We Keep Talking About It, When Will We Solve For Identity in the Digital Space

This morning I read an article in the Financial Times The real story behind push payments fraud.  What is disturbing, the acceptance of fraud and the focus of bankers on adding fees (like Interchange) to help cover the cost of fraud.  This article speaks to Push Payments and how liability shifts from the merchant back to the Issuer and ultimately the consumer.  It makes reference to Pull Payments and the use of debit cards where the fraud liability, unless online, is the merchants’.

To address card payment fraud in the physical world the payment schemes developed EMV.  In the digital or eCommerce realm everyone accepted allowing the merchants to not attempt to authenticate the cardholder and simply ask the consumer to provide openly available data {cardholder name, PAN the account number, expiry date, and address details}; if they, the merchant, would accept liability for any fraud.

As the world moves to embrace “Faster Payments” and Real-Time Gross Settlement ‘RTGS’, instead of focusing on assuring the identity of the sender and the recipient; we assume fraud will occur.

Why not focus on solving the problem?  Solving for Digital Identity solves for Card Not Present fraud, RTGS fraud, Faster Payment fraud, and so much more.

 

 

Account TakeOver should be the Bankers concern

FASTER PAYMENTS, FASTER FRAUDSTERS

Another article published by PYMNTS.COM causes me to reflect on a discussion I had last we at the Payment Summit organized by the Secure Technology Alliance.  When the US Faster Payments work groups where stood up on e of the working groups focuses on security, yet no particular drive exists to protect the consumer of the corporate treasure from their account being hacked into by some phishing, vishing or other criminal act.  Account takeover will become a much more interesting attack vector.  Moneys will irrevocably flow out of the hacked account and to whatever account the criminal so directs them.

Key word real time gross settlement and faster payments depend on the irrefutability of the funds.  once executed they instantaneously transfer to the receiving party.  What is required is a concerted effort to implement strong multi-factor authentication, at least at the time the transaction is authorized by the sending party.  Some will say the risk is no greater than what exists today when a consumer or treasurer executes a Wire Transfer or any form of transfer between two financial institutions.  This maybe true.  the availability and assumed convenience will as the article described lead to heightened risk.

As I have written in other blogs we need to embrace strong Multi-Factor Authentication.  The standards exist, the security of the device in many case is present.  Relaying parties need to decide security is worth the investment.  They need to recognize the value of  satisfying the consumers’ need to have access to their funds properly protected.

Multi-Factor Authentication – Faster Payments and the Immutability of a Transaction

Multi-Factor Authentication – Faster Payments and the Immutability of a Transaction

Karen Webster
CEO, Market Platform Dynamics
President, PYMNTS.com

Karen,

Last week in your publication I read the article Deep Dive: Security In The Time Of Faster Payments and I had to offer the following thoughts:

The concept of Multi-Factor Authentication is based on the idea of layering multiple authentication techniques on top of each other.

We typically speak of three factors “What You Have”, “What You Know” and “What You Are”.

When we think of “What You Have” we think of a “Thing”.  An object that cannot be replicated or cannot be counterfeited.

An object “a secure computer” that can be upgraded and made more secure as threats like Quantum emerge.
A unique object with a False Reject Rate FRR and a False Accept Rate FAR approaching zero.

In the physical world “the thing” is a card or passport.  You will remember our first discussion, we came to agree the “secure computer” embedded inside provides a future proof mechanism.  In the digital world, we depend on Cryptography.  This Thing, inside our computers, mobile phones and other technologies; many refer to as a ROE “Restricted Operating Environment”.  Technology people may call it a Secure Element, a SIM, an eSIM, a TPM, a TEE, an eUICC or even Security in Chip.  Companies like ARM specialize in creating the design of these things and silicon manufacturers embrace and license their designs.

Today these connected devices (be they: personal computers, identity & payment cards, FOBs, mobiles phones, bracelets, watches and hopefully every IoT device) need to be secured.  This array of cheap ~$1 security circuitry provides a place to create and/or store private keys & secrets keys, perform cryptographic functions and assure the integrity of the BIOS and software being loaded or currently running in these computers.

Think Bitcoin for a second.  The key to its architecture is the Private Key associated with your store of coins.  Lose it and they are lost.  Many people store these in hardware, based on the use of a ROE.

The second factor is all about proving that you are present.  Behavior, location, PIN, fingerprint or passwords are second or even third factors, be they something you know or something you are.

This is what FIDO and what WebAuthN is all about.  Especially since they introducing the security certification regime. This is what the Apple Secure Enclave is and Samsung and others embed into their devices.  This is what we put into payment cards, government identity cards and the Yubico keys we see various enterprises embracing.  This is what Bill Gates started talking about in 2002.  BILL GATES: TRUSTWORTHY COMPUTING

As we move to Faster Payments we must move to Secure payments.  Immutability and irrefutably become key requirements.  To achieve this goal I suggest we need to understand one fundamental security principle.

The First Factor
is Something(s) You Have
My Thing(s)

The Second and Third factors
Prove You Are Present

Storing Biometrics in the Cloud
Creates a Honey Pot
And, begs questions of Privacy

Let me identify myself to My Thing.

Then let My Thing
Authentication my presence to
The Relying Party (Bank or Credit Union)

Critical mass versus ubiquity the future of payments

In a paper recently published by the Federal Reserve they begin to consider what actions the FRB should take to drive the further adoption of P2P electronic payments and the reduction in paper checks.

http://www.bos.frb.org/economic/ppdp/2010/ppdp1001.pdf

Their introduction speaks to the differences in adoption of electronic payments in the USA and Europe.  Intriguingly they include privacy concerns as a key issue.  This being said, having lived in Europe for 15 years, I am not sure the desire for privacy is greater in America.  What can be said is that the moment when the underlining infrastructure was developed defines the ideas and feature sets.  Newer systems learned grew as other economies embraced and proved the viability of innovative ideas.

They go on to discuss the fate of eCash (Mondex, VisaCash) and the need to create ubiquity in order to assure success.    Clearly, as they outline, the major adoption issue in the field of payments is achieving a density of merchants willing to accept a particular means of payment  and simultaneously demonstrating a significant number of consumers willing to employ said means of payment.

Unfortunately for the inventors of neat solutions the reality is that without figuring out how to assure ubiquity the new idea they will not be a success.  If we look at contactless, MasterCard clearly recognised this reality and funded the initial investment in equipment.  Without this investment one wonders if PayPass would have reached the low levels it has.

The interesting thought that emerges from this paper is that the wide spread deployment of mobile phones means that an infrastructure that both merchants and consumers have is in place and if one can find an intuitive means of exploiting this installed base, part of the deployment problem is mitigated.

In my heart, I believe mobile will allow the establishment of new ways of paying,  The next question can today’s infrastructure support P2P payment instructions and will the issuers and acquirers figure out how to make money without cannibalizing existing revenue streams.