be surprised at this form of attack.  I knew and teh media presented the realtities of such attacks back in 1994.  As the size cost of the equipment shrinks and the capabilities of technology expands the incidence simply increase and proportional to the rewards.

To put a point on my analysis; when most countries decide to migrate to EMV it is not the Credit side of the cardholder relationship that seals the deal for the CEO and senior executives.  It is the Debit side that pushes the bankers to say yes we must migrate to EMV.  MasterCard and Visa,  who participant in both credit and debit, want the publicity.  Whereas the debit networks would prefer to not talk about the problem.   End result we are left thinking credit cards drive the migration to EMV.  Compounded by the reality that for credit cards in the USA, there is simply not a business case.

For the US banks to come together to decide that EMV is the right thing to do; there must be a place where the Issuers and Acquirers can come to terms with the cost and agree on an equitable way to fund the investment required.  For the debit card side of the Banks there is not an obvious place to have this discussion.  Most PIN Debit networks are either regional or owned by publicly traded organizations.  There does not appear to be a common forum capable of bringing the executives together to agree and commit.

Migration to EMV is expensive – YET really it is not

 

Everyone talks about how expensive it would be for America to migrate to EMV. 

Yes if we are to approach the migration with the Big Bang theory it will be ridiculously expensive.  Instead what the powers that be should agree is that all cards and terminals will be EMV by say 2019, ten years.

Let’s acknowledge that most of the major acquirers and processors have already implemented EMV on their international platforms; so the implications are understood and if they where intelligent when upgrading for Canada, England, Europe, Latin America, Middle East and Asia, they should have considerted how to cost effective assure the inclusion of EMV on their American platforms, someday. 

So now they simply have to add it to the list of requirements that will be included in one of the yearly upgrades, or, as part of their technology replacement plans.  Remember we are saying EMV in 10 years. 

Ten years is a long time when we think about technology.  Therefore they have no justification to argue it is punitive to force them to implement EMV.

On the terminal side we must remember that for the merchant there are only intangible benefits to implementing EMV.  Yes, like MasterCard Visa etc, EMV can be positioned as the cost of doing business and included in one of the compliance upgrades. 

Or, if we are intelligent, we say to the ATM operators, merchants, ISOs and acquirers, the next time you upgrade your point of sale system – buy an EMV compliant PIN pad and include EMV as one of the requirement for the systems that drives the device and transmits the approval requests and clearing records to the acquirer. 

Any ATM/POS supplier who sells outside the USA has EMV devices in their catalogue.  All the Value Added Resellers who sell international have support for EMV within their software.  NCR, Wincor-Nixdorf, IBM, EFunds, ACI, S1 … all support EMV.

With this plan in place, over time EMV will progressively be enabled at the point of sale. with minimal cost impact.   Yes the vendors will have to be told to play nice and not exploit the opportunity.  Yes for merchants that attact significant International clientele they should migrate sooner.  Yes, locations that are known to be high risk merchants they should be made to implement EMV sooner. 

This leaves the Issuer with an easy question to answer, when do I add an EMV chip to my card.  Well the answer is easy and it is complex.  On the simple side, when they think there are enough terminals to achieve the fraud saving then do it.  Or, we can add the contactless and mobile payment dimension and start talking about Combi cards, embedding EMV into the handset, considering Multi-application opportunities.  I’ll talk about that another day.

Agree to move and give people enough time so that there is no pain

 

Bottom line my message to the US market is the question is no longer about who will pay it is simply about how much time should we allow everyone, so that the incremental cost is irrelevant.

 This Blog was driven by reading a recent review from CTST

U.S. getting squeezed by EMV  Wednesday, May 6, 2009 in News

http://www.contactlessnews.com/2009/05/06/u-s-getting-squeezed-my-emv

With Canada and Mexico both going to EMV and most of the rest of the world doing the same it may be a matter of time before U.S. card issuers are forced to go to chip and PIN. EMV in the U.S. was the topic of a panel at the CTST Conference in New Orleans.

Crooks Have Your Card and You Don’t Even Know It

How Thieves Copy Credit and Debit Cards and Drain Accounts

By ELISABETH LEAMY – ABC News

May 2, 2008—

 While your ATM card is tucked in your wallet, thieves half a world away could be cloning it and using it. The crime is called “white card fraud,” and ABC News investigated just how easy it is for thieves to make a copy of your card and use it to drain your account.

It’s difficult to get an exact figure, but it’s estimated that identity thieves net an estimated $345 million this way every year. Gary Burkey of Wilmington, Del., discovered somebody was withdrawing money from his account at ATM machines in a part of Pennsylvania he had never even visited.

Criminals get people’s numbers in a variety of ways. One way they capture card numbers is by installing skimmer devices over the slot where you insert your card when you use an ATM.

They also use hidden cameras to record your PIN. Miami Beach police have actual footage from a crook’s camera in Florida that shows a victim inputting his PIN. Clear as day: 1-4-2-6.

Click here for tips to protect you from today’s modern identity thieves.

“What makes this really sneaky, really devious, is once the criminals get the account information, they wait on it for a little while, said Cpl. Jeff Whitmarsh of the Delaware State Police. They replicate the cards and when the consumer least expects, that’s when they go in and hit the account.”

ABC News found the machines used to copy cards for sale right on the Internet, even though there are very few legitimate uses for them. We had our choice of 30 machines and bought one for about $500. We were even able to request priority shipping and received the package the next day.

ABC took the device to Chris O’Ferrell, an ethical hacker for a computer company called Command Information, which helps the federal government secure its systems.

We handed over an ABC News credit card and O’Ferrell swiped it so the machine could capture the information on the magnetic strip. Right away, the data popped up on the computer screen: name and account information.

With another swipe, O’Ferrell transferred it to a blank white card that came with our kit. Any card with a magnetic strip can be made into a clone — gift cards, hotel key cards, etc.

In less than five seconds, we had a duplicate credit card.

“That’s it. That’s all there is to it,.” O’Ferrell said.

We cloned an ATM card too. At one point we even accidentally deleted the data on one of our source cards, but since we had a clone, we were able to put the data back on.

Once we had clones of our cards, the question was, would they work? We tried the Visa card out at a gas pump. Without actually making a purchase (we didn’t want to violate any laws) we inserted the card to see if it would get authorized.

When the “lift the handle and begin fueling” message came up, we knew our clone was working. We tested the cloned ATM card by checking our balance at an ATM machine. When the screen read “Hello Elisabeth Leamy,” that was our first clue that that one was working.

It’s a bonanza for crooks. They used to have to risk going into stores to buy pricey merchandise, which they then sold for cash. Now they can just drain ATMs. Authorities say specialized crews do nothing but hit ATMs, cashing out on behalf of other identity thieves and taking a commission. One Bulgarian gang pulled $200,000 out of a single cash machine in Florida.

More than 65 other countries in Europe, Asia and South America now use smart chip technology that makes card cloning almost impossible. But the United States has stayed with magnetic strips to avoid the cost of converting ATMs. By one estimate, we have 400,000 cash machines in this country.

“It’s totally unacceptable,” O’Ferrell said. “It makes it extremely easy for the criminals to clone our cards and steal our identities.” Experts say since U.S. credit and debit cards are so much easier to tap, U.S. cardholders have become targets.

Copyright © 2008 ABC News Internet Ventures