Skip to main content

Safaricom probed over costly M-Pesa outage - Daily Nation

xxx

Safaricom is being investigated for the Saturday outage of its M-Pesa service that left millions of customers unable to receive or send money.

The blackout is estimated to have cost the economy billions of shillings.

From Safaricom probed over costly M-Pesa outage - Daily Nation.

xxx

xxx

CA statistics show that about Sh1.5 trillion moved through the M-Pesa platform in the three months to June, translating to an average Sh16.3 billion per day or about Sh679.3 million every hour.

M-Pesa agents were among the biggest losers in the blackout that stalled their business for hours. Multiple banks have hooked up their systems to M-Pesa.

From Safaricom probed over costly M-Pesa outage - Daily Nation.

 

xxx

Do the math. Suppose there are 100,000 agents with 100 “super agents” (network aggregators) managing 1,000 agents each. Suppose there are 100m customers (there are currently around 20m). Suppose a customer’s M-PESA balance and associated flags/status are 100 bytes.

So that’s 10^2 * 10^2 * 10^6, which is 10^10 bytes, or 10^7 kilobytes or 10^4 megabytes or 10 gigabytes. My phone can store 256Gb. In other other words, you could imagine a distributed M-PESA where every customers phone could store every customers’ balance. You don’t need an M-PESA system in the middle. When you make a transaction with your handset, it gets routed to a superagent who decrements your balance, increments your payee’s balance, and then transmits the new balances (all digitally-signed of course) to the other superagents.

It would be a bit like making an ATM network where every ATM knows the balance of every debit card. Nothing to go down. And if an ATM goes down, so what? When it comes back up 

Comments

Popular posts from this blog

We could fix mobile security, you know. We don't, but we could

Earlier in the week I blogged about mobile banking security , and I said that in design terms it is best to assume that the internet is in the hands of your enemies. In case you think I was exaggerating… The thieves also provided “free” wireless connections in public places to secretly mine users’ personal information. From Gone in minutes: Chinese cybertheft gangs mine smartphones for bank card data | South China Morning Post Personally, I always use an SSL VPN when connected by wifi (even at home!) but I doubt that most people would ever go to this trouble or take the time to configure a VPN and such like. Anyway, the point is that the internet isn’t secure. And actually SMS isn’t much better, which is why it shouldn’t really be used for securing anything as important as home banking. The report also described how gangs stole mobile security codes – which banks automatically send to card holders’ registered mobile phones to verify online transactions – by using either a Trojan...