Skip to main content

End user needs

xxx

In our Strategy, we prioritised the collaborative development of requirements and rules for 3 EUN solutions. These are:

  1. ‘Request to Pay’ which addresses detriments arising from a lack of sufficient control, flexibility and transparency in the current payment mechanisms to meet the evolving needs of some end-users. Apart from anything else, this is why there's no need for "pull" payments in NPA.
  2. ‘Assurance Data’ which addresses the lack of adequate assurance to the payer that they have sufficient funds to make a payment; that they are making the payment to the intended payee’s account and status of the payment once they make the payment. Right now, the assurance services envisaged are confirmation of available funds, payment tracking and the slightly more complex confirmation of payee.
  3. ‘Enhanced Data’ which addresses the limited capacity, in current payment systems, to carry more structured data alongside the payment.

The reason why I call the payee confirmation service more complex is… well… it’s more complex. As I said in connection with this last year:

There’s a long way to go with this though, because there are privacy and other issues. Is it any of my business what the name on your account is?

From Are the banks telling you that you may as well use bitcoin? | Consult Hyperion

The CoP will be a real-time 24/7 services and the response provided to the payer will be as clear and unequivocal as possible to allow the payer to make a decision that he or she is making the payment to the intended payee. All to the well and good. But you can see the problems lurking in the shadows of this apparently reasonable requirement. An obvious issue is that data protection regulations must be considered to ensure that payer data is handled lawfully especially in the case where the account information is played back. If you send a payment to your dentist, for example, should be provided with your dentist's real name, address and other personally-identifiable information (PII). I would have thought not. Then there's also the issue of accuracy and liability for incorrect information. And consider also that is some cases the system must not return the "correct" information (as part of law enforcement operationa, for example).

This isn’t just about bank accounts and instant payments, of course. If it was, I wouldn’t be blogging about it. I hate to say it, but the problem and the solution are all about identity.

From Super-complaints but no super-solutions | Consult Hyperion

One safeguard that the PSF puts forward is that the payee confirmation service can only be utilised for the purposes of making a payment and it assumes that PSPs will ensure relevant safeguards are put in place to ensure prudent use (e.g., to guard against phishing, profiling etc.). OK, so I may sound like a broken record on this, but without a working digital identity infrastructure in place, we will end up with something incomplete and expensive getting hacked up to support NPA implementation alone.

 

I wrote last year that

I imagine that an outcome of Payment UK’s deliberations on payee confirmation may well be the creation of a database of “paynames” (i.e., £dgwbirch) to make casual instant payments even easier.

From There you go bringing class into it again | Consult Hyperion

xxx

Comments

Popular posts from this blog

new survey results from USA Technologies (USAT) suggest. The payments technology company, which enables electronic payments for self-service machines, compared consumer spending activity at 35 of its vending machines in urban areas with a high concentration of iPhone users between week one and week four of the installation of new digital signage promoting Apple Pay. Consumers made more contactless purchases: The vending machine providers saw an average contactless transaction revenue increase of 89%, implying that consumers are making more mobile payments. This was likely driven by the clear advertisement of Apple Pay. Total transactions increased: Consumers made more purchases overall. This was probably driven by an uptick in mobile payments, given the major increase in contactless transaction revenue. And the vending machines may have attracted many first-time users who were drawn in by the digital advertising of Apple Pay. Boosting awareness is key to unlocking pent-up demand amon...

David | LinkedIn

Alex Todd rather kindly called this a “most lucid explanation of digital identity management” I would highly recommend this presentation to anyone interested in understanding prospective blockchain based identity architectures From David | LinkedIn This is very kind, but as I said in the link, this is thinking out loud and far from a fully-developed solution. We’re working on parts of this for different clients and I can see that there is something there - a genuinely new way of solving some old problems - but it’s early days.

We could fix mobile security, you know. We don't, but we could

Earlier in the week I blogged about mobile banking security , and I said that in design terms it is best to assume that the internet is in the hands of your enemies. In case you think I was exaggerating… The thieves also provided “free” wireless connections in public places to secretly mine users’ personal information. From Gone in minutes: Chinese cybertheft gangs mine smartphones for bank card data | South China Morning Post Personally, I always use an SSL VPN when connected by wifi (even at home!) but I doubt that most people would ever go to this trouble or take the time to configure a VPN and such like. Anyway, the point is that the internet isn’t secure. And actually SMS isn’t much better, which is why it shouldn’t really be used for securing anything as important as home banking. The report also described how gangs stole mobile security codes – which banks automatically send to card holders’ registered mobile phones to verify online transactions – by using either a Trojan...